{
  "type": "URL",
  "indicator": "https://d-ipv4.mmapiws.com",
  "general": {
    "sections": [
      "general",
      "url_list",
      "http_scans",
      "screenshot"
    ],
    "indicator": "https://d-ipv4.mmapiws.com",
    "type": "url",
    "type_title": "URL",
    "validation": [],
    "base_indicator": {
      "id": 3907693263,
      "indicator": "https://d-ipv4.mmapiws.com",
      "type": "URL",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 5,
      "pulses": [
        {
          "id": "69560fa62bddc3d965359168",
          "name": "Mirai H5DATACENTERS.COM \u2022 Regis University Blackout  | Extranet",
          "description": "It was Data Center 5. \nH5DATACENTERS.COM \u2022 Regis University Blackout PrometheusIntelligenceTechnology.com - Extranet.  Forced out of RU for finding malicious link that targeted , tracked ,conversations , behavior, etc.,  \u201cNo one willingly signed up to be tracked.\u201dis what Tsara told Dean Archer. He said he\u2019d never seen anything like this in his life. RU ignored the risks Tsara cautioned could irreparably damage incoming students college experience and negatively impact their future. I just hope the many students who attended do not continue to suffer. Guess who the villain was? The truth teller. \n\nToday activity has stepped up. Somehow the PIT Pulse has caused a crusade of aggressive following and investigation. \n\nThere may be 10,000 vs 1 in this battle. But the One is God.",
          "modified": "2026-01-31T03:04:09.490000",
          "created": "2026-01-01T06:09:42.057000",
          "tags": [
            "http",
            "files related",
            "related tags",
            "ipv4",
            "ccus asnas20029",
            "urls",
            "domain",
            "files ip",
            "address domain",
            "ip whois",
            "passive dns",
            "gmt path",
            "hostname add",
            "files",
            "united",
            "a li",
            "trackingpin a",
            "ip address",
            "unknown aaaa",
            "error",
            "back",
            "darkness",
            "present sep",
            "a domains",
            "script urls",
            "unknown ns",
            "script domains",
            "meta",
            "apache",
            "body doctype",
            "gmt server",
            "url analysis",
            "path",
            "accept",
            "pragma",
            "west domains",
            "present dec",
            "object",
            "com cnt",
            "dem fin",
            "gov int",
            "nav onl",
            "phy pre",
            "data upload",
            "extraction",
            "found",
            "datacenter",
            "hosting",
            "vps reverse",
            "america united",
            "america asn",
            "as398101",
            "body html",
            "head title",
            "title",
            "status",
            "name servers",
            "failed",
            "all se",
            "enter sc",
            "type",
            "extra data",
            "referen",
            "manualv add",
            "indicator data",
            "port",
            "destination",
            "south korea",
            "china as4134",
            "taiwan as3462",
            "as3786 lg",
            "as4766 korea",
            "as9318 sk",
            "high",
            "tcp syn",
            "trojan",
            "pegasus",
            "malware",
            "unknown",
            "search",
            "present jan",
            "pur sta",
            "uni idc",
            "cao oti",
            "dsp cor",
            "body",
            "win32",
            "united states",
            "pulse tags",
            "palantir",
            "ad maven",
            "technology",
            "url https",
            "url http",
            "indicator role",
            "title added",
            "active related",
            "Palantir",
            "Ad-Maven",
            "Palantir",
            "Ad- Maven",
            "Prometheus Intelligence Technology",
            "skynet",
            "starfield tech",
            "flock",
            "report spam",
            "palantir ad",
            "maven",
            "botnet",
            "created",
            "days ago",
            "education",
            "tsara",
            "mirai",
            "regis",
            "brashears",
            "discovery",
            "universities",
            "tsara brashears",
            "close",
            "stop",
            "ransom",
            "capture",
            "denver"
          ],
          "references": [
            "H5DATACENTERS.COM Name Servers: NS74.DOMAINCONTROL.COM",
            "https://prometheusintelligencetechnology.com/pit/",
            "https://prometheusintelligencetechnology.com/404javascript.js",
            "https://www.secureserver.net/default404.aspx",
            "http://ocsp.starfieldtech.com/ 443 Certificate",
            "https://www.secureserver.net/default404.aspx  Server: Microsoft-IIS/7.0",
            "Set-Cookie: market=en-US; domain=secureserver.net; expires=path=/  P3P:",
            "\u201cCNT DEM FIN GOV INT NAV ONL PHY PRE PUR STA UNI IDC CAO OTI DSP COR CUR OUR IND\"",
            "Powered-By: ARR/2.5  X-Powered-By: ASP.NET",
            "href= here /a . /h2 /body /html 443 Header \u2022 HTTP/1.1 302 Found  Content-Length: 161",
            "Location: policyref=\"/w3c/p3p.xml\", CP=\"COM   X-P3P: policyref=\"/w3c/p3p.xml\", CP=\"COM",
            "\u201cCNT DEM FIN GOV INT NAV ONL PHY PRE PUR STA UNI IDC CAO OTI DSP COR CUR i OUR IND\"",
            "(Date: Tue, 13 Jun 2017 10:21:34 GMT 443 )",
            "Certificate Crldistributionpoints",
            "http://crl.starfieldtech.com/sfig2s2-0.crl 443",
            "Certificate Subjectaltname\t*.secureserver.net 443 Certificate Subjectaltname\tsecureserver.net",
            "443 Certificate Notbefore\tAug 25 16:21:59 2014 GMT 443 Certificate Caissuers",
            "Serialnumber\t27B78B2246C9C1 443 Certificate Notafter \u2022 Aug 25 16:21:59 2017 GMT 443",
            "Certificate Version 3 443 Certificate Subject\tUS 443 Certificate Subject\tArizona 443",
            "Certificate Subject Scottsdale 443 Certificate Subject\tSpecial Domain Services, LLC 443",
            "Certificate Issuer\tStarfield Technologies, Inc. 443 Certificate Issuer",
            "http://certs.starfieldtech.com/repository/ 443",
            "Certificate Issuer: Starfield Secure Certificate Authority - G2 443 Title: Object moved 443",
            "A Domains \u2022 www.secureserver.net 443 Certificate",
            "Object moved /title /head body h2 Object moved to a href= http://www.secureserver.net/default404.aspx",
            "80 Body\t here /a . /h2 /body /html 80 Header\tHTTP/1.1 302 Found  Cache-Control: private",
            "Content-Length: 160  Location: http://www.secureserver.net/default404.aspx",
            "Server: Microsoft-IIS/7.0  Set-Cookie: market=en-US; domain=secureserver.net;",
            "expires=Wed, 13-Jun-2018 10:21:35 GMT; path=/  P3P: policyref=\"/w3c/p3p.xml\",",
            "CP=\"COM CNT DEM FIN GOV INT NAV ONL PHY PRE PUR STA UNI IDC CAO OTI DSP COR CUR OUR IND\"",
            "X-Powered-By: ARR/2.5  X-Powered-By: ASP.NET  P3P: policyref=\"/w3c/p3p.xml\", CP=\"",
            "\u201cCOM CNT DEM FIN GOV INT NAV ONL PHY PRE PUR STA UNI IDC CAO OTI DSP COR CUR i OUR IND\"",
            "Date: Tue, 13 Jun 2017 10:21:34 GMT",
            "Sha1 :e4ca8288d5e4912a00482418765b58a2e22fd5dc",
            "TrackingPin (Error) A Domains: trackingpin.com \u2022 Domains: forum.trackingpin.org",
            "PDNS11.DOMAINCONTROL.COM",
            "https://otx.alienvault.com/indicator/domain/secureserver.net",
            "Unix.TrojanMirai-7640640-0 IDS Detections Bad Login root login Yara Detections is__elf",
            "Alerts: dead_host network_icmp tcp_syn_scan nolookup_communication",
            "https://den.h5datacenters.com/",
            "http://prometheusintelligencetechnology.com/pitframeitem=22fsbout-regis-univer",
            "register.blackgirldroneworld.com (Is this racist)",
            "https://stetsed.xyz/apple",
            "Palantir Ad-Maven Palantir, Ad- Maven, Prometheus Intelligence Technology",
            "Review: Jeffrey Reimer DPT assaulted & egregiously injured a patient at AMS Concentra in Denver, Co",
            "It\u2019s was sexual and violent. Patient was under the oversight of Mark Montano MD and John T. Sacha MD",
            "Patient/ Victim unaware of her workers compensation rights.",
            "Do you line how they spend your tax dollars? Attacking victims? Protecting Corporations!",
            "Quasi Government, Meta, Twitter , Palantir , Gotham , Christopher P. Ahmann , Brian Sabey",
            "I haven\u2019t mentioned the hit men they hired.",
            "Fastly.com",
            "www.skynetsoftware.com",
            "http://www.skynetsoftware.com/SNSAuth/appauth.aspx?app=myPlayerDroid&ver=1.999&key=xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx&platform=Android&reg=&devId=92841014150fc3fd&devInfo=&devEmail=&width=480&height=764&owner=19&model=Lenovo A360t",
            "http://www.skynetsoftware.com/SNSAuth/appauth.aspx?app=myPlayerDroidPro&ver=2.800&key=2w6i4y1r0sdz6q9gchjcpkal0oaiem4u8ncy3bct1vcr8e6x2w&platform=Android&devId=92841014150fc3fd&width=480&height=764&owner=19&model=Lenovo%20A360t",
            "http://www.skynetsoftware.com/SNSAuth/appauth.aspx?app=myPlayerDroidPro&ver=3.700&key=53dbnf9wrz8vc0m5xfve2q1w2r4x8fv0g1b8sfg7qi0rdxck2j&platform=Android&devId=dc9c9a616665e073&width=800&height=561&owner=19&model=VirtualBox",
            "http://www.skynetsoftware.com/myPlayer/myPlayerDroid.xml"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "Mirai",
              "display_name": "Mirai",
              "target": null
            },
            {
              "id": "Virus:Win32/Triusor.A",
              "display_name": "Virus:Win32/Triusor.A",
              "target": "/malware/Virus:Win32/Triusor.A"
            },
            {
              "id": "!InstallCreatorPro_2_0",
              "display_name": "!InstallCreatorPro_2_0",
              "target": null
            },
            {
              "id": "Unix.Trojan.Mirai-7640640-0",
              "display_name": "Unix.Trojan.Mirai-7640640-0",
              "target": null
            },
            {
              "id": "#LowFiEnableDTContinueAfterUnpacking",
              "display_name": "#LowFiEnableDTContinueAfterUnpacking",
              "target": null
            },
            {
              "id": "Win.Downloader",
              "display_name": "Win.Downloader",
              "target": null
            },
            {
              "id": "Mirai",
              "display_name": "Mirai",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1069",
              "name": "Permission Groups Discovery",
              "display_name": "T1069 - Permission Groups Discovery"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1113",
              "name": "Screen Capture",
              "display_name": "T1113 - Screen Capture"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1203",
              "name": "Exploitation for Client Execution",
              "display_name": "T1203 - Exploitation for Client Execution"
            },
            {
              "id": "T1480",
              "name": "Execution Guardrails",
              "display_name": "T1480 - Execution Guardrails"
            },
            {
              "id": "T1518",
              "name": "Software Discovery",
              "display_name": "T1518 - Software Discovery"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1568",
              "name": "Dynamic Resolution",
              "display_name": "T1568 - Dynamic Resolution"
            },
            {
              "id": "T1583",
              "name": "Acquire Infrastructure",
              "display_name": "T1583 - Acquire Infrastructure"
            }
          ],
          "industries": [
            "Education",
            "Civil Society"
          ],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 6,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Q.Vashti",
            "id": "337942",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 2817,
            "domain": 487,
            "hostname": 983,
            "FileHash-SHA256": 611,
            "FileHash-MD5": 107,
            "FileHash-SHA1": 106,
            "email": 2
          },
          "indicator_count": 5113,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 138,
