{
  "type": "URL",
  "indicator": "https://bobross-pluto.cinedigm.com",
  "general": {
    "sections": [
      "general",
      "url_list",
      "http_scans",
      "screenshot"
    ],
    "indicator": "https://bobross-pluto.cinedigm.com",
    "type": "url",
    "type_title": "URL",
    "validation": [],
    "base_indicator": {
      "id": 3772634120,
      "indicator": "https://bobross-pluto.cinedigm.com",
      "type": "URL",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 17,
      "pulses": [
        {
          "id": "6533120ed78adc8baa57b9d0",
          "name": "quick look at 79.12.165.51",
          "description": "",
          "modified": "2025-10-25T02:11:11.653000",
          "created": "2023-10-20T23:49:34.890000",
          "tags": [],
          "references": [
            "https://www.virustotal.com/graph/g03fce3ad62f74ad59bbcda71bfdde96da39417641c9a470f99adfa9b14a7724c"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 20,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "skocherhan",
            "id": "249290",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_249290/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 9,
            "FileHash-SHA1": 9,
            "FileHash-SHA256": 1650,
            "URL": 1744,
            "domain": 339,
            "email": 1,
            "hostname": 834,
            "CVE": 1
          },
          "indicator_count": 4587,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 179,
          "modified_text": "177 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6564fa9a3d90d1cd14928b16",
          "name": "Lumma \u2022 University of Alberta \"No Problems\" | T1036 - Masquerading",
          "description": "I was contacted on this forum re: University of Alberta issue. Based on research  www.ualberta.ca redirects. There hasn't been a research effort for redirect. I researched a spoofed website. After viewing senders request, my devices operating system changed, isn't recognized by any accounts, keyloggers.\nFound: Anonymizers, Redirector, Masquerading, Network RAT, Serious Social Engineering, Botnetwork Army, Stealers, Lumma and weirdly targeted  'Tsara Brashears' as a malicious link on a spoofed University in Canada, UCHealth Colorado links.",
          "modified": "2023-12-27T19:03:02.665000",
          "created": "2023-11-27T20:22:50.050000",
          "tags": [
            "threat report",
            "back",
            "ip summary",
            "url summary",
            "summary",
            "download csv",
            "download",
            "json url",
            "urls",
            "detection list",
            "cisco umbrella",
            "site",
            "heur",
            "safe site",
            "alexa top",
            "million",
            "malware",
            "malicious site",
            "phishing site",
            "malicious url",
            "phishing",
            "riskware",
            "presenoker",
            "artemis",
            "agent",
            "unsafe",
            "opencandy",
            "ursnif",
            "wacatac",
            "team",
            "facebook",
            "runescape",
            "service",
            "downldr",
            "psexec",
            "occamy",
            "brontok",
            "zpevdo",
            "startpage",
            "nanocore",
            "keygen",
            "installcore",
            "fareit",
            "secrisk",
            "exploit",
            "mimikatz",
            "sorano",
            "emotet",
            "genkryptik",
            "fuery",
            "dbatloader",
            "qakbot",
            "alexa",
            "malicious",
            "union",
            "lumma stealer",
            "fusioncore",
            "cleaner",
            "azorult",
            "bank",
            "blacknet rat",
            "stealer",
            "iframe",
            "trojanspy",
            "analysis",
            "united",
            "firehol",
            "proxy",
            "mail spammer",
            "downloader",
            "malware site",
            "meterpreter",
            "qbot",
            "bankerx",
            "dropper",
            "nimda",
            "formbook",
            "swrort",
            "unruy",
            "adwind",
            "trojanx",
            "crack",
            "win64",
            "generic",
            "dnspionage",
            "expirestue",
            "path",
            "http response",
            "final url",
            "ip address",
            "status code",
            "body length",
            "kb body",
            "sha256",
            "headers",
            "alberta",
            "university",
            "edmonton",
            "html info",
            "alberta meta",
            "tags",
            "trackers google",
            "tag manager",
            "gtmkr32",
            "blacklist",
            "low risk",
            "apache",
            "domain",
            "malware found",
            "unknown",
            "minimal low",
            "security risk",
            "medium high",
            "critical",
            "protect",
            "college",
            "mtis",
            "faculties",
            "research",
            "health",
            "a about",
            "news",
            "events",
            "sport",
            "life",
            "find",
            "story",
            "tools",
            "getprocaddress",
            "indicator",
            "prefetch8",
            "mitre att",
            "ck id",
            "show technique",
            "ck matrix",
            "pattern match",
            "file",
            "date",
            "factory",
            "hybrid",
            "general",
            "cookie",
            "click",
            "strings",
            "djin",
            "no data",
            "tag count",
            "sample",
            "samples",
            "netsky",
            "cobalt strike",
            "xrat",
            "fakealert",
            "raccoon",
            "redline stealer",
            "metastealer",
            "icedid",
            "quasar rat",
            "acint",
            "anonymizer",
            "blockchain",
            "social engineering",
            "read c",
            "search",
            "show",
            "medium",
            "entries",
            "whitelisted",
            "memcommit",
            "delete",
            "yara detections",
            "next",
            "dock",
            "write",
            "execution",
            "copy",
            "south carolina",
            "federal credit",
            "team proxy",
            "static engine",
            "covid19",
            "redirector",
            "suspic",
            "tue mar",
            "zbot",
            "size68b type",
            "count blacklist",
            "tag tag",
            "rejected sample",
            "icon",
            "analyzed",
            "hwp support",
            "falcon sandbox",
            "multi scan",
            "update",
            "view details",
            "upgrade",
            "blacklist https",
            "keyloggers"
          ],
          "references": [
            "https://www.anyxxxtube.net/search-porn/tsara-brashears/ phishing",
            "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian  (iPhone unlocker)",
            "uchealth.com",
            "http://michaela.young@uchealth.com",
            "http://intranet.uchealth.com/Policies/Corporate%20Policies/Standards%20of%20Performance%20and%20Conduct.pdf",
            "https://api2018.uchealth.com/apihc/tass/webportal/apihealthcare_live/default.aspx",
            "https://www.uchealth.com/wp-content/uploads/2017/12/UCHealthInsuranceIndex_120417.pdf"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "TrojanSpy",
              "display_name": "TrojanSpy",
              "target": null
            },
            {
              "id": "Qakbot",
              "display_name": "Qakbot",
              "target": null
            },
            {
              "id": "MimiKatz",
              "display_name": "MimiKatz",
              "target": null
            },
            {
              "id": "RedLine Stealer",
              "display_name": "RedLine Stealer",
              "target": null
            },
            {
              "id": "Network RAT",
              "display_name": "Network RAT",
              "target": null
            },
            {
              "id": "Quasar RAT",
              "display_name": "Quasar RAT",
              "target": null
            },
            {
              "id": "Emotet",
              "display_name": "Emotet",
              "target": null
            },
            {
              "id": "Lumma Stealer",
              "display_name": "Lumma Stealer",
              "target": null
            },
            {
              "id": "Raccoon",
              "display_name": "Raccoon",
              "target": null
            },
            {
              "id": "OpenCandy",
              "display_name": "OpenCandy",
              "target": null
            },
            {
              "id": "Meterpreter",
              "display_name": "Meterpreter",
              "target": null
            },
            {
              "id": "Unruy",
              "display_name": "Unruy",
              "target": null
            },
            {
              "id": "TrojanX",
              "display_name": "TrojanX",
              "target": null
            },
            {
              "id": "BlackNET RAT",
              "display_name": "BlackNET RAT",
              "target": null
            },
            {
              "id": "Brontok",
              "display_name": "Brontok",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1114",
              "name": "Email Collection",
              "display_name": "T1114 - Email Collection"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1518",
              "name": "Software Discovery",
              "display_name": "T1518 - Software Discovery"
            },
            {
              "id": "T1546",
              "name": "Event Triggered Execution",
              "display_name": "T1546 - Event Triggered Execution"
            },
            {
              "id": "T1588",
              "name": "Obtain Capabilities",
              "display_name": "T1588 - Obtain Capabilities"
            },
            {
              "id": "T1588.004",
              "name": "Digital Certificates",
              "display_name": "T1588.004 - Digital Certificates"
            },
            {
              "id": "T1546.015",
              "name": "Component Object Model Hijacking",
              "display_name": "T1546.015 - Component Object Model Hijacking"
            },
            {
              "id": "T1126",
              "name": "Network Share Connection Removal",
              "display_name": "T1126 - Network Share Connection Removal"
            },
            {
              "id": "T1136",
              "name": "Create Account",
              "display_name": "T1136 - Create Account"
            },
            {
              "id": "T1071.004",
              "name": "DNS",
              "display_name": "T1071.004 - DNS"
            },
            {
              "id": "T1059.007",
              "name": "JavaScript",
              "display_name": "T1059.007 - JavaScript"
            },
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1071.003",
              "name": "Mail Protocols",
              "display_name": "T1071.003 - Mail Protocols"
            },
            {
              "id": "T1518.001",
              "name": "Security Software Discovery",
              "display_name": "T1518.001 - Security Software Discovery"
            },
            {
              "id": "T1053",
              "name": "Scheduled Task/Job",
              "display_name": "T1053 - Scheduled Task/Job"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1119",
              "name": "Automated Collection",
              "display_name": "T1119 - Automated Collection"
            },
            {
              "id": "T1143",
              "name": "Hidden Window",
              "display_name": "T1143 - Hidden Window"
            },
            {
              "id": "T1056.001",
              "name": "Keylogging",
              "display_name": "T1056.001 - Keylogging"
            },
            {
              "id": "T1134.004",
              "name": "Parent PID Spoofing",
              "display_name": "T1134.004 - Parent PID Spoofing"
            }
          ],
          "industries": [
            "Education",
            "Healthcare"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 83,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 320,
            "FileHash-SHA1": 172,
            "FileHash-SHA256": 4302,
            "URL": 8243,
            "CIDR": 1,
            "domain": 1742,
            "hostname": 2270,
            "CVE": 18,
            "SSLCertFingerprint": 3,
            "email": 4
          },
          "indicator_count": 17075,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 222,
          "modified_text": "844 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "655dafbe9ac9ac786fde45ad",
          "name": "http://malwaredomainlist.com/ \u2022 CNC \u2022 Spyware \u2022 Tracking",
          "description": "Network capture, dga domain, ecc domain, data collection, voicemail access, mail spammer, registrar abuse\n\n[Auto populated. I can't cannot confirm or deny the accuracy of the following information: A summary of key facts and information about a malicious web domain, hosted by the US government, has been released by Google.com and its parent company, Alphabet, for use on its website.]",
          "modified": "2023-12-22T06:03:01.993000",
          "created": "2023-11-22T07:37:34.595000",
          "tags": [
            "united",
            "as22612",
            "as2637",
            "creation date",
            "search",
            "moved",
            "expiration date",
            "date",
            "showing",
            "as397240",
            "next",
            "entries",
            "scan endpoints",
            "all octoseek",
            "dns replication",
            "win32 exe",
            "network capture",
            "android",
            "android adaway",
            "html",
            "files",
            "detections type",
            "name",
            "office open",
            "xml document",
            "namecheap",
            "namecheap inc",
            "whois lookups",
            "win32 dll",
            "text",
            "wextract",
            "text htaccess",
            "powershell",
            "detection list",
            "blacklist",
            "first",
            "ssl certificate",
            "whois record",
            "contacted",
            "december",
            "whois whois",
            "threat roundup",
            "historical ssl",
            "problems",
            "referrer",
            "pe resource",
            "startpage",
            "cyber threat",
            "redline stealer",
            "mail spammer",
            "hostname",
            "phishing site",
            "malicious site",
            "installcore",
            "http spammer",
            "malware site",
            "malware",
            "generic malware",
            "heur",
            "generic",
            "alexa top",
            "million",
            "site",
            "cisco umbrella",
            "alexa",
            "ip address",
            "algorithm",
            "data",
            "v3 serial",
            "number",
            "cat cnzerossl",
            "ecc domain",
            "secure site",
            "ca ozerossl",
            "validity",
            "subject public",
            "server",
            "email",
            "code",
            "registrar abuse",
            "country",
            "privacy service",
            "withheld",
            "privacy",
            "domain name",
            "pattern match",
            "ascii text",
            "appdata",
            "file",
            "windows nt",
            "svg scalable",
            "vector graphics",
            "indicator",
            "gif image",
            "accept",
            "hybrid",
            "general",
            "local",
            "pixel",
            "click",
            "twitter",
            "strings",
            "class",
            "generator",
            "critical",
            "command_and_control",
            "spyware",
            "tracking",
            "voicemail access",
            "dga",
            "apple"
          ],
          "references": [
            "https://www.hybrid-analysis.com/sample/c0c84df54b890bb408fc2289f1e75a29991127bbe207aa30042616b5ea150342/655d9af5679c7afcc409895e",
            "\u2193Interesting\u2193",
            "IPv4 198.54.117.211 command_and_control",
            "IPv4 198.54.117.210 command_and_control",
            "IPv4 198.54.117.212 command_and_control",
            "IPv4 198.54.117.215 command_and_control",
            "IPv4 198.54.117.217 command_and_control",
            "IPv4 198.54.117.218 command_and_control",
            "apple-securityiphone-icloud.com",
            "tx-p2p-pull.video-voip.com.dorm.com",
            "http://updates.voicemailaccess.net/b0f6a00b15311023",
            "tvapp-server.de",
            "zeustracker.abuse.ch",
            "ransomwaretracker.abuse.ch",
            "http://t.trkitok.com/track/rep?oid=2001&st=1&id=DP2441--w1VJE427J8SGGRTP02MD7UEG___93737493-c08b-4dc7-ad30-b17a2c09e771___$mid",
            "louisianarooflawyers.com         [phishing]",
            "hasownproperty.call"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "Generic",
              "display_name": "Generic",
              "target": null
            },
            {
              "id": "BlackNET",
              "display_name": "BlackNET",
              "target": null
            },
            {
              "id": "InstallCore",
              "display_name": "InstallCore",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1114",
              "name": "Email Collection",
              "display_name": "T1114 - Email Collection"
            },
            {
              "id": "T1560",
              "name": "Archive Collected Data",
              "display_name": "T1560 - Archive Collected Data"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 51,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 105,
            "FileHash-SHA1": 100,
            "FileHash-SHA256": 3072,
            "domain": 1188,
            "email": 5,
            "URL": 7940,
            "hostname": 1925,
            "CVE": 1
          },
          "indicator_count": 14336,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 228,
          "modified_text": "850 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "655ae7b85bce5b026a160389",
          "name": "Command and Control Server and Services CRITICAL",
          "description": "HSBC\nInmortal\nRadar Ineractive\nRuleset Match:\nBackSwap Trojan detection by Ariel Millahuel\nCARROTBAT Malware detection by Ariel Millahuel",
          "modified": "2023-12-20T03:01:11.128000",
          "created": "2023-11-20T04:59:36.506000",
          "tags": [
            "contacted",
            "execution",
            "dropped",
            "threat roundup",
            "august",
            "apple ios",
            "contacted urls",
            "referrer",
            "october",
            "april",
            "core",
            "february",
            "hacktool",
            "installer",
            "urls",
            "ovh sas",
            "domains",
            "ip detections",
            "country",
            "type name",
            "win32 exe",
            "noname057",
            "generic malware",
            "tag count",
            "threat report",
            "ip summary",
            "url summary",
            "summary",
            "sample",
            "samples",
            "detection list",
            "blacklist http",
            "cisco umbrella",
            "site",
            "safe site",
            "wormx",
            "malicious site",
            "alexa top",
            "malware site",
            "million",
            "malicious url",
            "phishing site",
            "malware",
            "alexa",
            "phishing",
            "agent",
            "bank",
            "inmortal",
            "united",
            "cyber threat",
            "pony",
            "cnc zeus",
            "tracker",
            "cnc server",
            "covid19",
            "engineering",
            "http spammer",
            "host",
            "azorult",
            "asyncrat",
            "cobalt strike",
            "team",
            "hsbc",
            "file size",
            "files",
            "file type",
            "kb file",
            "highly targeted",
            "apple",
            "password",
            "tsara brashears",
            "awful",
            "radar ineractive",
            "no data",
            "blacklist",
            "malvertizing",
            "masquerading",
            "tulach",
            "114.114.114.114",
            "Noname057"
          ],
          "references": [],
          "public": 1,
          "adversary": "Unconfirmed Adversary",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "Inmortal",
              "display_name": "Inmortal",
              "target": null
            },
            {
              "id": "HSBC",
              "display_name": "HSBC",
              "target": null
            },
            {
              "id": "Radar Ineractive",
              "display_name": "Radar Ineractive",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1176",
              "name": "Browser Extensions",
              "display_name": "T1176 - Browser Extensions"
            },
            {
              "id": "T1094",
              "name": "Custom Command and Control Protocol",
              "display_name": "T1094 - Custom Command and Control Protocol"
            },
            {
              "id": "TA0004",
              "name": "Privilege Escalation",
              "display_name": "TA0004 - Privilege Escalation"
            },
            {
              "id": "TA0002",
              "name": "Execution",
              "display_name": "TA0002 - Execution"
            },
            {
              "id": "TA0001",
              "name": "Initial Access",
              "display_name": "TA0001 - Initial Access"
            },
            {
              "id": "TA0009",
              "name": "Collection",
              "display_name": "TA0009 - Collection"
            },
            {
              "id": "TA0011",
              "name": "Command and Control",
              "display_name": "TA0011 - Command and Control"
            },
            {
              "id": "T1449",
              "name": "Exploit SS7 to Redirect Phone Calls/SMS",
              "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
            },
            {
              "id": "T1059.002",
              "name": "AppleScript",
              "display_name": "T1059.002 - AppleScript"
            },
            {
              "id": "T1102",
