{
  "type": "URL",
  "indicator": "https://ddome.matomo.cloud",
  "general": {
    "sections": [
      "general",
      "url_list",
      "http_scans",
      "screenshot"
    ],
    "indicator": "https://ddome.matomo.cloud",
    "type": "url",
    "type_title": "URL",
    "validation": [],
    "base_indicator": {
      "id": 3832015386,
      "indicator": "https://ddome.matomo.cloud",
      "type": "URL",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 7,
      "pulses": [
        {
          "id": "65bca8fcbe62297d71b47c33",
          "name": "Ragnar Locker",
          "description": "\u2022 FBI Flash CU-000163-MW: RagnarLocker Ransomware Indicators of Compromise\n\u2022 Found in https://www.Esurance.com\n  108.26.193.165\nAS 701 (UUNET)\n\u2022108.26.193.165 Postal Code: 02465 Reverse Domain Lookup: pool-108-26-193-165.bstnma.fios.verizon.net \n| Ragnar Locker is ransomware for Windows and Linux that exfiltrates information from a compromised machine, encrypts files using the Salsa20 encryption algorithm, and demands that victims pay a ransom to recover their data. The Ragnar Locker group is known to employ a double extortion tactic.",
          "modified": "2024-03-03T08:00:03.432000",
          "created": "2024-02-02T08:34:04.425000",
          "tags": [
            "referrer",
            "contacted",
            "whois record",
            "ssl certificate",
            "whois whois",
            "contacted urls",
            "execution",
            "historical ssl",
            "red team",
            "gang breached",
            "agent tesla",
            "redline stealer",
            "metro",
            "android",
            "urls url",
            "files",
            "kgs0",
            "kls0",
            "orgtechhandle",
            "orgtechref",
            "orgabusehandle",
            "orgdnshandle",
            "orgdnsref",
            "whois lookup",
            "netrange",
            "nethandle",
            "net108",
            "net1080000",
            "communicating",
            "urls http",
            "ransomware gang",
            "breached",
            "team",
            "first",
            "utc submissions",
            "submitters",
            "gandi sas",
            "psiusa",
            "domain robot",
            "porkbun llc",
            "keysystems gmbh",
            "csc corporate",
            "domains",
            "domain name",
            "network pty",
            "tucows",
            "com laude",
            "dynadot inc"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 23,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 8354,
            "FileHash-MD5": 104,
            "FileHash-SHA1": 81,
            "FileHash-SHA256": 2711,
            "CIDR": 5,
            "CVE": 6,
            "domain": 1489,
            "hostname": 3058,
            "email": 5
          },
          "indicator_count": 15813,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 228,
          "modified_text": "777 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "65b93e70b75e7dce7168f4dd",
          "name": "Google - Lumma Stealer| QakBot | Emotet",
          "description": "Lumma is classified as a stealer - a type of malware that extracts sensitive information from infected devices.\n\nYou can't see it. You will see https://www.google.com and your search. It's hidden spyware. extremely malicious. Targeted individual.",
          "modified": "2024-02-29T17:01:09.717000",
          "created": "2024-01-30T18:22:40.905000",
          "tags": [
            "ssl certificate",
            "whois record",
            "threat roundup",
            "contacted",
            "historical ssl",
            "referrer",
            "urls url",
            "whois whois",
            "october",
            "resolutions",
            "august",
            "execution",
            "installer",
            "iframe",
            "malware",
            "core",
            "emotet",
            "lumma stealer",
            "ransomexx",
            "azorult",
            "ursnif",
            "hacktool",
            "june",
            "qakbot",
            "qbot",
            "april",
            "targeting",
            "tsara brashears",
            "active threat"
          ],
          "references": [
            "google.com.uy [Google search browser, masked, links to malicious porn malware spreader, malvertizing, collection host]",
            "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian [ iOS unlocker & password cracker]",
            "toolbarqueries.google.com.uy"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "Lumma Stealer",
              "display_name": "Lumma Stealer",
              "target": null
            },
            {
              "id": "HackTool",
              "display_name": "HackTool",
              "target": null
            },
            {
              "id": "Emotet",
              "display_name": "Emotet",
              "target": null
            },
            {
              "id": "Azorult",
              "display_name": "Azorult",
              "target": null
            },
            {
              "id": "RansomEXX",
              "display_name": "RansomEXX",
              "target": null
            },
            {
              "id": "QakBot",
              "display_name": "QakBot",
              "target": null
            },
            {
              "id": "Qbot",
              "display_name": "Qbot",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1068",
              "name": "Exploitation for Privilege Escalation",
              "display_name": "T1068 - Exploitation for Privilege Escalation"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1449",
              "name": "Exploit SS7 to Redirect Phone Calls/SMS",
              "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
            },
            {
              "id": "T1583.005",
              "name": "Botnet",
              "display_name": "T1583.005 - Botnet"
            },
            {
              "id": "T1031",
              "name": "Modify Existing Service",
              "display_name": "T1031 - Modify Existing Service"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1071.004",
              "name": "DNS",
              "display_name": "T1071.004 - DNS"
            },
            {
              "id": "T1071.003",
              "name": "Mail Protocols",
              "display_name": "T1071.003 - Mail Protocols"
            },
            {
              "id": "TA0002",
              "name": "Execution",
              "display_name": "TA0002 - Execution"
            },
            {
              "id": "TA0003",
              "name": "Persistence",
              "display_name": "TA0003 - Persistence"
            },
            {
              "id": "TA0004",
              "name": "Privilege Escalation",
              "display_name": "TA0004 - Privilege Escalation"
            },
            {
              "id": "TA0005",
              "name": "Defense Evasion",
              "display_name": "TA0005 - Defense Evasion"
            },
            {
              "id": "TA0006",
              "name": "Credential Access",
              "display_name": "TA0006 - Credential Access"
            },
            {
              "id": "TA0007",
              "name": "Discovery",
              "display_name": "TA0007 - Discovery"
            },
            {
              "id": "TA0009",
              "name": "Collection",
              "display_name": "TA0009 - Collection"
            },
            {
              "id": "T1030",