          "modified_text": "78 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "695043197c2fbfda85abc1d4",
          "name": "Palantir Ad Maven tracking under various names | Espionage  Malware &Botnet associated",
          "description": "https://ad-maven.com/appcast.io/leadlander.com/affasi.com/clixtell.com/adgainersolutions.com/franecki.net/pixanalytics.com/wrethicap.info/ismatlab.com/y-track.com/ecsanalytics.com/albacross.com/bgclck.me/lptracker.io/ze-fir.com/eyereturn.com/bitmedia.io/azetklik.sk/fuelx.com/pixlee.com/hilltopads.net/reichelcormier.bid/mmapiws.com/betssonpalantir.com/b0e8.com/breaktime.com.tw/clearlink.com/sendpulse.com/pulpix.com/c3tag.com/ligatus.com/clickyab.com/buckridge.link/clickguard.com/bluecava.com/attributionmodel.com/psonstrentie.info/adnium.com/rsz.sk/aivalabs.com/dep-x.com/dmpxs.com/fraudjs.io/c3metrics.com/consumable.com/graphenedigitalanalytics.in/antifraudjs.friends2follow.com/fanplayr.com/mystighty.info/prometheusintelligencetechnology.com/fuel451.com/quitzon.net/islay.tech/vcmedia.vn/xcvgdf.party/ero-advertising.com/opolen.com.br/carts.guru/libertystmedia.com/provers.pro/bashirian.biz/mobials.com/guoshipartners.com/adabra.com/online-metrix.net/rollick.io/admicro.vn/maxmind.com/boudja.com/ppcprotect.com/just",
          "modified": "2025-12-27T20:35:37.012000",
          "created": "2025-12-27T20:35:37.012000",
          "tags": [
            "Palantir",
            "Ad- Maven",
            "Prometheus Intelligence Technology"
          ],
          "references": [
            "https://ad-maven.com/appcast.io/leadlander.com/affasi.com/clixtell.com/adgainersolutions.com/franecki.net/pixanalytics.com/wrethicap.info/ismatlab.com/y-track.com/ecsanalytics.com/albacross.com/bgclck.me/lptracker.io/ze-fir.com/eyereturn.com/bitmedia.io/azetklik.sk/fuelx.com/pixlee.com/hilltopads.net/reichelcormier.bid/mmapiws.com/betssonpalantir.com/b0e8.com/breaktime.com.tw/clearlink.com/sendpulse.com/pulpix.com/c3tag.com/ligatus.com/clickyab.com/buckridge.link/clickguard.com/bluecava.com/attributionmodel",
            "Everyone I attempt to pulse Palantir Ad-Maven it\u2019s immediately deleted from Pulse"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "Carts.Guru",
              "display_name": "Carts.Guru",
              "target": null
            }
          ],
          "attack_ids": [],
          "industries": [
            "Government",
            "Education",
            "Civil Society"
          ],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Q.Vashti",
            "id": "337942",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 82,
            "hostname": 180,
            "URL": 995,
            "FileHash-SHA256": 110
          },
          "indicator_count": 1367,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 138,
          "modified_text": "113 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "687d91b1a8f414040bfba430",
          "name": "Spyware",
          "description": "And I've been walking, talking\nBelieving the things that are true\nAnd I've been finding\nThe difference between right and wrong, bad and good\nSee me put things together\nPut them back where they belong\nWhen I look at each other\nHave I always been singing the same song?\n\nShe said\nThis is a perfect world\nRiding on an incline\nI'm staring in your face\nYou'll photograph mine\n\nI-I-I-I-I\nWhoo, ah-ha-ha\nHa-ha-ha-ha-ha-ha\n\nSomebody said that it happens all over the world\nI do believe that it's true (\u2022o\u2022)\n#spyware #MaaS #malvertizing #bullyfor$ #unethical #dangerous_tool",
          "modified": "2025-08-20T00:01:59.498000",
          "created": "2025-07-21T01:02:41.049000",
          "tags": [
            "serving ip",
            "address",
            "status",
            "utc na",
            "utc google",
            "utc facebook",
            "custom audience",
            "tag manager",
            "ua748443502",
            "utc gtmwrp73mt",
            "utc gsrdlm5jnx1",
            "utc aw937838002",
            "adsense na",
            "connect",
            "file type",
            "status code",
            "body length",
            "kb body",
            "sha256",
            "powershell",
            "b file",
            "ta0004 defense",
            "evasion ta0005",
            "command",
            "control ta0011",
            "c0002 wininet",
            "number",
            "azure rsa",
            "tls issuing",
            "cus subject",
            "stwa lredmond",
            "corporation cus",
            "algorithm",
            "cndigicert sha2",
            "secure server",
            "ca odigicert",
            "inc cus",
            "subject",
            "cnwe1 ogoogle",
            "trust",
            "cnmicrosoft ecc",
            "update secure",
            "server ca",
            "omicrosoft",
            "get http",
            "request",
            "windows nt",
            "win64",
            "khtml",
            "gecko",
            "response",
            "united",
            "search",
            "creation date",
            "expiration date",
            "name servers",
            "unknown soa",
            "germany unknown",
            "entries",
            "pulse submit",
            "url analysis",
            "date"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 8,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Q.Vashti",
            "id": "337942",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 304,
            "hostname": 796,
            "URL": 2590,
            "FileHash-SHA256": 2735,
            "FileHash-MD5": 253,
            "FileHash-SHA1": 144,
            "email": 1
          },
          "indicator_count": 6823,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 141,
          "modified_text": "243 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "66f351ce26a103377d8eb5fa",
          "name": "Sex Tokens | Injection \u00bb Porn dumping - Cyber Folks .PL | Spectrum",
          "description": "Porn dumping into targeted devices after great effort. \nHall Render has always been a Malware Hosting website.\nDrive by compromise,    \nPorn Storm compilation.\n\nhttps://api.dotz.com.br/accounts/api/default/externallogin/login",
          "modified": "2024-10-24T22:01:13.406000",
          "created": "2024-09-24T23:57:02.111000",
          "tags": [
            "url https",
            "search",
            "type indicator",
            "role title",
            "added active",
            "related pulses",
            "url http",
            "porn type",
            "showing",
            "entries",
            "tsara type",
            "pulses url",
            "adware backdoor",
            "email document",
            "exploit domain",
            "owner exploit",
            "kit exploit",
            "source file",
            "hacking tools",
            "hunting macro",
            "malware hosting",
            "memory scanning",
            "wild fantasy",
            "world",
            "download",
            "xxx video",
            "xxx sex",
            "desi",
            "tamil",
            "videos xxx",
            "hd posts",
            "photos pics",
            "https",
            "indicator role",
            "title added",
            "active related",
            "unknown",
            "united",
            "for privacy",
            "nxdomain",
            "meta",
            "internet gmbh",
            "creation date",
            "date",
            "audio",
            "clear hindi",
            "bhabi sex",
            "bedroom indian",
            "fakaid",
            "ww3008",
            "fingering her",
            "young boy",
            "sexy",
            "next",
            "witch",
            "filehashmd5",
            "ipv4",
            "months ago",
            "information",
            "scan endpoints",
            "all scoreblue",
            "report spam",
            "created",
            "modified",
            "zbot",
            "keyword",
            "latina",
            "teen sex",
            "jeffrey reimer",
            "reimer dpt",
            "jeff reimer sex",
            "reimer type",
            "hostname",
            "domain",
            "copyright",
            "remote",
            "t1003",
            "os credential",
            "dumping",
            "t1012",
            "t1036",
            "t1071",
            "protocol",
            "t1082",
            "as8075",
            "aaaa",
            "as30148 sucuri",
            "certificate",
            "record value",
            "body",
            "status",
            "passive dns",
            "urls",
            "hallrender",
            "brian sabey",
            "sabey xxx",
            "drive by compromise",
            "cobalt strike",
            "overview ip",
            "address",
            "related nids",
            "files location",
            "china flag",
            "china domain",
            "files related",
            "pulses none",
            "files domain",
            "analyzer paste",
            "iocs",
            "hostnames",
            "urls https",
            "china unknown",
            "as4837 china",
            "redacted for",
            "a domains",
            "cname",
            "jeffrey reimer pt",
            "sucuri website",
            "span td",
            "time",
            "firewall",
            "win64",
            "back",
            "xtra",
            "name servers",
            "files",
            "tls web",
            "log id",
            "gmtn",
            "false",
            "ocsp",
            "ca issuers",
            "phucket news",
            "hacking",
            "registrar abuse",
            "gateway protocol abuse",
            "swipper relationship"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1003",
              "name": "OS Credential Dumping",
              "display_name": "T1003 - OS Credential Dumping"
            },
            {
              "id": "T1012",
              "name": "Query Registry",
              "display_name": "T1012 - Query Registry"
            },
            {
              "id": "T1023",
              "name": "Shortcut Modification",
              "display_name": "T1023 - Shortcut Modification"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1040",
              "name": "Network Sniffing",
              "display_name": "T1040 - Network Sniffing"
            },
            {
              "id": "T1045",
              "name": "Software Packing",
              "display_name": "T1045 - Software Packing"
            },
            {
              "id": "T1047",
              "name": "Windows Management Instrumentation",
              "display_name": "T1047 - Windows Management Instrumentation"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1060",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1060 - Registry Run Keys / Startup Folder"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1089",
              "name": "Disabling Security Tools",
              "display_name": "T1089 - Disabling Security Tools"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1112",
              "name": "Modify Registry",
              "display_name": "T1112 - Modify Registry"
            },
            {
              "id": "T1119",
              "name": "Automated Collection",
              "display_name": "T1119 - Automated Collection"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1133",
              "name": "External Remote Services",
              "display_name": "T1133 - External Remote Services"
            },
            {
              "id": "T1143",
              "name": "Hidden Window",
              "display_name": "T1143 - Hidden Window"
            },
            {
              "id": "T1189",
              "name": "Drive-by Compromise",
              "display_name": "T1189 - Drive-by Compromise"
            },
            {
              "id": "T1203",
              "name": "Exploitation for Client Execution",
              "display_name": "T1203 - Exploitation for Client Execution"
            },
            {
              "id": "T1204",
              "name": "User Execution",
              "display_name": "T1204 - User Execution"
            },
            {
              "id": "T1210",
              "name": "Exploitation of Remote Services",
              "display_name": "T1210 - Exploitation of Remote Services"
            },
            {
              "id": "T1428",
              "name": "Exploit Enterprise Resources",
