{
  "type": "URL",
  "indicator": "https://device.login.partner.microsoftonline.cn",
  "general": {
    "sections": [
      "general",
      "url_list",
      "http_scans",
      "screenshot"
    ],
    "indicator": "https://device.login.partner.microsoftonline.cn",
    "type": "url",
    "type_title": "URL",
    "validation": [],
    "base_indicator": {
      "id": 3768714207,
      "indicator": "https://device.login.partner.microsoftonline.cn",
      "type": "URL",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 16,
      "pulses": [
        {
          "id": "6570a8e51a92ae866818d432",
          "name": "Apple link - Critical risk found",
          "description": "",
          "modified": "2023-12-06T17:01:25.538000",
          "created": "2023-12-06T17:01:25.538000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 9,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 1090,
            "URL": 866,
            "hostname": 581,
            "domain": 101,
            "FileHash-MD5": 72,
            "FileHash-SHA1": 63
          },
          "indicator_count": 2773,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "907 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6570a8e11f1fc3b551c19f8d",
          "name": "Apple - Malicious activities found in iOS link | verified cyber criminal.    | CVE 2023-????",
          "description": "",
          "modified": "2023-12-06T17:01:21.406000",
          "created": "2023-12-06T17:01:21.406000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 8,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 210,
            "hostname": 242,
            "domain": 87,
            "URL": 506,
            "FileHash-MD5": 21,
            "FileHash-SHA1": 13
          },
          "indicator_count": 1079,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "907 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6570a8ddf417154b2bfc3446",
          "name": "Apple - Malicious activities found in iOS link | verified cyber criminal.    | CVE 2023-????",
          "description": "",
          "modified": "2023-12-06T17:01:17.482000",
          "created": "2023-12-06T17:01:17.482000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 8,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 210,
            "hostname": 242,
            "domain": 87,
            "URL": 506,
            "FileHash-MD5": 21,
            "FileHash-SHA1": 13
          },
          "indicator_count": 1079,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "907 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6570a8d9de9710087f6f91b3",
          "name": "Apple - Malicious activities found in iOS link | verified cyber criminal.    | CVE 2023-????",
          "description": "",
          "modified": "2023-12-06T17:01:13.202000",
          "created": "2023-12-06T17:01:13.202000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 8,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 1090,
            "hostname": 427,
            "domain": 89,
            "URL": 545,
            "FileHash-MD5": 72,
            "FileHash-SHA1": 63
          },
          "indicator_count": 2286,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "907 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6570a8d167202b93ee502ff8",
          "name": "Apple iTunes| Malicious site | Anonyization | Siphoning | Trojan Downloader",
          "description": "",
          "modified": "2023-12-06T17:01:05.291000",
          "created": "2023-12-06T17:01:05.291000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 12,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "CVE": 12,
            "URL": 3839,
            "hostname": 1331,
            "FileHash-SHA256": 2976,
            "domain": 757,
            "FileHash-MD5": 250,
            "FileHash-SHA1": 80
          },
          "indicator_count": 9245,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 110,
          "modified_text": "907 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6570a857cae685fce7f5231e",
          "name": "Phishing - bam-cell.cell.nr-data.net",
          "description": "",
          "modified": "2023-12-06T16:59:03.209000",
          "created": "2023-12-06T16:59:03.209000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 8,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "CVE": 1,
            "FileHash-SHA256": 2052,
            "hostname": 1185,
            "domain": 460,
            "URL": 4294,
            "FileHash-MD5": 10,
            "FileHash-SHA1": 11
          },
          "indicator_count": 8013,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 110,
          "modified_text": "907 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6529abecabb0de583aad0aa3",
          "name": "Apple - Malicious activities found in iOS link | verified cyber criminal.    | CVE 2023-????",
          "description": "Very curious issue found in previous pulse.\nCyber warfare.\nUnspecified legal entities & verified cyber criminals?\nWorking together? Unverified.\ntargets:\ntsara brashears - verified\nsong culture - verified\nkedence - verified\nSkype - verified\nmessages - verified\napple iTunes - verified\nCVE? Pay me.\nInvolves legal entities targeting an individual, business and associates after an alleged physical SA attack of a female according to published sources. \nAppears to be silencing. Overwhelming amount of  threats found online.\n\nTests calls tracking me now\nD241 test successful/ DOS/ hacker initiated.\nSilencing me now. Verifiable\nRed Teams, attorneys, verified cyber criminals,  IC3 China IP. Malicious\nIP origination appears to be US. Bounces.\nNeeds further research.",