              "name": "Data Transfer Size Limits",
              "display_name": "T1030 - Data Transfer Size Limits"
            },
            {
              "id": "TA0010",
              "name": "Exfiltration",
              "display_name": "TA0010 - Exfiltration"
            },
            {
              "id": "TA0011",
              "name": "Command and Control",
              "display_name": "TA0011 - Command and Control"
            }
          ],
          "industries": [
            "Civil Society"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 27,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 1,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 50,
            "FileHash-SHA1": 46,
            "FileHash-SHA256": 3377,
            "hostname": 2502,
            "URL": 8531,
            "domain": 1250,
            "CVE": 2
          },
          "indicator_count": 15758,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 220,
          "modified_text": "780 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "65b7e3fe91a1aceb955e54f6",
          "name": "NSO Group Pegasus",
          "description": "NSO Group\nNSO Group Technologies is an Israeli cyber-intelligence firm primarily known for its proprietary spyware Pegasus, which is capable of remote zero-click.\n\nHeavily targeting Tsara Brashears\nSet in motion when  Brashears  was attacked and critically injured by Jeffrey Scott Reimer DPT in Denver Colorado at  Concentra AMS whilst bit knowing she was in the American Workers compensation system. Brashears was not represented by an attorney at the time. She was threatened by Mark Montano MD who wanted wife to be elected coroner. Denied care for a spinal cord injury. All records stolen or falsified. Death threats and other cyber or physical attacks, contact with this strange group is common. Recent, injurious attempt on life dismissed by alleged detective by phone. Found, confirmed, let another offender walk. Ghost car. Ghost offender. Frightened attorneys?  I am her only advocate.",
          "modified": "2024-02-28T15:01:20.140000",
          "created": "2024-01-29T17:44:30.147000",
          "tags": [
            "ssl certificate",
            "whois record",
            "whois whois",
            "communicating",
            "cellbrite",
            "urls http",
            "referrer",
            "historical ssl",
            "nullmixer",
            "smokeloader",
            "redline stealer",
            "installer",
            "hiddentear",
            "probe",
            "nso group",
            "pegasus",
            "community",
            "xcitium verdict",
            "cloud",
            "bitdefender",
            "history",
            "utc http",
            "response final",
            "url final",
            "ip address",
            "status code",
            "compiler",
            "basic",
            "pe32",
            "intel",
            "ms windows",
            "win16 ne",
            "os2 executable",
            "generic windos",
            "executable",
            "pe32 compiler",
            "rticon russian",
            "info header",
            "name md5",
            "contained",
            "type",
            "language",
            "ico rtgroupicon",
            "russian",
            "overlay",
            "urls",
            "domains",
            "gandi sas",
            "contacted",
            "markmonitor",
            "ip detections",
            "country",
            "pe resource",
            "children",
            "file type",
            "ico mainicon",
            "linkid252669",
            "win32 dll",
            "ms visual",
            "win32 dynamic",
            "win32 exe",
            "files",
            "afrefhttp",
            "execution",
            "highly targeted",
            "http",
            "agent tesla",
            "blackbag",
            "relations most",
            "core",
            "malware",
            "emotet",
            "critical",
            "copy",
            "qakbot",
            "trojan",
            "ransomexx",
            "ryuk",
            "ransomware",
            "matanbuchus",
            "cobalt strike",
            "bazarloader",
            "as15169 google",
            "united",
            "passive dns",
            "aaaa",
            "title",
            "a domains",
            "body html",
            "head meta",
            "moved title",
            "tsara brashears",
            "offender",
            "Robert neill",
            "jeffery scott reimer",
            "assaulted",
            "sci",
            "warning",
            "denver",
            "death threats",
            "porn malvertizing",
            "bomb",
            "bomb threats"
          ],
          "references": [
            "https://www.nsogroup.com/",
            "https://www.anyxxxtube.net/search-porn/tsara-brashears/",
            "ww.google.com.uy",
            "321Survive.exe",
            "https://en.m.wikipedia.org \u203a wiki NSO Group"
          ],
          "public": 1,
          "adversary": "NSO Group",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "trojan.wanna/wannacry",
              "display_name": "trojan.wanna/wannacry",
              "target": null
            }
          ],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 21,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 570,
            "URL": 2908,
            "FileHash-MD5": 98,
            "FileHash-SHA1": 84,
            "FileHash-SHA256": 2241,
            "hostname": 1043,
            "CVE": 3,
            "email": 1
          },
          "indicator_count": 6948,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 220,
          "modified_text": "781 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "65b7e3fe934ae9d391614c0d",
          "name": "NSO Group Pegasus",
          "description": "NSO Group\nNSO Group Technologies is an Israeli cyber-intelligence firm primarily known for its proprietary spyware Pegasus, which is capable of remote zero-click.\n\nHeavily targeting Tsara Brashears\nSet in motion when  Brashears  was attacked and critically injured by Jeffrey Scott Reimer DPT in Denver Colorado at  Concentra AMS whilst bit knowing she was in the American Workers compensation system. Brashears was not represented by an attorney at the time. She was threatened by Mark Montano MD who wanted wife to be elected coroner. Denied care for a spinal cord injury. All records stolen or falsified. Death threats and other cyber or physical attacks, contact with this strange group is common. Recent, injurious attempt on life dismissed by alleged detective by phone. Found, confirmed, let another offender walk. Ghost car. Ghost offender. Frightened attorneys?  I am her only advocate.",
          "modified": "2024-02-28T15:01:20.140000",
          "created": "2024-01-29T17:44:30.585000",
          "tags": [
            "ssl certificate",
            "whois record",
            "whois whois",
            "communicating",
            "cellbrite",
            "urls http",
            "referrer",
            "historical ssl",
            "nullmixer",
            "smokeloader",
            "redline stealer",
            "installer",
            "hiddentear",
            "probe",
            "nso group",
            "pegasus",
            "community",
            "xcitium verdict",
            "cloud",
            "bitdefender",
            "history",
            "utc http",
            "response final",
            "url final",
            "ip address",
            "status code",
            "compiler",
            "basic",