              "display_name": "T1428 - Exploit Enterprise Resources"
            },
            {
              "id": "T1485",
              "name": "Data Destruction",
              "display_name": "T1485 - Data Destruction"
            },
            {
              "id": "T1564",
              "name": "Hide Artifacts",
              "display_name": "T1564 - Hide Artifacts"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 29,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 1599,
            "hostname": 2988,
            "URL": 8561,
            "FileHash-SHA256": 1207,
            "email": 41,
            "FileHash-MD5": 126,
            "FileHash-SHA1": 36,
            "CVE": 1,
            "SSLCertFingerprint": 2
          },
          "indicator_count": 14561,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 226,
          "modified_text": "542 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6671e5844c155814e69ba4dd",
          "name": "Mirai Botnet Injection  affecting Alienvault.",
          "description": "It's unclear if some users or service itself is injecting users or if service is under a Mirai attack. I found evidence of both outbound & inbound activities.  *Crowdsourced context: Activity related to MIRAI - according to source Cluster25 - \nThis IPV4 is used by MIRAI. Mirai is a malware that created a big botnet of networked devices running Linux making them remotely controlled bots that can be used for large-scale network attacks. It primarily targets online consumer devices such as IP cameras and home routers.\n#zbetcheckin tracker\nDownloaded on 2023-11-07 19:34:59 UTC\nSRC URL : http://171.228.209.167/x86_64\nIP : 171.228.209.167\nAS : AS7552 Viettel Group\nYARA : #contentis_base64 #debuggerpattern__rdtsc #ip #math_entropy_6 #is__elf #http #ft_elf #executable_elf64",
          "modified": "2024-07-18T19:02:50.386000",
          "created": "2024-06-18T19:52:36.849000",
          "tags": [
            "problems",
            "threat network",
            "infrastructure",
            "historical ssl",
            "microsoft stuff",
            "domain check",
            "referrer",
            "generic malware",
            "injector",
            "no data",
            "tag count",
            "fri mar",
            "analyzer threat",
            "ip summary",
            "url summary",
            "summary",
            "downloader",
            "generic",
            "united",
            "as14315",
            "passive dns",
            "scan endpoints",
            "all scoreblue",
            "ipv4",
            "pulse pulses",
            "urls",
            "files",
            "america asn",
            "unknown",
            "ransom",
            "body",
            "coinminer",
            "malware generic",
            "wed jan",
            "first",
            "status",
            "creation date",
            "search",
            "date",
            "expiration date",
            "name servers",
            "next",
            "mirai",
            "yara detections",
            "filehash",
            "av detections",
            "ids detections",
            "alerts",
            "analysis date",
            "file score",
            "reverse dns",
            "location lao",
            "viet nam",
            "domain",
            "all search",
            "otx scoreblue",
            "hostname",
            "files ip",
            "lazarus",
            "as7552 viettel",
            "vietnam unknown",
            "win32",
            "worm",
            "win32sfone jul",
            "vietnam",
            "etag",
            "telecom",
            "as16625 akamai",
            "as20940",
            "germany",
            "united kingdom",
            "singapore",
            "as20546 soprado",
            "hong kong",
            "as45102 alibaba",
            "taobao network",
            "cname",
            "aaaa",
            "entries",
            "showing",
            "a domains",
            "as38731 vietel",
            "plesk",
            "a li",
            "default page",
            "plesk a",
            "mirai variant",
            "useragent",
            "apache",
            "accept",
            "hello",
            "create c",
            "read c",
            "delete",
            "write",
            "default",
            "create",
            "show",
            "medium",
            "dock",
            "execution",
            "copy",
            "xport",
            "address",
            "as131392",
            "cape",
            "orsam",
            "malware",
            "script urls",
            "moved",
            "record value",
            "cisco umbrella",
            "site",
            "heur",
            "alexa top",
            "safe site",
            "million",
            "malicious site",
            "phishing site",
            "malicious url",
            "opencandy",
            "exploit",
            "agent",
            "phishing",
            "acint",
            "iframe",
            "crack",
            "conduit",
            "artemis",
            "riskware",
            "mimikatz",
            "swrort",
            "downldr",
            "systweak",
            "behav",
            "tiggre",
            "genkryptik",
            "presenoker",
            "filetour",
            "cleaner",
            "wacatac",
            "outbreak",
            "installcore",
            "iobit",
            "rostpay",
            "dropper",
            "mediaget",
            "related pulses",
            "whois",
            "related",
            "msil",
            "zombie",
            "dridex",
            "location viet",
            "pulse submit",
            "url analysis",
            "content",
            "google tag",
            "utc gcfezl5ynvb",
            "utc na",
            "utc google",
            "analytics na",
            "utc linkedin",
            "insight tag",
            "deep malware",
            "iframes",
            "trackers",
            "external-resources",
            "text/html",
            "elf info",
            "header class",
            "elf64 data",
            "header version",
            "os abi",
            "unix",
            "v object",
            "file type",
            "exec",
            "executable file",
            "progbits",
            "type address",
            "offset size",
            "flags",
            "null",
            "nobits",
            "strtab",
            "ip detections",
            "country",
            "us bundled",
            "detections file",
            "name",
            "graph summary",
            "get hello",
            "jaws webserver",
            "outbound",
            "mvpower dvr",
            "shell uce",
            "inbound",
            "activity mirai",
            "mirai",
            "info",
            "performs dns",
            "mitre att",
            "access ta0006",
            "os credential",
            "dumping t1003",
            "enumerates",
            "command",
            "control ta0011",
            "protocol t1071",
            "protocol t1095",
            "relacionada",
            "mirai malware",
            "mirai 04022024",
            "nciipc",
            "ip reputaion",
            "msie",
            "windows nt",
            "slcc2",
            "media center",
            "china as37963",
            "simplified",
            "trojanspy",
            "virustotal",
            "panda",
            "detections type",
            "shell",
            "javascript",
            "dns replication",
            "files referring",
            "lookups",
            "as7552",
            "vhash",
            "ssdeep",
            "magic elf",
            "sysv",
            "trid elf",
            "executable",
            "linux",
            "elf executable",
            "loccel1",
            "echobot",
            "bashlite",
            "malwarebazaar",
            "echobot malware",
            "win32 exe",
            "magic msdos",
            "pe32 executable",
            "intel",
            "ms windows",
            "trid dos",
            "compiler",
            "delphi",
            "serial number",
            "algorithm",
            "thumbprint",
            "valid from",
            "code signing",
            "from",
            "microsoft root",
            "name microsoft",
            "verisign time",
            "stamping",
            "contained",
            "info sections",
            "name virtual",
            "address virtual",
            "size raw",
            "size entropy",
            "md5 chi2",
            "regsetvalueexa",
            "type rtrcdata",
            "sha256 file",
            "threat roundup",
            "october",
            "august",
            "june",
            "september",
            "highly targeted",
            "cyberstalking",
            "round",
            "december",
            "sneaky server",
            "facebook",
            "stealer",
            "agent tesla",
            "pony",
            "april",
            "whitelisted",
            "encrypt",
            "targeting",
            "tsara brashears",
            "otx",
            "alienvault",
            "memcommit",
            "regsz",
            "regopenkeyexw",
            "english",
            "module load",
            "t1129",
            "t1082",
            "windows module",
            "dlls",
            "redline stealer",
            "updater",
            "v3 serial",
            "number",
            "subject public",
            "key info",
            "key algorithm",
            "key identifier",
            "subject key",
            "identifier",
            "x509v3 key",
            "data redacted",
            "cloudflare",
            "redacted",
            "for privacy",
            "code",
            "server",
            "registrar abuse",
            "redacted for",
            "postal code",
            "registrant name",
            "red team",
            "shit",
            "logistics",
            "cyber defense",
            "gootloader",
            "march",
            "sinkhole",
            "just",
            "ramnit",
            "netsupport rat",
            "microsoft",
            "vault",
            "karen",
            "gifts",
            "hidden privacy",
            "threats",
            "malicious",
            "darkgate",
            "core",
            "hacktool",
            "emotet"
          ],
          "references": [
            "https://botnet.ngocronglau.xyz > link discovered by an Alienvault user who notified me they found it researching message from am active user.",
            "https://otx.alienvault.com/indicator/file/02b19639ad1efa59e77f45d130447c05bd2466e26a657cb9cc6ac2e8b30a0026",
            "https://otx.alienvault.com/indicator/file/001546d210a35b7c4c072b6c265f621cf4a9abdd152741d9b58deae2be204355",
            "https://otx.alienvault.com/indicator/hostname/botnet.ngocronglau.xyz",
            "Unix.Mirai Botnet: https://otx.alienvault.com/indicator/hostname/botnet.ngocronglau.xyz",
            "CnC IP: https://otx.alienvault.com/indicator/ip/142.202.242.45",
            "https://otx.alienvault.com/indicator/domain/bunny.net",
            "https://otx.alienvault.com/indicator/ip/210.211.117.205",
            "https://otx.alienvault.com/indicator/ip/143.244.50.212",
            "https://otx.alienvault.com/indicator/ip/125.235.4.59",
            "AV Detection: ELF:Mirai-GH\\ [Trj]",
            "IDS Detections:  MVPower DVR Shell UCE Mirai  | Variant User-Agent (Outbound) JAWS Webserver Unauthenticated Shell Command Execution",
            "IDS Detections: Huawei Remote Command Execution (CVE-2017-17215) Huawei Remote Command Execution - Outbound (CVE-2017-17215) Huawei HG532 RCE Vulnerability (CVE-2017-17215) Mirai Variant User-Agent (Inbound) HackingTrio UA (Hello, World) 401TRG Generic Webshell Request - POST with wget in body HTTP traffic on port 443 (POST",
            "IDS Detections: Mirai Variant User-Agent (Inbound) HackingTrio UA (Hello, World)",
            "IDS Detections: 401TRG Generic Webshell Request - POST with wget in body HTTP traffic on port 443 (POST) ...",
            "Alerts: dead_host network_icmp tcp_syn_scan nolookup_communication network_cnc_http network_http p2p_cnc writes_to_stdout",
            "Matches rule Linux_Trojan_Mirai_6a77af0f from ruleset Linux_Trojan_Mirai by Elastic Security | botnet.ngocronglau.xyz",
