{
  "type": "URL",
  "indicator": "https://cyberfolks.pl/wp-admin/admin-ajax.php",
  "general": {
    "sections": [
      "general",
      "url_list",
      "http_scans",
      "screenshot"
    ],
    "indicator": "https://cyberfolks.pl/wp-admin/admin-ajax.php",
    "type": "url",
    "type_title": "URL",
    "validation": [
      {
        "source": "majestic",
        "message": "Whitelisted domain cyberfolks.pl",
        "name": "Whitelisted domain"
      }
    ],
    "base_indicator": {
      "id": 3951394192,
      "indicator": "https://cyberfolks.pl/wp-admin/admin-ajax.php",
      "type": "URL",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 9,
      "pulses": [
        {
          "id": "66ce8795f74ccdc8a4ad972f",
          "name": "Home | Sanselo | Realizare site web \u0219i aplica\u021bii de mobil",
          "description": "Aplica\u021bii mobile, \u00c2\u00a31bn, \u00e2\u201a\u00ac1.5bn \u00e2\u20ac\u00b5\u00a6 \u00c3\u20ac\u201c  \u00f4l iau i'r iddo.",
          "modified": "2025-05-14T21:14:50.899000",
          "created": "2024-08-28T02:12:37.280000",
          "tags": [
            "sanselo",
            "i aplicaii",
            "home",
            "realizare site",
            "servicii web",
            "mobile app",
            "contact blog",
            "selecteaz",
            "pagin",
            "future",
            "adres url",
            "ipv4",
            "ccro asnas39668",
            "intersat srl",
            "rola",
            "url http",
            "odcisk palca"
          ],
          "references": [
            "https://sanselo.com/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 3,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Arek-BTC",
            "id": "212764",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_212764/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "IPv4": 11,
            "URL": 1533,
            "domain": 150,
            "email": 2,
            "hostname": 471,
            "FileHash-MD5": 236,
            "FileHash-SHA1": 141,
            "FileHash-SHA256": 979,
            "SSLCertFingerprint": 4
          },
          "indicator_count": 3527,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 124,
          "modified_text": "381 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "66c9103736c51f12e3bcfac8",
          "name": "VGT INTERNET - pozycjonowanie, serwery, domeny, strony www, poligrafia",
          "description": "Willi Echo wedi dweud wrthod wybodaeth iawno i'wodraeth o oryginalnej architekturze, a ddydd Sadwrn.",
          "modified": "2024-12-27T01:07:36.247000",
          "created": "2024-08-23T22:41:59.321000",
          "tags": [
            "adres url",
            "profesjonalne",
            "projektowanie",
            "tworzenie",
            "stron",
            "internetowych",
            "strony",
            "internetowe",
            "pozycjonowanie",
            "poligrafia",
            "web design",
            "hosting",
            "internet",
            "cms",
            "reklama",
            "vgt internet",
            "skuteczna",
            "przegldaj",
            "skontaktuj",
            "z nami",
            "info",
            "ssl domeny",
            "copyright",
            "authority key",
            "identifier id",
            "win32",
            "whasz",
            "oszczdno",
            "win32 exe",
            "magia plik",
            "pe32 dla",
            "ms windows",
            "intel",
            "oglny plik",
            "windos",
            "generic",
            "typ pliku",
            "typ jzyk",
            "ikona rt",
            "neutralny",
            "tekst ascii",
            "wersja rt",
            "angielski usa",
            "plik",
            "file name",
            "type win32",
            "exe size",
            "mb first",
            "seen",
            "size",
            "first seen",
            "avg win32",
            "bkav undetected",
            "malicious",
            "drweb",
            "sha1",
            "sha256",
            "pehash",
            "richhash",
            "meble na wymiar",
            "meble na zam\u00f3wienie",
            "szafy",
            "meble \u0142azienkowe",
            "meble kuchenne",
            "meble biurowe",
            "zabudowy wn\u0119k",
            "blaty kamienne",
            "sprawd",
            "strong",
            "wirtualne",
            "kreatywne meble",
            "produkcja",
            "kuchnie",
            "zabudowa",
            "zwizualizuj",
            "kliknij",
            "speedtest",
            "files proofs",
            "vin syd",
            "sgp sbg",
            "rbx hil",
            "gra eri",
            "bom bhs",
            "ssl certificate",
            "noclegi szklarska por\u0119ba",
            "nocleg w szklarskiej por\u0119bie",
            "szklarska por\u0119ba pensjonat",
            "szklarska por\u0119ba",
            "pokoje",
            "pensjonat",
            "spa",
            "wakacje",
            "relaks",
            "wypoczynek",
            "willa echo",
            "willi echo",
            "szrenic",
            "tobie",
            "pastwu",
            "znajduje si",
            "azienka",
            "wifi",
            "z naczyniami",
            "bajeczne",
            "e1 f7",
            "c5 e0",
            "algorithm",
            "key identifier",
            "x509v3 subject",
            "number",
            "cus olet",
            "encrypt cnr10",
            "validity",
            "subject public",
            "key info",
            "key algorithm",
            "vhash",
            "ssdeep",
            "file type",
            "ini text"
          ],
          "references": [
            "http://sanselo.pl",
            "http://www.sanselo.pl",
            "http://vgt.pl",
            "http://www.vgt.pl",
            "http://franas.pl",
            "http://www.franas.pl",
            "https://kreatywne-meble.pl",
            "http://ovh.net/common/font/lato/light/webfont.svg",
            "https://ws.nperf.com/partner/js?l=05d1f5db-f38f-42ed-924b-87e3b0f2d5b6",
            "http://willaecho.pl/",
            "http://www.willaecho.pl/",
            "http://www.tomasz.franas.pl"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 7,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Arek-BTC",