            "pe32",
            "intel",
            "ms windows",
            "win16 ne",
            "os2 executable",
            "generic windos",
            "executable",
            "pe32 compiler",
            "rticon russian",
            "info header",
            "name md5",
            "contained",
            "type",
            "language",
            "ico rtgroupicon",
            "russian",
            "overlay",
            "urls",
            "domains",
            "gandi sas",
            "contacted",
            "markmonitor",
            "ip detections",
            "country",
            "pe resource",
            "children",
            "file type",
            "ico mainicon",
            "linkid252669",
            "win32 dll",
            "ms visual",
            "win32 dynamic",
            "win32 exe",
            "files",
            "afrefhttp",
            "execution",
            "highly targeted",
            "http",
            "agent tesla",
            "blackbag",
            "relations most",
            "core",
            "malware",
            "emotet",
            "critical",
            "copy",
            "qakbot",
            "trojan",
            "ransomexx",
            "ryuk",
            "ransomware",
            "matanbuchus",
            "cobalt strike",
            "bazarloader",
            "as15169 google",
            "united",
            "passive dns",
            "aaaa",
            "title",
            "a domains",
            "body html",
            "head meta",
            "moved title",
            "tsara brashears",
            "offender",
            "Robert neill",
            "jeffery scott reimer",
            "assaulted",
            "sci",
            "warning",
            "denver",
            "death threats",
            "porn malvertizing",
            "bomb",
            "bomb threats"
          ],
          "references": [
            "https://www.nsogroup.com/",
            "https://www.anyxxxtube.net/search-porn/tsara-brashears/",
            "ww.google.com.uy",
            "321Survive.exe",
            "https://en.m.wikipedia.org \u203a wiki NSO Group"
          ],
          "public": 1,
          "adversary": "NSO Group",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "trojan.wanna/wannacry",
              "display_name": "trojan.wanna/wannacry",
              "target": null
            }
          ],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 21,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 570,
            "URL": 2908,
            "FileHash-MD5": 98,
            "FileHash-SHA1": 84,
            "FileHash-SHA256": 2241,
            "hostname": 1043,
            "CVE": 3,
            "email": 1
          },
          "indicator_count": 6948,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 219,
          "modified_text": "781 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "65b7e4017a14cda8d09c9bf8",
          "name": "NSO Group Pegasus",
          "description": "NSO Group\nNSO Group Technologies is an Israeli cyber-intelligence firm primarily known for its proprietary spyware Pegasus, which is capable of remote zero-click.\n\nHeavily targeting Tsara Brashears\nSet in motion when  Brashears  was attacked and critically injured by Jeffrey Scott Reimer DPT in Denver Colorado at  Concentra AMS whilst bit knowing she was in the American Workers compensation system. Brashears was not represented by an attorney at the time. She was threatened by Mark Montano MD who wanted wife to be elected coroner. Denied care for a spinal cord injury. All records stolen or falsified. Death threats and other cyber or physical attacks, contact with this strange group is common. Recent, injurious attempt on life dismissed by alleged detective by phone. Found, confirmed, let another offender walk. Ghost car. Ghost offender. Frightened attorneys?  I am her only advocate.",
          "modified": "2024-02-28T15:01:20.140000",
          "created": "2024-01-29T17:44:33.270000",
          "tags": [
            "ssl certificate",
            "whois record",
            "whois whois",
            "communicating",
            "cellbrite",
            "urls http",
            "referrer",
            "historical ssl",
            "nullmixer",
            "smokeloader",
            "redline stealer",
            "installer",
            "hiddentear",
            "probe",
            "nso group",
            "pegasus",
            "community",
            "xcitium verdict",
            "cloud",
            "bitdefender",
            "history",
            "utc http",
            "response final",
            "url final",
            "ip address",
            "status code",
            "compiler",
            "basic",
            "pe32",
            "intel",
            "ms windows",
            "win16 ne",
            "os2 executable",
            "generic windos",
            "executable",
            "pe32 compiler",
            "rticon russian",
            "info header",
            "name md5",
            "contained",
            "type",
            "language",
            "ico rtgroupicon",
            "russian",
            "overlay",
            "urls",
            "domains",
            "gandi sas",
            "contacted",
            "markmonitor",
            "ip detections",
            "country",
            "pe resource",
            "children",
            "file type",
            "ico mainicon",
            "linkid252669",
            "win32 dll",
            "ms visual",
            "win32 dynamic",
            "win32 exe",
            "files",
            "afrefhttp",
            "execution",
            "highly targeted",
            "http",
            "agent tesla",
            "blackbag",
            "relations most",
            "core",
            "malware",
            "emotet",
            "critical",
            "copy",
            "qakbot",
            "trojan",
            "ransomexx",
            "ryuk",
            "ransomware",
            "matanbuchus",
            "cobalt strike",
            "bazarloader",
            "as15169 google",
            "united",
            "passive dns",
            "aaaa",
            "title",
            "a domains",
            "body html",
            "head meta",
            "moved title",
            "tsara brashears",
            "offender",
            "Robert neill",
            "jeffery scott reimer",
            "assaulted",
            "sci",
            "warning",
            "denver",
            "death threats",
            "porn malvertizing",
            "bomb",
            "bomb threats"
          ],
          "references": [
            "https://www.nsogroup.com/",
            "https://www.anyxxxtube.net/search-porn/tsara-brashears/",
            "ww.google.com.uy",
            "321Survive.exe",
            "https://en.m.wikipedia.org \u203a wiki NSO Group"
          ],
          "public": 1,
          "adversary": "NSO Group",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "trojan.wanna/wannacry",
              "display_name": "trojan.wanna/wannacry",
              "target": null
            }
          ],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 21,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 570,
            "URL": 2908,
            "FileHash-MD5": 98,
            "FileHash-SHA1": 84,
            "FileHash-SHA256": 2241,
            "hostname": 1043,
            "CVE": 3,
            "email": 1
          },
          "indicator_count": 6948,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 220,