            "https://otx.alienvault.com/indicator/file/2b5deac6176124ee1f7d237f070c39b03c964fce9a9fba0aaa1bce102710d2e0",
            "cu-payment-porch.pdv-3.ap-southeast-2.production.jet-external.com | qa.proxy.cognito.tigomoney.io | https://trackon.fr/track/clique",
            "Crowdsourced YARA rules Matches:  rule INDICATOR_EXE_Packed_MEW from ruleset indicator_packed by ditekSHen",
            "Crowdsourced YARA rules Matches: INDICATOR_EXE_Packed_MEW from ruleset indicator_packed by ditekSHen",
            "Crowdsourced YARA rules Matches: SUSP_Unsigned_OSPPSVC from ruleset gen_sign_anomalies by Florian Roth (Nextron Systems",
            "Crowdsourced YARA rules Matches: IMPLANT_4_v3_AlternativeRule from ruleset apt_grizzlybear_uscert by Florian Roth (Nextron Systems)",
            "Crowdsourced YARA rules Matches: Matches rule IMPLANT_4_v3_AlternativeRule from ruleset apt_grizzlybear_uscert by Florian Roth (Nextron Systems",
            "https://wallpapers-nature.com/tsara-brashears/tse1-mm-bing-net",
            "wallpapers-nature.com",
            "Was anyone else notified? I'm not sure why I was.",
            "Through research I did notice many references to target I'm researching for. Phishing/Injection attempt? I didn't click on links.",
            "CS Sigma: Matches rule Python Initiated Connection by frack113"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Generic",
              "display_name": "Generic",
              "target": null
            },
            {
              "id": "Unix.Trojan.Mirai-9441505-0",
              "display_name": "Unix.Trojan.Mirai-9441505-0",
              "target": null
            },
            {
              "id": "ALF:E5.SpikeAex.rhh_mcv",
              "display_name": "ALF:E5.SpikeAex.rhh_mcv",
              "target": null
            },
            {
              "id": "Win.Dropper.Bulz-9910065-0",
              "display_name": "Win.Dropper.Bulz-9910065-0",
              "target": null
            },
            {
              "id": "Win32:Malware-gen",
              "display_name": "Win32:Malware-gen",
              "target": null
            },
            {
              "id": "ALF:HeraklezEval:Trojan:Win32/ClipBanker",
              "display_name": "ALF:HeraklezEval:Trojan:Win32/ClipBanker",
              "target": null
            },
            {
              "id": "Win.Dropper.Autoit-6688751-0",
              "display_name": "Win.Dropper.Autoit-6688751-0",
              "target": null
            },
            {
              "id": "ELF:Mirai-GH\\ [Trj]",
              "display_name": "ELF:Mirai-GH\\ [Trj]",
              "target": null
            },
            {
              "id": "Win.Dropper.Dridex-9986041-0",
              "display_name": "Win.Dropper.Dridex-9986041-0",
              "target": null
            },
            {
              "id": "ALF:HeraklezEval:Trojan:Win32/Zombie",
              "display_name": "ALF:HeraklezEval:Trojan:Win32/Zombie",
              "target": null
            },
            {
              "id": "Win.Packer.pkr_ce1a-9980177-0",
              "display_name": "Win.Packer.pkr_ce1a-9980177-0",
              "target": null
            },
            {
              "id": "Worm:Win32/Sfone.A",
              "display_name": "Worm:Win32/Sfone.A",
              "target": "/malware/Worm:Win32/Sfone.A"
            },
            {
              "id": "Worm:Win32/Sfone",
              "display_name": "Worm:Win32/Sfone",
              "target": "/malware/Worm:Win32/Sfone"
            },
            {
              "id": "Win.Malware.Bbabdcdc-7358312-0",
              "display_name": "Win.Malware.Bbabdcdc-7358312-0",
              "target": null
            },
            {
              "id": "Win32:Trojan-gen",
              "display_name": "Win32:Trojan-gen",
              "target": null
            },
            {
              "id": "trojan.mirai/fszhh",
              "display_name": "trojan.mirai/fszhh",
              "target": null
            },
            {
              "id": "DDOS:Linux/Mirai",
              "display_name": "DDOS:Linux/Mirai",
              "target": "/malware/DDOS:Linux/Mirai"
            },
            {
              "id": "ANDROID/AVE.Mirai.fszhh",
              "display_name": "ANDROID/AVE.Mirai.fszhh",
              "target": null
            },
            {
              "id": "Flyagent L",
              "display_name": "Flyagent L",
              "target": null
            },
            {
              "id": "Win-Trojan/Malpacked5.Gen",
              "display_name": "Win-Trojan/Malpacked5.Gen",
              "target": null
            },
            {
              "id": "Atros3.LDJ",
              "display_name": "Atros3.LDJ",
              "target": null
            },
            {
              "id": "a variant of Win32/FlyStudio.Packed.AD potentially unwanted",
              "display_name": "a variant of Win32/FlyStudio.Packed.AD potentially unwanted",
              "target": null
            },
            {
              "id": "TrojanSpy:Win32/Gucotut.A",
              "display_name": "TrojanSpy:Win32/Gucotut.A",
              "target": "/malware/TrojanSpy:Win32/Gucotut.A"
            },
            {
              "id": "W32/Pidgeon-A",
              "display_name": "W32/Pidgeon-A",
              "target": null
            },
            {
              "id": "Variant.Zusy.151902",
              "display_name": "Variant.Zusy.151902",
              "target": null
            },
            {
              "id": "trojan.mirai/fedr",
              "display_name": "trojan.mirai/fedr",
              "target": null
            },
            {
              "id": "Win.Malware.Trojanx-9862538-0",
              "display_name": "Win.Malware.Trojanx-9862538-0",
              "target": null
            },
            {
              "id": "Win32:PWSX-gen\\ [Trj]",
              "display_name": "Win32:PWSX-gen\\ [Trj]",
              "target": null
            },
            {
              "id": "virus.ramnit/nimnul",
              "display_name": "virus.ramnit/nimnul",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1053",
              "name": "Scheduled Task/Job",
              "display_name": "T1053 - Scheduled Task/Job"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1119",
              "name": "Automated Collection",
              "display_name": "T1119 - Automated Collection"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1143",
              "name": "Hidden Window",
              "display_name": "T1143 - Hidden Window"
            },
            {
              "id": "T1003",
              "name": "OS Credential Dumping",
              "display_name": "T1003 - OS Credential Dumping"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1095",
              "name": "Non-Application Layer Protocol",
              "display_name": "T1095 - Non-Application Layer Protocol"
            },
            {
              "id": "T1571",
              "name": "Non-Standard Port",
              "display_name": "T1571 - Non-Standard Port"
            },
            {
              "id": "TA0006",
              "name": "Credential Access",
              "display_name": "TA0006 - Credential Access"
            },
            {
              "id": "TA0011",
              "name": "Command and Control",
              "display_name": "TA0011 - Command and Control"
            },
            {
              "id": "T1045",
              "name": "Software Packing",
              "display_name": "T1045 - Software Packing"
            },
            {
              "id": "T1005",
              "name": "Data from Local System",
              "display_name": "T1005 - Data from Local System"
            },
            {
              "id": "T1012",
              "name": "Query Registry",
              "display_name": "T1012 - Query Registry"
            },
            {
              "id": "T1047",
              "name": "Windows Management Instrumentation",
              "display_name": "T1047 - Windows Management Instrumentation"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1060",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1060 - Registry Run Keys / Startup Folder"
            },
            {
              "id": "T1070",
              "name": "Indicator Removal on Host",
              "display_name": "T1070 - Indicator Removal on Host"
            },
            {
              "id": "T1081",
              "name": "Credentials in Files",
              "display_name": "T1081 - Credentials in Files"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 51,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 2,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 351,
            "FileHash-SHA1": 349,
            "FileHash-SHA256": 3715,
            "domain": 3326,
            "hostname": 5200,
            "URL": 13151,
            "email": 9,
            "CVE": 7,
            "CIDR": 2
          },
          "indicator_count": 26110,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 243,
          "modified_text": "640 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "Do you line how they spend your tax dollars? Attacking victims? Protecting Corporations!",
        "Review: Jeffrey Reimer DPT assaulted & egregiously injured a patient at AMS Concentra in Denver, Co",
        "80 Body\t here /a . /h2 /body /html 80 Header\tHTTP/1.1 302 Found  Cache-Control: private",
        "Alerts: dead_host network_icmp tcp_syn_scan nolookup_communication",
        "(Date: Tue, 13 Jun 2017 10:21:34 GMT 443 )",
        "IDS Detections: Mirai Variant User-Agent (Inbound) HackingTrio UA (Hello, World)",
        "I haven\u2019t mentioned the hit men they hired.",
        "Crowdsourced YARA rules Matches:  rule INDICATOR_EXE_Packed_MEW from ruleset indicator_packed by ditekSHen",
        "Patient/ Victim unaware of her workers compensation rights.",
        "Location: policyref=\"/w3c/p3p.xml\", CP=\"COM   X-P3P: policyref=\"/w3c/p3p.xml\", CP=\"COM",
        "https://otx.alienvault.com/indicator/ip/210.211.117.205",
        "http://www.skynetsoftware.com/SNSAuth/appauth.aspx?app=myPlayerDroidPro&ver=2.800&key=2w6i4y1r0sdz6q9gchjcpkal0oaiem4u8ncy3bct1vcr8e6x2w&platform=Android&devId=92841014150fc3fd&width=480&height=764&owner=19&model=Lenovo%20A360t",
        "cu-payment-porch.pdv-3.ap-southeast-2.production.jet-external.com | qa.proxy.cognito.tigomoney.io | https://trackon.fr/track/clique",
        "expires=Wed, 13-Jun-2018 10:21:35 GMT; path=/  P3P: policyref=\"/w3c/p3p.xml\",",
        "http://crl.starfieldtech.com/sfig2s2-0.crl 443",
        "Certificate Subject Scottsdale 443 Certificate Subject\tSpecial Domain Services, LLC 443",
        "PDNS11.DOMAINCONTROL.COM",
        "Crowdsourced YARA rules Matches: SUSP_Unsigned_OSPPSVC from ruleset gen_sign_anomalies by Florian Roth (Nextron Systems",
        "https://ad-maven.com/appcast.io/leadlander.com/affasi.com/clixtell.com/adgainersolutions.com/franecki.net/pixanalytics.com/wrethicap.info/ismatlab.com/y-track.com/ecsanalytics.com/albacross.com/bgclck.me/lptracker.io/ze-fir.com/eyereturn.com/bitmedia.io/azetklik.sk/fuelx.com/pixlee.com/hilltopads.net/reichelcormier.bid/mmapiws.com/betssonpalantir.com/b0e8.com/breaktime.com.tw/clearlink.com/sendpulse.com/pulpix.com/c3tag.com/ligatus.com/clickyab.com/buckridge.link/clickguard.com/bluecava.com/attributionmodel",
        "Everyone I attempt to pulse Palantir Ad-Maven it\u2019s immediately deleted from Pulse",
        "https://den.h5datacenters.com/",
        "Crowdsourced YARA rules Matches: Matches rule IMPLANT_4_v3_AlternativeRule from ruleset apt_grizzlybear_uscert by Florian Roth (Nextron Systems",
        "Powered-By: ARR/2.5  X-Powered-By: ASP.NET",
        "Certificate Subjectaltname\t*.secureserver.net 443 Certificate Subjectaltname\tsecureserver.net",
        "X-Powered-By: ARR/2.5  X-Powered-By: ASP.NET  P3P: policyref=\"/w3c/p3p.xml\", CP=\"",
        "http://www.skynetsoftware.com/SNSAuth/appauth.aspx?app=myPlayerDroid&ver=1.999&key=xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx&platform=Android&reg=&devId=92841014150fc3fd&devInfo=&devEmail=&width=480&height=764&owner=19&model=Lenovo A360t",
        "CS Sigma: Matches rule Python Initiated Connection by frack113",
        "\u201cCNT DEM FIN GOV INT NAV ONL PHY PRE PUR STA UNI IDC CAO OTI DSP COR CUR OUR IND\"",
        "Crowdsourced YARA rules Matches: INDICATOR_EXE_Packed_MEW from ruleset indicator_packed by ditekSHen",
        "Unix.TrojanMirai-7640640-0 IDS Detections Bad Login root login Yara Detections is__elf",
        "http://certs.starfieldtech.com/repository/ 443",