              "name": "Web Service",
              "display_name": "T1102 - Web Service"
            },
            {
              "id": "T1011",
              "name": "Exfiltration Over Other Network Medium",
              "display_name": "T1011 - Exfiltration Over Other Network Medium"
            },
            {
              "id": "T1100",
              "name": "Web Shell",
              "display_name": "T1100 - Web Shell"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1059.007",
              "name": "JavaScript",
              "display_name": "T1059.007 - JavaScript"
            },
            {
              "id": "T1041",
              "name": "Exfiltration Over C2 Channel",
              "display_name": "T1041 - Exfiltration Over C2 Channel"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1548",
              "name": "Abuse Elevation Control Mechanism",
              "display_name": "T1548 - Abuse Elevation Control Mechanism"
            },
            {
              "id": "T1098",
              "name": "Account Manipulation",
              "display_name": "T1098 - Account Manipulation"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 28,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 1,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 729,
            "FileHash-MD5": 950,
            "FileHash-SHA1": 482,
            "FileHash-SHA256": 878,
            "domain": 139,
            "hostname": 300,
            "CVE": 1
          },
          "indicator_count": 3479,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 220,
          "modified_text": "852 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "654d29a8dbbe8d0bcc16ed1a",
          "name": "iOS Tracking \u2192 imitation imap: imap.kehlenbach.net | C2 | Cybercrime",
          "description": "",
          "modified": "2023-12-09T08:01:01.882000",
          "created": "2023-11-09T18:49:12.887000",
          "tags": [
            "ssl certificate",
            "tsara brashears",
            "apple ios",
            "whois record",
            "virus network",
            "critical risk",
            "tracker",
            "cyberstalking",
            "drive",
            "apple phone",
            "hacktool",
            "installer",
            "brashears",
            "et"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "BRASHEARS",
              "display_name": "BRASHEARS",
              "target": null
            },
            {
              "id": "ET",
              "display_name": "ET",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1056",
              "name": "Input Capture",
              "display_name": "T1056 - Input Capture"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": "654cabd6bb3319558bf2cd38",
          "export_count": 7,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 99,
            "FileHash-SHA1": 97,
            "FileHash-SHA256": 1170,
            "domain": 593,
            "hostname": 1179,
            "URL": 3246
          },
          "indicator_count": 6384,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 224,
          "modified_text": "863 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "654cabd6bb3319558bf2cd38",
          "name": "iOS Tracking \u2192 imitation imap: imap.kehlenbach.net | C2 | Cybercrime",
          "description": "BotNet campaign, malvertizing, radar tracking, iOS, OS, IP, dns, location tracking, password cracker, faux Pinterest, phishing, malicious domain.\nTargets:\nhttps://pin.it/ (Dangerous IP)\nhttps://www.anyxxxtube.net/search-porn/tsara-brashears/ (phishing)\t\nhttps://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian\n(password cracker)\t\nhttps://www.pornhub.com/video/search?search=tsara+brashears ( Buff Achievement Tracker)\nhttps://www.sweetheartvideo.com/tsara-brashears/   (botnetwork, tracking):\npin.it (TB IP)\nww.google.com.uy. (Brashears IP addresses) \notc.greatcall.com (Botnetwork, tracking call)\n0-129-103-71imap-intranet-pv-175-166.matomo.cloud (location collection, call, message, email)\nhttps://www.assurant.com/?utm_source=email&utm_medium=email&utm_campaign=Mobile_Transactional_withad&utm_content=Deductible+Charge+Acknowledgement+PD-MB&utm_term= (Transactional email collection)\n\napple iOS, imap",
          "modified": "2023-12-09T08:01:01.882000",
          "created": "2023-11-09T09:52:22.834000",
          "tags": [
            "ssl certificate",
            "tsara brashears",
            "apple ios",
            "whois record",
            "virus network",
            "critical risk",
            "tracker",
            "cyberstalking",
            "drive",
            "apple phone",
            "hacktool",
            "installer",
            "brashears",
            "et"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "BRASHEARS",
              "display_name": "BRASHEARS",
              "target": null
            },
            {
              "id": "ET",
              "display_name": "ET",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1056",
              "name": "Input Capture",
              "display_name": "T1056 - Input Capture"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 9,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 99,
            "FileHash-SHA1": 97,
            "FileHash-SHA256": 1170,
            "domain": 593,
            "hostname": 1179,
            "URL": 3246
          },
          "indicator_count": 6384,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 218,
          "modified_text": "863 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6570a989843b7acf6d0a79ac",
          "name": "Qakbot. Again. Today. Pulled from own device. Quasar RAT, Malvertizing",
          "description": "",
          "modified": "2023-12-06T17:04:09.133000",
          "created": "2023-12-06T17:04:09.133000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 15,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "CVE": 2,
            "domain": 290,
            "FileHash-SHA256": 1478,
            "hostname": 1047,
            "URL": 4055,
            "FileHash-MD5": 89,
            "FileHash-SHA1": 85,
            "email": 1,
            "FilePath": 2,
            "Mutex": 1,
            "CIDR": 1
          },
          "indicator_count": 7051,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 110,
          "modified_text": "865 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "653eb87c9e4d74a97585f1d1",
          "name": "https://developer.paypal.com/docs/classic/paypal-payments-standard/integration-guide/encryptedwebpayments/",
          "description": "",
          "modified": "2023-11-28T20:03:34.441000",
          "created": "2023-10-29T19:54:36.146000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 16,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "ellenmmm",
            "id": "233693",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 1747,
            "domain": 552,
            "hostname": 623,
            "FileHash-SHA256": 303,
            "FileHash-MD5": 135,
            "FileHash-SHA1": 49
          },
          "indicator_count": 3409,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 82,
          "modified_text": "873 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "653f1ffb074d89724cb81371",
          "name": "Tracker and Botnet campaign - Canto XXVI",
          "description": "",
          "modified": "2023-11-19T00:04:57.528000",
          "created": "2023-10-30T03:16:11.181000",
          "tags": [
            "contacted",
            "tsara brashears",
            "whois record",
            "whois whois",
            "threat roundup",
            "december",
            "execution",
            "referrer",
            "pe resource",
            "remcos",
            "malware",
            "quasar",
            "nanocore",
            "attack",
            "core",
            "qakbot",
            "azorult",
            "njrat",
            "colibri loader",
            "metro",
            "nokoyawa",
            "formbook",
            "bank",
            "installer",
            "daxin",
            "awful",
            "open",
            "korplug",
            "dark power",
            "cobalt strike",
            "hacktool",
            "emotet",
            "chaos",
            "ransomexx",
            "ursnif",
            "ransomware",
            "pattern match",
            "et tor",
            "known tor",
            "misc attack",
            "relayrouter",
            "exit",
            "node traffic",
            "beginstring",
            "script",
            "segoe ui",
            "null",
            "error",
            "unknown",
            "span",
            "date",
            "body",
            "refresh",
            "class",
            "critical",
            "tools",
            "look",
            "verify",
            "restart",
            "hybrid",
            "general",
            "click",
            "strings",
            "meta",
            "xiongmao group",
            "district",
            "nanjing",
            "china country",
            "beijing",
            "please",
            "apnic person",
            "road",
            "china phone",
            "whois lookup",
            "cnnic",
            "dns replication",
            "domain",
            "win32 exe",
            "files",
            "detections type",
            "name",
            "notepad",
            "java",
            "update checker",
            "type name",
            "android",
            "win32 dll",
            "cyber criminals",
            "cyber stalking",
            "cyber warfare",
            "framing",
            "tulach.cc",
            "exploit_source",
            "scanning_host",
            "phishing",
            "adware",
            "command_and_control",
            "C2",
            "technology",
            "virustotal xn",
            "technology xn",
            "rich text",
            "format po",
            "jyoti cnc",
            "detection list",
            "blacklist",
            "noname057",
            "proxy",
            "prism.exe",
            "password cracker",
            "skynet",
            "malvertizing",
            "spyware",
            "colorado",
            "arizona",
            "prism command line tool",
            "keyloggers",
            "apple",
            "I'm being followed",
            "threats",
            "sha256",
            "osint",
            "vmware",
            "gpt",
            "nginx",
            "piracy",
            "intellectual property",
            "spammer",
            "honeypot",
            "tracker",
            "tracking campaign",
            "Botnet campaign"
          ],
          "references": [
            "114.114.1114.114",
            "https://www.anyxxxtube.net/search-porn/tsara-brashears/    phishing",
            "https://wallpapers-nature.com/tsara-brashears/tse1-mm-bing-net \tketogenic switch , BitcoinAussie",
            "wallpapers-nature.com",
            "https://wallpapers-nature.com/%20tsara-brashears/urlscan-io        BitcoinAussie",
            "www.sweetheartvideo.com",
            "https://www.sweetheartvideo.com/tsara-brashears/Tracker and Botnet campaign",
            "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian     password cracker",
            "a-poster.info                 [tagging tool]",
            "https://tulach.cc/    phishing | Proxy | Skynet",
            "67.227.226.240             command_and_control. [lb01.parklogic.com] Lansing Michigan",
            "20.99.186.246               exploit_source",
            "https://www.hybrid-analysis.com/sample/06558031f63aca4f043b4770ae780337408b276df3b1e3e05b3d536839c3ad9e/652c962002e18b99e20e891a",
            "1.62.64.108                  malware_hosting",
            "110.249.196.101.          malware_hosting",
            "CVE-2022-26134",
            "www.anyxxxtube.net               prism.exe",
            "https://www.pornhub.com    prism.exe  [Massachusetts, US]",
            "https://www.milehighmedia.com/en/Charlie-Dean/pornstar/49512   [Colorado, US referenced malvertizing outfit]",
            "https://www.milehighmedia.com/en/pornstar/milehighmedia/Justin-Hunt/51017 [Colorado, US references]",
            "https://twitter.com/PORNO_SEXYBABES - Nokoyawa  catapult spider",
            "https://twitter.com/               catapult spider/spider",
            "nr-data.net                                 Private Apple data collection",
            "tv.apple.com                               Apple hacking",
            "newrelic.se                                  New Update Apple iPhone 199.59.243.222",
            "0.0.0.0                                            iplocal=comcast [iplocalpple.com, possibly misconfigured]         exploit",
            "https://itunes.apple.com/app/apple-store/id284815942/us/app/samsung-galaxy-watch-gear-s/id1117310635   exploit  [You can pair older Samsung watches with an iPhone by downloading the Samsung Galaxy Watch (Gear S) app from the iOS App. Abused remotely?]",
            "itunes.apple.com.                     [https:///app/apple-store",
            "https://itunes.apple.com/app/apple-store/id284815942/us/app/samsung-galaxy-watch-gear-s/id1117310635 [HappyRabbit]",
            "a0bc39001c6efcf39dbc6b7684232cce5126dcf0364c37e902714898ec097e94 [apple to windows China ??]",
            "https://otx.alienvault.com/indicator/url/https://www.milehighmedia.com/en/Charlie-Dean/pornstar/49512 ?  A target on my devices?",
            "https://www.milehighmedia.com/en/pornstar/milehighmedia/Justin-Hunt/51017    Another target?",
            "https://lelosexgame.com/datingsm?ad_campaign_id=3161239&cost=0&creative_id=2032565&external_id=0&keyword=%25KW%25&ref=https://example.com&ref_domain=example.com&server_node=0&source=0",
            "199.249.230.74            traffic group 78",
            "https://gpt.ocloo.cn/auth",
            "vmwarevmc.com",
            "http://karnalketo.com/sound-found                             error code 432      server nginx",
            "http://ww1.karnalketo.com/astroshift-soundtrack-cheat-code-incl-product-key-download-3264bit-latest/                  error code 432    server nginx",
            "64.190.63.136        Malicious. IP: Sedo GmbH",
            "www.sweetheartvideo.com      Tracking and Botnet campaign"
          ],
          "public": 1,
          "adversary": "[Unnamed US Teams and Hacker group]",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "QakBot - S0650",
              "display_name": "QakBot - S0650",
              "target": null
            },
            {
              "id": "Ransomexx",
              "display_name": "Ransomexx",
              "target": null
            },
            {
              "id": "Azorult - S0344",
              "display_name": "Azorult - S0344",
              "target": null
            },
            {
              "id": "Formbook",
              "display_name": "Formbook",
              "target": null
            },
            {
              "id": "Korplug",
              "display_name": "Korplug",
              "target": null
            },
            {
              "id": "Colbalt Strike",
              "display_name": "Colbalt Strike",
              "target": null
            },
            {
              "id": "Remcos",
              "display_name": "Remcos",
              "target": null
            },
            {
              "id": "Colibri Loader",
              "display_name": "Colibri Loader",
              "target": null
            },
            {
              "id": "Quasar RAT",
              "display_name": "Quasar RAT",
              "target": null
            },
            {
              "id": "Nokoyawa",
              "display_name": "Nokoyawa",
              "target": null
            },
            {
              "id": "Emotet",
              "display_name": "Emotet",
              "target": null
            },
            {
              "id": "njRAT - S0385",
              "display_name": "njRAT - S0385",
              "target": null
            },
            {
              "id": "Chaos",
              "display_name": "Chaos",
              "target": null
            },
            {
              "id": "Ursnif - S0386",
              "display_name": "Ursnif - S0386",
              "target": null
            },
            {
              "id": "Virus:DOS/Nanjing",
              "display_name": "Virus:DOS/Nanjing",
              "target": "/malware/Virus:DOS/Nanjing"
            },
            {
              "id": "Daxin",
              "display_name": "Daxin",
              "target": null
            },
            {
              "id": "Tulach",
              "display_name": "Tulach",
              "target": null
            },
            {
              "id": "Ransomware",
              "display_name": "Ransomware",
              "target": null
            },
            {
              "id": "Virus:WM/Look",
              "display_name": "Virus:WM/Look",
              "target": "/malware/Virus:WM/Look"
            },
            {
              "id": "Skynet",
              "display_name": "Skynet",
              "target": null
            },
            {
              "id": "ketogenic switch",
              "display_name": "ketogenic switch",
              "target": null
            },
            {
              "id": "BitcoinAussie",
              "display_name": "BitcoinAussie",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1059.007",
              "name": "JavaScript",
              "display_name": "T1059.007 - JavaScript"
            },
            {
              "id": "TA0011",
              "name": "Command and Control",
              "display_name": "TA0011 - Command and Control"
            },
            {
              "id": "T1003",
              "name": "OS Credential Dumping",
              "display_name": "T1003 - OS Credential Dumping"
            },
            {
              "id": "T1071.002",
              "name": "File Transfer Protocols",
              "display_name": "T1071.002 - File Transfer Protocols"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": "653323de61317f6ca7a3e875",
          "export_count": 26,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 173,
            "FileHash-SHA1": 166,
            "FileHash-SHA256": 2841,
            "URL": 6670,
            "CVE": 4,
            "domain": 684,
            "hostname": 1930,
            "CIDR": 2,
            "email": 3
          },
          "indicator_count": 12473,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 218,
          "modified_text": "883 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "653f200c20e12f03f749c403",
          "name": "114.114.114.114 Tracking | Botnet | Malvertizing",
          "description": "",
          "modified": "2023-11-19T00:04:57.528000",
          "created": "2023-10-30T03:16:28.252000",
          "tags": [
            "contacted",
            "tsara brashears",
            "whois record",
            "whois whois",
            "threat roundup",
            "december",
            "execution",
            "referrer",
            "pe resource",
            "remcos",
            "malware",
            "quasar",
            "nanocore",
            "attack",
            "core",
            "qakbot",
            "azorult",
            "njrat",
            "colibri loader",
            "metro",
            "nokoyawa",
            "formbook",
            "bank",
            "installer",
            "daxin",
            "awful",
            "open",
            "korplug",
            "dark power",
            "cobalt strike",
            "hacktool",
            "emotet",
            "chaos",
            "ransomexx",
            "ursnif",
            "ransomware",
            "pattern match",
            "et tor",
            "known tor",
            "misc attack",
            "relayrouter",
            "exit",
            "node traffic",
            "beginstring",
            "script",
            "segoe ui",
            "null",
            "error",
            "unknown",
            "span",
            "date",
            "body",
            "refresh",
            "class",
            "critical",
            "tools",
            "look",
            "verify",
            "restart",
            "hybrid",
            "general",
            "click",
            "strings",
            "meta",
            "xiongmao group",
            "district",
            "nanjing",
            "china country",
            "beijing",
            "please",
            "apnic person",
            "road",
            "china phone",
            "whois lookup",
            "cnnic",
            "dns replication",
            "domain",
            "win32 exe",
            "files",
            "detections type",
            "name",
            "notepad",
            "java",
            "update checker",
            "type name",
            "android",
            "win32 dll",
            "cyber criminals",
            "cyber stalking",
            "cyber warfare",
            "framing",
            "tulach.cc",
            "exploit_source",
            "scanning_host",
            "phishing",
            "adware",
            "command_and_control",
            "C2",
            "technology",
            "virustotal xn",
            "technology xn",
            "rich text",
            "format po",
            "jyoti cnc",
            "detection list",
            "blacklist",
            "noname057",
            "proxy",
            "prism.exe",
            "password cracker",
            "skynet",
            "malvertizing",
            "spyware",
            "colorado",
            "arizona",
            "prism command line tool",
            "keyloggers",
            "apple",
            "I'm being followed",
            "threats",
            "sha256",
            "osint",
            "vmware",
            "gpt",
            "nginx",
            "piracy",
            "intellectual property",
            "spammer",
            "honeypot",
            "tracker",
            "tracking campaign",
            "Botnet campaign"
          ],
          "references": [
            "114.114.1114.114",
            "https://www.anyxxxtube.net/search-porn/tsara-brashears/    phishing",
            "https://wallpapers-nature.com/tsara-brashears/tse1-mm-bing-net \tketogenic switch , BitcoinAussie",
            "wallpapers-nature.com",
            "https://wallpapers-nature.com/%20tsara-brashears/urlscan-io        BitcoinAussie",
            "www.sweetheartvideo.com",
            "https://www.sweetheartvideo.com/tsara-brashears/Tracker and Botnet campaign",
            "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian     password cracker",
            "a-poster.info                 [tagging tool]",
            "https://tulach.cc/    phishing | Proxy | Skynet",
            "67.227.226.240             command_and_control. [lb01.parklogic.com] Lansing Michigan",
            "20.99.186.246               exploit_source",
            "https://www.hybrid-analysis.com/sample/06558031f63aca4f043b4770ae780337408b276df3b1e3e05b3d536839c3ad9e/652c962002e18b99e20e891a",
            "1.62.64.108                  malware_hosting",