          "modified_text": "781 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "65b7e406028ca6f363f41315",
          "name": "NSO Group Pegasus",
          "description": "NSO Group\nNSO Group Technologies is an Israeli cyber-intelligence firm primarily known for its proprietary spyware Pegasus, which is capable of remote zero-click.\n\nHeavily targeting Tsara Brashears\nSet in motion when  Brashears  was attacked and critically injured by Jeffrey Scott Reimer DPT in Denver Colorado at  Concentra AMS whilst bit knowing she was in the American Workers compensation system. Brashears was not represented by an attorney at the time. She was threatened by Mark Montano MD who wanted wife to be elected coroner. Denied care for a spinal cord injury. All records stolen or falsified. Death threats and other cyber or physical attacks, contact with this strange group is common. Recent, injurious attempt on life dismissed by alleged detective by phone. Found, confirmed, let another offender walk. Ghost car. Ghost offender. Frightened attorneys?  I am her only advocate.",
          "modified": "2024-02-28T15:01:20.140000",
          "created": "2024-01-29T17:44:38.424000",
          "tags": [
            "ssl certificate",
            "whois record",
            "whois whois",
            "communicating",
            "cellbrite",
            "urls http",
            "referrer",
            "historical ssl",
            "nullmixer",
            "smokeloader",
            "redline stealer",
            "installer",
            "hiddentear",
            "probe",
            "nso group",
            "pegasus",
            "community",
            "xcitium verdict",
            "cloud",
            "bitdefender",
            "history",
            "utc http",
            "response final",
            "url final",
            "ip address",
            "status code",
            "compiler",
            "basic",
            "pe32",
            "intel",
            "ms windows",
            "win16 ne",
            "os2 executable",
            "generic windos",
            "executable",
            "pe32 compiler",
            "rticon russian",
            "info header",
            "name md5",
            "contained",
            "type",
            "language",
            "ico rtgroupicon",
            "russian",
            "overlay",
            "urls",
            "domains",
            "gandi sas",
            "contacted",
            "markmonitor",
            "ip detections",
            "country",
            "pe resource",
            "children",
            "file type",
            "ico mainicon",
            "linkid252669",
            "win32 dll",
            "ms visual",
            "win32 dynamic",
            "win32 exe",
            "files",
            "afrefhttp",
            "execution",
            "highly targeted",
            "http",
            "agent tesla",
            "blackbag",
            "relations most",
            "core",
            "malware",
            "emotet",
            "critical",
            "copy",
            "qakbot",
            "trojan",
            "ransomexx",
            "ryuk",
            "ransomware",
            "matanbuchus",
            "cobalt strike",
            "bazarloader",
            "as15169 google",
            "united",
            "passive dns",
            "aaaa",
            "title",
            "a domains",
            "body html",
            "head meta",
            "moved title",
            "tsara brashears",
            "offender",
            "Robert neill",
            "jeffery scott reimer",
            "assaulted",
            "sci",
            "warning",
            "denver",
            "death threats",
            "porn malvertizing",
            "bomb",
            "bomb threats"
          ],
          "references": [
            "https://www.nsogroup.com/",
            "https://www.anyxxxtube.net/search-porn/tsara-brashears/",
            "ww.google.com.uy",
            "321Survive.exe",
            "https://en.m.wikipedia.org \u203a wiki NSO Group"
          ],
          "public": 1,
          "adversary": "NSO Group",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "trojan.wanna/wannacry",
              "display_name": "trojan.wanna/wannacry",
              "target": null
            }
          ],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 22,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 570,
            "URL": 2908,
            "FileHash-MD5": 98,
            "FileHash-SHA1": 84,
            "FileHash-SHA256": 2241,
            "hostname": 1043,
            "CVE": 3,
            "email": 1
          },
          "indicator_count": 6948,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 220,
          "modified_text": "781 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "65b8071976a7e6dccaabbada",
          "name": "NSO Group Pegasus",
          "description": "",
          "modified": "2024-02-28T15:01:20.140000",
          "created": "2024-01-29T20:14:17.001000",
          "tags": [
            "ssl certificate",
            "whois record",
            "whois whois",
            "communicating",
            "cellbrite",
            "urls http",
            "referrer",
            "historical ssl",
            "nullmixer",
            "smokeloader",
            "redline stealer",
            "installer",
            "hiddentear",
            "probe",
            "nso group",
            "pegasus",
            "community",
            "xcitium verdict",
            "cloud",
            "bitdefender",
            "history",
            "utc http",
            "response final",
            "url final",
            "ip address",
            "status code",
            "compiler",
            "basic",
            "pe32",
            "intel",
            "ms windows",
            "win16 ne",
            "os2 executable",
            "generic windos",
            "executable",
            "pe32 compiler",
            "rticon russian",
            "info header",
            "name md5",
            "contained",
            "type",
            "language",
            "ico rtgroupicon",
            "russian",
            "overlay",
            "urls",
            "domains",
            "gandi sas",
            "contacted",
            "markmonitor",
            "ip detections",
            "country",
            "pe resource",
            "children",
            "file type",
            "ico mainicon",
            "linkid252669",
            "win32 dll",
            "ms visual",
            "win32 dynamic",
            "win32 exe",
            "files",
            "afrefhttp",
            "execution",
            "highly targeted",
            "http",
            "agent tesla",
            "blackbag",
            "relations most",
            "core",
            "malware",
            "emotet",
            "critical",
            "copy",
            "qakbot",
            "trojan",
            "ransomexx",
            "ryuk",
            "ransomware",
            "matanbuchus",
            "cobalt strike",
            "bazarloader",
            "as15169 google",
            "united",
            "passive dns",
            "aaaa",
            "title",
            "a domains",
            "body html",
            "head meta",
            "moved title",
            "tsara brashears",
            "offender",
            "Robert neill",
            "jeffery scott reimer",
            "assaulted",
            "sci",
            "warning",
            "denver",
            "death threats",
            "porn malvertizing",