        "443 Certificate Notbefore\tAug 25 16:21:59 2014 GMT 443 Certificate Caissuers",
        "https://otx.alienvault.com/indicator/ip/125.235.4.59",
        "https://otx.alienvault.com/indicator/ip/143.244.50.212",
        "AV Detection: ELF:Mirai-GH\\ [Trj]",
        "Fastly.com",
        "Quasi Government, Meta, Twitter , Palantir , Gotham , Christopher P. Ahmann , Brian Sabey",
        "\u201cCNT DEM FIN GOV INT NAV ONL PHY PRE PUR STA UNI IDC CAO OTI DSP COR CUR i OUR IND\"",
        "https://otx.alienvault.com/indicator/hostname/botnet.ngocronglau.xyz",
        "IDS Detections: 401TRG Generic Webshell Request - POST with wget in body HTTP traffic on port 443 (POST) ...",
        "Was anyone else notified? I'm not sure why I was.",
        "Content-Length: 160  Location: http://www.secureserver.net/default404.aspx",
        "IDS Detections:  MVPower DVR Shell UCE Mirai  | Variant User-Agent (Outbound) JAWS Webserver Unauthenticated Shell Command Execution",
        "https://otx.alienvault.com/indicator/domain/secureserver.net",
        "https://www.secureserver.net/default404.aspx  Server: Microsoft-IIS/7.0",
        "register.blackgirldroneworld.com (Is this racist)",
        "It\u2019s was sexual and violent. Patient was under the oversight of Mark Montano MD and John T. Sacha MD",
        "wallpapers-nature.com",
        "Date: Tue, 13 Jun 2017 10:21:34 GMT",
        "\u201cCOM CNT DEM FIN GOV INT NAV ONL PHY PRE PUR STA UNI IDC CAO OTI DSP COR CUR i OUR IND\"",
        "www.skynetsoftware.com",
        "Matches rule Linux_Trojan_Mirai_6a77af0f from ruleset Linux_Trojan_Mirai by Elastic Security | botnet.ngocronglau.xyz",
        "Server: Microsoft-IIS/7.0  Set-Cookie: market=en-US; domain=secureserver.net;",
        "Certificate Crldistributionpoints",
        "http://ocsp.starfieldtech.com/ 443 Certificate",
        "https://otx.alienvault.com/indicator/domain/bunny.net",
        "Through research I did notice many references to target I'm researching for. Phishing/Injection attempt? I didn't click on links.",
        "https://stetsed.xyz/apple",
        "CnC IP: https://otx.alienvault.com/indicator/ip/142.202.242.45",
        "Palantir Ad-Maven Palantir, Ad- Maven, Prometheus Intelligence Technology",
        "https://wallpapers-nature.com/tsara-brashears/tse1-mm-bing-net",
        "Object moved /title /head body h2 Object moved to a href= http://www.secureserver.net/default404.aspx",
        "Alerts: dead_host network_icmp tcp_syn_scan nolookup_communication network_cnc_http network_http p2p_cnc writes_to_stdout",
        "https://botnet.ngocronglau.xyz > link discovered by an Alienvault user who notified me they found it researching message from am active user.",
        "https://otx.alienvault.com/indicator/file/02b19639ad1efa59e77f45d130447c05bd2466e26a657cb9cc6ac2e8b30a0026",
        "Set-Cookie: market=en-US; domain=secureserver.net; expires=path=/  P3P:",
        "http://prometheusintelligencetechnology.com/pitframeitem=22fsbout-regis-univer",
        "CP=\"COM CNT DEM FIN GOV INT NAV ONL PHY PRE PUR STA UNI IDC CAO OTI DSP COR CUR OUR IND\"",
        "Unix.Mirai Botnet: https://otx.alienvault.com/indicator/hostname/botnet.ngocronglau.xyz",
        "http://www.skynetsoftware.com/SNSAuth/appauth.aspx?app=myPlayerDroidPro&ver=3.700&key=53dbnf9wrz8vc0m5xfve2q1w2r4x8fv0g1b8sfg7qi0rdxck2j&platform=Android&devId=dc9c9a616665e073&width=800&height=561&owner=19&model=VirtualBox",
        "A Domains \u2022 www.secureserver.net 443 Certificate",
        "href= here /a . /h2 /body /html 443 Header \u2022 HTTP/1.1 302 Found  Content-Length: 161",
        "https://www.secureserver.net/default404.aspx",
        "Serialnumber\t27B78B2246C9C1 443 Certificate Notafter \u2022 Aug 25 16:21:59 2017 GMT 443",
        "Certificate Version 3 443 Certificate Subject\tUS 443 Certificate Subject\tArizona 443",
        "https://prometheusintelligencetechnology.com/404javascript.js",
        "https://otx.alienvault.com/indicator/file/2b5deac6176124ee1f7d237f070c39b03c964fce9a9fba0aaa1bce102710d2e0",
        "Sha1 :e4ca8288d5e4912a00482418765b58a2e22fd5dc",
        "Crowdsourced YARA rules Matches: IMPLANT_4_v3_AlternativeRule from ruleset apt_grizzlybear_uscert by Florian Roth (Nextron Systems)",
        "http://www.skynetsoftware.com/myPlayer/myPlayerDroid.xml",
        "https://otx.alienvault.com/indicator/file/001546d210a35b7c4c072b6c265f621cf4a9abdd152741d9b58deae2be204355",
        "IDS Detections: Huawei Remote Command Execution (CVE-2017-17215) Huawei Remote Command Execution - Outbound (CVE-2017-17215) Huawei HG532 RCE Vulnerability (CVE-2017-17215) Mirai Variant User-Agent (Inbound) HackingTrio UA (Hello, World) 401TRG Generic Webshell Request - POST with wget in body HTTP traffic on port 443 (POST",
        "https://prometheusintelligencetechnology.com/pit/",
        "Certificate Issuer\tStarfield Technologies, Inc. 443 Certificate Issuer",
        "H5DATACENTERS.COM Name Servers: NS74.DOMAINCONTROL.COM",
        "Certificate Issuer: Starfield Secure Certificate Authority - G2 443 Title: Object moved 443",
        "TrackingPin (Error) A Domains: trackingpin.com \u2022 Domains: forum.trackingpin.org"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 0
        },
        "other": {
          "adversary": [],
          "malware_families": [
            "Mirai",
            "Win.dropper.dridex-9986041-0",
            "Alf:heraklezeval:trojan:win32/zombie",
            "Worm:win32/sfone.a",
            "Virus:win32/triusor.a",
            "Elf:mirai-gh\\ [trj]",
            "Win32:pwsx-gen\\ [trj]",
            "Win32:trojan-gen",
            "Win.downloader",
            "Virus.ramnit/nimnul",
            "Generic",
            "Win.malware.bbabdcdc-7358312-0",
            "Win.malware.trojanx-9862538-0",
            "Alf:heraklezeval:trojan:win32/clipbanker",
            "Worm:win32/sfone",
            "Trojan.mirai/fedr",
            "Unix.trojan.mirai-7640640-0",
            "Trojan.mirai/fszhh",
            "Android/ave.mirai.fszhh",
            "!installcreatorpro_2_0",
            "W32/pidgeon-a",
            "Flyagent l",
            "#lowfienabledtcontinueafterunpacking",
            "Win.dropper.autoit-6688751-0",
            "Win-trojan/malpacked5.gen",
            "Atros3.ldj",
            "Win.dropper.bulz-9910065-0",
            "Variant.zusy.151902",
            "Carts.guru",
            "Trojanspy:win32/gucotut.a",
            "Unix.trojan.mirai-9441505-0",
            "Ddos:linux/mirai",
            "A variant of win32/flystudio.packed.ad potentially unwanted",
            "Win.packer.pkr_ce1a-9980177-0",
            "Win32:malware-gen",
            "Alf:e5.spikeaex.rhh_mcv"
          ],
          "industries": [
            "Education",
            "Government",
            "Civil society"
          ],
          "unique_indicators": 51971
        }
      }
    },
    "false_positive": [],
    "alexa": "http://www.alexa.com/siteinfo/mmapiws.com",
    "whois": "http://whois.domaintools.com/mmapiws.com",
    "domain": "mmapiws.com",
    "hostname": "d-ipv4.mmapiws.com"
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 5,
  "pulses": [
    {
      "id": "69560fa62bddc3d965359168",
      "name": "Mirai H5DATACENTERS.COM \u2022 Regis University Blackout  | Extranet",
      "description": "It was Data Center 5. \nH5DATACENTERS.COM \u2022 Regis University Blackout PrometheusIntelligenceTechnology.com - Extranet.  Forced out of RU for finding malicious link that targeted , tracked ,conversations , behavior, etc.,  \u201cNo one willingly signed up to be tracked.\u201dis what Tsara told Dean Archer. He said he\u2019d never seen anything like this in his life. RU ignored the risks Tsara cautioned could irreparably damage incoming students college experience and negatively impact their future. I just hope the many students who attended do not continue to suffer. Guess who the villain was? The truth teller. \n\nToday activity has stepped up. Somehow the PIT Pulse has caused a crusade of aggressive following and investigation. \n\nThere may be 10,000 vs 1 in this battle. But the One is God.",
      "modified": "2026-01-31T03:04:09.490000",
      "created": "2026-01-01T06:09:42.057000",
      "tags": [
        "http",
        "files related",
        "related tags",
        "ipv4",
        "ccus asnas20029",
        "urls",
        "domain",
        "files ip",
        "address domain",
        "ip whois",
        "passive dns",
        "gmt path",
        "hostname add",
        "files",
        "united",
        "a li",
        "trackingpin a",
        "ip address",
        "unknown aaaa",
        "error",
        "back",
        "darkness",
        "present sep",
        "a domains",
        "script urls",
        "unknown ns",
        "script domains",
        "meta",
        "apache",
        "body doctype",
        "gmt server",
        "url analysis",
        "path",
        "accept",
        "pragma",
        "west domains",
        "present dec",
        "object",
        "com cnt",
        "dem fin",
        "gov int",
        "nav onl",
        "phy pre",
        "data upload",
        "extraction",
        "found",
        "datacenter",
        "hosting",
        "vps reverse",
        "america united",
        "america asn",
        "as398101",
        "body html",
        "head title",
        "title",
        "status",
        "name servers",
        "failed",
        "all se",
        "enter sc",
        "type",
        "extra data",
        "referen",
        "manualv add",
        "indicator data",
        "port",
        "destination",
        "south korea",
        "china as4134",
        "taiwan as3462",
        "as3786 lg",
        "as4766 korea",
        "as9318 sk",
        "high",
        "tcp syn",
        "trojan",
        "pegasus",
        "malware",
        "unknown",
        "search",
        "present jan",
        "pur sta",
        "uni idc",
        "cao oti",
        "dsp cor",
        "body",
        "win32",
        "united states",
        "pulse tags",
        "palantir",
        "ad maven",
        "technology",
        "url https",
        "url http",
        "indicator role",
        "title added",
        "active related",
        "Palantir",
        "Ad-Maven",
        "Palantir",
        "Ad- Maven",
        "Prometheus Intelligence Technology",
        "skynet",
        "starfield tech",
        "flock",
        "report spam",
        "palantir ad",
        "maven",
        "botnet",
        "created",
        "days ago",
        "education",
        "tsara",
        "mirai",
        "regis",
        "brashears",
        "discovery",
        "universities",
        "tsara brashears",
        "close",
        "stop",
        "ransom",
        "capture",
        "denver"
      ],
      "references": [
        "H5DATACENTERS.COM Name Servers: NS74.DOMAINCONTROL.COM",
        "https://prometheusintelligencetechnology.com/pit/",
        "https://prometheusintelligencetechnology.com/404javascript.js",
        "https://www.secureserver.net/default404.aspx",
        "http://ocsp.starfieldtech.com/ 443 Certificate",
        "https://www.secureserver.net/default404.aspx  Server: Microsoft-IIS/7.0",
        "Set-Cookie: market=en-US; domain=secureserver.net; expires=path=/  P3P:",
        "\u201cCNT DEM FIN GOV INT NAV ONL PHY PRE PUR STA UNI IDC CAO OTI DSP COR CUR OUR IND\"",
        "Powered-By: ARR/2.5  X-Powered-By: ASP.NET",
        "href= here /a . /h2 /body /html 443 Header \u2022 HTTP/1.1 302 Found  Content-Length: 161",
        "Location: policyref=\"/w3c/p3p.xml\", CP=\"COM   X-P3P: policyref=\"/w3c/p3p.xml\", CP=\"COM",
        "\u201cCNT DEM FIN GOV INT NAV ONL PHY PRE PUR STA UNI IDC CAO OTI DSP COR CUR i OUR IND\"",
        "(Date: Tue, 13 Jun 2017 10:21:34 GMT 443 )",
        "Certificate Crldistributionpoints",
        "http://crl.starfieldtech.com/sfig2s2-0.crl 443",
        "Certificate Subjectaltname\t*.secureserver.net 443 Certificate Subjectaltname\tsecureserver.net",
        "443 Certificate Notbefore\tAug 25 16:21:59 2014 GMT 443 Certificate Caissuers",
        "Serialnumber\t27B78B2246C9C1 443 Certificate Notafter \u2022 Aug 25 16:21:59 2017 GMT 443",
        "Certificate Version 3 443 Certificate Subject\tUS 443 Certificate Subject\tArizona 443",
        "Certificate Subject Scottsdale 443 Certificate Subject\tSpecial Domain Services, LLC 443",
        "Certificate Issuer\tStarfield Technologies, Inc. 443 Certificate Issuer",
        "http://certs.starfieldtech.com/repository/ 443",