            "110.249.196.101.          malware_hosting",
            "CVE-2022-26134",
            "www.anyxxxtube.net               prism.exe",
            "https://www.pornhub.com    prism.exe  [Massachusetts, US]",
            "https://www.milehighmedia.com/en/Charlie-Dean/pornstar/49512   [Colorado, US referenced malvertizing outfit]",
            "https://www.milehighmedia.com/en/pornstar/milehighmedia/Justin-Hunt/51017 [Colorado, US references]",
            "https://twitter.com/PORNO_SEXYBABES - Nokoyawa  catapult spider",
            "https://twitter.com/               catapult spider/spider",
            "nr-data.net                                 Private Apple data collection",
            "tv.apple.com                               Apple hacking",
            "newrelic.se                                  New Update Apple iPhone 199.59.243.222",
            "0.0.0.0                                            iplocal=comcast [iplocalpple.com, possibly misconfigured]         exploit",
            "https://itunes.apple.com/app/apple-store/id284815942/us/app/samsung-galaxy-watch-gear-s/id1117310635   exploit  [You can pair older Samsung watches with an iPhone by downloading the Samsung Galaxy Watch (Gear S) app from the iOS App. Abused remotely?]",
            "itunes.apple.com.                     [https:///app/apple-store",
            "https://itunes.apple.com/app/apple-store/id284815942/us/app/samsung-galaxy-watch-gear-s/id1117310635 [HappyRabbit]",
            "a0bc39001c6efcf39dbc6b7684232cce5126dcf0364c37e902714898ec097e94 [apple to windows China ??]",
            "https://otx.alienvault.com/indicator/url/https://www.milehighmedia.com/en/Charlie-Dean/pornstar/49512 ?  A target on my devices?",
            "https://www.milehighmedia.com/en/pornstar/milehighmedia/Justin-Hunt/51017    Another target?",
            "https://lelosexgame.com/datingsm?ad_campaign_id=3161239&cost=0&creative_id=2032565&external_id=0&keyword=%25KW%25&ref=https://example.com&ref_domain=example.com&server_node=0&source=0",
            "199.249.230.74            traffic group 78",
            "https://gpt.ocloo.cn/auth",
            "vmwarevmc.com",
            "http://karnalketo.com/sound-found                             error code 432      server nginx",
            "http://ww1.karnalketo.com/astroshift-soundtrack-cheat-code-incl-product-key-download-3264bit-latest/                  error code 432    server nginx",
            "64.190.63.136        Malicious. IP: Sedo GmbH",
            "www.sweetheartvideo.com      Tracking and Botnet campaign"
          ],
          "public": 1,
          "adversary": "[Unnamed US Teams and Hacker group]",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "QakBot - S0650",
              "display_name": "QakBot - S0650",
              "target": null
            },
            {
              "id": "Ransomexx",
              "display_name": "Ransomexx",
              "target": null
            },
            {
              "id": "Azorult - S0344",
              "display_name": "Azorult - S0344",
              "target": null
            },
            {
              "id": "Formbook",
              "display_name": "Formbook",
              "target": null
            },
            {
              "id": "Korplug",
              "display_name": "Korplug",
              "target": null
            },
            {
              "id": "Colbalt Strike",
              "display_name": "Colbalt Strike",
              "target": null
            },
            {
              "id": "Remcos",
              "display_name": "Remcos",
              "target": null
            },
            {
              "id": "Colibri Loader",
              "display_name": "Colibri Loader",
              "target": null
            },
            {
              "id": "Quasar RAT",
              "display_name": "Quasar RAT",
              "target": null
            },
            {
              "id": "Nokoyawa",
              "display_name": "Nokoyawa",
              "target": null
            },
            {
              "id": "Emotet",
              "display_name": "Emotet",
              "target": null
            },
            {
              "id": "njRAT - S0385",
              "display_name": "njRAT - S0385",
              "target": null
            },
            {
              "id": "Chaos",
              "display_name": "Chaos",
              "target": null
            },
            {
              "id": "Ursnif - S0386",
              "display_name": "Ursnif - S0386",
              "target": null
            },
            {
              "id": "Virus:DOS/Nanjing",
              "display_name": "Virus:DOS/Nanjing",
              "target": "/malware/Virus:DOS/Nanjing"
            },
            {
              "id": "Daxin",
              "display_name": "Daxin",
              "target": null
            },
            {
              "id": "Tulach",
              "display_name": "Tulach",
              "target": null
            },
            {
              "id": "Ransomware",
              "display_name": "Ransomware",
              "target": null
            },
            {
              "id": "Virus:WM/Look",
              "display_name": "Virus:WM/Look",
              "target": "/malware/Virus:WM/Look"
            },
            {
              "id": "Skynet",
              "display_name": "Skynet",
              "target": null
            },
            {
              "id": "ketogenic switch",
              "display_name": "ketogenic switch",
              "target": null
            },
            {
              "id": "BitcoinAussie",
              "display_name": "BitcoinAussie",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1059.007",
              "name": "JavaScript",
              "display_name": "T1059.007 - JavaScript"
            },
            {
              "id": "TA0011",
              "name": "Command and Control",
              "display_name": "TA0011 - Command and Control"
            },
            {
              "id": "T1003",
              "name": "OS Credential Dumping",
              "display_name": "T1003 - OS Credential Dumping"
            },
            {
              "id": "T1071.002",
              "name": "File Transfer Protocols",
              "display_name": "T1071.002 - File Transfer Protocols"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": "6533b20cf4ad384a0193c655",
          "export_count": 28,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 173,
            "FileHash-SHA1": 166,
            "FileHash-SHA256": 2841,
            "URL": 6670,
            "CVE": 4,
            "domain": 684,
            "hostname": 1930,
            "CIDR": 2,
            "email": 3
          },
          "indicator_count": 12473,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 218,
          "modified_text": "883 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "653f205bac4b92f025125962",
          "name": "Tracker and Botnet campaign - Canto XXVI",
          "description": "",
          "modified": "2023-11-19T00:04:57.528000",
          "created": "2023-10-30T03:17:47.051000",
          "tags": [
            "contacted",
            "tsara brashears",
            "whois record",
            "whois whois",
            "threat roundup",
            "december",
            "execution",
            "referrer",
            "pe resource",
            "remcos",
            "malware",
            "quasar",
            "nanocore",
            "attack",
            "core",
            "qakbot",
            "azorult",
            "njrat",
            "colibri loader",
            "metro",
            "nokoyawa",
            "formbook",
            "bank",
            "installer",
            "daxin",
            "awful",
            "open",
            "korplug",
            "dark power",
            "cobalt strike",
            "hacktool",
            "emotet",
            "chaos",
            "ransomexx",
            "ursnif",
            "ransomware",
            "pattern match",
            "et tor",
            "known tor",
            "misc attack",
            "relayrouter",
            "exit",
            "node traffic",
            "beginstring",
            "script",
            "segoe ui",
            "null",
            "error",
            "unknown",
            "span",
            "date",
            "body",
            "refresh",
            "class",
            "critical",
            "tools",
            "look",
            "verify",
            "restart",
            "hybrid",
            "general",
            "click",
            "strings",
            "meta",
            "xiongmao group",
            "district",
            "nanjing",
            "china country",
            "beijing",
            "please",
            "apnic person",
            "road",
            "china phone",
            "whois lookup",
            "cnnic",
            "dns replication",
            "domain",
            "win32 exe",
            "files",
            "detections type",
            "name",
            "notepad",
            "java",
            "update checker",
            "type name",
            "android",
            "win32 dll",
            "cyber criminals",
            "cyber stalking",
            "cyber warfare",
            "framing",
            "tulach.cc",
            "exploit_source",
            "scanning_host",
            "phishing",
            "adware",
            "command_and_control",
            "C2",
            "technology",
            "virustotal xn",
            "technology xn",
            "rich text",
            "format po",
            "jyoti cnc",
            "detection list",
            "blacklist",
            "noname057",
            "proxy",
            "prism.exe",
            "password cracker",
            "skynet",
            "malvertizing",
            "spyware",
            "colorado",
            "arizona",
            "prism command line tool",
            "keyloggers",
            "apple",
            "I'm being followed",
            "threats",
            "sha256",
            "osint",
            "vmware",
            "gpt",
            "nginx",
            "piracy",
            "intellectual property",
            "spammer",
            "honeypot",
            "tracker",
            "tracking campaign",
            "Botnet campaign"
          ],
          "references": [
            "114.114.1114.114",
            "https://www.anyxxxtube.net/search-porn/tsara-brashears/    phishing",
            "https://wallpapers-nature.com/tsara-brashears/tse1-mm-bing-net \tketogenic switch , BitcoinAussie",
            "wallpapers-nature.com",
            "https://wallpapers-nature.com/%20tsara-brashears/urlscan-io        BitcoinAussie",
            "www.sweetheartvideo.com",
            "https://www.sweetheartvideo.com/tsara-brashears/Tracker and Botnet campaign",
            "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian     password cracker",
            "a-poster.info                 [tagging tool]",
            "https://tulach.cc/    phishing | Proxy | Skynet",
            "67.227.226.240             command_and_control. [lb01.parklogic.com] Lansing Michigan",
            "20.99.186.246               exploit_source",
            "https://www.hybrid-analysis.com/sample/06558031f63aca4f043b4770ae780337408b276df3b1e3e05b3d536839c3ad9e/652c962002e18b99e20e891a",
            "1.62.64.108                  malware_hosting",
            "110.249.196.101.          malware_hosting",
            "CVE-2022-26134",
            "www.anyxxxtube.net               prism.exe",
            "https://www.pornhub.com    prism.exe  [Massachusetts, US]",
            "https://www.milehighmedia.com/en/Charlie-Dean/pornstar/49512   [Colorado, US referenced malvertizing outfit]",
            "https://www.milehighmedia.com/en/pornstar/milehighmedia/Justin-Hunt/51017 [Colorado, US references]",
            "https://twitter.com/PORNO_SEXYBABES - Nokoyawa  catapult spider",
            "https://twitter.com/               catapult spider/spider",
            "nr-data.net                                 Private Apple data collection",
            "tv.apple.com                               Apple hacking",
            "newrelic.se                                  New Update Apple iPhone 199.59.243.222",
            "0.0.0.0                                            iplocal=comcast [iplocalpple.com, possibly misconfigured]         exploit",
            "https://itunes.apple.com/app/apple-store/id284815942/us/app/samsung-galaxy-watch-gear-s/id1117310635   exploit  [You can pair older Samsung watches with an iPhone by downloading the Samsung Galaxy Watch (Gear S) app from the iOS App. Abused remotely?]",
            "itunes.apple.com.                     [https:///app/apple-store",
            "https://itunes.apple.com/app/apple-store/id284815942/us/app/samsung-galaxy-watch-gear-s/id1117310635 [HappyRabbit]",
            "a0bc39001c6efcf39dbc6b7684232cce5126dcf0364c37e902714898ec097e94 [apple to windows China ??]",
            "https://otx.alienvault.com/indicator/url/https://www.milehighmedia.com/en/Charlie-Dean/pornstar/49512 ?  A target on my devices?",
            "https://www.milehighmedia.com/en/pornstar/milehighmedia/Justin-Hunt/51017    Another target?",
            "https://lelosexgame.com/datingsm?ad_campaign_id=3161239&cost=0&creative_id=2032565&external_id=0&keyword=%25KW%25&ref=https://example.com&ref_domain=example.com&server_node=0&source=0",
            "199.249.230.74            traffic group 78",
            "https://gpt.ocloo.cn/auth",
            "vmwarevmc.com",
            "http://karnalketo.com/sound-found                             error code 432      server nginx",
            "http://ww1.karnalketo.com/astroshift-soundtrack-cheat-code-incl-product-key-download-3264bit-latest/                  error code 432    server nginx",
            "64.190.63.136        Malicious. IP: Sedo GmbH",
            "www.sweetheartvideo.com      Tracking and Botnet campaign"
          ],
          "public": 1,
          "adversary": "[Unnamed US Teams and Hacker group]",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "QakBot - S0650",
              "display_name": "QakBot - S0650",
              "target": null
            },
            {
              "id": "Ransomexx",
              "display_name": "Ransomexx",
              "target": null
            },
            {
              "id": "Azorult - S0344",
              "display_name": "Azorult - S0344",
              "target": null
            },
            {
              "id": "Formbook",
              "display_name": "Formbook",
              "target": null
            },
            {
              "id": "Korplug",
              "display_name": "Korplug",
              "target": null
            },
            {
              "id": "Colbalt Strike",
              "display_name": "Colbalt Strike",
              "target": null
            },
            {
              "id": "Remcos",
              "display_name": "Remcos",
              "target": null
            },
            {
              "id": "Colibri Loader",
              "display_name": "Colibri Loader",
              "target": null
            },
            {
              "id": "Quasar RAT",
              "display_name": "Quasar RAT",
              "target": null
            },
            {
              "id": "Nokoyawa",
              "display_name": "Nokoyawa",
              "target": null
            },
            {
              "id": "Emotet",
              "display_name": "Emotet",
              "target": null
            },
            {
              "id": "njRAT - S0385",
              "display_name": "njRAT - S0385",
              "target": null
            },
            {
              "id": "Chaos",
              "display_name": "Chaos",
              "target": null
            },
            {
              "id": "Ursnif - S0386",
              "display_name": "Ursnif - S0386",
              "target": null
            },
            {
              "id": "Virus:DOS/Nanjing",
              "display_name": "Virus:DOS/Nanjing",
              "target": "/malware/Virus:DOS/Nanjing"
            },
            {
              "id": "Daxin",
              "display_name": "Daxin",
              "target": null
            },
            {
              "id": "Tulach",
              "display_name": "Tulach",
              "target": null
            },
            {
              "id": "Ransomware",
              "display_name": "Ransomware",
              "target": null
            },
            {
              "id": "Virus:WM/Look",
              "display_name": "Virus:WM/Look",
              "target": "/malware/Virus:WM/Look"
            },
            {
              "id": "Skynet",
              "display_name": "Skynet",
              "target": null
            },
            {
              "id": "ketogenic switch",
              "display_name": "ketogenic switch",
              "target": null
            },
            {
              "id": "BitcoinAussie",
              "display_name": "BitcoinAussie",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1059.007",
              "name": "JavaScript",
              "display_name": "T1059.007 - JavaScript"
            },
            {
              "id": "TA0011",
              "name": "Command and Control",
              "display_name": "TA0011 - Command and Control"
            },
            {
              "id": "T1003",
              "name": "OS Credential Dumping",
              "display_name": "T1003 - OS Credential Dumping"
            },
            {
              "id": "T1071.002",
              "name": "File Transfer Protocols",
              "display_name": "T1071.002 - File Transfer Protocols"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": "653323d24f9946946c804be4",
          "export_count": 28,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 173,
            "FileHash-SHA1": 166,
            "FileHash-SHA256": 2841,
            "URL": 6670,
            "CVE": 4,
            "domain": 684,
            "hostname": 1930,
            "CIDR": 2,
            "email": 3
          },
          "indicator_count": 12473,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 218,
          "modified_text": "883 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6533b20cf4ad384a0193c655",
          "name": "114.114.114.114 Tracking | Botnet | Malvertizing ",
          "description": "",
          "modified": "2023-11-19T00:04:57.528000",
          "created": "2023-10-21T11:12:12.005000",
          "tags": [
            "contacted",
            "tsara brashears",
            "whois record",
            "whois whois",
            "threat roundup",
            "december",
            "execution",
            "referrer",
            "pe resource",
            "remcos",
            "malware",
            "quasar",
            "nanocore",
            "attack",
            "core",
            "qakbot",
            "azorult",
            "njrat",
            "colibri loader",
            "metro",
            "nokoyawa",
            "formbook",
            "bank",
            "installer",
            "daxin",
            "awful",
            "open",
            "korplug",
            "dark power",
            "cobalt strike",
            "hacktool",
            "emotet",
            "chaos",
            "ransomexx",
            "ursnif",
            "ransomware",
            "pattern match",
            "et tor",
            "known tor",
            "misc attack",
            "relayrouter",
            "exit",
            "node traffic",
            "beginstring",
            "script",
            "segoe ui",
            "null",
            "error",
            "unknown",
            "span",
            "date",
            "body",
            "refresh",
            "class",
            "critical",
            "tools",
            "look",
            "verify",
            "restart",
            "hybrid",
            "general",
            "click",
            "strings",
            "meta",
            "xiongmao group",
            "district",
            "nanjing",
            "china country",
            "beijing",
            "please",
            "apnic person",
            "road",
            "china phone",
            "whois lookup",
            "cnnic",
            "dns replication",
            "domain",
            "win32 exe",
            "files",
            "detections type",
            "name",
            "notepad",
            "java",
            "update checker",
            "type name",
            "android",
            "win32 dll",
            "cyber criminals",
            "cyber stalking",
            "cyber warfare",
            "framing",
            "tulach.cc",
            "exploit_source",
            "scanning_host",
            "phishing",
            "adware",
            "command_and_control",
            "C2",
            "technology",
            "virustotal xn",
            "technology xn",
            "rich text",
            "format po",
            "jyoti cnc",
            "detection list",
            "blacklist",
            "noname057",
            "proxy",
            "prism.exe",
            "password cracker",
            "skynet",
            "malvertizing",
            "spyware",
            "colorado",
            "arizona",
            "prism command line tool",
            "keyloggers",
            "apple",
            "I'm being followed",
            "threats",
            "sha256",
            "osint",
            "vmware",
            "gpt",
            "nginx",
            "piracy",
            "intellectual property",
            "spammer",
            "honeypot",
            "tracker",
            "tracking campaign",
            "Botnet campaign"
          ],
          "references": [
            "114.114.1114.114",
            "https://www.anyxxxtube.net/search-porn/tsara-brashears/    phishing",
            "https://wallpapers-nature.com/tsara-brashears/tse1-mm-bing-net \tketogenic switch , BitcoinAussie",
            "wallpapers-nature.com",
            "https://wallpapers-nature.com/%20tsara-brashears/urlscan-io        BitcoinAussie",
            "www.sweetheartvideo.com",
            "https://www.sweetheartvideo.com/tsara-brashears/Tracker and Botnet campaign",
            "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian     password cracker",
            "a-poster.info                 [tagging tool]",
            "https://tulach.cc/    phishing | Proxy | Skynet",
            "67.227.226.240             command_and_control. [lb01.parklogic.com] Lansing Michigan",
            "20.99.186.246               exploit_source",
            "https://www.hybrid-analysis.com/sample/06558031f63aca4f043b4770ae780337408b276df3b1e3e05b3d536839c3ad9e/652c962002e18b99e20e891a",
            "1.62.64.108                  malware_hosting",
            "110.249.196.101.          malware_hosting",
            "CVE-2022-26134",
            "www.anyxxxtube.net               prism.exe",
            "https://www.pornhub.com    prism.exe  [Massachusetts, US]",
            "https://www.milehighmedia.com/en/Charlie-Dean/pornstar/49512   [Colorado, US referenced malvertizing outfit]",