            "bomb",
            "bomb threats"
          ],
          "references": [
            "https://www.nsogroup.com/",
            "https://www.anyxxxtube.net/search-porn/tsara-brashears/",
            "ww.google.com.uy",
            "321Survive.exe",
            "https://en.m.wikipedia.org \u203a wiki NSO Group"
          ],
          "public": 1,
          "adversary": "NSO Group",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "trojan.wanna/wannacry",
              "display_name": "trojan.wanna/wannacry",
              "target": null
            }
          ],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": "65b7e406028ca6f363f41315",
          "export_count": 21,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 570,
            "URL": 2908,
            "FileHash-MD5": 98,
            "FileHash-SHA1": 84,
            "FileHash-SHA256": 2241,
            "hostname": 1043,
            "CVE": 3,
            "email": 1
          },
          "indicator_count": 6948,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 227,
          "modified_text": "781 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian [ iOS unlocker & password cracker]",
        "321Survive.exe",
        "google.com.uy [Google search browser, masked, links to malicious porn malware spreader, malvertizing, collection host]",
        "toolbarqueries.google.com.uy",
        "https://en.m.wikipedia.org \u203a wiki NSO Group",
        "https://www.nsogroup.com/",
        "ww.google.com.uy",
        "https://www.anyxxxtube.net/search-porn/tsara-brashears/"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 0
        },
        "other": {
          "adversary": [
            "NSO Group"
          ],
          "malware_families": [
            "Hacktool",
            "Qakbot",
            "Qbot",
            "Emotet",
            "Ransomexx",
            "Azorult",
            "Lumma stealer",
            "Trojan.wanna/wannacry"
          ],
          "industries": [
            "Civil society"
          ],
          "unique_indicators": 34418
        }
      }
    },
    "false_positive": [],
    "alexa": "http://www.alexa.com/siteinfo/matomo.cloud",
    "whois": "http://whois.domaintools.com/matomo.cloud",
    "domain": "matomo.cloud",
    "hostname": "ddome.matomo.cloud"
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 7,
  "pulses": [
    {
      "id": "65bca8fcbe62297d71b47c33",
      "name": "Ragnar Locker",
      "description": "\u2022 FBI Flash CU-000163-MW: RagnarLocker Ransomware Indicators of Compromise\n\u2022 Found in https://www.Esurance.com\n  108.26.193.165\nAS 701 (UUNET)\n\u2022108.26.193.165 Postal Code: 02465 Reverse Domain Lookup: pool-108-26-193-165.bstnma.fios.verizon.net \n| Ragnar Locker is ransomware for Windows and Linux that exfiltrates information from a compromised machine, encrypts files using the Salsa20 encryption algorithm, and demands that victims pay a ransom to recover their data. The Ragnar Locker group is known to employ a double extortion tactic.",
      "modified": "2024-03-03T08:00:03.432000",
      "created": "2024-02-02T08:34:04.425000",
      "tags": [
        "referrer",
        "contacted",
        "whois record",
        "ssl certificate",
        "whois whois",
        "contacted urls",
        "execution",
        "historical ssl",
        "red team",
        "gang breached",
        "agent tesla",
        "redline stealer",
        "metro",
        "android",
        "urls url",
        "files",
        "kgs0",
        "kls0",
        "orgtechhandle",
        "orgtechref",
        "orgabusehandle",
        "orgdnshandle",
        "orgdnsref",
        "whois lookup",
        "netrange",
        "nethandle",
        "net108",
        "net1080000",
        "communicating",
        "urls http",
        "ransomware gang",
        "breached",
        "team",
        "first",
        "utc submissions",
        "submitters",
        "gandi sas",
        "psiusa",
        "domain robot",
        "porkbun llc",
        "keysystems gmbh",
        "csc corporate",
        "domains",
        "domain name",
        "network pty",
        "tucows",
        "com laude",
        "dynadot inc"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 23,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 8354,
        "FileHash-MD5": 104,
        "FileHash-SHA1": 81,
        "FileHash-SHA256": 2711,
        "CIDR": 5,
        "CVE": 6,
        "domain": 1489,
        "hostname": 3058,
        "email": 5
      },
      "indicator_count": 15813,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 228,
      "modified_text": "777 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "65b93e70b75e7dce7168f4dd",
      "name": "Google - Lumma Stealer| QakBot | Emotet",
      "description": "Lumma is classified as a stealer - a type of malware that extracts sensitive information from infected devices.\n\nYou can't see it. You will see https://www.google.com and your search. It's hidden spyware. extremely malicious. Targeted individual.",
      "modified": "2024-02-29T17:01:09.717000",
      "created": "2024-01-30T18:22:40.905000",
      "tags": [
        "ssl certificate",
        "whois record",
        "threat roundup",
        "contacted",
        "historical ssl",
        "referrer",
        "urls url",
        "whois whois",
        "october",
        "resolutions",
        "august",
        "execution",
        "installer",
        "iframe",
        "malware",
        "core",
        "emotet",
        "lumma stealer",
        "ransomexx",
        "azorult",
        "ursnif",
        "hacktool",
        "june",
        "qakbot",
        "qbot",
        "april",
        "targeting",
        "tsara brashears",
        "active threat"
      ],
      "references": [
        "google.com.uy [Google search browser, masked, links to malicious porn malware spreader, malvertizing, collection host]",
        "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian [ iOS unlocker & password cracker]",
        "toolbarqueries.google.com.uy"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "Lumma Stealer",
          "display_name": "Lumma Stealer",
          "target": null
        },
        {
          "id": "HackTool",
          "display_name": "HackTool",
          "target": null
        },
        {
          "id": "Emotet",
          "display_name": "Emotet",
          "target": null
        },
        {
          "id": "Azorult",
          "display_name": "Azorult",
          "target": null
        },
        {
          "id": "RansomEXX",
          "display_name": "RansomEXX",
          "target": null
        },
        {
          "id": "QakBot",
          "display_name": "QakBot",
          "target": null
        },
        {
          "id": "Qbot",
          "display_name": "Qbot",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1068",
          "name": "Exploitation for Privilege Escalation",
          "display_name": "T1068 - Exploitation for Privilege Escalation"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1449",
          "name": "Exploit SS7 to Redirect Phone Calls/SMS",
          "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
        },
        {
          "id": "T1583.005",
          "name": "Botnet",
          "display_name": "T1583.005 - Botnet"
        },
        {
          "id": "T1031",
          "name": "Modify Existing Service",
          "display_name": "T1031 - Modify Existing Service"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1071.001",
          "name": "Web Protocols",
          "display_name": "T1071.001 - Web Protocols"
        },