        "Certificate Issuer: Starfield Secure Certificate Authority - G2 443 Title: Object moved 443",
        "A Domains \u2022 www.secureserver.net 443 Certificate",
        "Object moved /title /head body h2 Object moved to a href= http://www.secureserver.net/default404.aspx",
        "80 Body\t here /a . /h2 /body /html 80 Header\tHTTP/1.1 302 Found  Cache-Control: private",
        "Content-Length: 160  Location: http://www.secureserver.net/default404.aspx",
        "Server: Microsoft-IIS/7.0  Set-Cookie: market=en-US; domain=secureserver.net;",
        "expires=Wed, 13-Jun-2018 10:21:35 GMT; path=/  P3P: policyref=\"/w3c/p3p.xml\",",
        "CP=\"COM CNT DEM FIN GOV INT NAV ONL PHY PRE PUR STA UNI IDC CAO OTI DSP COR CUR OUR IND\"",
        "X-Powered-By: ARR/2.5  X-Powered-By: ASP.NET  P3P: policyref=\"/w3c/p3p.xml\", CP=\"",
        "\u201cCOM CNT DEM FIN GOV INT NAV ONL PHY PRE PUR STA UNI IDC CAO OTI DSP COR CUR i OUR IND\"",
        "Date: Tue, 13 Jun 2017 10:21:34 GMT",
        "Sha1 :e4ca8288d5e4912a00482418765b58a2e22fd5dc",
        "TrackingPin (Error) A Domains: trackingpin.com \u2022 Domains: forum.trackingpin.org",
        "PDNS11.DOMAINCONTROL.COM",
        "https://otx.alienvault.com/indicator/domain/secureserver.net",
        "Unix.TrojanMirai-7640640-0 IDS Detections Bad Login root login Yara Detections is__elf",
        "Alerts: dead_host network_icmp tcp_syn_scan nolookup_communication",
        "https://den.h5datacenters.com/",
        "http://prometheusintelligencetechnology.com/pitframeitem=22fsbout-regis-univer",
        "register.blackgirldroneworld.com (Is this racist)",
        "https://stetsed.xyz/apple",
        "Palantir Ad-Maven Palantir, Ad- Maven, Prometheus Intelligence Technology",
        "Review: Jeffrey Reimer DPT assaulted & egregiously injured a patient at AMS Concentra in Denver, Co",
        "It\u2019s was sexual and violent. Patient was under the oversight of Mark Montano MD and John T. Sacha MD",
        "Patient/ Victim unaware of her workers compensation rights.",
        "Do you line how they spend your tax dollars? Attacking victims? Protecting Corporations!",
        "Quasi Government, Meta, Twitter , Palantir , Gotham , Christopher P. Ahmann , Brian Sabey",
        "I haven\u2019t mentioned the hit men they hired.",
        "Fastly.com",
        "www.skynetsoftware.com",
        "http://www.skynetsoftware.com/SNSAuth/appauth.aspx?app=myPlayerDroid&ver=1.999&key=xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx&platform=Android&reg=&devId=92841014150fc3fd&devInfo=&devEmail=&width=480&height=764&owner=19&model=Lenovo A360t",
        "http://www.skynetsoftware.com/SNSAuth/appauth.aspx?app=myPlayerDroidPro&ver=2.800&key=2w6i4y1r0sdz6q9gchjcpkal0oaiem4u8ncy3bct1vcr8e6x2w&platform=Android&devId=92841014150fc3fd&width=480&height=764&owner=19&model=Lenovo%20A360t",
        "http://www.skynetsoftware.com/SNSAuth/appauth.aspx?app=myPlayerDroidPro&ver=3.700&key=53dbnf9wrz8vc0m5xfve2q1w2r4x8fv0g1b8sfg7qi0rdxck2j&platform=Android&devId=dc9c9a616665e073&width=800&height=561&owner=19&model=VirtualBox",
        "http://www.skynetsoftware.com/myPlayer/myPlayerDroid.xml"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "Mirai",
          "display_name": "Mirai",
          "target": null
        },
        {
          "id": "Virus:Win32/Triusor.A",
          "display_name": "Virus:Win32/Triusor.A",
          "target": "/malware/Virus:Win32/Triusor.A"
        },
        {
          "id": "!InstallCreatorPro_2_0",
          "display_name": "!InstallCreatorPro_2_0",
          "target": null
        },
        {
          "id": "Unix.Trojan.Mirai-7640640-0",
          "display_name": "Unix.Trojan.Mirai-7640640-0",
          "target": null
        },
        {
          "id": "#LowFiEnableDTContinueAfterUnpacking",
          "display_name": "#LowFiEnableDTContinueAfterUnpacking",
          "target": null
        },
        {
          "id": "Win.Downloader",
          "display_name": "Win.Downloader",
          "target": null
        },
        {
          "id": "Mirai",
          "display_name": "Mirai",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1069",
          "name": "Permission Groups Discovery",
          "display_name": "T1069 - Permission Groups Discovery"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1113",
          "name": "Screen Capture",
          "display_name": "T1113 - Screen Capture"
        },
        {
          "id": "T1129",
          "name": "Shared Modules",
          "display_name": "T1129 - Shared Modules"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1203",
          "name": "Exploitation for Client Execution",
          "display_name": "T1203 - Exploitation for Client Execution"
        },
        {
          "id": "T1480",
          "name": "Execution Guardrails",
          "display_name": "T1480 - Execution Guardrails"
        },
        {
          "id": "T1518",
          "name": "Software Discovery",
          "display_name": "T1518 - Software Discovery"
        },
        {
          "id": "T1553",
          "name": "Subvert Trust Controls",
          "display_name": "T1553 - Subvert Trust Controls"
        },
        {
          "id": "T1568",
          "name": "Dynamic Resolution",
          "display_name": "T1568 - Dynamic Resolution"
        },
        {
          "id": "T1583",
          "name": "Acquire Infrastructure",
          "display_name": "T1583 - Acquire Infrastructure"
        }
      ],
      "industries": [
        "Education",
        "Civil Society"
      ],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 6,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Q.Vashti",
        "id": "337942",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 2817,
        "domain": 487,
        "hostname": 983,
        "FileHash-SHA256": 611,
        "FileHash-MD5": 107,
        "FileHash-SHA1": 106,
        "email": 2
      },
      "indicator_count": 5113,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 138,
      "modified_text": "78 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "695043197c2fbfda85abc1d4",
      "name": "Palantir Ad Maven tracking under various names | Espionage  Malware &Botnet associated",
      "description": "https://ad-maven.com/appcast.io/leadlander.com/affasi.com/clixtell.com/adgainersolutions.com/franecki.net/pixanalytics.com/wrethicap.info/ismatlab.com/y-track.com/ecsanalytics.com/albacross.com/bgclck.me/lptracker.io/ze-fir.com/eyereturn.com/bitmedia.io/azetklik.sk/fuelx.com/pixlee.com/hilltopads.net/reichelcormier.bid/mmapiws.com/betssonpalantir.com/b0e8.com/breaktime.com.tw/clearlink.com/sendpulse.com/pulpix.com/c3tag.com/ligatus.com/clickyab.com/buckridge.link/clickguard.com/bluecava.com/attributionmodel.com/psonstrentie.info/adnium.com/rsz.sk/aivalabs.com/dep-x.com/dmpxs.com/fraudjs.io/c3metrics.com/consumable.com/graphenedigitalanalytics.in/antifraudjs.friends2follow.com/fanplayr.com/mystighty.info/prometheusintelligencetechnology.com/fuel451.com/quitzon.net/islay.tech/vcmedia.vn/xcvgdf.party/ero-advertising.com/opolen.com.br/carts.guru/libertystmedia.com/provers.pro/bashirian.biz/mobials.com/guoshipartners.com/adabra.com/online-metrix.net/rollick.io/admicro.vn/maxmind.com/boudja.com/ppcprotect.com/just",
      "modified": "2025-12-27T20:35:37.012000",
      "created": "2025-12-27T20:35:37.012000",
      "tags": [
        "Palantir",
        "Ad- Maven",
        "Prometheus Intelligence Technology"
      ],
      "references": [
        "https://ad-maven.com/appcast.io/leadlander.com/affasi.com/clixtell.com/adgainersolutions.com/franecki.net/pixanalytics.com/wrethicap.info/ismatlab.com/y-track.com/ecsanalytics.com/albacross.com/bgclck.me/lptracker.io/ze-fir.com/eyereturn.com/bitmedia.io/azetklik.sk/fuelx.com/pixlee.com/hilltopads.net/reichelcormier.bid/mmapiws.com/betssonpalantir.com/b0e8.com/breaktime.com.tw/clearlink.com/sendpulse.com/pulpix.com/c3tag.com/ligatus.com/clickyab.com/buckridge.link/clickguard.com/bluecava.com/attributionmodel",
        "Everyone I attempt to pulse Palantir Ad-Maven it\u2019s immediately deleted from Pulse"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "Carts.Guru",
          "display_name": "Carts.Guru",
          "target": null
        }
      ],
      "attack_ids": [],
      "industries": [
        "Government",
        "Education",
        "Civil Society"
      ],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 1,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Q.Vashti",
        "id": "337942",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 82,
        "hostname": 180,
        "URL": 995,
        "FileHash-SHA256": 110
      },
      "indicator_count": 1367,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 138,
      "modified_text": "113 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "687d91b1a8f414040bfba430",
      "name": "Spyware",
      "description": "And I've been walking, talking\nBelieving the things that are true\nAnd I've been finding\nThe difference between right and wrong, bad and good\nSee me put things together\nPut them back where they belong\nWhen I look at each other\nHave I always been singing the same song?\n\nShe said\nThis is a perfect world\nRiding on an incline\nI'm staring in your face\nYou'll photograph mine\n\nI-I-I-I-I\nWhoo, ah-ha-ha\nHa-ha-ha-ha-ha-ha\n\nSomebody said that it happens all over the world\nI do believe that it's true (\u2022o\u2022)\n#spyware #MaaS #malvertizing #bullyfor$ #unethical #dangerous_tool",
      "modified": "2025-08-20T00:01:59.498000",
      "created": "2025-07-21T01:02:41.049000",
      "tags": [
        "serving ip",
        "address",
        "status",
        "utc na",
        "utc google",
        "utc facebook",
        "custom audience",
        "tag manager",
        "ua748443502",
        "utc gtmwrp73mt",
        "utc gsrdlm5jnx1",
        "utc aw937838002",
        "adsense na",
        "connect",
        "file type",
        "status code",
        "body length",
        "kb body",
        "sha256",
        "powershell",
        "b file",
        "ta0004 defense",
        "evasion ta0005",
        "command",
        "control ta0011",
        "c0002 wininet",
        "number",
        "azure rsa",
        "tls issuing",
        "cus subject",
        "stwa lredmond",
        "corporation cus",
        "algorithm",
        "cndigicert sha2",
        "secure server",
        "ca odigicert",
        "inc cus",
        "subject",
        "cnwe1 ogoogle",
        "trust",
        "cnmicrosoft ecc",
        "update secure",
        "server ca",
        "omicrosoft",
        "get http",
        "request",
        "windows nt",
        "win64",
        "khtml",
        "gecko",
        "response",
        "united",
        "search",
        "creation date",
        "expiration date",
        "name servers",
        "unknown soa",
        "germany unknown",
        "entries",
        "pulse submit",
        "url analysis",
        "date"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 8,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Q.Vashti",
        "id": "337942",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 304,
        "hostname": 796,
        "URL": 2590,
        "FileHash-SHA256": 2735,
        "FileHash-MD5": 253,
        "FileHash-SHA1": 144,
        "email": 1
      },
      "indicator_count": 6823,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 141,
      "modified_text": "243 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "66f351ce26a103377d8eb5fa",
      "name": "Sex Tokens | Injection \u00bb Porn dumping - Cyber Folks .PL | Spectrum",
      "description": "Porn dumping into targeted devices after great effort. \nHall Render has always been a Malware Hosting website.\nDrive by compromise,    \nPorn Storm compilation.\n\nhttps://api.dotz.com.br/accounts/api/default/externallogin/login",
      "modified": "2024-10-24T22:01:13.406000",
      "created": "2024-09-24T23:57:02.111000",
      "tags": [
        "url https",
        "search",
        "type indicator",
        "role title",
        "added active",
        "related pulses",
        "url http",
        "porn type",
        "showing",
        "entries",
        "tsara type",
        "pulses url",
        "adware backdoor",
        "email document",
        "exploit domain",
        "owner exploit",
        "kit exploit",
        "source file",
        "hacking tools",
        "hunting macro",
        "malware hosting",
        "memory scanning",
        "wild fantasy",
        "world",
        "download",
        "xxx video",
        "xxx sex",
        "desi",
        "tamil",
        "videos xxx",