            "https://www.milehighmedia.com/en/pornstar/milehighmedia/Justin-Hunt/51017 [Colorado, US references]",
            "https://twitter.com/PORNO_SEXYBABES - Nokoyawa  catapult spider",
            "https://twitter.com/               catapult spider/spider",
            "nr-data.net                                 Private Apple data collection",
            "tv.apple.com                               Apple hacking",
            "newrelic.se                                  New Update Apple iPhone 199.59.243.222",
            "0.0.0.0                                            iplocal=comcast [iplocalpple.com, possibly misconfigured]         exploit",
            "https://itunes.apple.com/app/apple-store/id284815942/us/app/samsung-galaxy-watch-gear-s/id1117310635   exploit  [You can pair older Samsung watches with an iPhone by downloading the Samsung Galaxy Watch (Gear S) app from the iOS App. Abused remotely?]",
            "itunes.apple.com.                     [https:///app/apple-store",
            "https://itunes.apple.com/app/apple-store/id284815942/us/app/samsung-galaxy-watch-gear-s/id1117310635 [HappyRabbit]",
            "a0bc39001c6efcf39dbc6b7684232cce5126dcf0364c37e902714898ec097e94 [apple to windows China ??]",
            "https://otx.alienvault.com/indicator/url/https://www.milehighmedia.com/en/Charlie-Dean/pornstar/49512 ?  A target on my devices?",
            "https://www.milehighmedia.com/en/pornstar/milehighmedia/Justin-Hunt/51017    Another target?",
            "https://lelosexgame.com/datingsm?ad_campaign_id=3161239&cost=0&creative_id=2032565&external_id=0&keyword=%25KW%25&ref=https://example.com&ref_domain=example.com&server_node=0&source=0",
            "199.249.230.74            traffic group 78",
            "https://gpt.ocloo.cn/auth",
            "vmwarevmc.com",
            "http://karnalketo.com/sound-found                             error code 432      server nginx",
            "http://ww1.karnalketo.com/astroshift-soundtrack-cheat-code-incl-product-key-download-3264bit-latest/                  error code 432    server nginx",
            "64.190.63.136        Malicious. IP: Sedo GmbH",
            "www.sweetheartvideo.com      Tracking and Botnet campaign"
          ],
          "public": 1,
          "adversary": "[Unnamed US Teams and Hacker group]",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "QakBot - S0650",
              "display_name": "QakBot - S0650",
              "target": null
            },
            {
              "id": "Ransomexx",
              "display_name": "Ransomexx",
              "target": null
            },
            {
              "id": "Azorult - S0344",
              "display_name": "Azorult - S0344",
              "target": null
            },
            {
              "id": "Formbook",
              "display_name": "Formbook",
              "target": null
            },
            {
              "id": "Korplug",
              "display_name": "Korplug",
              "target": null
            },
            {
              "id": "Colbalt Strike",
              "display_name": "Colbalt Strike",
              "target": null
            },
            {
              "id": "Remcos",
              "display_name": "Remcos",
              "target": null
            },
            {
              "id": "Colibri Loader",
              "display_name": "Colibri Loader",
              "target": null
            },
            {
              "id": "Quasar RAT",
              "display_name": "Quasar RAT",
              "target": null
            },
            {
              "id": "Nokoyawa",
              "display_name": "Nokoyawa",
              "target": null
            },
            {
              "id": "Emotet",
              "display_name": "Emotet",
              "target": null
            },
            {
              "id": "njRAT - S0385",
              "display_name": "njRAT - S0385",
              "target": null
            },
            {
              "id": "Chaos",
              "display_name": "Chaos",
              "target": null
            },
            {
              "id": "Ursnif - S0386",
              "display_name": "Ursnif - S0386",
              "target": null
            },
            {
              "id": "Virus:DOS/Nanjing",
              "display_name": "Virus:DOS/Nanjing",
              "target": "/malware/Virus:DOS/Nanjing"
            },
            {
              "id": "Daxin",
              "display_name": "Daxin",
              "target": null
            },
            {
              "id": "Tulach",
              "display_name": "Tulach",
              "target": null
            },
            {
              "id": "Ransomware",
              "display_name": "Ransomware",
              "target": null
            },
            {
              "id": "Virus:WM/Look",
              "display_name": "Virus:WM/Look",
              "target": "/malware/Virus:WM/Look"
            },
            {
              "id": "Skynet",
              "display_name": "Skynet",
              "target": null
            },
            {
              "id": "ketogenic switch",
              "display_name": "ketogenic switch",
              "target": null
            },
            {
              "id": "BitcoinAussie",
              "display_name": "BitcoinAussie",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1059.007",
              "name": "JavaScript",
              "display_name": "T1059.007 - JavaScript"
            },
            {
              "id": "TA0011",
              "name": "Command and Control",
              "display_name": "TA0011 - Command and Control"
            },
            {
              "id": "T1003",
              "name": "OS Credential Dumping",
              "display_name": "T1003 - OS Credential Dumping"
            },
            {
              "id": "T1071.002",
              "name": "File Transfer Protocols",
              "display_name": "T1071.002 - File Transfer Protocols"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": "653323d24f9946946c804be4",
          "export_count": 53,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 173,
            "FileHash-SHA1": 166,
            "FileHash-SHA256": 2841,
            "URL": 6670,
            "CVE": 4,
            "domain": 684,
            "hostname": 1930,
            "CIDR": 2,
            "email": 3
          },
          "indicator_count": 12473,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 225,
          "modified_text": "883 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "65580ba704bae549b90948b5",
          "name": "Tracker and Botnet campaign - Canto XXVI",
          "description": "",
          "modified": "2023-11-19T00:04:57.528000",
          "created": "2023-11-18T00:56:07.651000",
          "tags": [
            "contacted",
            "tsara brashears",
            "whois record",
            "whois whois",
            "threat roundup",
            "december",
            "execution",
            "referrer",
            "pe resource",
            "remcos",
            "malware",
            "quasar",
            "nanocore",
            "attack",
            "core",
            "qakbot",
            "azorult",
            "njrat",
            "colibri loader",
            "metro",
            "nokoyawa",
            "formbook",
            "bank",
            "installer",
            "daxin",
            "awful",
            "open",
            "korplug",
            "dark power",
            "cobalt strike",
            "hacktool",
            "emotet",
            "chaos",
            "ransomexx",
            "ursnif",
            "ransomware",
            "pattern match",
            "et tor",
            "known tor",
            "misc attack",
            "relayrouter",
            "exit",
            "node traffic",
            "beginstring",
            "script",
            "segoe ui",
            "null",
            "error",
            "unknown",
            "span",
            "date",
            "body",
            "refresh",
            "class",
            "critical",
            "tools",
            "look",
            "verify",
            "restart",
            "hybrid",
            "general",
            "click",
            "strings",
            "meta",
            "xiongmao group",
            "district",
            "nanjing",
            "china country",
            "beijing",
            "please",
            "apnic person",
            "road",
            "china phone",
            "whois lookup",
            "cnnic",
            "dns replication",
            "domain",
            "win32 exe",
            "files",
            "detections type",
            "name",
            "notepad",
            "java",
            "update checker",
            "type name",
            "android",
            "win32 dll",
            "cyber criminals",
            "cyber stalking",
            "cyber warfare",
            "framing",
            "tulach.cc",
            "exploit_source",
            "scanning_host",
            "phishing",
            "adware",
            "command_and_control",
            "C2",
            "technology",
            "virustotal xn",
            "technology xn",
            "rich text",
            "format po",
            "jyoti cnc",
            "detection list",
            "blacklist",
            "noname057",
            "proxy",
            "prism.exe",
            "password cracker",
            "skynet",
            "malvertizing",
            "spyware",
            "colorado",
            "arizona",
            "prism command line tool",
            "keyloggers",
            "apple",
            "I'm being followed",
            "threats",
            "sha256",
            "osint",
            "vmware",
            "gpt",
            "nginx",
            "piracy",
            "intellectual property",
            "spammer",
            "honeypot",
            "tracker",
            "tracking campaign",
            "Botnet campaign"
          ],
          "references": [
            "114.114.1114.114",
            "https://www.anyxxxtube.net/search-porn/tsara-brashears/    phishing",
            "https://wallpapers-nature.com/tsara-brashears/tse1-mm-bing-net \tketogenic switch , BitcoinAussie",
            "wallpapers-nature.com",
            "https://wallpapers-nature.com/%20tsara-brashears/urlscan-io        BitcoinAussie",
            "www.sweetheartvideo.com",
            "https://www.sweetheartvideo.com/tsara-brashears/Tracker and Botnet campaign",
            "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian     password cracker",
            "a-poster.info                 [tagging tool]",
            "https://tulach.cc/    phishing | Proxy | Skynet",
            "67.227.226.240             command_and_control. [lb01.parklogic.com] Lansing Michigan",
            "20.99.186.246               exploit_source",
            "https://www.hybrid-analysis.com/sample/06558031f63aca4f043b4770ae780337408b276df3b1e3e05b3d536839c3ad9e/652c962002e18b99e20e891a",
            "1.62.64.108                  malware_hosting",
            "110.249.196.101.          malware_hosting",
            "CVE-2022-26134",
            "www.anyxxxtube.net               prism.exe",
            "https://www.pornhub.com    prism.exe  [Massachusetts, US]",
            "https://www.milehighmedia.com/en/Charlie-Dean/pornstar/49512   [Colorado, US referenced malvertizing outfit]",
            "https://www.milehighmedia.com/en/pornstar/milehighmedia/Justin-Hunt/51017 [Colorado, US references]",
            "https://twitter.com/PORNO_SEXYBABES - Nokoyawa  catapult spider",
            "https://twitter.com/               catapult spider/spider",
            "nr-data.net                                 Private Apple data collection",
            "tv.apple.com                               Apple hacking",
            "newrelic.se                                  New Update Apple iPhone 199.59.243.222",
            "0.0.0.0                                            iplocal=comcast [iplocalpple.com, possibly misconfigured]         exploit",
            "https://itunes.apple.com/app/apple-store/id284815942/us/app/samsung-galaxy-watch-gear-s/id1117310635   exploit  [You can pair older Samsung watches with an iPhone by downloading the Samsung Galaxy Watch (Gear S) app from the iOS App. Abused remotely?]",
            "itunes.apple.com.                     [https:///app/apple-store",
            "https://itunes.apple.com/app/apple-store/id284815942/us/app/samsung-galaxy-watch-gear-s/id1117310635 [HappyRabbit]",
            "a0bc39001c6efcf39dbc6b7684232cce5126dcf0364c37e902714898ec097e94 [apple to windows China ??]",
            "https://otx.alienvault.com/indicator/url/https://www.milehighmedia.com/en/Charlie-Dean/pornstar/49512 ?  A target on my devices?",
            "https://www.milehighmedia.com/en/pornstar/milehighmedia/Justin-Hunt/51017    Another target?",
            "https://lelosexgame.com/datingsm?ad_campaign_id=3161239&cost=0&creative_id=2032565&external_id=0&keyword=%25KW%25&ref=https://example.com&ref_domain=example.com&server_node=0&source=0",
            "199.249.230.74            traffic group 78",
            "https://gpt.ocloo.cn/auth",
            "vmwarevmc.com",
            "http://karnalketo.com/sound-found                             error code 432      server nginx",
            "http://ww1.karnalketo.com/astroshift-soundtrack-cheat-code-incl-product-key-download-3264bit-latest/                  error code 432    server nginx",
            "64.190.63.136        Malicious. IP: Sedo GmbH",
            "www.sweetheartvideo.com      Tracking and Botnet campaign"
          ],
          "public": 1,
          "adversary": "[Unnamed US Teams and Hacker group]",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "QakBot - S0650",
              "display_name": "QakBot - S0650",
              "target": null
            },
            {
              "id": "Ransomexx",
              "display_name": "Ransomexx",
              "target": null
            },
            {
              "id": "Azorult - S0344",
              "display_name": "Azorult - S0344",
              "target": null
            },
            {
              "id": "Formbook",
              "display_name": "Formbook",
              "target": null
            },
            {
              "id": "Korplug",
              "display_name": "Korplug",
              "target": null
            },
            {
              "id": "Colbalt Strike",
              "display_name": "Colbalt Strike",
              "target": null
            },
            {
              "id": "Remcos",
              "display_name": "Remcos",
              "target": null
            },
            {
              "id": "Colibri Loader",
              "display_name": "Colibri Loader",
              "target": null
            },
            {
              "id": "Quasar RAT",
              "display_name": "Quasar RAT",
              "target": null
            },
            {
              "id": "Nokoyawa",
              "display_name": "Nokoyawa",
              "target": null
            },
            {
              "id": "Emotet",
              "display_name": "Emotet",
              "target": null
            },
            {
              "id": "njRAT - S0385",
              "display_name": "njRAT - S0385",
              "target": null
            },
            {
              "id": "Chaos",
              "display_name": "Chaos",
              "target": null
            },
            {
              "id": "Ursnif - S0386",
              "display_name": "Ursnif - S0386",
              "target": null
            },
            {
              "id": "Virus:DOS/Nanjing",
              "display_name": "Virus:DOS/Nanjing",
              "target": "/malware/Virus:DOS/Nanjing"
            },
            {
              "id": "Daxin",
              "display_name": "Daxin",
              "target": null
            },
            {
              "id": "Tulach",
              "display_name": "Tulach",
              "target": null
            },
            {
              "id": "Ransomware",
              "display_name": "Ransomware",
              "target": null
            },
            {
              "id": "Virus:WM/Look",
              "display_name": "Virus:WM/Look",
              "target": "/malware/Virus:WM/Look"
            },
            {
              "id": "Skynet",
              "display_name": "Skynet",
              "target": null
            },
            {
              "id": "ketogenic switch",
              "display_name": "ketogenic switch",
              "target": null
            },
            {
              "id": "BitcoinAussie",
              "display_name": "BitcoinAussie",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1059.007",
              "name": "JavaScript",
              "display_name": "T1059.007 - JavaScript"
            },
            {
              "id": "TA0011",
              "name": "Command and Control",
              "display_name": "TA0011 - Command and Control"
            },
            {
              "id": "T1003",
              "name": "OS Credential Dumping",
              "display_name": "T1003 - OS Credential Dumping"
            },
            {
              "id": "T1071.002",
              "name": "File Transfer Protocols",
              "display_name": "T1071.002 - File Transfer Protocols"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": "653f1ffb074d89724cb81371",
          "export_count": 21,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 173,
            "FileHash-SHA1": 166,
            "FileHash-SHA256": 2841,
            "URL": 6670,
            "CVE": 4,
            "domain": 684,
            "hostname": 1930,
            "CIDR": 2,
            "email": 3
          },
          "indicator_count": 12473,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 225,
          "modified_text": "883 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "653323de61317f6ca7a3e875",
          "name": "Tracker and Botnet campaign  - Canto XXVI",
          "description": "Sounds crazy made up. This is an expensive campaign. Talented, lost individuals.\nI'm naming this campaign.\n'Canto XXVI'  Bolgia 8 \u2013 Counsellors of Fraud\nThat's where they'll return.",
          "modified": "2023-11-19T00:04:57.528000",
          "created": "2023-10-21T01:05:34.166000",
          "tags": [
            "contacted",
            "tsara brashears",
            "whois record",
            "whois whois",
            "threat roundup",
            "december",
            "execution",
            "referrer",
            "pe resource",
            "remcos",
            "malware",
            "quasar",
            "nanocore",
            "attack",
            "core",
            "qakbot",
            "azorult",
            "njrat",
            "colibri loader",
            "metro",
            "nokoyawa",
            "formbook",
            "bank",
            "installer",
            "daxin",
            "awful",
            "open",
            "korplug",
            "dark power",
            "cobalt strike",
            "hacktool",
            "emotet",
            "chaos",
            "ransomexx",
            "ursnif",
            "ransomware",
            "pattern match",
            "et tor",
            "known tor",
            "misc attack",
            "relayrouter",
            "exit",
            "node traffic",
            "beginstring",
            "script",
            "segoe ui",
            "null",
            "error",
            "unknown",
            "span",
            "date",
            "body",
            "refresh",
            "class",
            "critical",
            "tools",
            "look",
            "verify",
            "restart",
            "hybrid",
            "general",
            "click",
            "strings",
            "meta",
            "xiongmao group",
            "district",
            "nanjing",
            "china country",
            "beijing",
            "please",
            "apnic person",
            "road",
            "china phone",
            "whois lookup",
            "cnnic",
            "dns replication",
            "domain",
            "win32 exe",
            "files",
            "detections type",
            "name",
            "notepad",
            "java",
            "update checker",
            "type name",
            "android",
            "win32 dll",
            "cyber criminals",
            "cyber stalking",
            "cyber warfare",
            "framing",
            "tulach.cc",
            "exploit_source",
            "scanning_host",
            "phishing",
            "adware",
            "command_and_control",
            "C2",
            "technology",
            "virustotal xn",
            "technology xn",
            "rich text",
            "format po",
            "jyoti cnc",
            "detection list",
            "blacklist",
            "noname057",
            "proxy",
            "prism.exe",
            "password cracker",
            "skynet",
            "malvertizing",
            "spyware",
            "colorado",
            "arizona",
            "prism command line tool",
            "keyloggers",
            "apple",
            "I'm being followed",
            "threats",
            "sha256",
            "osint",
            "vmware",
            "gpt",
            "nginx",
            "piracy",
            "intellectual property",
            "spammer",
            "honeypot",
            "tracker",
            "tracking campaign",
            "Botnet campaign"
          ],
          "references": [
            "114.114.1114.114",
            "https://www.anyxxxtube.net/search-porn/tsara-brashears/    phishing",
            "https://wallpapers-nature.com/tsara-brashears/tse1-mm-bing-net \tketogenic switch , BitcoinAussie",
            "wallpapers-nature.com",
            "https://wallpapers-nature.com/%20tsara-brashears/urlscan-io        BitcoinAussie",
            "www.sweetheartvideo.com",
            "https://www.sweetheartvideo.com/tsara-brashears/Tracker and Botnet campaign",
            "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian     password cracker",
            "a-poster.info                 [tagging tool]",
            "https://tulach.cc/    phishing | Proxy | Skynet",
            "67.227.226.240             command_and_control. [lb01.parklogic.com] Lansing Michigan",
            "20.99.186.246               exploit_source",
            "https://www.hybrid-analysis.com/sample/06558031f63aca4f043b4770ae780337408b276df3b1e3e05b3d536839c3ad9e/652c962002e18b99e20e891a",
            "1.62.64.108                  malware_hosting",
            "110.249.196.101.          malware_hosting",
            "CVE-2022-26134",
            "www.anyxxxtube.net               prism.exe",
            "https://www.pornhub.com    prism.exe  [Massachusetts, US]",
            "https://www.milehighmedia.com/en/Charlie-Dean/pornstar/49512   [Colorado, US referenced malvertizing outfit]",
            "https://www.milehighmedia.com/en/pornstar/milehighmedia/Justin-Hunt/51017 [Colorado, US references]",