          "modified": "2023-11-13T04:04:31.274000",
          "created": "2023-10-13T20:43:24.771000",
          "tags": [
            "pattern match",
            "script",
            "beginstring",
            "mitre att",
            "file",
            "ck id",
            "show technique",
            "ck matrix",
            "indicator",
            "ascii text",
            "date",
            "null",
            "unknown",
            "error",
            "span",
            "class",
            "critical",
            "refresh",
            "body",
            "hybrid",
            "general",
            "local",
            "click",
            "strings",
            "tools",
            "look",
            "verify",
            "restart",
            "meta",
            "http response",
            "final url",
            "serving ip",
            "address",
            "name verdict",
            "falcon sandbox",
            "detection list",
            "blacklist"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 13,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 707,
            "FileHash-MD5": 276,
            "FileHash-SHA1": 263,
            "FileHash-SHA256": 4615,
            "domain": 108,
            "hostname": 1292
          },
          "indicator_count": 7261,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 227,
          "modified_text": "931 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "653f1a3a03614354a606c383",
          "name": "Apple - Malicious activities found in iOS link | verified cyber criminal",
          "description": "",
          "modified": "2023-11-13T04:04:31.274000",
          "created": "2023-10-30T02:51:38.882000",
          "tags": [
            "pattern match",
            "script",
            "beginstring",
            "mitre att",
            "file",
            "ck id",
            "show technique",
            "ck matrix",
            "indicator",
            "ascii text",
            "date",
            "null",
            "unknown",
            "error",
            "span",
            "class",
            "critical",
            "refresh",
            "body",
            "hybrid",
            "general",
            "local",
            "click",
            "strings",
            "tools",
            "look",
            "verify",
            "restart",
            "meta",
            "http response",
            "final url",
            "serving ip",
            "address",
            "name verdict",
            "falcon sandbox",
            "detection list",
            "blacklist"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": "6529abecabb0de583aad0aa3",
          "export_count": 8,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 707,
            "FileHash-MD5": 276,
            "FileHash-SHA1": 263,
            "FileHash-SHA256": 4615,
            "domain": 108,
            "hostname": 1292
          },
          "indicator_count": 7261,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 220,
          "modified_text": "931 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6529ac30efd59e5ff6f5f709",
          "name": "Apple link - Critical risk found ",
          "description": "",
          "modified": "2023-11-13T03:03:18.483000",
          "created": "2023-10-13T20:44:32.429000",
          "tags": [
            "pattern match",
            "script",
            "beginstring",
            "mitre att",
            "file",
            "ck id",
            "show technique",
            "ck matrix",
            "indicator",
            "ascii text",
            "date",
            "null",
            "unknown",
            "error",
            "span",
            "class",
            "critical",
            "refresh",
            "body",
            "hybrid",
            "general",
            "local",
            "click",
            "strings",
            "tools",
            "look",
            "verify",
            "restart",
            "meta",
            "http response",
            "final url",
            "serving ip",
            "address",
            "name verdict",
            "falcon sandbox",
            "detection list",
            "blacklist"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": "6529abecabb0de583aad0aa3",
          "export_count": 12,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 2291,
            "FileHash-MD5": 225,
            "FileHash-SHA1": 213,
            "FileHash-SHA256": 3746,
            "domain": 159,
            "hostname": 1922
          },
          "indicator_count": 8556,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 227,
          "modified_text": "931 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "653f1c14640441b2e0b7ec5e",
          "name": "Apple link - Critical risk found",
          "description": "",
          "modified": "2023-11-13T03:03:18.483000",