            "id": "212764",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_212764/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 438,
            "domain": 128,
            "hostname": 524,
            "URL": 943,
            "IPv4": 23,
            "FileHash-SHA256": 3021,
            "FileHash-SHA1": 397,
            "email": 4,
            "CVE": 1
          },
          "indicator_count": 5479,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 124,
          "modified_text": "520 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "66d0a996b288ca46ab7e63ae",
          "name": "CEIDG (www.pitprojekt.pl , pitprojekt.pl) jak otworzy\u0107 firm\u0119, jak rozpocz\u0105\u0107 biznes, dzia\u0142alno\u015b\u0107 gospodarcza zak\u0142adanie, jak rozpocz\u0105\u0107 dzia\u0142alno\u015b\u0107 gospodarcz\u0105",
          "description": "Zawarte zasoby wed\u0142ug j\u0119zyka \u00c2\u00a31.1bn, a total of 7.4bn euros ($9.6bn; \u00a36.3bn)",
          "modified": "2024-12-05T21:16:06.820000",
          "created": "2024-08-29T17:02:13.392000",
          "tags": [
            "admin",
            "asset",
            "dufur",
            "jnswj",
            "3px center",
            "saxla",
            "zjloj",
            "whasz htm",
            "oszczdno",
            "png ikona",
            "rt angielski",
            "angielski usa",
            "wersja rt",
            "narzuta chi2",
            "plik",
            "whasz",
            "bogaty hash",
            "sha256",
            "ssdeep",
            "schema",
            "strings",
            "guid",
            "blob",
            "sha256 file",
            "type type",
            "vhash",
            "imphash",
            "bvgquf",
            "cblrxf",
            "coqbmf",
            "efq78c",
            "gkrikb",
            "hdvrde",
            "hlo3ef",
            "izt63",
            "jnoxi",
            "kg2exe",
            "pejzasz",
            "rticon english",
            "english us",
            "chi2",
            "png rticon",
            "ico rtgroupicon",
            "code signing",
            "algorithm",
            "serial number",
            "sectigo public",
            "thumbprint",
            "rsa time",
            "valid from",
            "name sectigo",
            "valid",
            "valid usage",
            "ascii text",
            "neutral",
            "data rtcursor",
            "data rtdialog",
            "default",
            "rticon maori",
            "ceidg",
            "informacja o",
            "usugi",
            "z wniosek",
            "sprawd",
            "zarejestruj spk",
            "centralna",
            "ewidencja",
            "strona gwna",
            "formularze i",
            "sha1",
            "pehash",
            "richhash",
            "authentihash",
            "skrt",
            "system",
            "podaj",
            "windows z",
            "kreator",
            "dostawca",
            "wifi",
            "nazwa typ",
            "md5 nazwa",
            "imphasz",
            "kropelka",
            "smyczki",
            "zasb manifestu",
            "neutralny",
            "ikona rt",
            "zawarte zasoby",
            "md5 chi2",
            "ikonagrupyrt",
            "rtmanifest",
            "zawarte",
            "sha256 typ"
          ],
          "references": [
            "https://aplikacja.ceidg.gov.pl/ceidg.cms.engine/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 16,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Arek-BTC",
            "id": "212764",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_212764/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 4501,
            "URL": 4559,
            "hostname": 1957,
            "domain": 729,
            "FileHash-MD5": 903,
            "FileHash-SHA1": 849,
            "IPv4": 180,
            "email": 3,
            "IPv6": 2,
            "CVE": 1
          },
          "indicator_count": 13684,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 125,
          "modified_text": "541 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "66caffd62b03fba176499249",
          "name": "192.168.122.26  RFC 1918 - Address Allocation for Private Internets",
          "description": "https://static.ietf.org/dt/12.22.0/ietf/js/select2.js\nhttps://static.ietf.org/dt/12.22.0/ietf/js/document_timeline.js\nhttps://static.ietf.org/dt/12.22.0/ietf/js/d3.js\n27d3ed3ed0003ed00042d43d00041df04c41293ba84f6efe3a613b22f983e6\nhttps://static.ietf.org/dt/12.22.0/ietf/js/ietf.js\nhttps://static.ietf.org/dt/12.22.0/assets/embedded-8b6f56ff.js\nhttps://static.ietf.org/dt/12.22.0/ietf/js/theme.js",
          "modified": "2024-11-29T19:44:18.974000",
          "created": "2024-08-25T09:56:38.383000",
          "tags": [
            "internet",
            "practice",
            "rekhter",
            "february",
            "best current",
            "page",
            "ip connectivity",
            "ip address",
            "allocation",
            "tcpip",
            "formats",
            "regexp",
            "string",
            "function",
            "boolean",
            "null",
            "notification",
            "number",
            "object",
            "dtbt",
            "chatlog",
            "status",
            "vhash",
            "ssdeep",
            "sha256",
            "authentihash",
            "imphash",
            "rich pe",
            "coolnovo",
            "olet",
            "encrypt",
            "cnr3",
            "oszyfrujmy",
            "cne1",
            "cnr11",
            "cnr10",
            "cne5",
            "cloudflare",
            "cne6",
            "bn english",
            "rticon english",
            "vs2010 sp1",
            "vs2010",
            "contained",
            "english us",
            "compiler",
            "utc first",
            "submission",
            "symantec time",
            "date",
            "class"
          ],
          "references": [
            "https://datatracker.ietf.org/doc/rfc1918/",
            "http://datatracker.ietf.org/doc/rfc1918/",
            "https://static.ietf.org/dt/12.22.0/ietf/js/theme.js",
            "https://static.ietf.org/dt/12.22.0/assets/embedded-8b6f56ff.js"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Arek-BTC",