            "https://twitter.com/PORNO_SEXYBABES - Nokoyawa  catapult spider",
            "https://twitter.com/               catapult spider/spider",
            "nr-data.net                                 Private Apple data collection",
            "tv.apple.com                               Apple hacking",
            "newrelic.se                                  New Update Apple iPhone 199.59.243.222",
            "0.0.0.0                                            iplocal=comcast [iplocalpple.com, possibly misconfigured]         exploit",
            "https://itunes.apple.com/app/apple-store/id284815942/us/app/samsung-galaxy-watch-gear-s/id1117310635   exploit  [You can pair older Samsung watches with an iPhone by downloading the Samsung Galaxy Watch (Gear S) app from the iOS App. Abused remotely?]",
            "itunes.apple.com.                     [https:///app/apple-store",
            "https://itunes.apple.com/app/apple-store/id284815942/us/app/samsung-galaxy-watch-gear-s/id1117310635 [HappyRabbit]",
            "a0bc39001c6efcf39dbc6b7684232cce5126dcf0364c37e902714898ec097e94 [apple to windows China ??]",
            "https://otx.alienvault.com/indicator/url/https://www.milehighmedia.com/en/Charlie-Dean/pornstar/49512 ?  A target on my devices?",
            "https://www.milehighmedia.com/en/pornstar/milehighmedia/Justin-Hunt/51017    Another target?",
            "https://lelosexgame.com/datingsm?ad_campaign_id=3161239&cost=0&creative_id=2032565&external_id=0&keyword=%25KW%25&ref=https://example.com&ref_domain=example.com&server_node=0&source=0",
            "199.249.230.74            traffic group 78",
            "https://gpt.ocloo.cn/auth",
            "vmwarevmc.com",
            "http://karnalketo.com/sound-found                             error code 432      server nginx",
            "http://ww1.karnalketo.com/astroshift-soundtrack-cheat-code-incl-product-key-download-3264bit-latest/                  error code 432    server nginx",
            "64.190.63.136        Malicious. IP: Sedo GmbH",
            "www.sweetheartvideo.com      Tracking and Botnet campaign"
          ],
          "public": 1,
          "adversary": "[Unnamed US Teams and Hacker group]",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "QakBot - S0650",
              "display_name": "QakBot - S0650",
              "target": null
            },
            {
              "id": "Ransomexx",
              "display_name": "Ransomexx",
              "target": null
            },
            {
              "id": "Azorult - S0344",
              "display_name": "Azorult - S0344",
              "target": null
            },
            {
              "id": "Formbook",
              "display_name": "Formbook",
              "target": null
            },
            {
              "id": "Korplug",
              "display_name": "Korplug",
              "target": null
            },
            {
              "id": "Colbalt Strike",
              "display_name": "Colbalt Strike",
              "target": null
            },
            {
              "id": "Remcos",
              "display_name": "Remcos",
              "target": null
            },
            {
              "id": "Colibri Loader",
              "display_name": "Colibri Loader",
              "target": null
            },
            {
              "id": "Quasar RAT",
              "display_name": "Quasar RAT",
              "target": null
            },
            {
              "id": "Nokoyawa",
              "display_name": "Nokoyawa",
              "target": null
            },
            {
              "id": "Emotet",
              "display_name": "Emotet",
              "target": null
            },
            {
              "id": "njRAT - S0385",
              "display_name": "njRAT - S0385",
              "target": null
            },
            {
              "id": "Chaos",
              "display_name": "Chaos",
              "target": null
            },
            {
              "id": "Ursnif - S0386",
              "display_name": "Ursnif - S0386",
              "target": null
            },
            {
              "id": "Virus:DOS/Nanjing",
              "display_name": "Virus:DOS/Nanjing",
              "target": "/malware/Virus:DOS/Nanjing"
            },
            {
              "id": "Daxin",
              "display_name": "Daxin",
              "target": null
            },
            {
              "id": "Tulach",
              "display_name": "Tulach",
              "target": null
            },
            {
              "id": "Ransomware",
              "display_name": "Ransomware",
              "target": null
            },
            {
              "id": "Virus:WM/Look",
              "display_name": "Virus:WM/Look",
              "target": "/malware/Virus:WM/Look"
            },
            {
              "id": "Skynet",
              "display_name": "Skynet",
              "target": null
            },
            {
              "id": "ketogenic switch",
              "display_name": "ketogenic switch",
              "target": null
            },
            {
              "id": "BitcoinAussie",
              "display_name": "BitcoinAussie",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1059.007",
              "name": "JavaScript",
              "display_name": "T1059.007 - JavaScript"
            },
            {
              "id": "TA0011",
              "name": "Command and Control",
              "display_name": "TA0011 - Command and Control"
            },
            {
              "id": "T1003",
              "name": "OS Credential Dumping",
              "display_name": "T1003 - OS Credential Dumping"
            },
            {
              "id": "T1071.002",
              "name": "File Transfer Protocols",
              "display_name": "T1071.002 - File Transfer Protocols"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 44,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 173,
            "FileHash-SHA1": 166,
            "FileHash-SHA256": 2841,
            "URL": 6670,
            "CVE": 4,
            "domain": 684,
            "hostname": 1930,
            "CIDR": 2,
            "email": 3
          },
          "indicator_count": 12473,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 224,
          "modified_text": "883 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "653323d24f9946946c804be4",
          "name": "Tracker and Botnet campaign  - Canto XXVI",
          "description": "Sounds crazy made up. This is an expensive campaign. Talented, lost individuals.\nI'm naming this campaign.\n'Canto XXVI'  Bolgia 8 \u2013 Counsellors of Fraud\nThat's where they'll return.",
          "modified": "2023-11-19T00:04:57.528000",
          "created": "2023-10-21T01:05:22.903000",
          "tags": [
            "contacted",
            "tsara brashears",
            "whois record",
            "whois whois",
            "threat roundup",
            "december",
            "execution",
            "referrer",
            "pe resource",
            "remcos",
            "malware",
            "quasar",
            "nanocore",
            "attack",
            "core",
            "qakbot",
            "azorult",
            "njrat",
            "colibri loader",
            "metro",
            "nokoyawa",
            "formbook",
            "bank",
            "installer",
            "daxin",
            "awful",
            "open",
            "korplug",
            "dark power",
            "cobalt strike",
            "hacktool",
            "emotet",
            "chaos",
            "ransomexx",
            "ursnif",
            "ransomware",
            "pattern match",
            "et tor",
            "known tor",
            "misc attack",
            "relayrouter",
            "exit",
            "node traffic",
            "beginstring",
            "script",
            "segoe ui",
            "null",
            "error",
            "unknown",
            "span",
            "date",
            "body",
            "refresh",
            "class",
            "critical",
            "tools",
            "look",
            "verify",
            "restart",
            "hybrid",
            "general",
            "click",
            "strings",
            "meta",
            "xiongmao group",
            "district",
            "nanjing",
            "china country",
            "beijing",
            "please",
            "apnic person",
            "road",
            "china phone",
            "whois lookup",
            "cnnic",
            "dns replication",
            "domain",
            "win32 exe",
            "files",
            "detections type",
            "name",
            "notepad",
            "java",
            "update checker",
            "type name",
            "android",
            "win32 dll",
            "cyber criminals",
            "cyber stalking",
            "cyber warfare",
            "framing",
            "tulach.cc",
            "exploit_source",
            "scanning_host",
            "phishing",
            "adware",
            "command_and_control",
            "C2",
            "technology",
            "virustotal xn",
            "technology xn",
            "rich text",
            "format po",
            "jyoti cnc",
            "detection list",
            "blacklist",
            "noname057",
            "proxy",
            "prism.exe",
            "password cracker",
            "skynet",
            "malvertizing",
            "spyware",
            "colorado",
            "arizona",
            "prism command line tool",
            "keyloggers",
            "apple",
            "I'm being followed",
            "threats",
            "sha256",
            "osint",
            "vmware",
            "gpt",
            "nginx",
            "piracy",
            "intellectual property",
            "spammer",
            "honeypot",
            "tracker",
            "tracking campaign",
            "Botnet campaign"
          ],
          "references": [
            "114.114.1114.114",
            "https://www.anyxxxtube.net/search-porn/tsara-brashears/    phishing",
            "https://wallpapers-nature.com/tsara-brashears/tse1-mm-bing-net \tketogenic switch , BitcoinAussie",
            "wallpapers-nature.com",
            "https://wallpapers-nature.com/%20tsara-brashears/urlscan-io        BitcoinAussie",
            "www.sweetheartvideo.com",
            "https://www.sweetheartvideo.com/tsara-brashears/Tracker and Botnet campaign",
            "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian     password cracker",
            "a-poster.info                 [tagging tool]",
            "https://tulach.cc/    phishing | Proxy | Skynet",
            "67.227.226.240             command_and_control. [lb01.parklogic.com] Lansing Michigan",
            "20.99.186.246               exploit_source",
            "https://www.hybrid-analysis.com/sample/06558031f63aca4f043b4770ae780337408b276df3b1e3e05b3d536839c3ad9e/652c962002e18b99e20e891a",
            "1.62.64.108                  malware_hosting",
            "110.249.196.101.          malware_hosting",
            "CVE-2022-26134",
            "www.anyxxxtube.net               prism.exe",
            "https://www.pornhub.com    prism.exe  [Massachusetts, US]",
            "https://www.milehighmedia.com/en/Charlie-Dean/pornstar/49512   [Colorado, US referenced malvertizing outfit]",
            "https://www.milehighmedia.com/en/pornstar/milehighmedia/Justin-Hunt/51017 [Colorado, US references]",
            "https://twitter.com/PORNO_SEXYBABES - Nokoyawa  catapult spider",
            "https://twitter.com/               catapult spider/spider",
            "nr-data.net                                 Private Apple data collection",
            "tv.apple.com                               Apple hacking",
            "newrelic.se                                  New Update Apple iPhone 199.59.243.222",
            "0.0.0.0                                            iplocal=comcast [iplocalpple.com, possibly misconfigured]         exploit",
            "https://itunes.apple.com/app/apple-store/id284815942/us/app/samsung-galaxy-watch-gear-s/id1117310635   exploit  [You can pair older Samsung watches with an iPhone by downloading the Samsung Galaxy Watch (Gear S) app from the iOS App. Abused remotely?]",
            "itunes.apple.com.                     [https:///app/apple-store",
            "https://itunes.apple.com/app/apple-store/id284815942/us/app/samsung-galaxy-watch-gear-s/id1117310635 [HappyRabbit]",
            "a0bc39001c6efcf39dbc6b7684232cce5126dcf0364c37e902714898ec097e94 [apple to windows China ??]",
            "https://otx.alienvault.com/indicator/url/https://www.milehighmedia.com/en/Charlie-Dean/pornstar/49512 ?  A target on my devices?",
            "https://www.milehighmedia.com/en/pornstar/milehighmedia/Justin-Hunt/51017    Another target?",
            "https://lelosexgame.com/datingsm?ad_campaign_id=3161239&cost=0&creative_id=2032565&external_id=0&keyword=%25KW%25&ref=https://example.com&ref_domain=example.com&server_node=0&source=0",
            "199.249.230.74            traffic group 78",
            "https://gpt.ocloo.cn/auth",
            "vmwarevmc.com",
            "http://karnalketo.com/sound-found                             error code 432      server nginx",
            "http://ww1.karnalketo.com/astroshift-soundtrack-cheat-code-incl-product-key-download-3264bit-latest/                  error code 432    server nginx",
            "64.190.63.136        Malicious. IP: Sedo GmbH",
            "www.sweetheartvideo.com      Tracking and Botnet campaign"
          ],
          "public": 1,
          "adversary": "[Unnamed US Teams and Hacker group]",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "QakBot - S0650",
              "display_name": "QakBot - S0650",
              "target": null
            },
            {
              "id": "Ransomexx",
              "display_name": "Ransomexx",
              "target": null
            },
            {
              "id": "Azorult - S0344",
              "display_name": "Azorult - S0344",
              "target": null
            },
            {
              "id": "Formbook",
              "display_name": "Formbook",
              "target": null
            },
            {
              "id": "Korplug",
              "display_name": "Korplug",
              "target": null
            },
            {
              "id": "Colbalt Strike",
              "display_name": "Colbalt Strike",
              "target": null
            },
            {
              "id": "Remcos",
              "display_name": "Remcos",
              "target": null
            },
            {
              "id": "Colibri Loader",
              "display_name": "Colibri Loader",
              "target": null
            },
            {
              "id": "Quasar RAT",
              "display_name": "Quasar RAT",
              "target": null
            },
            {
              "id": "Nokoyawa",
              "display_name": "Nokoyawa",
              "target": null
            },
            {
              "id": "Emotet",
              "display_name": "Emotet",
              "target": null
            },
            {
              "id": "njRAT - S0385",
              "display_name": "njRAT - S0385",
              "target": null
            },
            {
              "id": "Chaos",
              "display_name": "Chaos",
              "target": null
            },
            {
              "id": "Ursnif - S0386",
              "display_name": "Ursnif - S0386",
              "target": null
            },
            {
              "id": "Virus:DOS/Nanjing",
              "display_name": "Virus:DOS/Nanjing",
              "target": "/malware/Virus:DOS/Nanjing"
            },
            {
              "id": "Daxin",
              "display_name": "Daxin",
              "target": null
            },
            {
              "id": "Tulach",
              "display_name": "Tulach",
              "target": null
            },
            {
              "id": "Ransomware",
              "display_name": "Ransomware",
              "target": null
            },
            {
              "id": "Virus:WM/Look",
              "display_name": "Virus:WM/Look",
              "target": "/malware/Virus:WM/Look"
            },
            {
              "id": "Skynet",
              "display_name": "Skynet",
              "target": null
            },
            {
              "id": "ketogenic switch",
              "display_name": "ketogenic switch",
              "target": null
            },
            {
              "id": "BitcoinAussie",
              "display_name": "BitcoinAussie",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1059.007",
              "name": "JavaScript",
              "display_name": "T1059.007 - JavaScript"
            },
            {
              "id": "TA0011",
              "name": "Command and Control",
              "display_name": "TA0011 - Command and Control"
            },
            {
              "id": "T1003",
              "name": "OS Credential Dumping",
              "display_name": "T1003 - OS Credential Dumping"
            },
            {
              "id": "T1071.002",
              "name": "File Transfer Protocols",
              "display_name": "T1071.002 - File Transfer Protocols"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 41,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 173,
            "FileHash-SHA1": 166,
            "FileHash-SHA256": 2841,
            "URL": 6670,
            "CVE": 4,
            "domain": 684,
            "hostname": 1930,
            "CIDR": 2,
            "email": 3
          },
          "indicator_count": 12473,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 224,
          "modified_text": "883 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "65331eeded285a25c31d63a4",
          "name": "Tracking and Botnet campaign",
          "description": "US attackers making an exit by dumping to my devices & spreading to various other unsuspecting?\nRevenge for researching? Dumping to make it hard to implicate a single source. \nDump of Tsara Brashears and other adult content , malvertizing by a cyber stalker campaigners. As reported previously, entered my device and took control. Evidence pulled from a device while attack in progress. Device read Michigan, shopping, advertising, news, etc. Location not associated with any failed privacy controls on devices listing other locations.\nI listed a few IOC's Dumped to device in references. \nDump was continuous. Device modification for storage, new systems interface created upon device update. Moderete byte load per minute. Example 227 KB per minute. Prism command line tool\nChina foolish enough to implicate themselves for unclear crimes against American citizens? If an alleged crime against a target was allegedly committed in US someone is silencing her big time. There are a few other names as well. Targets?",
          "modified": "2023-11-19T00:04:57.528000",
          "created": "2023-10-21T00:44:29.344000",
          "tags": [
            "contacted",
            "tsara brashears",
            "whois record",
            "whois whois",
            "threat roundup",
            "december",
            "execution",
            "referrer",
            "pe resource",
            "remcos",
            "malware",
            "quasar",
            "nanocore",
            "attack",
            "core",
            "qakbot",
            "azorult",
            "njrat",
            "colibri loader",
            "metro",
            "nokoyawa",
            "formbook",
            "bank",
            "installer",
            "daxin",
            "awful",
            "open",
            "korplug",
            "dark power",
            "cobalt strike",
            "hacktool",
            "emotet",
            "chaos",
            "ransomexx",
            "ursnif",
            "ransomware",
            "pattern match",
            "et tor",
            "known tor",
            "misc attack",
            "relayrouter",
            "exit",
            "node traffic",
            "beginstring",
            "script",
            "segoe ui",
            "null",
            "error",
            "unknown",
            "span",
            "date",
            "body",
            "refresh",
            "class",
            "critical",
            "tools",
            "look",
            "verify",
            "restart",
            "hybrid",
            "general",
            "click",
            "strings",
            "meta",
            "xiongmao group",
            "district",
            "nanjing",
            "china country",
            "beijing",
            "please",
            "apnic person",
            "road",
            "china phone",
            "whois lookup",
            "cnnic",
            "dns replication",
            "domain",
            "win32 exe",
            "files",
            "detections type",
            "name",
            "notepad",
            "java",
            "update checker",
            "type name",
            "android",
            "win32 dll",
            "cyber criminals",
            "cyber stalking",
            "cyber warfare",
            "framing",
            "tulach.cc",
            "exploit_source",
            "scanning_host",
            "phishing",
            "adware",
            "command_and_control",
            "C2",
            "technology",
            "virustotal xn",
            "technology xn",
            "rich text",
            "format po",
            "jyoti cnc",
            "detection list",
            "blacklist",
            "noname057",
            "proxy",
            "prism.exe",
            "password cracker",
            "skynet",
            "malvertizing",
            "spyware",
            "colorado",
            "arizona",
            "prism command line tool",
            "keyloggers",
            "apple",
            "I'm being followed",
            "threats",
            "sha256",
            "osint",
            "vmware",
            "gpt",
            "nginx",
            "piracy",
            "intellectual property",
            "spammer",
            "honeypot",
            "tracker",
            "tracking campaign",
            "Botnet campaign"
          ],
          "references": [
            "114.114.1114.114",
            "https://www.anyxxxtube.net/search-porn/tsara-brashears/    phishing",
            "https://wallpapers-nature.com/tsara-brashears/tse1-mm-bing-net \tketogenic switch , BitcoinAussie",
            "wallpapers-nature.com",
            "https://wallpapers-nature.com/%20tsara-brashears/urlscan-io        BitcoinAussie",
            "www.sweetheartvideo.com",
            "https://www.sweetheartvideo.com/tsara-brashears/Tracker and Botnet campaign",
            "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian     password cracker",
            "a-poster.info                 [tagging tool]",
            "https://tulach.cc/    phishing | Proxy | Skynet",
            "67.227.226.240             command_and_control. [lb01.parklogic.com] Lansing Michigan",