          "created": "2023-10-30T02:59:32.811000",
          "tags": [
            "pattern match",
            "script",
            "beginstring",
            "mitre att",
            "file",
            "ck id",
            "show technique",
            "ck matrix",
            "indicator",
            "ascii text",
            "date",
            "null",
            "unknown",
            "error",
            "span",
            "class",
            "critical",
            "refresh",
            "body",
            "hybrid",
            "general",
            "local",
            "click",
            "strings",
            "tools",
            "look",
            "verify",
            "restart",
            "meta",
            "http response",
            "final url",
            "serving ip",
            "address",
            "name verdict",
            "falcon sandbox",
            "detection list",
            "blacklist"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": "6529ac30efd59e5ff6f5f709",
          "export_count": 8,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 2291,
            "FileHash-MD5": 225,
            "FileHash-SHA1": 213,
            "FileHash-SHA256": 3746,
            "domain": 159,
            "hostname": 1922
          },
          "indicator_count": 8556,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 220,
          "modified_text": "931 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6529abeea42ff162d737873d",
          "name": "Apple - Malicious activities found in iOS link | verified cyber criminal.    | CVE 2023-????",
          "description": "Very curious issue found in previous pulse.\nCyber warfare.\nUnspecified legal entities & verified cyber criminals?\nWorking together? Unverified.\ntargets:\ntsara brashears - verified\nsong culture - verified\nkedence - verified\nSkype - verified\nmessages - verified\napple iTunes - verified\nCVE? Pay me.\nInvolves legal entities targeting an individual, business and associates after an alleged physical SA attack of a female according to published sources. \nAppears to be silencing. Overwhelming amount of  threats found online.\n\nTests calls tracking me now\nD241 test successful/ DOS/ hacker initiated.\nSilencing me now. Verifiable\nRed Teams, attorneys, verified cyber criminals,  IC3 China IP. Malicious\nIP origination appears to be US. Bounces.\nNeeds further research.",
          "modified": "2023-11-12T20:00:47.471000",
          "created": "2023-10-13T20:43:26.158000",
          "tags": [
            "pattern match",
            "script",
            "beginstring",
            "mitre att",
            "file",
            "ck id",
            "show technique",
            "ck matrix",
            "indicator",
            "ascii text",
            "date",
            "null",
            "unknown",
            "error",
            "span",
            "class",
            "critical",
            "refresh",
            "body",
            "hybrid",
            "general",
            "local",
            "click",
            "strings",
            "tools",
            "look",
            "verify",
            "restart",
            "meta",
            "http response",
            "final url",
            "serving ip",
            "address",
            "name verdict",
            "falcon sandbox",
            "detection list",
            "blacklist"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 13,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 506,
            "FileHash-MD5": 21,
            "FileHash-SHA1": 13,
            "FileHash-SHA256": 210,
            "domain": 87,
            "hostname": 242
          },
          "indicator_count": 1079,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 227,
          "modified_text": "931 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6529abf05c98d1f861b4f5c2",
          "name": "Apple - Malicious activities found in iOS link | verified cyber criminal.    | CVE 2023-????",
          "description": "Very curious issue found in previous pulse.\nCyber warfare.\nUnspecified legal entities & verified cyber criminals?\nWorking together? Unverified.\ntargets:\ntsara brashears - verified\nsong culture - verified\nkedence - verified\nSkype - verified\nmessages - verified\napple iTunes - verified\nCVE? Pay me.\nInvolves legal entities targeting an individual, business and associates after an alleged physical SA attack of a female according to published sources. \nAppears to be silencing. Overwhelming amount of  threats found online.\n\nTests calls tracking me now\nD241 test successful/ DOS/ hacker initiated.\nSilencing me now. Verifiable\nRed Teams, attorneys, verified cyber criminals,  IC3 China IP. Malicious\nIP origination appears to be US. Bounces.\nNeeds further research.",
          "modified": "2023-11-12T20:00:47.471000",
          "created": "2023-10-13T20:43:28.475000",
          "tags": [
            "pattern match",
            "script",
            "beginstring",
            "mitre att",
            "file",
            "ck id",
            "show technique",
            "ck matrix",
            "indicator",
            "ascii text",
            "date",
            "null",
            "unknown",