        {
          "id": "T1071.004",
          "name": "DNS",
          "display_name": "T1071.004 - DNS"
        },
        {
          "id": "T1071.003",
          "name": "Mail Protocols",
          "display_name": "T1071.003 - Mail Protocols"
        },
        {
          "id": "TA0002",
          "name": "Execution",
          "display_name": "TA0002 - Execution"
        },
        {
          "id": "TA0003",
          "name": "Persistence",
          "display_name": "TA0003 - Persistence"
        },
        {
          "id": "TA0004",
          "name": "Privilege Escalation",
          "display_name": "TA0004 - Privilege Escalation"
        },
        {
          "id": "TA0005",
          "name": "Defense Evasion",
          "display_name": "TA0005 - Defense Evasion"
        },
        {
          "id": "TA0006",
          "name": "Credential Access",
          "display_name": "TA0006 - Credential Access"
        },
        {
          "id": "TA0007",
          "name": "Discovery",
          "display_name": "TA0007 - Discovery"
        },
        {
          "id": "TA0009",
          "name": "Collection",
          "display_name": "TA0009 - Collection"
        },
        {
          "id": "T1030",
          "name": "Data Transfer Size Limits",
          "display_name": "T1030 - Data Transfer Size Limits"
        },
        {
          "id": "TA0010",
          "name": "Exfiltration",
          "display_name": "TA0010 - Exfiltration"
        },
        {
          "id": "TA0011",
          "name": "Command and Control",
          "display_name": "TA0011 - Command and Control"
        }
      ],
      "industries": [
        "Civil Society"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 27,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 1,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 50,
        "FileHash-SHA1": 46,
        "FileHash-SHA256": 3377,
        "hostname": 2502,
        "URL": 8531,
        "domain": 1250,
        "CVE": 2
      },
      "indicator_count": 15758,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 220,
      "modified_text": "780 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "65b7e3fe91a1aceb955e54f6",
      "name": "NSO Group Pegasus",
      "description": "NSO Group\nNSO Group Technologies is an Israeli cyber-intelligence firm primarily known for its proprietary spyware Pegasus, which is capable of remote zero-click.\n\nHeavily targeting Tsara Brashears\nSet in motion when  Brashears  was attacked and critically injured by Jeffrey Scott Reimer DPT in Denver Colorado at  Concentra AMS whilst bit knowing she was in the American Workers compensation system. Brashears was not represented by an attorney at the time. She was threatened by Mark Montano MD who wanted wife to be elected coroner. Denied care for a spinal cord injury. All records stolen or falsified. Death threats and other cyber or physical attacks, contact with this strange group is common. Recent, injurious attempt on life dismissed by alleged detective by phone. Found, confirmed, let another offender walk. Ghost car. Ghost offender. Frightened attorneys?  I am her only advocate.",
      "modified": "2024-02-28T15:01:20.140000",
      "created": "2024-01-29T17:44:30.147000",
      "tags": [
        "ssl certificate",
        "whois record",
        "whois whois",
        "communicating",
        "cellbrite",
        "urls http",
        "referrer",
        "historical ssl",
        "nullmixer",
        "smokeloader",
        "redline stealer",
        "installer",
        "hiddentear",
        "probe",
        "nso group",
        "pegasus",
        "community",
        "xcitium verdict",
        "cloud",
        "bitdefender",
        "history",
        "utc http",
        "response final",
        "url final",
        "ip address",
        "status code",
        "compiler",
        "basic",
        "pe32",
        "intel",
        "ms windows",
        "win16 ne",
        "os2 executable",
        "generic windos",
        "executable",
        "pe32 compiler",
        "rticon russian",
        "info header",
        "name md5",
        "contained",
        "type",
        "language",
        "ico rtgroupicon",
        "russian",
        "overlay",
        "urls",
        "domains",
        "gandi sas",
        "contacted",
        "markmonitor",
        "ip detections",
        "country",
        "pe resource",
        "children",
        "file type",
        "ico mainicon",
        "linkid252669",
        "win32 dll",
        "ms visual",
        "win32 dynamic",
        "win32 exe",
        "files",
        "afrefhttp",
        "execution",
        "highly targeted",
        "http",
        "agent tesla",
        "blackbag",
        "relations most",
        "core",
        "malware",
        "emotet",
        "critical",
        "copy",
        "qakbot",
        "trojan",
        "ransomexx",
        "ryuk",
        "ransomware",
        "matanbuchus",
        "cobalt strike",
        "bazarloader",
        "as15169 google",
        "united",
        "passive dns",
        "aaaa",
        "title",
        "a domains",
        "body html",
        "head meta",
        "moved title",
        "tsara brashears",
        "offender",
        "Robert neill",
        "jeffery scott reimer",
        "assaulted",
        "sci",
        "warning",
        "denver",
        "death threats",
        "porn malvertizing",
        "bomb",
        "bomb threats"
      ],
      "references": [
        "https://www.nsogroup.com/",
        "https://www.anyxxxtube.net/search-porn/tsara-brashears/",
        "ww.google.com.uy",
        "321Survive.exe",
        "https://en.m.wikipedia.org \u203a wiki NSO Group"
      ],
      "public": 1,
      "adversary": "NSO Group",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "trojan.wanna/wannacry",
          "display_name": "trojan.wanna/wannacry",
          "target": null
        }
      ],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 21,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 570,
        "URL": 2908,
        "FileHash-MD5": 98,
        "FileHash-SHA1": 84,
        "FileHash-SHA256": 2241,
        "hostname": 1043,
        "CVE": 3,
        "email": 1
      },
      "indicator_count": 6948,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 220,
      "modified_text": "781 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "65b7e3fe934ae9d391614c0d",
      "name": "NSO Group Pegasus",
      "description": "NSO Group\nNSO Group Technologies is an Israeli cyber-intelligence firm primarily known for its proprietary spyware Pegasus, which is capable of remote zero-click.\n\nHeavily targeting Tsara Brashears\nSet in motion when  Brashears  was attacked and critically injured by Jeffrey Scott Reimer DPT in Denver Colorado at  Concentra AMS whilst bit knowing she was in the American Workers compensation system. Brashears was not represented by an attorney at the time. She was threatened by Mark Montano MD who wanted wife to be elected coroner. Denied care for a spinal cord injury. All records stolen or falsified. Death threats and other cyber or physical attacks, contact with this strange group is common. Recent, injurious attempt on life dismissed by alleged detective by phone. Found, confirmed, let another offender walk. Ghost car. Ghost offender. Frightened attorneys?  I am her only advocate.",
      "modified": "2024-02-28T15:01:20.140000",
      "created": "2024-01-29T17:44:30.585000",
      "tags": [
        "ssl certificate",
        "whois record",
        "whois whois",
        "communicating",
        "cellbrite",