            "20.99.186.246               exploit_source",
            "https://www.hybrid-analysis.com/sample/06558031f63aca4f043b4770ae780337408b276df3b1e3e05b3d536839c3ad9e/652c962002e18b99e20e891a",
            "1.62.64.108                  malware_hosting",
            "110.249.196.101.          malware_hosting",
            "CVE-2022-26134",
            "www.anyxxxtube.net               prism.exe",
            "https://www.pornhub.com    prism.exe  [Massachusetts, US]",
            "https://www.milehighmedia.com/en/Charlie-Dean/pornstar/49512   [Colorado, US referenced malvertizing outfit]",
            "https://www.milehighmedia.com/en/pornstar/milehighmedia/Justin-Hunt/51017 [Colorado, US references]",
            "https://twitter.com/PORNO_SEXYBABES - Nokoyawa  catapult spider",
            "https://twitter.com/               catapult spider/spider",
            "nr-data.net                                 Private Apple data collection",
            "tv.apple.com                               Apple hacking",
            "newrelic.se                                  New Update Apple iPhone 199.59.243.222",
            "0.0.0.0                                            iplocal=comcast [iplocalpple.com, possibly misconfigured]         exploit",
            "https://itunes.apple.com/app/apple-store/id284815942/us/app/samsung-galaxy-watch-gear-s/id1117310635   exploit  [You can pair older Samsung watches with an iPhone by downloading the Samsung Galaxy Watch (Gear S) app from the iOS App. Abused remotely?]",
            "itunes.apple.com.                     [https:///app/apple-store",
            "https://itunes.apple.com/app/apple-store/id284815942/us/app/samsung-galaxy-watch-gear-s/id1117310635 [HappyRabbit]",
            "a0bc39001c6efcf39dbc6b7684232cce5126dcf0364c37e902714898ec097e94 [apple to windows China ??]",
            "https://otx.alienvault.com/indicator/url/https://www.milehighmedia.com/en/Charlie-Dean/pornstar/49512 ?  A target on my devices?",
            "https://www.milehighmedia.com/en/pornstar/milehighmedia/Justin-Hunt/51017    Another target?",
            "https://lelosexgame.com/datingsm?ad_campaign_id=3161239&cost=0&creative_id=2032565&external_id=0&keyword=%25KW%25&ref=https://example.com&ref_domain=example.com&server_node=0&source=0",
            "199.249.230.74            traffic group 78",
            "https://gpt.ocloo.cn/auth",
            "vmwarevmc.com",
            "http://karnalketo.com/sound-found                             error code 432      server nginx",
            "http://ww1.karnalketo.com/astroshift-soundtrack-cheat-code-incl-product-key-download-3264bit-latest/                  error code 432    server nginx",
            "64.190.63.136        Malicious. IP: Sedo GmbH",
            "www.sweetheartvideo.com      Tracking and Botnet campaign"
          ],
          "public": 1,
          "adversary": "[Unnamed US Teams and Hacker group]",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "QakBot - S0650",
              "display_name": "QakBot - S0650",
              "target": null
            },
            {
              "id": "Ransomexx",
              "display_name": "Ransomexx",
              "target": null
            },
            {
              "id": "Azorult - S0344",
              "display_name": "Azorult - S0344",
              "target": null
            },
            {
              "id": "Formbook",
              "display_name": "Formbook",
              "target": null
            },
            {
              "id": "Korplug",
              "display_name": "Korplug",
              "target": null
            },
            {
              "id": "Colbalt Strike",
              "display_name": "Colbalt Strike",
              "target": null
            },
            {
              "id": "Remcos",
              "display_name": "Remcos",
              "target": null
            },
            {
              "id": "Colibri Loader",
              "display_name": "Colibri Loader",
              "target": null
            },
            {
              "id": "Quasar RAT",
              "display_name": "Quasar RAT",
              "target": null
            },
            {
              "id": "Nokoyawa",
              "display_name": "Nokoyawa",
              "target": null
            },
            {
              "id": "Emotet",
              "display_name": "Emotet",
              "target": null
            },
            {
              "id": "njRAT - S0385",
              "display_name": "njRAT - S0385",
              "target": null
            },
            {
              "id": "Chaos",
              "display_name": "Chaos",
              "target": null
            },
            {
              "id": "Ursnif - S0386",
              "display_name": "Ursnif - S0386",
              "target": null
            },
            {
              "id": "Virus:DOS/Nanjing",
              "display_name": "Virus:DOS/Nanjing",
              "target": "/malware/Virus:DOS/Nanjing"
            },
            {
              "id": "Daxin",
              "display_name": "Daxin",
              "target": null
            },
            {
              "id": "Tulach",
              "display_name": "Tulach",
              "target": null
            },
            {
              "id": "Ransomware",
              "display_name": "Ransomware",
              "target": null
            },
            {
              "id": "Virus:WM/Look",
              "display_name": "Virus:WM/Look",
              "target": "/malware/Virus:WM/Look"
            },
            {
              "id": "Skynet",
              "display_name": "Skynet",
              "target": null
            },
            {
              "id": "ketogenic switch",
              "display_name": "ketogenic switch",
              "target": null
            },
            {
              "id": "BitcoinAussie",
              "display_name": "BitcoinAussie",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1059.007",
              "name": "JavaScript",
              "display_name": "T1059.007 - JavaScript"
            },
            {
              "id": "TA0011",
              "name": "Command and Control",
              "display_name": "TA0011 - Command and Control"
            },
            {
              "id": "T1003",
              "name": "OS Credential Dumping",
              "display_name": "T1003 - OS Credential Dumping"
            },
            {
              "id": "T1071.002",
              "name": "File Transfer Protocols",
              "display_name": "T1071.002 - File Transfer Protocols"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 46,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 173,
            "FileHash-SHA1": 166,
            "FileHash-SHA256": 2841,
            "URL": 6670,
            "CVE": 4,
            "domain": 684,
            "hostname": 1930,
            "CIDR": 2,
            "email": 3
          },
          "indicator_count": 12473,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 225,
          "modified_text": "883 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "652cc4de6aa3848c3722e9a6",
          "name": "Qakbot. Again. Today. Pulled from own device. Quasar RAT, Malvertizing",
          "description": "Serious concerns. Approached, threatened & told no cyber tool or literature would help me by a stranger in public place seconds after a male demanded to know if I had a SQL book or knowledge, asked for phone #, a date , to buy only 2 books and come with him? WHAT? He really wanted my number not me. he got so close to, I thought he had a wearable hacktool device. Ongoing. I realized dumping when I typed, the letter T only for another search term, results = Tsara Brashears dead? Clean search browser history. No Auto DL file titled: government Qbot Qakbot?! I couldn't open it. Last night I got a free unauthorized penetration test, apps, awful attack. Adult content dumping from listed in references. . I don't attack is China based despite server locations.. It's too easy to appear to be attacking from another country. Can't make it up. Ongoing long. Major disruption. Issue predates research.",
          "modified": "2023-11-15T01:03:46.666000",
          "created": "2023-10-16T05:06:38.412000",
          "tags": [
            "whois record",
            "tsara brashears",
            "contacted",
            "threat roundup",
            "whois whois",
            "remcos",
            "iocs",
            "cyberstalking",
            "cry kill",
            "nanocore",
            "attack",
            "core",
            "qakbot",
            "azorult",
            "njrat",
            "colibri loader",
            "metro",
            "nokoyawa",
            "formbook",
            "bank",
            "installer",
            "daxin",
            "malware",
            "awful",
            "open",
            "korplug",
            "execution",
            "pe resource",
            "referrer",
            "dark power",
            "cobalt strike",
            "hacktool",
            "emotet",
            "chaos",
            "ransomexx",
            "quasar",
            "ursnif",
            "name verdict",
            "falcon sandbox",
            "sha256",
            "size",
            "sha1",
            "show process",
            "runtime process",
            "unicode",
            "crlf line",
            "ascii text",
            "mitre att",
            "type data",
            "hybrid",
            "general",
            "local",
            "path",
            "click",
            "strings",
            "nanjing xinfeng",
            "xiongmao group",
            "road descr",
            "district",
            "nanjing",
            "jiangsu",
            "china country",
            "apnic irt",
            "beijing",
            "china email",
            "copy md5",
            "copy sha1",
            "copy sha256",
            "AMERICA",
            "threat",
            "cyber criminal",
            "teams",
            "bounce",
            "Please Stop \u2205",
            "eminent threat",
            "Apple",
            "Android",
            "adversarial",
            "injection",
            "Tulach.cc malware",
            "scanning_host",
            "exploit_source",
            "ransomware"
          ],
          "references": [
            "https://www.hybrid-analysis.com/sample/06558031f63aca4f043b4770ae780337408b276df3b1e3e05b3d536839c3ad9e",
            "114.114.114.114",
            "http://login.live.com/oauth20_remoteconnect.srf",
            "a-poster.info",
            "https://www.anyxxxtube.net/search-porn/tsara-brashears/",
            "https://www.sweetheartvideo.com/tsara-brashears/",
            "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian"
          ],
          "public": 1,
          "adversary": "[Unnamed Teams Hacking Group]",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "Quasar RAT",
              "display_name": "Quasar RAT",
              "target": null
            },
            {
              "id": "QakBot - S0650",
              "display_name": "QakBot - S0650",
              "target": null
            },
            {
              "id": "njRAT - S0385",
              "display_name": "njRAT - S0385",
              "target": null
            },
            {
              "id": "Remcos",
              "display_name": "Remcos",
              "target": null
            },
            {
              "id": "Wanna Cry Kill Switch",
              "display_name": "Wanna Cry Kill Switch",
              "target": null
            },
            {
              "id": "RansomEXX (Windows)",
              "display_name": "RansomEXX (Windows)",
              "target": null
            },
            {
              "id": "Nanocore RAT",
              "display_name": "Nanocore RAT",
              "target": null
            },
            {
              "id": "Azorult - S0344",
              "display_name": "Azorult - S0344",
              "target": null
            },
            {
              "id": "Daxin",
              "display_name": "Daxin",
              "target": null
            },
            {
              "id": "Dark Power",
              "display_name": "Dark Power",
              "target": null
            },
            {
              "id": "Cobalt Strike",
              "display_name": "Cobalt Strike",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1176",
              "name": "Browser Extensions",
              "display_name": "T1176 - Browser Extensions"
            },
            {
              "id": "T1035",
              "name": "Service Execution",
              "display_name": "T1035 - Service Execution"
            },
            {
              "id": "T1043",
              "name": "Commonly Used Port",
              "display_name": "T1043 - Commonly Used Port"
            },
            {
              "id": "T1179",
              "name": "Hooking",
              "display_name": "T1179 - Hooking"
            },
            {
              "id": "TA0011",
              "name": "Command and Control",
              "display_name": "TA0011 - Command and Control"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 31,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 4055,
            "FileHash-MD5": 89,
            "FileHash-SHA1": 85,
            "FileHash-SHA256": 1478,
            "domain": 290,
            "hostname": 1047,
            "FilePath": 2,
            "Mutex": 1,
            "CVE": 2,
            "CIDR": 1,
            "email": 1
          },
          "indicator_count": 7051,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 225,
          "modified_text": "887 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "http://ww1.karnalketo.com/astroshift-soundtrack-cheat-code-incl-product-key-download-3264bit-latest/                  error code 432    server nginx",
        "67.227.226.240             command_and_control. [lb01.parklogic.com] Lansing Michigan",
        "110.249.196.101.          malware_hosting",
        "https://www.milehighmedia.com/en/pornstar/milehighmedia/Justin-Hunt/51017    Another target?",
        "louisianarooflawyers.com         [phishing]",
        "vmwarevmc.com",
        "https://www.hybrid-analysis.com/sample/06558031f63aca4f043b4770ae780337408b276df3b1e3e05b3d536839c3ad9e/652c962002e18b99e20e891a",
        "1.62.64.108                  malware_hosting",
        "a0bc39001c6efcf39dbc6b7684232cce5126dcf0364c37e902714898ec097e94 [apple to windows China ??]",
        "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian",
        "https://www.anyxxxtube.net/search-porn/tsara-brashears/",
        "www.sweetheartvideo.com",
        "https://wallpapers-nature.com/%20tsara-brashears/urlscan-io        BitcoinAussie",
        "wallpapers-nature.com",
        "nr-data.net                                 Private Apple data collection",
        "0.0.0.0                                            iplocal=comcast [iplocalpple.com, possibly misconfigured]         exploit",
        "https://www.anyxxxtube.net/search-porn/tsara-brashears/    phishing",
        "IPv4 198.54.117.218 command_and_control",
        "https://www.pornhub.com    prism.exe  [Massachusetts, US]",
        "https://twitter.com/PORNO_SEXYBABES - Nokoyawa  catapult spider",
        "199.249.230.74            traffic group 78",
        "64.190.63.136        Malicious. IP: Sedo GmbH",
        "114.114.114.114",
        "a-poster.info",
        "https://www.hybrid-analysis.com/sample/c0c84df54b890bb408fc2289f1e75a29991127bbe207aa30042616b5ea150342/655d9af5679c7afcc409895e",
        "https://www.hybrid-analysis.com/sample/06558031f63aca4f043b4770ae780337408b276df3b1e3e05b3d536839c3ad9e",
        "IPv4 198.54.117.212 command_and_control",
        "http://michaela.young@uchealth.com",
        "IPv4 198.54.117.215 command_and_control",
        "IPv4 198.54.117.217 command_and_control",
        "newrelic.se                                  New Update Apple iPhone 199.59.243.222",
        "https://itunes.apple.com/app/apple-store/id284815942/us/app/samsung-galaxy-watch-gear-s/id1117310635 [HappyRabbit]",
        "https://tulach.cc/    phishing | Proxy | Skynet",
        "https://www.uchealth.com/wp-content/uploads/2017/12/UCHealthInsuranceIndex_120417.pdf",
        "https://lelosexgame.com/datingsm?ad_campaign_id=3161239&cost=0&creative_id=2032565&external_id=0&keyword=%25KW%25&ref=https://example.com&ref_domain=example.com&server_node=0&source=0",
        "itunes.apple.com.                     [https:///app/apple-store",
        "IPv4 198.54.117.210 command_and_control",
        "tv.apple.com                               Apple hacking",
        "IPv4 198.54.117.211 command_and_control",
        "20.99.186.246               exploit_source",
        "https://itunes.apple.com/app/apple-store/id284815942/us/app/samsung-galaxy-watch-gear-s/id1117310635   exploit  [You can pair older Samsung watches with an iPhone by downloading the Samsung Galaxy Watch (Gear S) app from the iOS App. Abused remotely?]",
        "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian     password cracker",
        "https://otx.alienvault.com/indicator/url/https://www.milehighmedia.com/en/Charlie-Dean/pornstar/49512 ?  A target on my devices?",
        "https://www.sweetheartvideo.com/tsara-brashears/Tracker and Botnet campaign",
        "http://karnalketo.com/sound-found                             error code 432      server nginx",
        "114.114.1114.114",
        "https://www.anyxxxtube.net/search-porn/tsara-brashears/ phishing",
        "https://www.milehighmedia.com/en/Charlie-Dean/pornstar/49512   [Colorado, US referenced malvertizing outfit]",
        "http://t.trkitok.com/track/rep?oid=2001&st=1&id=DP2441--w1VJE427J8SGGRTP02MD7UEG___93737493-c08b-4dc7-ad30-b17a2c09e771___$mid",
        "a-poster.info                 [tagging tool]",
        "CVE-2022-26134",
        "hasownproperty.call",
        "tx-p2p-pull.video-voip.com.dorm.com",
        "uchealth.com",
        "tvapp-server.de",
        "apple-securityiphone-icloud.com",
        "www.anyxxxtube.net               prism.exe",
        "http://intranet.uchealth.com/Policies/Corporate%20Policies/Standards%20of%20Performance%20and%20Conduct.pdf",
        "https://www.milehighmedia.com/en/pornstar/milehighmedia/Justin-Hunt/51017 [Colorado, US references]",
        "https://www.sweetheartvideo.com/tsara-brashears/",
        "https://www.virustotal.com/graph/g03fce3ad62f74ad59bbcda71bfdde96da39417641c9a470f99adfa9b14a7724c",
        "https://wallpapers-nature.com/tsara-brashears/tse1-mm-bing-net \tketogenic switch , BitcoinAussie",
        "http://login.live.com/oauth20_remoteconnect.srf",
        "www.sweetheartvideo.com      Tracking and Botnet campaign",
        "\u2193Interesting\u2193",
        "https://gpt.ocloo.cn/auth",
        "zeustracker.abuse.ch",
        "ransomwaretracker.abuse.ch",
        "http://updates.voicemailaccess.net/b0f6a00b15311023",
        "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian  (iPhone unlocker)",
        "https://api2018.uchealth.com/apihc/tass/webportal/apihealthcare_live/default.aspx",
        "https://twitter.com/               catapult spider/spider"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 0
        },
        "other": {
          "adversary": [
            "[Unnamed Teams Hacking Group]",
            "Unconfirmed Adversary",
            "[Unnamed US Teams and Hacker group]"
          ],
          "malware_families": [
            "Korplug",
            "Redline stealer",
            "Dark power",
            "Mimikatz",
            "Azorult - s0344",
            "Meterpreter",
            "Installcore",
            "Qakbot - s0650",
            "Colbalt strike",
            "Qakbot",
            "Bitcoinaussie",
            "Opencandy",
            "Wanna cry kill switch",
            "Chaos",
            "Emotet",
            "Quasar rat",
            "Virus:wm/look",
            "Daxin",
            "Formbook",
            "Ransomware",
            "Skynet",
            "Trojanx",
            "Hsbc",
            "Ketogenic switch",
            "Virus:dos/nanjing",
            "Ursnif - s0386",
            "Raccoon",
            "Tulach",
            "Inmortal",
            "Et",
            "Blacknet",
            "Unruy",
            "Generic",
            "Ransomexx (windows)",
            "Colibri loader",
            "Nanocore rat",
            "Lumma stealer",
            "Njrat - s0385",
            "Brashears",
            "Ransomexx",
            "Cobalt strike",
            "Network rat",
            "Trojanspy",
            "Radar ineractive",
            "Remcos",
            "Nokoyawa",
            "Brontok",
            "Blacknet rat"
          ],
          "industries": [
            "Healthcare",
            "Education"
          ],
          "unique_indicators": 57808
        }
      }
    },
    "false_positive": [],
    "alexa": "http://www.alexa.com/siteinfo/cinedigm.com",
    "whois": "http://whois.domaintools.com/cinedigm.com",
    "domain": "cinedigm.com",
    "hostname": "bobross-pluto.cinedigm.com"
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 17,
  "pulses": [
    {
      "id": "6533120ed78adc8baa57b9d0",
      "name": "quick look at 79.12.165.51",
      "description": "",
      "modified": "2025-10-25T02:11:11.653000",
      "created": "2023-10-20T23:49:34.890000",
      "tags": [],
      "references": [
        "https://www.virustotal.com/graph/g03fce3ad62f74ad59bbcda71bfdde96da39417641c9a470f99adfa9b14a7724c"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 20,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "skocherhan",
        "id": "249290",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_249290/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 9,
        "FileHash-SHA1": 9,
        "FileHash-SHA256": 1650,
        "URL": 1744,
        "domain": 339,
        "email": 1,
        "hostname": 834,
        "CVE": 1
      },
      "indicator_count": 4587,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 179,
      "modified_text": "177 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6564fa9a3d90d1cd14928b16",
      "name": "Lumma \u2022 University of Alberta \"No Problems\" | T1036 - Masquerading",
      "description": "I was contacted on this forum re: University of Alberta issue. Based on research  www.ualberta.ca redirects. There hasn't been a research effort for redirect. I researched a spoofed website. After viewing senders request, my devices operating system changed, isn't recognized by any accounts, keyloggers.\nFound: Anonymizers, Redirector, Masquerading, Network RAT, Serious Social Engineering, Botnetwork Army, Stealers, Lumma and weirdly targeted  'Tsara Brashears' as a malicious link on a spoofed University in Canada, UCHealth Colorado links.",
      "modified": "2023-12-27T19:03:02.665000",
      "created": "2023-11-27T20:22:50.050000",
      "tags": [
        "threat report",
        "back",
        "ip summary",
        "url summary",
        "summary",
        "download csv",
        "download",
        "json url",
        "urls",
        "detection list",
        "cisco umbrella",
        "site",
        "heur",