            "error",
            "span",
            "class",
            "critical",
            "refresh",
            "body",
            "hybrid",
            "general",
            "local",
            "click",
            "strings",
            "tools",
            "look",
            "verify",
            "restart",
            "meta",
            "http response",
            "final url",
            "serving ip",
            "address",
            "name verdict",
            "falcon sandbox",
            "detection list",
            "blacklist"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 13,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 506,
            "FileHash-MD5": 21,
            "FileHash-SHA1": 13,
            "FileHash-SHA256": 210,
            "domain": 87,
            "hostname": 242
          },
          "indicator_count": 1079,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 227,
          "modified_text": "931 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "65298a6839a49a9aa732bcac",
          "name": "Apple iTunes| Malicious site | Anonyization | Siphoning | Trojan Downloader",
          "description": "IC3 attached to links, apple , messaging, Skype.\nIC3 CN?\nChina? Unclear. Possibly intercepting  IC3 complaints or linking to FBI to frame targets. Links show attack is Attorney orchestrated. \nSame group of Apple iTune links affected by Java.Trojan.GenericGB, Apple NetWorm Trojan.Buzus, Dropper.Mudrop, GenPack:Trojan.Generic, Worm.Mytob ,Phishing site, Anonymizer , netsky ,worm and other vulnerabilities over time. \u200eSign of the Times \u2013 Album par Dembiak Music \u2013 Apple Music Autonomous Systems: AS714 Apple Inc AS14061 Digital Ocean Inc AS8560 1 1 Internet SE Anonymizer: Proxy - FireHol malicious url, evasive, pua, worm, network, attack, bad actor, targeting",
          "modified": "2023-11-12T17:01:15.222000",
          "created": "2023-10-13T18:20:24.042000",
          "tags": [
            "ssl certificate",
            "historical ssl",
            "referrer",
            "communicating",
            "unlocker",
            "legal entities",
            "using ip",
            "amazon aws",
            "apple ios",
            "passcode",
            "attack",
            "verified",
            "cyber criminal",
            "name verdict",
            "falcon sandbox",
            "united",
            "flag",
            "date",
            "name server",
            "markmonitor",
            "contains",
            "external",
            "new relic",
            "logo",
            "av detection",
            "hybrid",
            "general",
            "click",
            "misc attack",
            "et tor",
            "known tor",
            "relayrouter",
            "exit",
            "node traffic",
            "proxy",
            "firehol",
            "malware",
            "heur",
            "cisco umbrella",
            "site",
            "safe site",
            "million",
            "alexa top",
            "malicious site",
            "malware site",
            "adware",
            "artemis",
            "iframe",
            "cleaner",
            "unsafe",
            "riskware",
            "opencandy",
            "downldr",
            "nircmd",
            "swrort",
            "presenoker",
            "wacatac",
            "phishing",
            "xtrat",
            "crack",
            "tiggre",
            "exploit",
            "agent",
            "filetour",
            "conduit",
            "acint",
            "systweak",
            "behav",
            "genkryptik",
            "softcnapp",
            "fusioncore",
            "azorult",
            "service",
            "runescape",
            "facebook",
            "bank",
            "download",
            "xrat",
            "gamehack",
            "webtoolbar",
            "trojanspy",
            "maltiverse",
            "urls",
            "detection list",
            "blacklist https",
            "path",
            "maxage31536000",
            "expiressat",
            "http response",
            "final url",
            "ip address",
            "status code",
            "body length",
            "kb body",
            "sha256",
            "pragma",
            "html info",
            "title kedence",
            "official apk",
            "meta tags",
            "apk download",
            "android",
            "google tag",
            "utc google",
            "utc na",
            "phishing site",
            "anonymizer",
            "malicious host",
            "driverpack",
            "ransomware",
            "installcore",
            "suppobox",
            "patcher",
            "generic",
            "dropper",
            "fakealert",
            "quasar rat",
            "applicunwnt",
            "mimikatz",
            "team",
            "blacklist"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Verified",
              "display_name": "Verified",
              "target": null
            },
            {
              "id": "Cyber Criminal",
              "display_name": "Cyber Criminal",
              "target": null
            },
            {
              "id": "GameHack",