            "id": "212764",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_212764/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 45,
            "email": 18,
            "hostname": 1714,
            "URL": 261,
            "FileHash-MD5": 113,
            "FileHash-SHA1": 103,
            "FileHash-SHA256": 565
          },
          "indicator_count": 2819,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 125,
          "modified_text": "547 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "66cb1a82b938d97fca42577b",
          "name": "http://sni.cloudflaressl.com/  SSL dla sni.com  and Cloudflaressl.cloudflAressL.org",
          "description": "urz\u0105dzenie5695310-7a1dc9c7-local.wd2go.com\nurz\u0105dzenie4491421-0ffc7b50-local.wd2go.com",
          "modified": "2024-11-29T19:44:16.599000",
          "created": "2024-08-25T11:50:26.438000",
          "tags": [
            "cloudflare",
            "read",
            "report",
            "zero trust",
            "contact",
            "sign",
            "view",
            "discover",
            "gartner magic",
            "quadrant",
            "protect",
            "enterprise",
            "fortune",
            "ssl certificate"
          ],
          "references": [
            "http://sni.cloudflaressl.com/"
          ],
          "public": 1,
          "adversary": "TrojanDownloader:Win32/Nemucod",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 9,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Arek-BTC",
            "id": "212764",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_212764/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 8863,
            "hostname": 2526,
            "domain": 3054,
            "FileHash-SHA256": 703,
            "FileHash-SHA1": 16,
            "IPv4": 227,
            "FileHash-MD5": 10,
            "IPv6": 8,
            "CVE": 2
          },
          "indicator_count": 15409,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 125,
          "modified_text": "547 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "66cb5560913a9cb8d451a1cd",
          "name": "Log In | Criminal IP",
          "description": "https://www.criminalip.io/intelligence/maps?query=cve_id%3Acve-1999-0016&lat=57.996911700633525&lng=20.307597029382432&latmax=85&latmin=-85&lngmax=180&lngmin=-180\nIf you want to know what is going on in your browser, spare a thought for the three-year-old, who has been caught up in the latest version of the \"rum\" search engine.",
          "modified": "2024-11-29T19:44:16.076000",
          "created": "2024-08-25T16:01:36.377000",
          "tags": [
            "typeof require",
            "typeof module",
            "typeof define",
            "error",
            "modulenotfound",
            "string",
            "date",
            "function",
            "doublequote",
            "null",
            "regexp",
            "iframe",
            "script",
            "style",
            "embed",
            "keygen",
            "meta",
            "typeof t",
            "typeerror",
            "typeof window",
            "uint8array",
            "ithis",
            "typeof",
            "invalid uuid",
            "othis",
            "typeof symbol",
            "generator",
            "array",
            "pfunction",
            "rfunction",
            "ttfb",
            "typeof crypto",
            "typeof mscrypto",
            "typeof e",
            "typeof r",
            "whasz",
            "ip lookup",
            "port check",
            "vulnerability scanner",
            "attack surface",
            "cyber threat intelligence",
            "cti",
            "asm",
            "domain",
            "exploit",
            "phishing",
            "criminal ip",
            "apis",
            "criminal",
            "search engine",
            "strong",
            "login",
            "ai spera",
            "ip search",
            "engine products",
            "about contact",
            "twitter",
            "contact",
            "sha1"
          ],
          "references": [
            "https://cdnjs.cloudflare.com/ajax/libs/parallax/3.1.0/parallax.min.js",
            "https://apis.google.com/js/platform.js",
            "https://static.ads-twitter.com/uwt.js",
            "https://static.cloudflareinsights.com/beacon.min.js/vcd15cbe7772f49c399c6a5babf22c1241717689176015/",
            "https://www.criminalip.io/intelligence/maps?query=cve_id%3Acve-1999-0016&lat=57.996911700633525&lng=20.307597029382432&latmax=85&latmin=-85&lngmax=180&lngmin=-180"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 31,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Arek-BTC",
            "id": "212764",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_212764/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 118,
            "URL": 242,
            "FileHash-MD5": 773,
            "FileHash-SHA1": 752,
            "FileHash-SHA256": 3277,
            "domain": 24,
            "email": 11
          },
          "indicator_count": 5197,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 125,
          "modified_text": "547 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "66c515f2f84211938e2fbeb5",
          "name": "www.domek-karkonosze.pl , www.domwkrate.pl , www.dom-w-karkonoszach.com",
          "description": "A.T.J. Sp. z o.o.\n' Domek-Karkonosze.pl '\nul. \u015awierczewskiego 70 58-531 \u0141omnica Polska Tel .075 \u2013 644 07 16 kom 605 115 258\n' DomwKrate.pl '\nul. Karkonoska 70 ( ko\u0142o Ko\u015bcio\u0142a) 58-531 \u0141omnica Polska Tel. kom. 605 115 258\n 'Dom w Karkonoszach '\nul. Prusa 17 58-540 Karpacz, Polska tel. Polska: +48 605 11 52 58 \ntel. Niemcy: +49 30 212 34 190",
          "modified": "2024-11-02T18:45:48.928000",
          "created": "2024-08-20T22:17:22.809000",
          "tags": [
            "karkonoszach",
            "karkonoszy",
            "euro za",
            "pastwo",
            "krat",
            "polska",
            "polskie",
            "okolica domu",
            "pastwo spdzi",
            "dajemy wam",
            "domeny",
            "wersja",
            "www tls",
            "encrypt",
            "wystawcy ca",
            "b59bn znak",
            "ad26",
            "kod odpowiedzi",