        "hd posts",
        "photos pics",
        "https",
        "indicator role",
        "title added",
        "active related",
        "unknown",
        "united",
        "for privacy",
        "nxdomain",
        "meta",
        "internet gmbh",
        "creation date",
        "date",
        "audio",
        "clear hindi",
        "bhabi sex",
        "bedroom indian",
        "fakaid",
        "ww3008",
        "fingering her",
        "young boy",
        "sexy",
        "next",
        "witch",
        "filehashmd5",
        "ipv4",
        "months ago",
        "information",
        "scan endpoints",
        "all scoreblue",
        "report spam",
        "created",
        "modified",
        "zbot",
        "keyword",
        "latina",
        "teen sex",
        "jeffrey reimer",
        "reimer dpt",
        "jeff reimer sex",
        "reimer type",
        "hostname",
        "domain",
        "copyright",
        "remote",
        "t1003",
        "os credential",
        "dumping",
        "t1012",
        "t1036",
        "t1071",
        "protocol",
        "t1082",
        "as8075",
        "aaaa",
        "as30148 sucuri",
        "certificate",
        "record value",
        "body",
        "status",
        "passive dns",
        "urls",
        "hallrender",
        "brian sabey",
        "sabey xxx",
        "drive by compromise",
        "cobalt strike",
        "overview ip",
        "address",
        "related nids",
        "files location",
        "china flag",
        "china domain",
        "files related",
        "pulses none",
        "files domain",
        "analyzer paste",
        "iocs",
        "hostnames",
        "urls https",
        "china unknown",
        "as4837 china",
        "redacted for",
        "a domains",
        "cname",
        "jeffrey reimer pt",
        "sucuri website",
        "span td",
        "time",
        "firewall",
        "win64",
        "back",
        "xtra",
        "name servers",
        "files",
        "tls web",
        "log id",
        "gmtn",
        "false",
        "ocsp",
        "ca issuers",
        "phucket news",
        "hacking",
        "registrar abuse",
        "gateway protocol abuse",
        "swipper relationship"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1003",
          "name": "OS Credential Dumping",
          "display_name": "T1003 - OS Credential Dumping"
        },
        {
          "id": "T1012",
          "name": "Query Registry",
          "display_name": "T1012 - Query Registry"
        },
        {
          "id": "T1023",
          "name": "Shortcut Modification",
          "display_name": "T1023 - Shortcut Modification"
        },
        {
          "id": "T1036",
          "name": "Masquerading",
          "display_name": "T1036 - Masquerading"
        },
        {
          "id": "T1040",
          "name": "Network Sniffing",
          "display_name": "T1040 - Network Sniffing"
        },
        {
          "id": "T1045",
          "name": "Software Packing",
          "display_name": "T1045 - Software Packing"
        },
        {
          "id": "T1047",
          "name": "Windows Management Instrumentation",
          "display_name": "T1047 - Windows Management Instrumentation"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1060",
          "name": "Registry Run Keys / Startup Folder",
          "display_name": "T1060 - Registry Run Keys / Startup Folder"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1089",
          "name": "Disabling Security Tools",
          "display_name": "T1089 - Disabling Security Tools"
        },
        {
          "id": "T1106",
          "name": "Native API",
          "display_name": "T1106 - Native API"
        },
        {
          "id": "T1112",
          "name": "Modify Registry",
          "display_name": "T1112 - Modify Registry"
        },
        {
          "id": "T1119",
          "name": "Automated Collection",
          "display_name": "T1119 - Automated Collection"
        },
        {
          "id": "T1129",
          "name": "Shared Modules",
          "display_name": "T1129 - Shared Modules"
        },
        {
          "id": "T1133",
          "name": "External Remote Services",
          "display_name": "T1133 - External Remote Services"
        },
        {
          "id": "T1143",
          "name": "Hidden Window",
          "display_name": "T1143 - Hidden Window"
        },
        {
          "id": "T1189",
          "name": "Drive-by Compromise",
          "display_name": "T1189 - Drive-by Compromise"
        },
        {
          "id": "T1203",
          "name": "Exploitation for Client Execution",
          "display_name": "T1203 - Exploitation for Client Execution"
        },
        {
          "id": "T1204",
          "name": "User Execution",
          "display_name": "T1204 - User Execution"
        },
        {
          "id": "T1210",
          "name": "Exploitation of Remote Services",
          "display_name": "T1210 - Exploitation of Remote Services"
        },
        {
          "id": "T1428",
          "name": "Exploit Enterprise Resources",
          "display_name": "T1428 - Exploit Enterprise Resources"
        },
        {
          "id": "T1485",
          "name": "Data Destruction",
          "display_name": "T1485 - Data Destruction"
        },
        {
          "id": "T1564",
          "name": "Hide Artifacts",
          "display_name": "T1564 - Hide Artifacts"
        },
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        },
        {
          "id": "T1573",
          "name": "Encrypted Channel",
          "display_name": "T1573 - Encrypted Channel"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 29,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "scoreblue",
        "id": "254100",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 1599,
        "hostname": 2988,
        "URL": 8561,
        "FileHash-SHA256": 1207,
        "email": 41,
        "FileHash-MD5": 126,
        "FileHash-SHA1": 36,
        "CVE": 1,
        "SSLCertFingerprint": 2
      },
      "indicator_count": 14561,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 226,
      "modified_text": "542 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6671e5844c155814e69ba4dd",
      "name": "Mirai Botnet Injection  affecting Alienvault.",
      "description": "It's unclear if some users or service itself is injecting users or if service is under a Mirai attack. I found evidence of both outbound & inbound activities.  *Crowdsourced context: Activity related to MIRAI - according to source Cluster25 - \nThis IPV4 is used by MIRAI. Mirai is a malware that created a big botnet of networked devices running Linux making them remotely controlled bots that can be used for large-scale network attacks. It primarily targets online consumer devices such as IP cameras and home routers.\n#zbetcheckin tracker\nDownloaded on 2023-11-07 19:34:59 UTC\nSRC URL : http://171.228.209.167/x86_64\nIP : 171.228.209.167\nAS : AS7552 Viettel Group\nYARA : #contentis_base64 #debuggerpattern__rdtsc #ip #math_entropy_6 #is__elf #http #ft_elf #executable_elf64",
      "modified": "2024-07-18T19:02:50.386000",
      "created": "2024-06-18T19:52:36.849000",
      "tags": [
        "problems",
        "threat network",
        "infrastructure",
        "historical ssl",
        "microsoft stuff",
        "domain check",
        "referrer",
        "generic malware",
        "injector",
        "no data",
        "tag count",
        "fri mar",
        "analyzer threat",
        "ip summary",
        "url summary",
        "summary",
        "downloader",
        "generic",
        "united",
        "as14315",
        "passive dns",
        "scan endpoints",
        "all scoreblue",
        "ipv4",
        "pulse pulses",
        "urls",
        "files",
        "america asn",
        "unknown",
        "ransom",
        "body",
        "coinminer",
        "malware generic",
        "wed jan",
        "first",
        "status",
        "creation date",
        "search",
        "date",
        "expiration date",
        "name servers",
        "next",
        "mirai",
        "yara detections",
        "filehash",
        "av detections",
        "ids detections",
        "alerts",
        "analysis date",
        "file score",
        "reverse dns",
        "location lao",
        "viet nam",
        "domain",
        "all search",
        "otx scoreblue",
        "hostname",
        "files ip",
        "lazarus",
        "as7552 viettel",
        "vietnam unknown",
        "win32",
        "worm",
        "win32sfone jul",
        "vietnam",
        "etag",
        "telecom",
        "as16625 akamai",
        "as20940",
        "germany",
        "united kingdom",
        "singapore",
        "as20546 soprado",
        "hong kong",
        "as45102 alibaba",
        "taobao network",
        "cname",
        "aaaa",
        "entries",
        "showing",
        "a domains",
        "as38731 vietel",
        "plesk",
        "a li",
        "default page",
        "plesk a",
        "mirai variant",
        "useragent",
        "apache",
        "accept",
        "hello",
        "create c",
        "read c",
        "delete",
        "write",
        "default",
        "create",
        "show",
        "medium",
        "dock",
        "execution",
        "copy",
        "xport",
        "address",
        "as131392",
        "cape",
        "orsam",
        "malware",
        "script urls",
        "moved",
        "record value",
        "cisco umbrella",
        "site",
        "heur",
        "alexa top",
        "safe site",
        "million",
        "malicious site",
        "phishing site",
        "malicious url",
        "opencandy",
        "exploit",
        "agent",
        "phishing",
        "acint",
        "iframe",
        "crack",
        "conduit",
        "artemis",
        "riskware",
        "mimikatz",
        "swrort",
        "downldr",
        "systweak",
        "behav",
        "tiggre",
        "genkryptik",
        "presenoker",
        "filetour",
        "cleaner",
        "wacatac",
        "outbreak",
        "installcore",
        "iobit",
        "rostpay",
        "dropper",
        "mediaget",
        "related pulses",
        "whois",
        "related",
        "msil",
        "zombie",
        "dridex",
        "location viet",
        "pulse submit",
        "url analysis",
        "content",
        "google tag",
        "utc gcfezl5ynvb",
        "utc na",
        "utc google",
        "analytics na",
        "utc linkedin",
        "insight tag",
        "deep malware",
        "iframes",
        "trackers",
        "external-resources",
        "text/html",
        "elf info",
        "header class",
        "elf64 data",
        "header version",
        "os abi",
        "unix",
        "v object",
        "file type",
        "exec",
        "executable file",
        "progbits",
        "type address",
        "offset size",
        "flags",
        "null",
        "nobits",
        "strtab",
        "ip detections",
        "country",
        "us bundled",
        "detections file",
        "name",
        "graph summary",
        "get hello",
        "jaws webserver",
        "outbound",
        "mvpower dvr",
        "shell uce",
        "inbound",
        "activity mirai",
        "mirai",
        "info",
        "performs dns",
        "mitre att",
        "access ta0006",
        "os credential",
        "dumping t1003",
        "enumerates",
        "command",
        "control ta0011",
        "protocol t1071",
        "protocol t1095",
        "relacionada",
        "mirai malware",
        "mirai 04022024",
        "nciipc",
        "ip reputaion",
        "msie",
        "windows nt",
        "slcc2",
        "media center",
        "china as37963",
        "simplified",
        "trojanspy",
        "virustotal",
        "panda",
        "detections type",
        "shell",
        "javascript",
        "dns replication",
        "files referring",
        "lookups",
        "as7552",
        "vhash",
        "ssdeep",
        "magic elf",
        "sysv",
        "trid elf",
        "executable",
        "linux",
        "elf executable",
        "loccel1",
        "echobot",
        "bashlite",
        "malwarebazaar",
        "echobot malware",
        "win32 exe",
        "magic msdos",
        "pe32 executable",
        "intel",
        "ms windows",
        "trid dos",
        "compiler",
        "delphi",
        "serial number",
        "algorithm",