              "display_name": "GameHack",
              "target": null
            },
            {
              "id": "WebToolbar",
              "display_name": "WebToolbar",
              "target": null
            },
            {
              "id": "TrojanSpy",
              "display_name": "TrojanSpy",
              "target": null
            },
            {
              "id": "Maltiverse",
              "display_name": "Maltiverse",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 25,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 250,
            "FileHash-SHA1": 80,
            "FileHash-SHA256": 2976,
            "domain": 757,
            "hostname": 1331,
            "URL": 3839,
            "CVE": 12
          },
          "indicator_count": 9245,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 227,
          "modified_text": "931 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "653f19f703614354a606c382",
          "name": "Apple iTunes| Malicious site | Anonyization | Siphoning | Trojan Downloader",
          "description": "",
          "modified": "2023-11-12T17:01:15.222000",
          "created": "2023-10-30T02:50:31.950000",
          "tags": [
            "ssl certificate",
            "historical ssl",
            "referrer",
            "communicating",
            "unlocker",
            "legal entities",
            "using ip",
            "amazon aws",
            "apple ios",
            "passcode",
            "attack",
            "verified",
            "cyber criminal",
            "name verdict",
            "falcon sandbox",
            "united",
            "flag",
            "date",
            "name server",
            "markmonitor",
            "contains",
            "external",
            "new relic",
            "logo",
            "av detection",
            "hybrid",
            "general",
            "click",
            "misc attack",
            "et tor",
            "known tor",
            "relayrouter",
            "exit",
            "node traffic",
            "proxy",
            "firehol",
            "malware",
            "heur",
            "cisco umbrella",
            "site",
            "safe site",
            "million",
            "alexa top",
            "malicious site",
            "malware site",
            "adware",
            "artemis",
            "iframe",
            "cleaner",
            "unsafe",
            "riskware",
            "opencandy",
            "downldr",
            "nircmd",
            "swrort",
            "presenoker",
            "wacatac",
            "phishing",
            "xtrat",
            "crack",
            "tiggre",
            "exploit",
            "agent",
            "filetour",
            "conduit",
            "acint",
            "systweak",
            "behav",
            "genkryptik",
            "softcnapp",
            "fusioncore",
            "azorult",
            "service",
            "runescape",
            "facebook",
            "bank",
            "download",
            "xrat",
            "gamehack",
            "webtoolbar",
            "trojanspy",
            "maltiverse",
            "urls",
            "detection list",
            "blacklist https",
            "path",
            "maxage31536000",
            "expiressat",
            "http response",
            "final url",
            "ip address",
            "status code",
            "body length",
            "kb body",
            "sha256",
            "pragma",
            "html info",
            "title kedence",
            "official apk",
            "meta tags",
            "apk download",
            "android",
            "google tag",
            "utc google",
            "utc na",
            "phishing site",
            "anonymizer",
            "malicious host",
            "driverpack",
            "ransomware",
            "installcore",
            "suppobox",
            "patcher",
            "generic",
            "dropper",
            "fakealert",
            "quasar rat",
            "applicunwnt",
            "mimikatz",
            "team",
            "blacklist"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Verified",
              "display_name": "Verified",
              "target": null
            },
            {
              "id": "Cyber Criminal",
              "display_name": "Cyber Criminal",
              "target": null
            },
            {
              "id": "GameHack",
              "display_name": "GameHack",
              "target": null
            },
            {
              "id": "WebToolbar",
              "display_name": "WebToolbar",
              "target": null
            },
            {
              "id": "TrojanSpy",
              "display_name": "TrojanSpy",
              "target": null
            },
            {
              "id": "Maltiverse",
              "display_name": "Maltiverse",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": "65298a6839a49a9aa732bcac",
          "export_count": 19,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 250,
            "FileHash-SHA1": 80,
            "FileHash-SHA256": 2976,
            "domain": 757,
            "hostname": 1331,
            "URL": 3839,