            "gmt typ",
            "treci",
            "vary",
            "false",
            "dom w karkonoszach",
            "apartamenty karkonosze",
            "apartamenty karpacz",
            "strong",
            "karkonoszach z",
            "karpacz",
            "home",
            "o domu",
            "galeria cennik",
            "wolne terminy",
            "kontakt",
            "relaks",
            "sha256",
            "oszczdno",
            "authority key",
            "identifier id",
            "vhash",
            "ssdeep",
            "historical ssl",
            "ssl certificate",
            "pe resource",
            "whois",
            "referrer",
            "malware",
            "ta569"
          ],
          "references": [
            "http://domek-karkonosze.pl",
            "https://www.dom-w-karkonoszach.com/",
            "http://www.dom-w-karkonoszach.com/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 35,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Arek-BTC",
            "id": "212764",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_212764/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 197,
            "SSLCertFingerprint": 2,
            "domain": 49,
            "hostname": 118,
            "URL": 393,
            "FileHash-SHA256": 575,
            "FileHash-SHA1": 182,
            "IPv4": 3,
            "CVE": 22,
            "email": 1
          },
          "indicator_count": 1542,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 124,
          "modified_text": "574 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "66c043ccdf906b54eb6daeeb",
          "name": "EPP Status Codes | What Do They Mean, and Why Should I Know? - ICANN",
          "description": "If you are trying to register a new domain name, or want to do so, you need to know that your name is in a \"status code\" or \"registration status\" that may not be working.",
          "modified": "2024-11-02T18:45:46.177000",
          "created": "2024-08-17T06:31:40.333000",
          "tags": [
            "status",
            "epp status",
            "registry lock",
            "service",
            "whois lookup",
            "server status",
            "your domain",
            "protocol",
            "finding",
            "registry grace",
            "period",
            "icann lookup"
          ],
          "references": [
            "https://www.icann.org/resources/pages/epp-status-codes-2014-06-16-en",
            "https://lookup.icann.org/en"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1047",
              "name": "Windows Management Instrumentation",
              "display_name": "T1047 - Windows Management Instrumentation"
            },
            {
              "id": "T1543",
              "name": "Create or Modify System Process",
              "display_name": "T1543 - Create or Modify System Process"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 8,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Arek-BTC",
            "id": "212764",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_212764/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 109,
            "domain": 2,
            "hostname": 5,
            "FileHash-SHA256": 30,
            "FileHash-SHA1": 4,
            "FileHash-MD5": 10
          },
          "indicator_count": 160,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 124,
          "modified_text": "574 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "670c5ff728e6e5b891e26e45",
          "name": "IOC",
          "description": "",
          "modified": "2024-10-14T00:04:07.913000",
          "created": "2024-10-14T00:04:07.913000",
          "tags": [
            "admin",
            "asset",
            "dufur",
            "jnswj",
            "3px center",
            "saxla",
            "zjloj",
            "whasz htm",
            "oszczdno",
            "png ikona",
            "rt angielski",
            "angielski usa",
            "wersja rt",
            "narzuta chi2",
            "plik",
            "whasz",
            "bogaty hash",
            "sha256",
            "ssdeep",
            "schema",
            "strings",
            "guid",
            "blob",
            "sha256 file",
            "type type",
            "vhash",
            "imphash",
            "bvgquf",
            "cblrxf",
            "coqbmf",
            "efq78c",
            "gkrikb",
            "hdvrde",
            "hlo3ef",
            "izt63",
            "jnoxi",
            "kg2exe",
            "pejzasz",
            "rticon english",
            "english us",
            "chi2",
            "png rticon",
            "ico rtgroupicon",
            "code signing",
            "algorithm",
            "serial number",
            "sectigo public",
            "thumbprint",
            "rsa time",
            "valid from",
            "name sectigo",
            "valid",
            "valid usage",
            "ascii text",
            "neutral",
            "data rtcursor",
            "data rtdialog",
            "default",
            "rticon maori",
            "ceidg",
            "informacja o",
            "usugi",
            "z wniosek",
            "sprawd",
            "zarejestruj spk",
            "centralna",
            "ewidencja",
            "strona gwna",
            "formularze i",
            "sha1",
            "pehash",
            "richhash",
            "authentihash",
            "skrt",
            "system",
            "podaj",
            "windows z",
            "kreator",
            "dostawca",
            "wifi",
            "nazwa typ",
            "md5 nazwa",
            "imphasz",
            "kropelka",
            "smyczki",
            "zasb manifestu",
            "neutralny",
            "ikona rt",
            "zawarte zasoby",
            "md5 chi2",
            "ikonagrupyrt",
            "rtmanifest",
            "zawarte",
            "sha256 typ"
          ],
          "references": [
            "https://aplikacja.ceidg.gov.pl/ceidg.cms.engine/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": "66d0a996b288ca46ab7e63ae",
          "export_count": 15,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "WayneState",
            "id": "296756",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 4243,