        "safe site",
        "alexa top",
        "million",
        "malware",
        "malicious site",
        "phishing site",
        "malicious url",
        "phishing",
        "riskware",
        "presenoker",
        "artemis",
        "agent",
        "unsafe",
        "opencandy",
        "ursnif",
        "wacatac",
        "team",
        "facebook",
        "runescape",
        "service",
        "downldr",
        "psexec",
        "occamy",
        "brontok",
        "zpevdo",
        "startpage",
        "nanocore",
        "keygen",
        "installcore",
        "fareit",
        "secrisk",
        "exploit",
        "mimikatz",
        "sorano",
        "emotet",
        "genkryptik",
        "fuery",
        "dbatloader",
        "qakbot",
        "alexa",
        "malicious",
        "union",
        "lumma stealer",
        "fusioncore",
        "cleaner",
        "azorult",
        "bank",
        "blacknet rat",
        "stealer",
        "iframe",
        "trojanspy",
        "analysis",
        "united",
        "firehol",
        "proxy",
        "mail spammer",
        "downloader",
        "malware site",
        "meterpreter",
        "qbot",
        "bankerx",
        "dropper",
        "nimda",
        "formbook",
        "swrort",
        "unruy",
        "adwind",
        "trojanx",
        "crack",
        "win64",
        "generic",
        "dnspionage",
        "expirestue",
        "path",
        "http response",
        "final url",
        "ip address",
        "status code",
        "body length",
        "kb body",
        "sha256",
        "headers",
        "alberta",
        "university",
        "edmonton",
        "html info",
        "alberta meta",
        "tags",
        "trackers google",
        "tag manager",
        "gtmkr32",
        "blacklist",
        "low risk",
        "apache",
        "domain",
        "malware found",
        "unknown",
        "minimal low",
        "security risk",
        "medium high",
        "critical",
        "protect",
        "college",
        "mtis",
        "faculties",
        "research",
        "health",
        "a about",
        "news",
        "events",
        "sport",
        "life",
        "find",
        "story",
        "tools",
        "getprocaddress",
        "indicator",
        "prefetch8",
        "mitre att",
        "ck id",
        "show technique",
        "ck matrix",
        "pattern match",
        "file",
        "date",
        "factory",
        "hybrid",
        "general",
        "cookie",
        "click",
        "strings",
        "djin",
        "no data",
        "tag count",
        "sample",
        "samples",
        "netsky",
        "cobalt strike",
        "xrat",
        "fakealert",
        "raccoon",
        "redline stealer",
        "metastealer",
        "icedid",
        "quasar rat",
        "acint",
        "anonymizer",
        "blockchain",
        "social engineering",
        "read c",
        "search",
        "show",
        "medium",
        "entries",
        "whitelisted",
        "memcommit",
        "delete",
        "yara detections",
        "next",
        "dock",
        "write",
        "execution",
        "copy",
        "south carolina",
        "federal credit",
        "team proxy",
        "static engine",
        "covid19",
        "redirector",
        "suspic",
        "tue mar",
        "zbot",
        "size68b type",
        "count blacklist",
        "tag tag",
        "rejected sample",
        "icon",
        "analyzed",
        "hwp support",
        "falcon sandbox",
        "multi scan",
        "update",
        "view details",
        "upgrade",
        "blacklist https",
        "keyloggers"
      ],
      "references": [
        "https://www.anyxxxtube.net/search-porn/tsara-brashears/ phishing",
        "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian  (iPhone unlocker)",
        "uchealth.com",
        "http://michaela.young@uchealth.com",
        "http://intranet.uchealth.com/Policies/Corporate%20Policies/Standards%20of%20Performance%20and%20Conduct.pdf",
        "https://api2018.uchealth.com/apihc/tass/webportal/apihealthcare_live/default.aspx",
        "https://www.uchealth.com/wp-content/uploads/2017/12/UCHealthInsuranceIndex_120417.pdf"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "TrojanSpy",
          "display_name": "TrojanSpy",
          "target": null
        },
        {
          "id": "Qakbot",
          "display_name": "Qakbot",
          "target": null
        },
        {
          "id": "MimiKatz",
          "display_name": "MimiKatz",
          "target": null
        },
        {
          "id": "RedLine Stealer",
          "display_name": "RedLine Stealer",
          "target": null
        },
        {
          "id": "Network RAT",
          "display_name": "Network RAT",
          "target": null
        },
        {
          "id": "Quasar RAT",
          "display_name": "Quasar RAT",
          "target": null
        },
        {
          "id": "Emotet",
          "display_name": "Emotet",
          "target": null
        },
        {
          "id": "Lumma Stealer",
          "display_name": "Lumma Stealer",
          "target": null
        },
        {
          "id": "Raccoon",
          "display_name": "Raccoon",
          "target": null
        },
        {
          "id": "OpenCandy",
          "display_name": "OpenCandy",
          "target": null
        },
        {
          "id": "Meterpreter",
          "display_name": "Meterpreter",
          "target": null
        },
        {
          "id": "Unruy",
          "display_name": "Unruy",
          "target": null
        },
        {
          "id": "TrojanX",
          "display_name": "TrojanX",
          "target": null
        },
        {
          "id": "BlackNET RAT",
          "display_name": "BlackNET RAT",
          "target": null
        },
        {
          "id": "Brontok",
          "display_name": "Brontok",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1036",
          "name": "Masquerading",
          "display_name": "T1036 - Masquerading"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1083",
          "name": "File and Directory Discovery",
          "display_name": "T1083 - File and Directory Discovery"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1106",
          "name": "Native API",
          "display_name": "T1106 - Native API"
        },
        {
          "id": "T1114",
          "name": "Email Collection",
          "display_name": "T1114 - Email Collection"
        },
        {
          "id": "T1129",
          "name": "Shared Modules",
          "display_name": "T1129 - Shared Modules"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1518",
          "name": "Software Discovery",
          "display_name": "T1518 - Software Discovery"
        },
        {
          "id": "T1546",
          "name": "Event Triggered Execution",
          "display_name": "T1546 - Event Triggered Execution"
        },
        {
          "id": "T1588",
          "name": "Obtain Capabilities",
          "display_name": "T1588 - Obtain Capabilities"
        },
        {
          "id": "T1588.004",
          "name": "Digital Certificates",
          "display_name": "T1588.004 - Digital Certificates"
        },
        {
          "id": "T1546.015",
          "name": "Component Object Model Hijacking",
          "display_name": "T1546.015 - Component Object Model Hijacking"
        },
        {
          "id": "T1126",
          "name": "Network Share Connection Removal",
          "display_name": "T1126 - Network Share Connection Removal"
        },
        {
          "id": "T1136",
          "name": "Create Account",
          "display_name": "T1136 - Create Account"
        },
        {
          "id": "T1071.004",
          "name": "DNS",
          "display_name": "T1071.004 - DNS"
        },
        {
          "id": "T1059.007",
          "name": "JavaScript",
          "display_name": "T1059.007 - JavaScript"
        },
        {
          "id": "T1071.001",
          "name": "Web Protocols",
          "display_name": "T1071.001 - Web Protocols"
        },
        {
          "id": "T1071.003",
          "name": "Mail Protocols",
          "display_name": "T1071.003 - Mail Protocols"
        },
        {
          "id": "T1518.001",
          "name": "Security Software Discovery",
          "display_name": "T1518.001 - Security Software Discovery"
        },
        {
          "id": "T1053",
          "name": "Scheduled Task/Job",
          "display_name": "T1053 - Scheduled Task/Job"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1119",
          "name": "Automated Collection",
          "display_name": "T1119 - Automated Collection"
        },
        {
          "id": "T1143",
          "name": "Hidden Window",
          "display_name": "T1143 - Hidden Window"
        },
        {
          "id": "T1056.001",
          "name": "Keylogging",
          "display_name": "T1056.001 - Keylogging"
        },
        {
          "id": "T1134.004",
          "name": "Parent PID Spoofing",
          "display_name": "T1134.004 - Parent PID Spoofing"
        }
      ],
      "industries": [
        "Education",
        "Healthcare"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 83,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 320,
        "FileHash-SHA1": 172,
        "FileHash-SHA256": 4302,
        "URL": 8243,
        "CIDR": 1,
        "domain": 1742,
        "hostname": 2270,
        "CVE": 18,
        "SSLCertFingerprint": 3,
        "email": 4
      },
      "indicator_count": 17075,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 222,
      "modified_text": "844 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "655dafbe9ac9ac786fde45ad",
      "name": "http://malwaredomainlist.com/ \u2022 CNC \u2022 Spyware \u2022 Tracking",
      "description": "Network capture, dga domain, ecc domain, data collection, voicemail access, mail spammer, registrar abuse\n\n[Auto populated. I can't cannot confirm or deny the accuracy of the following information: A summary of key facts and information about a malicious web domain, hosted by the US government, has been released by Google.com and its parent company, Alphabet, for use on its website.]",
      "modified": "2023-12-22T06:03:01.993000",
      "created": "2023-11-22T07:37:34.595000",
      "tags": [
        "united",
        "as22612",
        "as2637",
        "creation date",
        "search",
        "moved",
        "expiration date",
        "date",
        "showing",
        "as397240",
        "next",
        "entries",
        "scan endpoints",
        "all octoseek",
        "dns replication",
        "win32 exe",
        "network capture",
        "android",
        "android adaway",
        "html",
        "files",
        "detections type",
        "name",
        "office open",
        "xml document",
        "namecheap",
        "namecheap inc",
        "whois lookups",
        "win32 dll",
        "text",
        "wextract",
        "text htaccess",
        "powershell",
        "detection list",
        "blacklist",
        "first",
        "ssl certificate",
        "whois record",
        "contacted",
        "december",
        "whois whois",
        "threat roundup",
        "historical ssl",
        "problems",
        "referrer",
        "pe resource",
        "startpage",
        "cyber threat",
        "redline stealer",
        "mail spammer",
        "hostname",
        "phishing site",
        "malicious site",
        "installcore",
        "http spammer",
        "malware site",
        "malware",
        "generic malware",
        "heur",
        "generic",
        "alexa top",
        "million",
        "site",
        "cisco umbrella",
        "alexa",
        "ip address",
        "algorithm",
        "data",
        "v3 serial",
        "number",
        "cat cnzerossl",
        "ecc domain",
        "secure site",
        "ca ozerossl",
        "validity",
        "subject public",
        "server",
        "email",
        "code",
        "registrar abuse",
        "country",
        "privacy service",
        "withheld",
        "privacy",
        "domain name",
        "pattern match",
        "ascii text",
        "appdata",
        "file",
        "windows nt",
        "svg scalable",
        "vector graphics",
        "indicator",
        "gif image",
        "accept",
        "hybrid",
        "general",
        "local",
        "pixel",
        "click",
        "twitter",
        "strings",
        "class",
        "generator",
        "critical",
        "command_and_control",
        "spyware",
        "tracking",
        "voicemail access",
        "dga",
        "apple"
      ],
      "references": [
        "https://www.hybrid-analysis.com/sample/c0c84df54b890bb408fc2289f1e75a29991127bbe207aa30042616b5ea150342/655d9af5679c7afcc409895e",
        "\u2193Interesting\u2193",
        "IPv4 198.54.117.211 command_and_control",
        "IPv4 198.54.117.210 command_and_control",
        "IPv4 198.54.117.212 command_and_control",
        "IPv4 198.54.117.215 command_and_control",
        "IPv4 198.54.117.217 command_and_control",
        "IPv4 198.54.117.218 command_and_control",
        "apple-securityiphone-icloud.com",
        "tx-p2p-pull.video-voip.com.dorm.com",
        "http://updates.voicemailaccess.net/b0f6a00b15311023",
        "tvapp-server.de",
        "zeustracker.abuse.ch",
        "ransomwaretracker.abuse.ch",
        "http://t.trkitok.com/track/rep?oid=2001&st=1&id=DP2441--w1VJE427J8SGGRTP02MD7UEG___93737493-c08b-4dc7-ad30-b17a2c09e771___$mid",
        "louisianarooflawyers.com         [phishing]",
        "hasownproperty.call"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "Generic",
          "display_name": "Generic",
          "target": null
        },
        {
          "id": "BlackNET",
          "display_name": "BlackNET",
          "target": null
        },
        {
          "id": "InstallCore",
          "display_name": "InstallCore",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1114",
          "name": "Email Collection",
          "display_name": "T1114 - Email Collection"
        },
        {
          "id": "T1560",
          "name": "Archive Collected Data",
          "display_name": "T1560 - Archive Collected Data"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 51,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 105,
        "FileHash-SHA1": 100,
        "FileHash-SHA256": 3072,
        "domain": 1188,
        "email": 5,
        "URL": 7940,
        "hostname": 1925,
        "CVE": 1
      },
      "indicator_count": 14336,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 228,
      "modified_text": "850 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "655ae7b85bce5b026a160389",
      "name": "Command and Control Server and Services CRITICAL",
      "description": "HSBC\nInmortal\nRadar Ineractive\nRuleset Match:\nBackSwap Trojan detection by Ariel Millahuel\nCARROTBAT Malware detection by Ariel Millahuel",
      "modified": "2023-12-20T03:01:11.128000",
      "created": "2023-11-20T04:59:36.506000",
      "tags": [
        "contacted",
        "execution",
        "dropped",
        "threat roundup",
        "august",
        "apple ios",
        "contacted urls",
        "referrer",
        "october",
        "april",
        "core",
        "february",
        "hacktool",
        "installer",
        "urls",
        "ovh sas",
        "domains",
        "ip detections",
        "country",
        "type name",
        "win32 exe",
        "noname057",
        "generic malware",
        "tag count",
        "threat report",
        "ip summary",
        "url summary",
        "summary",
        "sample",
        "samples",
        "detection list",
        "blacklist http",
        "cisco umbrella",
        "site",
        "safe site",
        "wormx",
        "malicious site",
        "alexa top",
        "malware site",
        "million",
        "malicious url",
        "phishing site",
        "malware",
        "alexa",
        "phishing",
        "agent",
        "bank",
        "inmortal",
        "united",
        "cyber threat",
        "pony",
        "cnc zeus",
        "tracker",
        "cnc server",
        "covid19",
        "engineering",
        "http spammer",
        "host",
        "azorult",
        "asyncrat",
        "cobalt strike",
        "team",
        "hsbc",
        "file size",
        "files",
        "file type",
        "kb file",
        "highly targeted",
        "apple",
        "password",
        "tsara brashears",
        "awful",
        "radar ineractive",
        "no data",
        "blacklist",
        "malvertizing",
        "masquerading",
        "tulach",
        "114.114.114.114",
        "Noname057"
      ],
      "references": [],
      "public": 1,
      "adversary": "Unconfirmed Adversary",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "Inmortal",
          "display_name": "Inmortal",
          "target": null
        },
        {
          "id": "HSBC",
          "display_name": "HSBC",
          "target": null
        },
        {
          "id": "Radar Ineractive",
          "display_name": "Radar Ineractive",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1176",
          "name": "Browser Extensions",
          "display_name": "T1176 - Browser Extensions"
        },
        {
          "id": "T1094",
          "name": "Custom Command and Control Protocol",
          "display_name": "T1094 - Custom Command and Control Protocol"
        },
        {
          "id": "TA0004",
          "name": "Privilege Escalation",
          "display_name": "TA0004 - Privilege Escalation"
        },
        {
          "id": "TA0002",
          "name": "Execution",
          "display_name": "TA0002 - Execution"
        },
        {
          "id": "TA0001",
          "name": "Initial Access",
          "display_name": "TA0001 - Initial Access"
        },
        {
          "id": "TA0009",
          "name": "Collection",
          "display_name": "TA0009 - Collection"
        },
        {
          "id": "TA0011",
          "name": "Command and Control",
          "display_name": "TA0011 - Command and Control"
        },
        {
          "id": "T1449",
          "name": "Exploit SS7 to Redirect Phone Calls/SMS",
          "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
        },
        {
          "id": "T1059.002",
          "name": "AppleScript",
          "display_name": "T1059.002 - AppleScript"
        },
        {
          "id": "T1102",
          "name": "Web Service",
          "display_name": "T1102 - Web Service"
        },
        {
          "id": "T1011",
          "name": "Exfiltration Over Other Network Medium",
          "display_name": "T1011 - Exfiltration Over Other Network Medium"
        },
        {
          "id": "T1100",
          "name": "Web Shell",
          "display_name": "T1100 - Web Shell"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1059.007",
          "name": "JavaScript",
          "display_name": "T1059.007 - JavaScript"
        },
        {
          "id": "T1041",
          "name": "Exfiltration Over C2 Channel",
          "display_name": "T1041 - Exfiltration Over C2 Channel"
        },
        {
          "id": "T1036",
          "name": "Masquerading",
          "display_name": "T1036 - Masquerading"
        },
        {
          "id": "T1548",
          "name": "Abuse Elevation Control Mechanism",
          "display_name": "T1548 - Abuse Elevation Control Mechanism"
        },
        {
          "id": "T1098",
          "name": "Account Manipulation",
          "display_name": "T1098 - Account Manipulation"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 28,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 1,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 729,
        "FileHash-MD5": 950,
        "FileHash-SHA1": 482,
        "FileHash-SHA256": 878,
        "domain": 139,
        "hostname": 300,
        "CVE": 1
      },
      "indicator_count": 3479,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 220,
      "modified_text": "852 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "654d29a8dbbe8d0bcc16ed1a",
      "name": "iOS Tracking \u2192 imitation imap: imap.kehlenbach.net | C2 | Cybercrime",
      "description": "",
      "modified": "2023-12-09T08:01:01.882000",
      "created": "2023-11-09T18:49:12.887000",
      "tags": [
        "ssl certificate",
        "tsara brashears",
        "apple ios",
        "whois record",
        "virus network",
        "critical risk",
        "tracker",
        "cyberstalking",
        "drive",
        "apple phone",
        "hacktool",
        "installer",
        "brashears",
        "et"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "BRASHEARS",
          "display_name": "BRASHEARS",
          "target": null
        },
        {
          "id": "ET",
          "display_name": "ET",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1056",
          "name": "Input Capture",
          "display_name": "T1056 - Input Capture"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": "654cabd6bb3319558bf2cd38",
      "export_count": 7,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "scoreblue",
        "id": "254100",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 99,
        "FileHash-SHA1": 97,
        "FileHash-SHA256": 1170,
        "domain": 593,
        "hostname": 1179,
        "URL": 3246
      },
      "indicator_count": 6384,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 224,
      "modified_text": "863 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "654cabd6bb3319558bf2cd38",
      "name": "iOS Tracking \u2192 imitation imap: imap.kehlenbach.net | C2 | Cybercrime",
      "description": "BotNet campaign, malvertizing, radar tracking, iOS, OS, IP, dns, location tracking, password cracker, faux Pinterest, phishing, malicious domain.\nTargets:\nhttps://pin.it/ (Dangerous IP)\nhttps://www.anyxxxtube.net/search-porn/tsara-brashears/ (phishing)\t\nhttps://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian\n(password cracker)\t\nhttps://www.pornhub.com/video/search?search=tsara+brashears ( Buff Achievement Tracker)\nhttps://www.sweetheartvideo.com/tsara-brashears/   (botnetwork, tracking):\npin.it (TB IP)\nww.google.com.uy. (Brashears IP addresses) \notc.greatcall.com (Botnetwork, tracking call)\n0-129-103-71imap-intranet-pv-175-166.matomo.cloud (location collection, call, message, email)\nhttps://www.assurant.com/?utm_source=email&utm_medium=email&utm_campaign=Mobile_Transactional_withad&utm_content=Deductible+Charge+Acknowledgement+PD-MB&utm_term= (Transactional email collection)\n\napple iOS, imap",
      "modified": "2023-12-09T08:01:01.882000",
      "created": "2023-11-09T09:52:22.834000",
      "tags": [
        "ssl certificate",
        "tsara brashears",
        "apple ios",
        "whois record",
        "virus network",
        "critical risk",
        "tracker",
        "cyberstalking",
        "drive",
        "apple phone",
        "hacktool",
        "installer",
        "brashears",
        "et"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "BRASHEARS",
          "display_name": "BRASHEARS",