            "CVE": 12
          },
          "indicator_count": 9245,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 220,
          "modified_text": "931 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6524f2a85b4dd064922b8c7a",
          "name": "Phishing - bam-cell.cell.nr-data.net",
          "description": "Phishing\nAPT's\nAnonymization\nProxy: FireHOL\ncloud collector-newrelic\nG0032 - Lazarus Group 03/2023\nAS23467 New Relic",
          "modified": "2023-11-09T05:05:01.692000",
          "created": "2023-10-10T06:43:52.526000",
          "tags": [
            "whois record",
            "contacted",
            "ssl certificate",
            "parent",
            "historical ssl",
            "communicating",
            "siblings",
            "execution",
            "resolutions",
            "collections",
            "malicious",
            "generic malware",
            "hybridanalysis",
            "fri jan",
            "mon jan",
            "date filename",
            "blacklist fri",
            "install league",
            "legends",
            "fri dec",
            "sun jan",
            "allusersprofile",
            "osuser",
            "dns requests",
            "process list",
            "gamesmetadata",
            "cisco umbrella",
            "site",
            "mon jul",
            "online thu",
            "safe site",
            "malware",
            "cname",
            "record type",
            "ttl value",
            "algorithm",
            "full name",
            "data",
            "v3 serial",
            "number",
            "cus cndigicert",
            "tls rsa",
            "sha256",
            "ca1 odigicert",
            "inc validity",
            "relic"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 11,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 4294,
            "FileHash-MD5": 10,
            "FileHash-SHA1": 11,
            "FileHash-SHA256": 2052,
            "domain": 460,
            "hostname": 1185,
            "CVE": 1
          },
          "indicator_count": 8013,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 227,
          "modified_text": "935 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "653f155cf81da97fd82bba62",
          "name": "Phishing - bam-cell.cell.nr-data.net",
          "description": "",
          "modified": "2023-11-09T05:05:01.692000",
          "created": "2023-10-30T02:30:52.720000",
          "tags": [
            "whois record",
            "contacted",
            "ssl certificate",
            "parent",
            "historical ssl",
            "communicating",
            "siblings",
            "execution",
            "resolutions",
            "collections",
            "malicious",
            "generic malware",
            "hybridanalysis",
            "fri jan",
            "mon jan",
            "date filename",
            "blacklist fri",
            "install league",
            "legends",
            "fri dec",
            "sun jan",
            "allusersprofile",
            "osuser",
            "dns requests",
            "process list",
            "gamesmetadata",
            "cisco umbrella",
            "site",
            "mon jul",
            "online thu",
            "safe site",
            "malware",
            "cname",
            "record type",
            "ttl value",
            "algorithm",
            "full name",
            "data",
            "v3 serial",
            "number",
            "cus cndigicert",
            "tls rsa",
            "sha256",
            "ca1 odigicert",
            "inc validity",
            "relic"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": "6524f2a85b4dd064922b8c7a",
          "export_count": 11,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 4294,
            "FileHash-MD5": 10,
            "FileHash-SHA1": 11,
            "FileHash-SHA256": 2052,
            "domain": 460,
            "hostname": 1185,
            "CVE": 1
          },
          "indicator_count": 8013,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 220,
          "modified_text": "935 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        }
      ],
      "references": [],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 0
        },
        "other": {
          "adversary": [],
          "malware_families": [
            "Cyber criminal",
            "Webtoolbar",
            "Gamehack",
            "Verified",
            "Trojanspy",
            "Maltiverse"
          ],
          "industries": [],
          "unique_indicators": 19555
        }
      }
    },
    "false_positive": [],
    "alexa": "http://www.alexa.com/siteinfo/microsoftonline.cn",
    "whois": "http://whois.domaintools.com/microsoftonline.cn",
    "domain": "microsoftonline.cn",
    "hostname": "device.login.partner.microsoftonline.cn"
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 16,
  "pulses": [
    {
      "id": "6570a8e51a92ae866818d432",
      "name": "Apple link - Critical risk found",
      "description": "",
      "modified": "2023-12-06T17:01:25.538000",
      "created": "2023-12-06T17:01:25.538000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 9,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 1090,