        "thumbprint",
        "valid from",
        "code signing",
        "from",
        "microsoft root",
        "name microsoft",
        "verisign time",
        "stamping",
        "contained",
        "info sections",
        "name virtual",
        "address virtual",
        "size raw",
        "size entropy",
        "md5 chi2",
        "regsetvalueexa",
        "type rtrcdata",
        "sha256 file",
        "threat roundup",
        "october",
        "august",
        "june",
        "september",
        "highly targeted",
        "cyberstalking",
        "round",
        "december",
        "sneaky server",
        "facebook",
        "stealer",
        "agent tesla",
        "pony",
        "april",
        "whitelisted",
        "encrypt",
        "targeting",
        "tsara brashears",
        "otx",
        "alienvault",
        "memcommit",
        "regsz",
        "regopenkeyexw",
        "english",
        "module load",
        "t1129",
        "t1082",
        "windows module",
        "dlls",
        "redline stealer",
        "updater",
        "v3 serial",
        "number",
        "subject public",
        "key info",
        "key algorithm",
        "key identifier",
        "subject key",
        "identifier",
        "x509v3 key",
        "data redacted",
        "cloudflare",
        "redacted",
        "for privacy",
        "code",
        "server",
        "registrar abuse",
        "redacted for",
        "postal code",
        "registrant name",
        "red team",
        "shit",
        "logistics",
        "cyber defense",
        "gootloader",
        "march",
        "sinkhole",
        "just",
        "ramnit",
        "netsupport rat",
        "microsoft",
        "vault",
        "karen",
        "gifts",
        "hidden privacy",
        "threats",
        "malicious",
        "darkgate",
        "core",
        "hacktool",
        "emotet"
      ],
      "references": [
        "https://botnet.ngocronglau.xyz > link discovered by an Alienvault user who notified me they found it researching message from am active user.",
        "https://otx.alienvault.com/indicator/file/02b19639ad1efa59e77f45d130447c05bd2466e26a657cb9cc6ac2e8b30a0026",
        "https://otx.alienvault.com/indicator/file/001546d210a35b7c4c072b6c265f621cf4a9abdd152741d9b58deae2be204355",
        "https://otx.alienvault.com/indicator/hostname/botnet.ngocronglau.xyz",
        "Unix.Mirai Botnet: https://otx.alienvault.com/indicator/hostname/botnet.ngocronglau.xyz",
        "CnC IP: https://otx.alienvault.com/indicator/ip/142.202.242.45",
        "https://otx.alienvault.com/indicator/domain/bunny.net",
        "https://otx.alienvault.com/indicator/ip/210.211.117.205",
        "https://otx.alienvault.com/indicator/ip/143.244.50.212",
        "https://otx.alienvault.com/indicator/ip/125.235.4.59",
        "AV Detection: ELF:Mirai-GH\\ [Trj]",
        "IDS Detections:  MVPower DVR Shell UCE Mirai  | Variant User-Agent (Outbound) JAWS Webserver Unauthenticated Shell Command Execution",
        "IDS Detections: Huawei Remote Command Execution (CVE-2017-17215) Huawei Remote Command Execution - Outbound (CVE-2017-17215) Huawei HG532 RCE Vulnerability (CVE-2017-17215) Mirai Variant User-Agent (Inbound) HackingTrio UA (Hello, World) 401TRG Generic Webshell Request - POST with wget in body HTTP traffic on port 443 (POST",
        "IDS Detections: Mirai Variant User-Agent (Inbound) HackingTrio UA (Hello, World)",
        "IDS Detections: 401TRG Generic Webshell Request - POST with wget in body HTTP traffic on port 443 (POST) ...",
        "Alerts: dead_host network_icmp tcp_syn_scan nolookup_communication network_cnc_http network_http p2p_cnc writes_to_stdout",
        "Matches rule Linux_Trojan_Mirai_6a77af0f from ruleset Linux_Trojan_Mirai by Elastic Security | botnet.ngocronglau.xyz",
        "https://otx.alienvault.com/indicator/file/2b5deac6176124ee1f7d237f070c39b03c964fce9a9fba0aaa1bce102710d2e0",
        "cu-payment-porch.pdv-3.ap-southeast-2.production.jet-external.com | qa.proxy.cognito.tigomoney.io | https://trackon.fr/track/clique",
        "Crowdsourced YARA rules Matches:  rule INDICATOR_EXE_Packed_MEW from ruleset indicator_packed by ditekSHen",
        "Crowdsourced YARA rules Matches: INDICATOR_EXE_Packed_MEW from ruleset indicator_packed by ditekSHen",
        "Crowdsourced YARA rules Matches: SUSP_Unsigned_OSPPSVC from ruleset gen_sign_anomalies by Florian Roth (Nextron Systems",
        "Crowdsourced YARA rules Matches: IMPLANT_4_v3_AlternativeRule from ruleset apt_grizzlybear_uscert by Florian Roth (Nextron Systems)",
        "Crowdsourced YARA rules Matches: Matches rule IMPLANT_4_v3_AlternativeRule from ruleset apt_grizzlybear_uscert by Florian Roth (Nextron Systems",
        "https://wallpapers-nature.com/tsara-brashears/tse1-mm-bing-net",
        "wallpapers-nature.com",
        "Was anyone else notified? I'm not sure why I was.",
        "Through research I did notice many references to target I'm researching for. Phishing/Injection attempt? I didn't click on links.",
        "CS Sigma: Matches rule Python Initiated Connection by frack113"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Generic",
          "display_name": "Generic",
          "target": null
        },
        {
          "id": "Unix.Trojan.Mirai-9441505-0",
          "display_name": "Unix.Trojan.Mirai-9441505-0",
          "target": null
        },
        {
          "id": "ALF:E5.SpikeAex.rhh_mcv",
          "display_name": "ALF:E5.SpikeAex.rhh_mcv",
          "target": null
        },
        {
          "id": "Win.Dropper.Bulz-9910065-0",
          "display_name": "Win.Dropper.Bulz-9910065-0",
          "target": null
        },
        {
          "id": "Win32:Malware-gen",
          "display_name": "Win32:Malware-gen",
          "target": null
        },
        {
          "id": "ALF:HeraklezEval:Trojan:Win32/ClipBanker",
          "display_name": "ALF:HeraklezEval:Trojan:Win32/ClipBanker",
          "target": null
        },
        {
          "id": "Win.Dropper.Autoit-6688751-0",
          "display_name": "Win.Dropper.Autoit-6688751-0",
          "target": null
        },
        {
          "id": "ELF:Mirai-GH\\ [Trj]",
          "display_name": "ELF:Mirai-GH\\ [Trj]",
          "target": null
        },
        {
          "id": "Win.Dropper.Dridex-9986041-0",
          "display_name": "Win.Dropper.Dridex-9986041-0",
          "target": null
        },
        {
          "id": "ALF:HeraklezEval:Trojan:Win32/Zombie",
          "display_name": "ALF:HeraklezEval:Trojan:Win32/Zombie",
          "target": null
        },
        {
          "id": "Win.Packer.pkr_ce1a-9980177-0",
          "display_name": "Win.Packer.pkr_ce1a-9980177-0",
          "target": null
        },
        {
          "id": "Worm:Win32/Sfone.A",
          "display_name": "Worm:Win32/Sfone.A",
          "target": "/malware/Worm:Win32/Sfone.A"
        },
        {
          "id": "Worm:Win32/Sfone",
          "display_name": "Worm:Win32/Sfone",
          "target": "/malware/Worm:Win32/Sfone"
        },
        {
          "id": "Win.Malware.Bbabdcdc-7358312-0",
          "display_name": "Win.Malware.Bbabdcdc-7358312-0",
          "target": null
        },
        {
          "id": "Win32:Trojan-gen",
          "display_name": "Win32:Trojan-gen",
          "target": null
        },
        {
          "id": "trojan.mirai/fszhh",
          "display_name": "trojan.mirai/fszhh",
          "target": null
        },
        {
          "id": "DDOS:Linux/Mirai",
          "display_name": "DDOS:Linux/Mirai",
          "target": "/malware/DDOS:Linux/Mirai"
        },
        {
          "id": "ANDROID/AVE.Mirai.fszhh",
          "display_name": "ANDROID/AVE.Mirai.fszhh",
          "target": null
        },
        {
          "id": "Flyagent L",
          "display_name": "Flyagent L",
          "target": null
        },
        {
          "id": "Win-Trojan/Malpacked5.Gen",
          "display_name": "Win-Trojan/Malpacked5.Gen",
          "target": null
        },
        {
          "id": "Atros3.LDJ",
          "display_name": "Atros3.LDJ",
          "target": null
        },
        {
          "id": "a variant of Win32/FlyStudio.Packed.AD potentially unwanted",
          "display_name": "a variant of Win32/FlyStudio.Packed.AD potentially unwanted",
          "target": null
        },
        {
          "id": "TrojanSpy:Win32/Gucotut.A",
          "display_name": "TrojanSpy:Win32/Gucotut.A",
          "target": "/malware/TrojanSpy:Win32/Gucotut.A"
        },
        {
          "id": "W32/Pidgeon-A",
          "display_name": "W32/Pidgeon-A",
          "target": null
        },
        {
          "id": "Variant.Zusy.151902",
          "display_name": "Variant.Zusy.151902",
          "target": null
        },
        {
          "id": "trojan.mirai/fedr",
          "display_name": "trojan.mirai/fedr",
          "target": null
        },
        {
          "id": "Win.Malware.Trojanx-9862538-0",
          "display_name": "Win.Malware.Trojanx-9862538-0",
          "target": null
        },
        {
          "id": "Win32:PWSX-gen\\ [Trj]",
          "display_name": "Win32:PWSX-gen\\ [Trj]",
          "target": null
        },
        {
          "id": "virus.ramnit/nimnul",
          "display_name": "virus.ramnit/nimnul",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1053",
          "name": "Scheduled Task/Job",
          "display_name": "T1053 - Scheduled Task/Job"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1119",
          "name": "Automated Collection",
          "display_name": "T1119 - Automated Collection"
        },
        {
          "id": "T1129",
          "name": "Shared Modules",
          "display_name": "T1129 - Shared Modules"
        },
        {
          "id": "T1143",
          "name": "Hidden Window",
          "display_name": "T1143 - Hidden Window"
        },
        {
          "id": "T1003",
          "name": "OS Credential Dumping",
          "display_name": "T1003 - OS Credential Dumping"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1095",
          "name": "Non-Application Layer Protocol",
          "display_name": "T1095 - Non-Application Layer Protocol"
        },
        {
          "id": "T1571",
          "name": "Non-Standard Port",
          "display_name": "T1571 - Non-Standard Port"
        },
        {
          "id": "TA0006",
          "name": "Credential Access",
          "display_name": "TA0006 - Credential Access"
        },
        {
          "id": "TA0011",
          "name": "Command and Control",
          "display_name": "TA0011 - Command and Control"
        },
        {
          "id": "T1045",
          "name": "Software Packing",
          "display_name": "T1045 - Software Packing"
        },
        {
          "id": "T1005",
          "name": "Data from Local System",
          "display_name": "T1005 - Data from Local System"
        },
        {
          "id": "T1012",
          "name": "Query Registry",
          "display_name": "T1012 - Query Registry"
        },
        {
          "id": "T1047",
          "name": "Windows Management Instrumentation",
          "display_name": "T1047 - Windows Management Instrumentation"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1060",
          "name": "Registry Run Keys / Startup Folder",
          "display_name": "T1060 - Registry Run Keys / Startup Folder"
        },
        {
          "id": "T1070",
          "name": "Indicator Removal on Host",
          "display_name": "T1070 - Indicator Removal on Host"
        },
        {
          "id": "T1081",
          "name": "Credentials in Files",
          "display_name": "T1081 - Credentials in Files"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 51,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 2,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "scoreblue",
        "id": "254100",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 351,
        "FileHash-SHA1": 349,
        "FileHash-SHA256": 3715,
        "domain": 3326,
        "hostname": 5200,
        "URL": 13151,
        "email": 9,
        "CVE": 7,
        "CIDR": 2
      },
      "indicator_count": 26110,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 243,
      "modified_text": "640 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "https://d-ipv4.mmapiws.com",
    "type": "URL"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "https://d-ipv4.mmapiws.com",
    "type": "URL",
    "found": false,
    "verdict": "clean",
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1776644067.0065637
}