        "urls http",
        "referrer",
        "historical ssl",
        "nullmixer",
        "smokeloader",
        "redline stealer",
        "installer",
        "hiddentear",
        "probe",
        "nso group",
        "pegasus",
        "community",
        "xcitium verdict",
        "cloud",
        "bitdefender",
        "history",
        "utc http",
        "response final",
        "url final",
        "ip address",
        "status code",
        "compiler",
        "basic",
        "pe32",
        "intel",
        "ms windows",
        "win16 ne",
        "os2 executable",
        "generic windos",
        "executable",
        "pe32 compiler",
        "rticon russian",
        "info header",
        "name md5",
        "contained",
        "type",
        "language",
        "ico rtgroupicon",
        "russian",
        "overlay",
        "urls",
        "domains",
        "gandi sas",
        "contacted",
        "markmonitor",
        "ip detections",
        "country",
        "pe resource",
        "children",
        "file type",
        "ico mainicon",
        "linkid252669",
        "win32 dll",
        "ms visual",
        "win32 dynamic",
        "win32 exe",
        "files",
        "afrefhttp",
        "execution",
        "highly targeted",
        "http",
        "agent tesla",
        "blackbag",
        "relations most",
        "core",
        "malware",
        "emotet",
        "critical",
        "copy",
        "qakbot",
        "trojan",
        "ransomexx",
        "ryuk",
        "ransomware",
        "matanbuchus",
        "cobalt strike",
        "bazarloader",
        "as15169 google",
        "united",
        "passive dns",
        "aaaa",
        "title",
        "a domains",
        "body html",
        "head meta",
        "moved title",
        "tsara brashears",
        "offender",
        "Robert neill",
        "jeffery scott reimer",
        "assaulted",
        "sci",
        "warning",
        "denver",
        "death threats",
        "porn malvertizing",
        "bomb",
        "bomb threats"
      ],
      "references": [
        "https://www.nsogroup.com/",
        "https://www.anyxxxtube.net/search-porn/tsara-brashears/",
        "ww.google.com.uy",
        "321Survive.exe",
        "https://en.m.wikipedia.org \u203a wiki NSO Group"
      ],
      "public": 1,
      "adversary": "NSO Group",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "trojan.wanna/wannacry",
          "display_name": "trojan.wanna/wannacry",
          "target": null
        }
      ],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 21,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 570,
        "URL": 2908,
        "FileHash-MD5": 98,
        "FileHash-SHA1": 84,
        "FileHash-SHA256": 2241,
        "hostname": 1043,
        "CVE": 3,
        "email": 1
      },
      "indicator_count": 6948,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 219,
      "modified_text": "781 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "65b7e4017a14cda8d09c9bf8",
      "name": "NSO Group Pegasus",
      "description": "NSO Group\nNSO Group Technologies is an Israeli cyber-intelligence firm primarily known for its proprietary spyware Pegasus, which is capable of remote zero-click.\n\nHeavily targeting Tsara Brashears\nSet in motion when  Brashears  was attacked and critically injured by Jeffrey Scott Reimer DPT in Denver Colorado at  Concentra AMS whilst bit knowing she was in the American Workers compensation system. Brashears was not represented by an attorney at the time. She was threatened by Mark Montano MD who wanted wife to be elected coroner. Denied care for a spinal cord injury. All records stolen or falsified. Death threats and other cyber or physical attacks, contact with this strange group is common. Recent, injurious attempt on life dismissed by alleged detective by phone. Found, confirmed, let another offender walk. Ghost car. Ghost offender. Frightened attorneys?  I am her only advocate.",
      "modified": "2024-02-28T15:01:20.140000",
      "created": "2024-01-29T17:44:33.270000",
      "tags": [
        "ssl certificate",
        "whois record",
        "whois whois",
        "communicating",
        "cellbrite",
        "urls http",
        "referrer",
        "historical ssl",
        "nullmixer",
        "smokeloader",
        "redline stealer",
        "installer",
        "hiddentear",
        "probe",
        "nso group",
        "pegasus",
        "community",
        "xcitium verdict",
        "cloud",
        "bitdefender",
        "history",
        "utc http",
        "response final",
        "url final",
        "ip address",
        "status code",
        "compiler",
        "basic",
        "pe32",
        "intel",
        "ms windows",
        "win16 ne",
        "os2 executable",
        "generic windos",
        "executable",
        "pe32 compiler",
        "rticon russian",
        "info header",
        "name md5",
        "contained",
        "type",
        "language",
        "ico rtgroupicon",
        "russian",
        "overlay",
        "urls",
        "domains",
        "gandi sas",
        "contacted",
        "markmonitor",
        "ip detections",
        "country",
        "pe resource",
        "children",
        "file type",
        "ico mainicon",
        "linkid252669",
        "win32 dll",
        "ms visual",
        "win32 dynamic",
        "win32 exe",
        "files",
        "afrefhttp",
        "execution",
        "highly targeted",
        "http",
        "agent tesla",
        "blackbag",
        "relations most",
        "core",
        "malware",
        "emotet",
        "critical",
        "copy",
        "qakbot",
        "trojan",
        "ransomexx",
        "ryuk",
        "ransomware",
        "matanbuchus",
        "cobalt strike",
        "bazarloader",
        "as15169 google",
        "united",
        "passive dns",
        "aaaa",
        "title",
        "a domains",
        "body html",
        "head meta",
        "moved title",
        "tsara brashears",
        "offender",
        "Robert neill",
        "jeffery scott reimer",
        "assaulted",
        "sci",
        "warning",
        "denver",
        "death threats",
        "porn malvertizing",
        "bomb",
        "bomb threats"
      ],
      "references": [
        "https://www.nsogroup.com/",
        "https://www.anyxxxtube.net/search-porn/tsara-brashears/",
        "ww.google.com.uy",
        "321Survive.exe",
        "https://en.m.wikipedia.org \u203a wiki NSO Group"
      ],
      "public": 1,
      "adversary": "NSO Group",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "trojan.wanna/wannacry",
          "display_name": "trojan.wanna/wannacry",
          "target": null
        }
      ],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 21,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 570,
        "URL": 2908,
        "FileHash-MD5": 98,
        "FileHash-SHA1": 84,
        "FileHash-SHA256": 2241,
        "hostname": 1043,
        "CVE": 3,
        "email": 1
      },
      "indicator_count": 6948,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 220,
      "modified_text": "781 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "65b7e406028ca6f363f41315",
      "name": "NSO Group Pegasus",