        "URL": 866,
        "hostname": 581,
        "domain": 101,
        "FileHash-MD5": 72,
        "FileHash-SHA1": 63
      },
      "indicator_count": 2773,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "907 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6570a8e11f1fc3b551c19f8d",
      "name": "Apple - Malicious activities found in iOS link | verified cyber criminal.    | CVE 2023-????",
      "description": "",
      "modified": "2023-12-06T17:01:21.406000",
      "created": "2023-12-06T17:01:21.406000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 8,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 210,
        "hostname": 242,
        "domain": 87,
        "URL": 506,
        "FileHash-MD5": 21,
        "FileHash-SHA1": 13
      },
      "indicator_count": 1079,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "907 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6570a8ddf417154b2bfc3446",
      "name": "Apple - Malicious activities found in iOS link | verified cyber criminal.    | CVE 2023-????",
      "description": "",
      "modified": "2023-12-06T17:01:17.482000",
      "created": "2023-12-06T17:01:17.482000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 8,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 210,
        "hostname": 242,
        "domain": 87,
        "URL": 506,
        "FileHash-MD5": 21,
        "FileHash-SHA1": 13
      },
      "indicator_count": 1079,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "907 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6570a8d9de9710087f6f91b3",
      "name": "Apple - Malicious activities found in iOS link | verified cyber criminal.    | CVE 2023-????",
      "description": "",
      "modified": "2023-12-06T17:01:13.202000",
      "created": "2023-12-06T17:01:13.202000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 8,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 1090,
        "hostname": 427,
        "domain": 89,
        "URL": 545,
        "FileHash-MD5": 72,
        "FileHash-SHA1": 63
      },
      "indicator_count": 2286,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "907 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6570a8d167202b93ee502ff8",
      "name": "Apple iTunes| Malicious site | Anonyization | Siphoning | Trojan Downloader",
      "description": "",
      "modified": "2023-12-06T17:01:05.291000",
      "created": "2023-12-06T17:01:05.291000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 12,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "CVE": 12,
        "URL": 3839,
        "hostname": 1331,
        "FileHash-SHA256": 2976,
        "domain": 757,
        "FileHash-MD5": 250,
        "FileHash-SHA1": 80
      },
      "indicator_count": 9245,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 110,
      "modified_text": "907 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6570a857cae685fce7f5231e",
      "name": "Phishing - bam-cell.cell.nr-data.net",
      "description": "",
      "modified": "2023-12-06T16:59:03.209000",
      "created": "2023-12-06T16:59:03.209000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 8,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "CVE": 1,
        "FileHash-SHA256": 2052,
        "hostname": 1185,
        "domain": 460,
        "URL": 4294,
        "FileHash-MD5": 10,
        "FileHash-SHA1": 11
      },
      "indicator_count": 8013,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 110,
      "modified_text": "907 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6529abecabb0de583aad0aa3",
      "name": "Apple - Malicious activities found in iOS link | verified cyber criminal.    | CVE 2023-????",
      "description": "Very curious issue found in previous pulse.\nCyber warfare.\nUnspecified legal entities & verified cyber criminals?\nWorking together? Unverified.\ntargets:\ntsara brashears - verified\nsong culture - verified\nkedence - verified\nSkype - verified\nmessages - verified\napple iTunes - verified\nCVE? Pay me.\nInvolves legal entities targeting an individual, business and associates after an alleged physical SA attack of a female according to published sources. \nAppears to be silencing. Overwhelming amount of  threats found online.\n\nTests calls tracking me now\nD241 test successful/ DOS/ hacker initiated.\nSilencing me now. Verifiable\nRed Teams, attorneys, verified cyber criminals,  IC3 China IP. Malicious\nIP origination appears to be US. Bounces.\nNeeds further research.",
      "modified": "2023-11-13T04:04:31.274000",
      "created": "2023-10-13T20:43:24.771000",
      "tags": [
        "pattern match",
        "script",
        "beginstring",
        "mitre att",
        "file",
        "ck id",
        "show technique",
        "ck matrix",
        "indicator",
        "ascii text",
        "date",
        "null",
        "unknown",
        "error",
        "span",
        "class",
        "critical",
        "refresh",
        "body",
        "hybrid",
        "general",
        "local",
        "click",
        "strings",
        "tools",
        "look",
        "verify",
        "restart",
        "meta",
        "http response",
        "final url",
        "serving ip",
        "address",
        "name verdict",
        "falcon sandbox",