          "target": null
        },
        {
          "id": "ET",
          "display_name": "ET",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1056",
          "name": "Input Capture",
          "display_name": "T1056 - Input Capture"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 9,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 99,
        "FileHash-SHA1": 97,
        "FileHash-SHA256": 1170,
        "domain": 593,
        "hostname": 1179,
        "URL": 3246
      },
      "indicator_count": 6384,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 218,
      "modified_text": "863 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6570a989843b7acf6d0a79ac",
      "name": "Qakbot. Again. Today. Pulled from own device. Quasar RAT, Malvertizing",
      "description": "",
      "modified": "2023-12-06T17:04:09.133000",
      "created": "2023-12-06T17:04:09.133000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 15,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "CVE": 2,
        "domain": 290,
        "FileHash-SHA256": 1478,
        "hostname": 1047,
        "URL": 4055,
        "FileHash-MD5": 89,
        "FileHash-SHA1": 85,
        "email": 1,
        "FilePath": 2,
        "Mutex": 1,
        "CIDR": 1
      },
      "indicator_count": 7051,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 110,
      "modified_text": "865 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "653eb87c9e4d74a97585f1d1",
      "name": "https://developer.paypal.com/docs/classic/paypal-payments-standard/integration-guide/encryptedwebpayments/",
      "description": "",
      "modified": "2023-11-28T20:03:34.441000",
      "created": "2023-10-29T19:54:36.146000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 16,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "ellenmmm",
        "id": "233693",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 1747,
        "domain": 552,
        "hostname": 623,
        "FileHash-SHA256": 303,
        "FileHash-MD5": 135,
        "FileHash-SHA1": 49
      },
      "indicator_count": 3409,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 82,
      "modified_text": "873 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "653f1ffb074d89724cb81371",
      "name": "Tracker and Botnet campaign - Canto XXVI",
      "description": "",
      "modified": "2023-11-19T00:04:57.528000",
      "created": "2023-10-30T03:16:11.181000",
      "tags": [
        "contacted",
        "tsara brashears",
        "whois record",
        "whois whois",
        "threat roundup",
        "december",
        "execution",
        "referrer",
        "pe resource",
        "remcos",
        "malware",
        "quasar",
        "nanocore",
        "attack",
        "core",
        "qakbot",
        "azorult",
        "njrat",
        "colibri loader",
        "metro",
        "nokoyawa",
        "formbook",
        "bank",
        "installer",
        "daxin",
        "awful",
        "open",
        "korplug",
        "dark power",
        "cobalt strike",
        "hacktool",
        "emotet",
        "chaos",
        "ransomexx",
        "ursnif",
        "ransomware",
        "pattern match",
        "et tor",
        "known tor",
        "misc attack",
        "relayrouter",
        "exit",
        "node traffic",
        "beginstring",
        "script",
        "segoe ui",
        "null",
        "error",
        "unknown",
        "span",
        "date",
        "body",
        "refresh",
        "class",
        "critical",
        "tools",
        "look",
        "verify",
        "restart",
        "hybrid",
        "general",
        "click",
        "strings",
        "meta",
        "xiongmao group",
        "district",
        "nanjing",
        "china country",
        "beijing",
        "please",
        "apnic person",
        "road",
        "china phone",
        "whois lookup",
        "cnnic",
        "dns replication",
        "domain",
        "win32 exe",
        "files",
        "detections type",
        "name",
        "notepad",
        "java",
        "update checker",
        "type name",
        "android",
        "win32 dll",
        "cyber criminals",
        "cyber stalking",
        "cyber warfare",
        "framing",
        "tulach.cc",
        "exploit_source",
        "scanning_host",
        "phishing",
        "adware",
        "command_and_control",
        "C2",
        "technology",
        "virustotal xn",
        "technology xn",
        "rich text",
        "format po",
        "jyoti cnc",
        "detection list",
        "blacklist",
        "noname057",
        "proxy",
        "prism.exe",
        "password cracker",
        "skynet",
        "malvertizing",
        "spyware",
        "colorado",
        "arizona",
        "prism command line tool",
        "keyloggers",
        "apple",
        "I'm being followed",
        "threats",
        "sha256",
        "osint",
        "vmware",
        "gpt",
        "nginx",
        "piracy",
        "intellectual property",
        "spammer",
        "honeypot",
        "tracker",
        "tracking campaign",
        "Botnet campaign"
      ],
      "references": [
        "114.114.1114.114",
        "https://www.anyxxxtube.net/search-porn/tsara-brashears/    phishing",
        "https://wallpapers-nature.com/tsara-brashears/tse1-mm-bing-net \tketogenic switch , BitcoinAussie",
        "wallpapers-nature.com",
        "https://wallpapers-nature.com/%20tsara-brashears/urlscan-io        BitcoinAussie",
        "www.sweetheartvideo.com",
        "https://www.sweetheartvideo.com/tsara-brashears/Tracker and Botnet campaign",
        "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian     password cracker",
        "a-poster.info                 [tagging tool]",
        "https://tulach.cc/    phishing | Proxy | Skynet",
        "67.227.226.240             command_and_control. [lb01.parklogic.com] Lansing Michigan",
        "20.99.186.246               exploit_source",
        "https://www.hybrid-analysis.com/sample/06558031f63aca4f043b4770ae780337408b276df3b1e3e05b3d536839c3ad9e/652c962002e18b99e20e891a",
        "1.62.64.108                  malware_hosting",
        "110.249.196.101.          malware_hosting",
        "CVE-2022-26134",
        "www.anyxxxtube.net               prism.exe",
        "https://www.pornhub.com    prism.exe  [Massachusetts, US]",
        "https://www.milehighmedia.com/en/Charlie-Dean/pornstar/49512   [Colorado, US referenced malvertizing outfit]",
        "https://www.milehighmedia.com/en/pornstar/milehighmedia/Justin-Hunt/51017 [Colorado, US references]",
        "https://twitter.com/PORNO_SEXYBABES - Nokoyawa  catapult spider",
        "https://twitter.com/               catapult spider/spider",
        "nr-data.net                                 Private Apple data collection",
        "tv.apple.com                               Apple hacking",
        "newrelic.se                                  New Update Apple iPhone 199.59.243.222",
        "0.0.0.0                                            iplocal=comcast [iplocalpple.com, possibly misconfigured]         exploit",
        "https://itunes.apple.com/app/apple-store/id284815942/us/app/samsung-galaxy-watch-gear-s/id1117310635   exploit  [You can pair older Samsung watches with an iPhone by downloading the Samsung Galaxy Watch (Gear S) app from the iOS App. Abused remotely?]",
        "itunes.apple.com.                     [https:///app/apple-store",
        "https://itunes.apple.com/app/apple-store/id284815942/us/app/samsung-galaxy-watch-gear-s/id1117310635 [HappyRabbit]",
        "a0bc39001c6efcf39dbc6b7684232cce5126dcf0364c37e902714898ec097e94 [apple to windows China ??]",
        "https://otx.alienvault.com/indicator/url/https://www.milehighmedia.com/en/Charlie-Dean/pornstar/49512 ?  A target on my devices?",
        "https://www.milehighmedia.com/en/pornstar/milehighmedia/Justin-Hunt/51017    Another target?",
        "https://lelosexgame.com/datingsm?ad_campaign_id=3161239&cost=0&creative_id=2032565&external_id=0&keyword=%25KW%25&ref=https://example.com&ref_domain=example.com&server_node=0&source=0",
        "199.249.230.74            traffic group 78",
        "https://gpt.ocloo.cn/auth",
        "vmwarevmc.com",
        "http://karnalketo.com/sound-found                             error code 432      server nginx",
        "http://ww1.karnalketo.com/astroshift-soundtrack-cheat-code-incl-product-key-download-3264bit-latest/                  error code 432    server nginx",
        "64.190.63.136        Malicious. IP: Sedo GmbH",
        "www.sweetheartvideo.com      Tracking and Botnet campaign"
      ],
      "public": 1,
      "adversary": "[Unnamed US Teams and Hacker group]",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "QakBot - S0650",
          "display_name": "QakBot - S0650",
          "target": null
        },
        {
          "id": "Ransomexx",
          "display_name": "Ransomexx",
          "target": null
        },
        {
          "id": "Azorult - S0344",
          "display_name": "Azorult - S0344",
          "target": null
        },
        {
          "id": "Formbook",
          "display_name": "Formbook",
          "target": null
        },
        {
          "id": "Korplug",
          "display_name": "Korplug",
          "target": null
        },
        {
          "id": "Colbalt Strike",
          "display_name": "Colbalt Strike",
          "target": null
        },
        {
          "id": "Remcos",
          "display_name": "Remcos",
          "target": null
        },
        {
          "id": "Colibri Loader",
          "display_name": "Colibri Loader",
          "target": null
        },
        {
          "id": "Quasar RAT",
          "display_name": "Quasar RAT",
          "target": null
        },
        {
          "id": "Nokoyawa",
          "display_name": "Nokoyawa",
          "target": null
        },
        {
          "id": "Emotet",
          "display_name": "Emotet",
          "target": null
        },
        {
          "id": "njRAT - S0385",
          "display_name": "njRAT - S0385",
          "target": null
        },
        {
          "id": "Chaos",
          "display_name": "Chaos",
          "target": null
        },
        {
          "id": "Ursnif - S0386",
          "display_name": "Ursnif - S0386",
          "target": null
        },
        {
          "id": "Virus:DOS/Nanjing",
          "display_name": "Virus:DOS/Nanjing",
          "target": "/malware/Virus:DOS/Nanjing"
        },
        {
          "id": "Daxin",
          "display_name": "Daxin",
          "target": null
        },
        {
          "id": "Tulach",
          "display_name": "Tulach",
          "target": null
        },
        {
          "id": "Ransomware",
          "display_name": "Ransomware",
          "target": null
        },
        {
          "id": "Virus:WM/Look",
          "display_name": "Virus:WM/Look",
          "target": "/malware/Virus:WM/Look"
        },
        {
          "id": "Skynet",
          "display_name": "Skynet",
          "target": null
        },
        {
          "id": "ketogenic switch",
          "display_name": "ketogenic switch",
          "target": null
        },
        {
          "id": "BitcoinAussie",
          "display_name": "BitcoinAussie",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1497",
          "name": "Virtualization/Sandbox Evasion",
          "display_name": "T1497 - Virtualization/Sandbox Evasion"
        },
        {
          "id": "T1059.007",
          "name": "JavaScript",
          "display_name": "T1059.007 - JavaScript"
        },
        {
          "id": "TA0011",
          "name": "Command and Control",
          "display_name": "TA0011 - Command and Control"
        },
        {
          "id": "T1003",
          "name": "OS Credential Dumping",
          "display_name": "T1003 - OS Credential Dumping"
        },
        {
          "id": "T1071.002",
          "name": "File Transfer Protocols",
          "display_name": "T1071.002 - File Transfer Protocols"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": "653323de61317f6ca7a3e875",
      "export_count": 26,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 173,
        "FileHash-SHA1": 166,
        "FileHash-SHA256": 2841,
        "URL": 6670,
        "CVE": 4,
        "domain": 684,
        "hostname": 1930,
        "CIDR": 2,
        "email": 3
      },
      "indicator_count": 12473,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 218,
      "modified_text": "883 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "653f200c20e12f03f749c403",
      "name": "114.114.114.114 Tracking | Botnet | Malvertizing",
      "description": "",
      "modified": "2023-11-19T00:04:57.528000",
      "created": "2023-10-30T03:16:28.252000",
      "tags": [
        "contacted",
        "tsara brashears",
        "whois record",
        "whois whois",
        "threat roundup",
        "december",
        "execution",
        "referrer",
        "pe resource",
        "remcos",
        "malware",
        "quasar",
        "nanocore",
        "attack",
        "core",
        "qakbot",
        "azorult",
        "njrat",
        "colibri loader",
        "metro",
        "nokoyawa",
        "formbook",
        "bank",
        "installer",
        "daxin",
        "awful",
        "open",
        "korplug",
        "dark power",
        "cobalt strike",
        "hacktool",
        "emotet",
        "chaos",
        "ransomexx",
        "ursnif",
        "ransomware",
        "pattern match",
        "et tor",
        "known tor",
        "misc attack",
        "relayrouter",
        "exit",
        "node traffic",
        "beginstring",
        "script",
        "segoe ui",
        "null",
        "error",
        "unknown",
        "span",
        "date",
        "body",
        "refresh",
        "class",
        "critical",
        "tools",
        "look",
        "verify",
        "restart",
        "hybrid",
        "general",
        "click",
        "strings",
        "meta",
        "xiongmao group",
        "district",
        "nanjing",
        "china country",
        "beijing",
        "please",
        "apnic person",
        "road",
        "china phone",
        "whois lookup",
        "cnnic",
        "dns replication",
        "domain",
        "win32 exe",
        "files",
        "detections type",
        "name",
        "notepad",
        "java",
        "update checker",
        "type name",
        "android",
        "win32 dll",
        "cyber criminals",
        "cyber stalking",
        "cyber warfare",
        "framing",
        "tulach.cc",
        "exploit_source",
        "scanning_host",
        "phishing",
        "adware",
        "command_and_control",
        "C2",
        "technology",
        "virustotal xn",
        "technology xn",
        "rich text",
        "format po",
        "jyoti cnc",
        "detection list",
        "blacklist",
        "noname057",
        "proxy",
        "prism.exe",
        "password cracker",
        "skynet",
        "malvertizing",
        "spyware",
        "colorado",
        "arizona",
        "prism command line tool",
        "keyloggers",
        "apple",
        "I'm being followed",
        "threats",
        "sha256",
        "osint",
        "vmware",
        "gpt",
        "nginx",
        "piracy",
        "intellectual property",
        "spammer",
        "honeypot",
        "tracker",
        "tracking campaign",
        "Botnet campaign"
      ],
      "references": [
        "114.114.1114.114",
        "https://www.anyxxxtube.net/search-porn/tsara-brashears/    phishing",
        "https://wallpapers-nature.com/tsara-brashears/tse1-mm-bing-net \tketogenic switch , BitcoinAussie",
        "wallpapers-nature.com",
        "https://wallpapers-nature.com/%20tsara-brashears/urlscan-io        BitcoinAussie",
        "www.sweetheartvideo.com",
        "https://www.sweetheartvideo.com/tsara-brashears/Tracker and Botnet campaign",
        "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian     password cracker",
        "a-poster.info                 [tagging tool]",
        "https://tulach.cc/    phishing | Proxy | Skynet",
        "67.227.226.240             command_and_control. [lb01.parklogic.com] Lansing Michigan",
        "20.99.186.246               exploit_source",
        "https://www.hybrid-analysis.com/sample/06558031f63aca4f043b4770ae780337408b276df3b1e3e05b3d536839c3ad9e/652c962002e18b99e20e891a",
        "1.62.64.108                  malware_hosting",
        "110.249.196.101.          malware_hosting",
        "CVE-2022-26134",
        "www.anyxxxtube.net               prism.exe",
        "https://www.pornhub.com    prism.exe  [Massachusetts, US]",
        "https://www.milehighmedia.com/en/Charlie-Dean/pornstar/49512   [Colorado, US referenced malvertizing outfit]",
        "https://www.milehighmedia.com/en/pornstar/milehighmedia/Justin-Hunt/51017 [Colorado, US references]",
        "https://twitter.com/PORNO_SEXYBABES - Nokoyawa  catapult spider",
        "https://twitter.com/               catapult spider/spider",
        "nr-data.net                                 Private Apple data collection",
        "tv.apple.com                               Apple hacking",
        "newrelic.se                                  New Update Apple iPhone 199.59.243.222",
        "0.0.0.0                                            iplocal=comcast [iplocalpple.com, possibly misconfigured]         exploit",
        "https://itunes.apple.com/app/apple-store/id284815942/us/app/samsung-galaxy-watch-gear-s/id1117310635   exploit  [You can pair older Samsung watches with an iPhone by downloading the Samsung Galaxy Watch (Gear S) app from the iOS App. Abused remotely?]",
        "itunes.apple.com.                     [https:///app/apple-store",
        "https://itunes.apple.com/app/apple-store/id284815942/us/app/samsung-galaxy-watch-gear-s/id1117310635 [HappyRabbit]",
        "a0bc39001c6efcf39dbc6b7684232cce5126dcf0364c37e902714898ec097e94 [apple to windows China ??]",
        "https://otx.alienvault.com/indicator/url/https://www.milehighmedia.com/en/Charlie-Dean/pornstar/49512 ?  A target on my devices?",
        "https://www.milehighmedia.com/en/pornstar/milehighmedia/Justin-Hunt/51017    Another target?",
        "https://lelosexgame.com/datingsm?ad_campaign_id=3161239&cost=0&creative_id=2032565&external_id=0&keyword=%25KW%25&ref=https://example.com&ref_domain=example.com&server_node=0&source=0",
        "199.249.230.74            traffic group 78",
        "https://gpt.ocloo.cn/auth",
        "vmwarevmc.com",
        "http://karnalketo.com/sound-found                             error code 432      server nginx",
        "http://ww1.karnalketo.com/astroshift-soundtrack-cheat-code-incl-product-key-download-3264bit-latest/                  error code 432    server nginx",
        "64.190.63.136        Malicious. IP: Sedo GmbH",
        "www.sweetheartvideo.com      Tracking and Botnet campaign"
      ],
      "public": 1,
      "adversary": "[Unnamed US Teams and Hacker group]",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "QakBot - S0650",
          "display_name": "QakBot - S0650",
          "target": null
        },
        {
          "id": "Ransomexx",
          "display_name": "Ransomexx",
          "target": null
        },
        {
          "id": "Azorult - S0344",
          "display_name": "Azorult - S0344",
          "target": null
        },
        {
          "id": "Formbook",
          "display_name": "Formbook",
          "target": null
        },
        {
          "id": "Korplug",
          "display_name": "Korplug",
          "target": null
        },
        {
          "id": "Colbalt Strike",
          "display_name": "Colbalt Strike",
          "target": null
        },
        {
          "id": "Remcos",
          "display_name": "Remcos",
          "target": null
        },
        {
          "id": "Colibri Loader",
          "display_name": "Colibri Loader",
          "target": null
        },
        {
          "id": "Quasar RAT",
          "display_name": "Quasar RAT",
          "target": null
        },
        {
          "id": "Nokoyawa",
          "display_name": "Nokoyawa",
          "target": null
        },
        {
          "id": "Emotet",
          "display_name": "Emotet",
          "target": null
        },
        {
          "id": "njRAT - S0385",
          "display_name": "njRAT - S0385",
          "target": null
        },
        {
          "id": "Chaos",
          "display_name": "Chaos",
          "target": null
        },
        {
          "id": "Ursnif - S0386",
          "display_name": "Ursnif - S0386",
          "target": null
        },
        {
          "id": "Virus:DOS/Nanjing",
          "display_name": "Virus:DOS/Nanjing",
          "target": "/malware/Virus:DOS/Nanjing"
        },
        {
          "id": "Daxin",
          "display_name": "Daxin",
          "target": null
        },
        {
          "id": "Tulach",
          "display_name": "Tulach",
          "target": null
        },
        {
          "id": "Ransomware",
          "display_name": "Ransomware",
          "target": null
        },
        {
          "id": "Virus:WM/Look",
          "display_name": "Virus:WM/Look",
          "target": "/malware/Virus:WM/Look"
        },
        {
          "id": "Skynet",
          "display_name": "Skynet",
          "target": null
        },
        {
          "id": "ketogenic switch",
          "display_name": "ketogenic switch",
          "target": null
        },
        {
          "id": "BitcoinAussie",
          "display_name": "BitcoinAussie",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1497",
          "name": "Virtualization/Sandbox Evasion",
          "display_name": "T1497 - Virtualization/Sandbox Evasion"
        },
        {
          "id": "T1059.007",
          "name": "JavaScript",
          "display_name": "T1059.007 - JavaScript"
        },
        {
          "id": "TA0011",
          "name": "Command and Control",
          "display_name": "TA0011 - Command and Control"
        },
        {
          "id": "T1003",
          "name": "OS Credential Dumping",
          "display_name": "T1003 - OS Credential Dumping"
        },
        {
          "id": "T1071.002",
          "name": "File Transfer Protocols",
          "display_name": "T1071.002 - File Transfer Protocols"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": "6533b20cf4ad384a0193c655",
      "export_count": 28,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 173,
        "FileHash-SHA1": 166,
        "FileHash-SHA256": 2841,
        "URL": 6670,
        "CVE": 4,
        "domain": 684,
        "hostname": 1930,
        "CIDR": 2,
        "email": 3
      },
      "indicator_count": 12473,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 218,
      "modified_text": "883 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "https://bobross-pluto.cinedigm.com",
    "type": "URL"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "https://bobross-pluto.cinedigm.com",
    "type": "URL",
    "found": false,
    "verdict": "clean",
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1776684781.8040216
}