            "URL": 4550,
            "hostname": 1957,
            "domain": 729,
            "FileHash-MD5": 801,
            "FileHash-SHA1": 747,
            "IPv4": 180,
            "email": 3,
            "IPv6": 2
          },
          "indicator_count": 13212,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 4,
          "modified_text": "594 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "http://www.vgt.pl",
        "http://domek-karkonosze.pl",
        "http://www.willaecho.pl/",
        "https://sanselo.com/",
        "https://kreatywne-meble.pl",
        "https://apis.google.com/js/platform.js",
        "http://www.franas.pl",
        "http://ovh.net/common/font/lato/light/webfont.svg",
        "https://www.criminalip.io/intelligence/maps?query=cve_id%3Acve-1999-0016&lat=57.996911700633525&lng=20.307597029382432&latmax=85&latmin=-85&lngmax=180&lngmin=-180",
        "https://cdnjs.cloudflare.com/ajax/libs/parallax/3.1.0/parallax.min.js",
        "https://www.dom-w-karkonoszach.com/",
        "https://datatracker.ietf.org/doc/rfc1918/",
        "https://www.icann.org/resources/pages/epp-status-codes-2014-06-16-en",
        "http://www.sanselo.pl",
        "http://franas.pl",
        "https://static.ietf.org/dt/12.22.0/assets/embedded-8b6f56ff.js",
        "http://www.dom-w-karkonoszach.com/",
        "http://vgt.pl",
        "https://lookup.icann.org/en",
        "http://sni.cloudflaressl.com/",
        "https://ws.nperf.com/partner/js?l=05d1f5db-f38f-42ed-924b-87e3b0f2d5b6",
        "https://static.ads-twitter.com/uwt.js",
        "http://datatracker.ietf.org/doc/rfc1918/",
        "http://sanselo.pl",
        "http://www.tomasz.franas.pl",
        "https://static.ietf.org/dt/12.22.0/ietf/js/theme.js",
        "https://aplikacja.ceidg.gov.pl/ceidg.cms.engine/",
        "http://willaecho.pl/",
        "https://static.cloudflareinsights.com/beacon.min.js/vcd15cbe7772f49c399c6a5babf22c1241717689176015/"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 0
        },
        "other": {
          "adversary": [
            "TrojanDownloader:Win32/Nemucod"
          ],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 34469
        }
      }
    },
    "false_positive": [],
    "alexa": "http://www.alexa.com/siteinfo/cyberfolks.pl",
    "whois": "http://whois.domaintools.com/cyberfolks.pl",
    "domain": "cyberfolks.pl",
    "hostname": "Unavailable"
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 9,
  "pulses": [
    {
      "id": "66ce8795f74ccdc8a4ad972f",
      "name": "Home | Sanselo | Realizare site web \u0219i aplica\u021bii de mobil",
      "description": "Aplica\u021bii mobile, \u00c2\u00a31bn, \u00e2\u201a\u00ac1.5bn \u00e2\u20ac\u00b5\u00a6 \u00c3\u20ac\u201c  \u00f4l iau i'r iddo.",
      "modified": "2025-05-14T21:14:50.899000",
      "created": "2024-08-28T02:12:37.280000",
      "tags": [
        "sanselo",
        "i aplicaii",
        "home",
        "realizare site",
        "servicii web",
        "mobile app",
        "contact blog",
        "selecteaz",
        "pagin",
        "future",
        "adres url",
        "ipv4",
        "ccro asnas39668",
        "intersat srl",
        "rola",
        "url http",
        "odcisk palca"
      ],
      "references": [
        "https://sanselo.com/"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 3,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Arek-BTC",
        "id": "212764",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_212764/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "IPv4": 11,
        "URL": 1533,
        "domain": 150,
        "email": 2,
        "hostname": 471,
        "FileHash-MD5": 236,
        "FileHash-SHA1": 141,
        "FileHash-SHA256": 979,
        "SSLCertFingerprint": 4
      },
      "indicator_count": 3527,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 124,
      "modified_text": "381 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "66c9103736c51f12e3bcfac8",
      "name": "VGT INTERNET - pozycjonowanie, serwery, domeny, strony www, poligrafia",
      "description": "Willi Echo wedi dweud wrthod wybodaeth iawno i'wodraeth o oryginalnej architekturze, a ddydd Sadwrn.",
      "modified": "2024-12-27T01:07:36.247000",
      "created": "2024-08-23T22:41:59.321000",
      "tags": [
        "adres url",
        "profesjonalne",
        "projektowanie",
        "tworzenie",
        "stron",
        "internetowych",
        "strony",
        "internetowe",
        "pozycjonowanie",
        "poligrafia",
        "web design",
        "hosting",
        "internet",
        "cms",
        "reklama",
        "vgt internet",
        "skuteczna",
        "przegldaj",
        "skontaktuj",
        "z nami",
        "info",
        "ssl domeny",
        "copyright",
        "authority key",
        "identifier id",
        "win32",
        "whasz",
        "oszczdno",
        "win32 exe",
        "magia plik",
        "pe32 dla",
        "ms windows",
        "intel",
        "oglny plik",
        "windos",
        "generic",
        "typ pliku",
        "typ jzyk",
        "ikona rt",
        "neutralny",
        "tekst ascii",
        "wersja rt",
        "angielski usa",
        "plik",
        "file name",
        "type win32",
        "exe size",
        "mb first",
        "seen",
        "size",
        "first seen",
        "avg win32",
        "bkav undetected",
        "malicious",
        "drweb",
        "sha1",
        "sha256",
        "pehash",
        "richhash",
        "meble na wymiar",
        "meble na zam\u00f3wienie",
        "szafy",
        "meble \u0142azienkowe",
        "meble kuchenne",
        "meble biurowe",
        "zabudowy wn\u0119k",
        "blaty kamienne",
        "sprawd",
        "strong",
        "wirtualne",
        "kreatywne meble",
        "produkcja",
        "kuchnie",
        "zabudowa",
        "zwizualizuj",
        "kliknij",
        "speedtest",
        "files proofs",
        "vin syd",
        "sgp sbg",
        "rbx hil",
        "gra eri",
        "bom bhs",
        "ssl certificate",
        "noclegi szklarska por\u0119ba",
        "nocleg w szklarskiej por\u0119bie",
        "szklarska por\u0119ba pensjonat",
        "szklarska por\u0119ba",
        "pokoje",
        "pensjonat",
        "spa",
        "wakacje",
        "relaks",
        "wypoczynek",
        "willa echo",