        "detection list",
        "blacklist"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 13,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "scoreblue",
        "id": "254100",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 707,
        "FileHash-MD5": 276,
        "FileHash-SHA1": 263,
        "FileHash-SHA256": 4615,
        "domain": 108,
        "hostname": 1292
      },
      "indicator_count": 7261,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 227,
      "modified_text": "931 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "653f1a3a03614354a606c383",
      "name": "Apple - Malicious activities found in iOS link | verified cyber criminal",
      "description": "",
      "modified": "2023-11-13T04:04:31.274000",
      "created": "2023-10-30T02:51:38.882000",
      "tags": [
        "pattern match",
        "script",
        "beginstring",
        "mitre att",
        "file",
        "ck id",
        "show technique",
        "ck matrix",
        "indicator",
        "ascii text",
        "date",
        "null",
        "unknown",
        "error",
        "span",
        "class",
        "critical",
        "refresh",
        "body",
        "hybrid",
        "general",
        "local",
        "click",
        "strings",
        "tools",
        "look",
        "verify",
        "restart",
        "meta",
        "http response",
        "final url",
        "serving ip",
        "address",
        "name verdict",
        "falcon sandbox",
        "detection list",
        "blacklist"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": "6529abecabb0de583aad0aa3",
      "export_count": 8,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 707,
        "FileHash-MD5": 276,
        "FileHash-SHA1": 263,
        "FileHash-SHA256": 4615,
        "domain": 108,
        "hostname": 1292
      },
      "indicator_count": 7261,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 220,
      "modified_text": "931 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6529ac30efd59e5ff6f5f709",
      "name": "Apple link - Critical risk found ",
      "description": "",
      "modified": "2023-11-13T03:03:18.483000",
      "created": "2023-10-13T20:44:32.429000",
      "tags": [
        "pattern match",
        "script",
        "beginstring",
        "mitre att",
        "file",
        "ck id",
        "show technique",
        "ck matrix",
        "indicator",
        "ascii text",
        "date",
        "null",
        "unknown",
        "error",
        "span",
        "class",
        "critical",
        "refresh",
        "body",
        "hybrid",
        "general",
        "local",
        "click",
        "strings",
        "tools",
        "look",
        "verify",
        "restart",
        "meta",
        "http response",
        "final url",
        "serving ip",
        "address",
        "name verdict",
        "falcon sandbox",
        "detection list",
        "blacklist"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": "6529abecabb0de583aad0aa3",
      "export_count": 12,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "scoreblue",
        "id": "254100",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 2291,
        "FileHash-MD5": 225,
        "FileHash-SHA1": 213,
        "FileHash-SHA256": 3746,
        "domain": 159,
        "hostname": 1922
      },
      "indicator_count": 8556,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 227,
      "modified_text": "931 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "653f1c14640441b2e0b7ec5e",
      "name": "Apple link - Critical risk found",
      "description": "",
      "modified": "2023-11-13T03:03:18.483000",
      "created": "2023-10-30T02:59:32.811000",
      "tags": [
        "pattern match",
        "script",
        "beginstring",
        "mitre att",
        "file",
        "ck id",
        "show technique",
        "ck matrix",
        "indicator",
        "ascii text",
        "date",
        "null",
        "unknown",
        "error",
        "span",
        "class",
        "critical",
        "refresh",
        "body",
        "hybrid",
        "general",
        "local",
        "click",
        "strings",
        "tools",
        "look",
        "verify",
        "restart",
        "meta",
        "http response",
        "final url",
        "serving ip",
        "address",
        "name verdict",
        "falcon sandbox",
        "detection list",
        "blacklist"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": "6529ac30efd59e5ff6f5f709",
      "export_count": 8,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 2291,
        "FileHash-MD5": 225,
        "FileHash-SHA1": 213,
        "FileHash-SHA256": 3746,
        "domain": 159,
        "hostname": 1922
      },
      "indicator_count": 8556,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 220,
      "modified_text": "931 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "https://device.login.partner.microsoftonline.cn",
    "type": "URL"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "https://device.login.partner.microsoftonline.cn",
    "type": "URL",
    "found": false,
    "verdict": "clean",
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780315750.4231985
}