      "description": "NSO Group\nNSO Group Technologies is an Israeli cyber-intelligence firm primarily known for its proprietary spyware Pegasus, which is capable of remote zero-click.\n\nHeavily targeting Tsara Brashears\nSet in motion when  Brashears  was attacked and critically injured by Jeffrey Scott Reimer DPT in Denver Colorado at  Concentra AMS whilst bit knowing she was in the American Workers compensation system. Brashears was not represented by an attorney at the time. She was threatened by Mark Montano MD who wanted wife to be elected coroner. Denied care for a spinal cord injury. All records stolen or falsified. Death threats and other cyber or physical attacks, contact with this strange group is common. Recent, injurious attempt on life dismissed by alleged detective by phone. Found, confirmed, let another offender walk. Ghost car. Ghost offender. Frightened attorneys?  I am her only advocate.",
      "modified": "2024-02-28T15:01:20.140000",
      "created": "2024-01-29T17:44:38.424000",
      "tags": [
        "ssl certificate",
        "whois record",
        "whois whois",
        "communicating",
        "cellbrite",
        "urls http",
        "referrer",
        "historical ssl",
        "nullmixer",
        "smokeloader",
        "redline stealer",
        "installer",
        "hiddentear",
        "probe",
        "nso group",
        "pegasus",
        "community",
        "xcitium verdict",
        "cloud",
        "bitdefender",
        "history",
        "utc http",
        "response final",
        "url final",
        "ip address",
        "status code",
        "compiler",
        "basic",
        "pe32",
        "intel",
        "ms windows",
        "win16 ne",
        "os2 executable",
        "generic windos",
        "executable",
        "pe32 compiler",
        "rticon russian",
        "info header",
        "name md5",
        "contained",
        "type",
        "language",
        "ico rtgroupicon",
        "russian",
        "overlay",
        "urls",
        "domains",
        "gandi sas",
        "contacted",
        "markmonitor",
        "ip detections",
        "country",
        "pe resource",
        "children",
        "file type",
        "ico mainicon",
        "linkid252669",
        "win32 dll",
        "ms visual",
        "win32 dynamic",
        "win32 exe",
        "files",
        "afrefhttp",
        "execution",
        "highly targeted",
        "http",
        "agent tesla",
        "blackbag",
        "relations most",
        "core",
        "malware",
        "emotet",
        "critical",
        "copy",
        "qakbot",
        "trojan",
        "ransomexx",
        "ryuk",
        "ransomware",
        "matanbuchus",
        "cobalt strike",
        "bazarloader",
        "as15169 google",
        "united",
        "passive dns",
        "aaaa",
        "title",
        "a domains",
        "body html",
        "head meta",
        "moved title",
        "tsara brashears",
        "offender",
        "Robert neill",
        "jeffery scott reimer",
        "assaulted",
        "sci",
        "warning",
        "denver",
        "death threats",
        "porn malvertizing",
        "bomb",
        "bomb threats"
      ],
      "references": [
        "https://www.nsogroup.com/",
        "https://www.anyxxxtube.net/search-porn/tsara-brashears/",
        "ww.google.com.uy",
        "321Survive.exe",
        "https://en.m.wikipedia.org \u203a wiki NSO Group"
      ],
      "public": 1,
      "adversary": "NSO Group",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "trojan.wanna/wannacry",
          "display_name": "trojan.wanna/wannacry",
          "target": null
        }
      ],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 22,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 570,
        "URL": 2908,
        "FileHash-MD5": 98,
        "FileHash-SHA1": 84,
        "FileHash-SHA256": 2241,
        "hostname": 1043,
        "CVE": 3,
        "email": 1
      },
      "indicator_count": 6948,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 220,
      "modified_text": "781 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "65b8071976a7e6dccaabbada",
      "name": "NSO Group Pegasus",
      "description": "",
      "modified": "2024-02-28T15:01:20.140000",
      "created": "2024-01-29T20:14:17.001000",
      "tags": [
        "ssl certificate",
        "whois record",
        "whois whois",
        "communicating",
        "cellbrite",
        "urls http",
        "referrer",
        "historical ssl",
        "nullmixer",
        "smokeloader",
        "redline stealer",
        "installer",
        "hiddentear",
        "probe",
        "nso group",
        "pegasus",
        "community",
        "xcitium verdict",
        "cloud",
        "bitdefender",
        "history",
        "utc http",
        "response final",
        "url final",
        "ip address",
        "status code",
        "compiler",
        "basic",
        "pe32",
        "intel",
        "ms windows",
        "win16 ne",
        "os2 executable",
        "generic windos",
        "executable",
        "pe32 compiler",
        "rticon russian",
        "info header",
        "name md5",
        "contained",
        "type",
        "language",
        "ico rtgroupicon",
        "russian",
        "overlay",
        "urls",
        "domains",
        "gandi sas",
        "contacted",
        "markmonitor",
        "ip detections",
        "country",
        "pe resource",
        "children",
        "file type",
        "ico mainicon",
        "linkid252669",
        "win32 dll",
        "ms visual",
        "win32 dynamic",
        "win32 exe",
        "files",
        "afrefhttp",
        "execution",
        "highly targeted",
        "http",
        "agent tesla",
        "blackbag",
        "relations most",
        "core",
        "malware",
        "emotet",
        "critical",
        "copy",
        "qakbot",
        "trojan",
        "ransomexx",
        "ryuk",
        "ransomware",
        "matanbuchus",
        "cobalt strike",
        "bazarloader",
        "as15169 google",
        "united",
        "passive dns",
        "aaaa",
        "title",
        "a domains",
        "body html",
        "head meta",
        "moved title",
        "tsara brashears",
        "offender",
        "Robert neill",
        "jeffery scott reimer",
        "assaulted",
        "sci",
        "warning",
        "denver",
        "death threats",
        "porn malvertizing",
        "bomb",
        "bomb threats"
      ],
      "references": [
        "https://www.nsogroup.com/",
        "https://www.anyxxxtube.net/search-porn/tsara-brashears/",
        "ww.google.com.uy",
        "321Survive.exe",
        "https://en.m.wikipedia.org \u203a wiki NSO Group"
      ],
      "public": 1,
      "adversary": "NSO Group",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "trojan.wanna/wannacry",
          "display_name": "trojan.wanna/wannacry",
          "target": null
        }
      ],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": "65b7e406028ca6f363f41315",
      "export_count": 21,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "scoreblue",
        "id": "254100",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 570,
        "URL": 2908,
        "FileHash-MD5": 98,
        "FileHash-SHA1": 84,
        "FileHash-SHA256": 2241,
        "hostname": 1043,
        "CVE": 3,
        "email": 1
      },
      "indicator_count": 6948,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 227,
      "modified_text": "781 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "https://ddome.matomo.cloud",
    "type": "URL"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "https://ddome.matomo.cloud",
    "type": "URL",
    "found": false,
    "verdict": "clean",
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1776630106.9169767
}