        "willi echo",
        "szrenic",
        "tobie",
        "pastwu",
        "znajduje si",
        "azienka",
        "wifi",
        "z naczyniami",
        "bajeczne",
        "e1 f7",
        "c5 e0",
        "algorithm",
        "key identifier",
        "x509v3 subject",
        "number",
        "cus olet",
        "encrypt cnr10",
        "validity",
        "subject public",
        "key info",
        "key algorithm",
        "vhash",
        "ssdeep",
        "file type",
        "ini text"
      ],
      "references": [
        "http://sanselo.pl",
        "http://www.sanselo.pl",
        "http://vgt.pl",
        "http://www.vgt.pl",
        "http://franas.pl",
        "http://www.franas.pl",
        "https://kreatywne-meble.pl",
        "http://ovh.net/common/font/lato/light/webfont.svg",
        "https://ws.nperf.com/partner/js?l=05d1f5db-f38f-42ed-924b-87e3b0f2d5b6",
        "http://willaecho.pl/",
        "http://www.willaecho.pl/",
        "http://www.tomasz.franas.pl"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 7,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Arek-BTC",
        "id": "212764",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_212764/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 438,
        "domain": 128,
        "hostname": 524,
        "URL": 943,
        "IPv4": 23,
        "FileHash-SHA256": 3021,
        "FileHash-SHA1": 397,
        "email": 4,
        "CVE": 1
      },
      "indicator_count": 5479,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 124,
      "modified_text": "520 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "66d0a996b288ca46ab7e63ae",
      "name": "CEIDG (www.pitprojekt.pl , pitprojekt.pl) jak otworzy\u0107 firm\u0119, jak rozpocz\u0105\u0107 biznes, dzia\u0142alno\u015b\u0107 gospodarcza zak\u0142adanie, jak rozpocz\u0105\u0107 dzia\u0142alno\u015b\u0107 gospodarcz\u0105",
      "description": "Zawarte zasoby wed\u0142ug j\u0119zyka \u00c2\u00a31.1bn, a total of 7.4bn euros ($9.6bn; \u00a36.3bn)",
      "modified": "2024-12-05T21:16:06.820000",
      "created": "2024-08-29T17:02:13.392000",
      "tags": [
        "admin",
        "asset",
        "dufur",
        "jnswj",
        "3px center",
        "saxla",
        "zjloj",
        "whasz htm",
        "oszczdno",
        "png ikona",
        "rt angielski",
        "angielski usa",
        "wersja rt",
        "narzuta chi2",
        "plik",
        "whasz",
        "bogaty hash",
        "sha256",
        "ssdeep",
        "schema",
        "strings",
        "guid",
        "blob",
        "sha256 file",
        "type type",
        "vhash",
        "imphash",
        "bvgquf",
        "cblrxf",
        "coqbmf",
        "efq78c",
        "gkrikb",
        "hdvrde",
        "hlo3ef",
        "izt63",
        "jnoxi",
        "kg2exe",
        "pejzasz",
        "rticon english",
        "english us",
        "chi2",
        "png rticon",
        "ico rtgroupicon",
        "code signing",
        "algorithm",
        "serial number",
        "sectigo public",
        "thumbprint",
        "rsa time",
        "valid from",
        "name sectigo",
        "valid",
        "valid usage",
        "ascii text",
        "neutral",
        "data rtcursor",
        "data rtdialog",
        "default",
        "rticon maori",
        "ceidg",
        "informacja o",
        "usugi",
        "z wniosek",
        "sprawd",
        "zarejestruj spk",
        "centralna",
        "ewidencja",
        "strona gwna",
        "formularze i",
        "sha1",
        "pehash",
        "richhash",
        "authentihash",
        "skrt",
        "system",
        "podaj",
        "windows z",
        "kreator",
        "dostawca",
        "wifi",
        "nazwa typ",
        "md5 nazwa",
        "imphasz",
        "kropelka",
        "smyczki",
        "zasb manifestu",
        "neutralny",
        "ikona rt",
        "zawarte zasoby",
        "md5 chi2",
        "ikonagrupyrt",
        "rtmanifest",
        "zawarte",
        "sha256 typ"
      ],
      "references": [
        "https://aplikacja.ceidg.gov.pl/ceidg.cms.engine/"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 16,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Arek-BTC",
        "id": "212764",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_212764/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 4501,
        "URL": 4559,
        "hostname": 1957,
        "domain": 729,
        "FileHash-MD5": 903,
        "FileHash-SHA1": 849,
        "IPv4": 180,
        "email": 3,
        "IPv6": 2,
        "CVE": 1
      },
      "indicator_count": 13684,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 125,
      "modified_text": "541 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "66caffd62b03fba176499249",
      "name": "192.168.122.26  RFC 1918 - Address Allocation for Private Internets",
      "description": "https://static.ietf.org/dt/12.22.0/ietf/js/select2.js\nhttps://static.ietf.org/dt/12.22.0/ietf/js/document_timeline.js\nhttps://static.ietf.org/dt/12.22.0/ietf/js/d3.js\n27d3ed3ed0003ed00042d43d00041df04c41293ba84f6efe3a613b22f983e6\nhttps://static.ietf.org/dt/12.22.0/ietf/js/ietf.js\nhttps://static.ietf.org/dt/12.22.0/assets/embedded-8b6f56ff.js\nhttps://static.ietf.org/dt/12.22.0/ietf/js/theme.js",
      "modified": "2024-11-29T19:44:18.974000",
      "created": "2024-08-25T09:56:38.383000",
      "tags": [
        "internet",
        "practice",
        "rekhter",
        "february",
        "best current",
        "page",
        "ip connectivity",
        "ip address",
        "allocation",
        "tcpip",
        "formats",
        "regexp",
        "string",
        "function",
        "boolean",
        "null",
        "notification",
        "number",
        "object",
        "dtbt",
        "chatlog",
        "status",
        "vhash",
        "ssdeep",
        "sha256",
        "authentihash",
        "imphash",
        "rich pe",
        "coolnovo",
        "olet",
        "encrypt",
        "cnr3",
        "oszyfrujmy",
        "cne1",
        "cnr11",
        "cnr10",
        "cne5",
        "cloudflare",
        "cne6",
        "bn english",
        "rticon english",
        "vs2010 sp1",
        "vs2010",
        "contained",
        "english us",
        "compiler",
        "utc first",
        "submission",
        "symantec time",
        "date",
        "class"
      ],
      "references": [
        "https://datatracker.ietf.org/doc/rfc1918/",
        "http://datatracker.ietf.org/doc/rfc1918/",
        "https://static.ietf.org/dt/12.22.0/ietf/js/theme.js",
        "https://static.ietf.org/dt/12.22.0/assets/embedded-8b6f56ff.js"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 1,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Arek-BTC",
        "id": "212764",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_212764/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 45,
        "email": 18,
        "hostname": 1714,
        "URL": 261,
        "FileHash-MD5": 113,
        "FileHash-SHA1": 103,
        "FileHash-SHA256": 565
      },
      "indicator_count": 2819,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 125,
      "modified_text": "547 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "66cb1a82b938d97fca42577b",
      "name": "http://sni.cloudflaressl.com/  SSL dla sni.com  and Cloudflaressl.cloudflAressL.org",
      "description": "urz\u0105dzenie5695310-7a1dc9c7-local.wd2go.com\nurz\u0105dzenie4491421-0ffc7b50-local.wd2go.com",
      "modified": "2024-11-29T19:44:16.599000",
      "created": "2024-08-25T11:50:26.438000",
      "tags": [
        "cloudflare",
        "read",
        "report",
        "zero trust",
        "contact",
        "sign",
        "view",
        "discover",
        "gartner magic",
        "quadrant",
        "protect",
        "enterprise",
        "fortune",
        "ssl certificate"
      ],
      "references": [
        "http://sni.cloudflaressl.com/"
      ],
      "public": 1,
      "adversary": "TrojanDownloader:Win32/Nemucod",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 9,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Arek-BTC",
        "id": "212764",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_212764/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 8863,
        "hostname": 2526,
        "domain": 3054,
        "FileHash-SHA256": 703,
        "FileHash-SHA1": 16,
        "IPv4": 227,
        "FileHash-MD5": 10,
        "IPv6": 8,
        "CVE": 2
      },
      "indicator_count": 15409,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 125,
      "modified_text": "547 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "66cb5560913a9cb8d451a1cd",
      "name": "Log In | Criminal IP",
      "description": "https://www.criminalip.io/intelligence/maps?query=cve_id%3Acve-1999-0016&lat=57.996911700633525&lng=20.307597029382432&latmax=85&latmin=-85&lngmax=180&lngmin=-180\nIf you want to know what is going on in your browser, spare a thought for the three-year-old, who has been caught up in the latest version of the \"rum\" search engine.",
      "modified": "2024-11-29T19:44:16.076000",
      "created": "2024-08-25T16:01:36.377000",
      "tags": [
        "typeof require",
        "typeof module",
        "typeof define",
        "error",
        "modulenotfound",
        "string",
        "date",
        "function",
        "doublequote",
        "null",
        "regexp",
        "iframe",
        "script",
        "style",
        "embed",
        "keygen",
        "meta",
        "typeof t",
        "typeerror",
        "typeof window",
        "uint8array",
        "ithis",
        "typeof",
        "invalid uuid",
        "othis",
        "typeof symbol",
        "generator",
        "array",
        "pfunction",
        "rfunction",
        "ttfb",
        "typeof crypto",
        "typeof mscrypto",
        "typeof e",
        "typeof r",
        "whasz",
        "ip lookup",
        "port check",
        "vulnerability scanner",
        "attack surface",
        "cyber threat intelligence",
        "cti",
        "asm",
        "domain",
        "exploit",
        "phishing",
        "criminal ip",
        "apis",
        "criminal",
        "search engine",
        "strong",
        "login",
        "ai spera",
        "ip search",
        "engine products",
        "about contact",
        "twitter",
        "contact",
        "sha1"
      ],
      "references": [
        "https://cdnjs.cloudflare.com/ajax/libs/parallax/3.1.0/parallax.min.js",
        "https://apis.google.com/js/platform.js",
        "https://static.ads-twitter.com/uwt.js",
        "https://static.cloudflareinsights.com/beacon.min.js/vcd15cbe7772f49c399c6a5babf22c1241717689176015/",
        "https://www.criminalip.io/intelligence/maps?query=cve_id%3Acve-1999-0016&lat=57.996911700633525&lng=20.307597029382432&latmax=85&latmin=-85&lngmax=180&lngmin=-180"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 31,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Arek-BTC",
        "id": "212764",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_212764/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 118,
        "URL": 242,
        "FileHash-MD5": 773,
        "FileHash-SHA1": 752,
        "FileHash-SHA256": 3277,
        "domain": 24,
        "email": 11
      },
      "indicator_count": 5197,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 125,
      "modified_text": "547 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "66c515f2f84211938e2fbeb5",
      "name": "www.domek-karkonosze.pl , www.domwkrate.pl , www.dom-w-karkonoszach.com",
      "description": "A.T.J. Sp. z o.o.\n' Domek-Karkonosze.pl '\nul. \u015awierczewskiego 70 58-531 \u0141omnica Polska Tel .075 \u2013 644 07 16 kom 605 115 258\n' DomwKrate.pl '\nul. Karkonoska 70 ( ko\u0142o Ko\u015bcio\u0142a) 58-531 \u0141omnica Polska Tel. kom. 605 115 258\n 'Dom w Karkonoszach '\nul. Prusa 17 58-540 Karpacz, Polska tel. Polska: +48 605 11 52 58 \ntel. Niemcy: +49 30 212 34 190",
      "modified": "2024-11-02T18:45:48.928000",
      "created": "2024-08-20T22:17:22.809000",
      "tags": [
        "karkonoszach",
        "karkonoszy",
        "euro za",
        "pastwo",
        "krat",
        "polska",
        "polskie",
        "okolica domu",
        "pastwo spdzi",
        "dajemy wam",
        "domeny",
        "wersja",
        "www tls",
        "encrypt",
        "wystawcy ca",
        "b59bn znak",
        "ad26",
        "kod odpowiedzi",
        "gmt typ",
        "treci",
        "vary",
        "false",
        "dom w karkonoszach",
        "apartamenty karkonosze",
        "apartamenty karpacz",
        "strong",
        "karkonoszach z",
        "karpacz",
        "home",
        "o domu",
        "galeria cennik",
        "wolne terminy",
        "kontakt",
        "relaks",
        "sha256",
        "oszczdno",
        "authority key",
        "identifier id",
        "vhash",
        "ssdeep",
        "historical ssl",
        "ssl certificate",
        "pe resource",
        "whois",
        "referrer",
        "malware",
        "ta569"
      ],
      "references": [
        "http://domek-karkonosze.pl",
        "https://www.dom-w-karkonoszach.com/",
        "http://www.dom-w-karkonoszach.com/"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 35,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Arek-BTC",
        "id": "212764",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_212764/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 197,
        "SSLCertFingerprint": 2,
        "domain": 49,
        "hostname": 118,
        "URL": 393,
        "FileHash-SHA256": 575,
        "FileHash-SHA1": 182,
        "IPv4": 3,
        "CVE": 22,
        "email": 1
      },
      "indicator_count": 1542,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 124,
      "modified_text": "574 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "66c043ccdf906b54eb6daeeb",
      "name": "EPP Status Codes | What Do They Mean, and Why Should I Know? - ICANN",
      "description": "If you are trying to register a new domain name, or want to do so, you need to know that your name is in a \"status code\" or \"registration status\" that may not be working.",
      "modified": "2024-11-02T18:45:46.177000",
      "created": "2024-08-17T06:31:40.333000",
      "tags": [
        "status",
        "epp status",
        "registry lock",
        "service",
        "whois lookup",
        "server status",
        "your domain",
        "protocol",
        "finding",
        "registry grace",
        "period",
        "icann lookup"
      ],
      "references": [
        "https://www.icann.org/resources/pages/epp-status-codes-2014-06-16-en",
        "https://lookup.icann.org/en"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1047",
          "name": "Windows Management Instrumentation",
          "display_name": "T1047 - Windows Management Instrumentation"
        },
        {
          "id": "T1543",
          "name": "Create or Modify System Process",
          "display_name": "T1543 - Create or Modify System Process"
        },
        {
          "id": "T1036",
          "name": "Masquerading",
          "display_name": "T1036 - Masquerading"
        },
        {
          "id": "T1547",
          "name": "Boot or Logon Autostart Execution",
          "display_name": "T1547 - Boot or Logon Autostart Execution"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 8,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Arek-BTC",
        "id": "212764",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_212764/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 109,
        "domain": 2,
        "hostname": 5,
        "FileHash-SHA256": 30,
        "FileHash-SHA1": 4,
        "FileHash-MD5": 10
      },
      "indicator_count": 160,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 124,
      "modified_text": "574 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "670c5ff728e6e5b891e26e45",
      "name": "IOC",
      "description": "",
      "modified": "2024-10-14T00:04:07.913000",
      "created": "2024-10-14T00:04:07.913000",
      "tags": [
        "admin",
        "asset",
        "dufur",
        "jnswj",
        "3px center",
        "saxla",
        "zjloj",
        "whasz htm",
        "oszczdno",
        "png ikona",
        "rt angielski",
        "angielski usa",
        "wersja rt",
        "narzuta chi2",
        "plik",
        "whasz",
        "bogaty hash",
        "sha256",
        "ssdeep",
        "schema",
        "strings",
        "guid",
        "blob",
        "sha256 file",
        "type type",
        "vhash",
        "imphash",
        "bvgquf",
        "cblrxf",
        "coqbmf",
        "efq78c",
        "gkrikb",
        "hdvrde",
        "hlo3ef",
        "izt63",
        "jnoxi",
        "kg2exe",
        "pejzasz",
        "rticon english",
        "english us",
        "chi2",
        "png rticon",
        "ico rtgroupicon",
        "code signing",
        "algorithm",
        "serial number",
        "sectigo public",
        "thumbprint",
        "rsa time",
        "valid from",
        "name sectigo",
        "valid",
        "valid usage",
        "ascii text",
        "neutral",
        "data rtcursor",
        "data rtdialog",
        "default",
        "rticon maori",
        "ceidg",
        "informacja o",
        "usugi",
        "z wniosek",
        "sprawd",
        "zarejestruj spk",
        "centralna",
        "ewidencja",
        "strona gwna",
        "formularze i",
        "sha1",
        "pehash",
        "richhash",
        "authentihash",
        "skrt",
        "system",
        "podaj",
        "windows z",
        "kreator",
        "dostawca",
        "wifi",
        "nazwa typ",
        "md5 nazwa",
        "imphasz",
        "kropelka",
        "smyczki",
        "zasb manifestu",
        "neutralny",
        "ikona rt",
        "zawarte zasoby",
        "md5 chi2",
        "ikonagrupyrt",
        "rtmanifest",
        "zawarte",
        "sha256 typ"
      ],
      "references": [
        "https://aplikacja.ceidg.gov.pl/ceidg.cms.engine/"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": "66d0a996b288ca46ab7e63ae",
      "export_count": 15,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "WayneState",
        "id": "296756",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 4243,
        "URL": 4550,
        "hostname": 1957,
        "domain": 729,
        "FileHash-MD5": 801,
        "FileHash-SHA1": 747,
        "IPv4": 180,
        "email": 3,
        "IPv6": 2
      },
      "indicator_count": 13212,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 4,
      "modified_text": "594 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "https://cyberfolks.pl/wp-admin/admin-ajax.php",
    "type": "URL"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "https://cyberfolks.pl/wp-admin/admin-ajax.php",
    "type": "URL",
    "found": false,
    "verdict": "clean",
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780248413.0421565
}