{
  "type": "URL",
  "indicator": "https://docs.google.com/",
  "general": {
    "sections": [
      "general",
      "url_list",
      "http_scans",
      "screenshot"
    ],
    "indicator": "https://docs.google.com/",
    "type": "url",
    "type_title": "URL",
    "validation": [
      {
        "source": "alexa",
        "message": "Alexa rank: #1",
        "name": "Listed on Alexa"
      },
      {
        "source": "akamai",
        "message": "Akamai rank: #3",
        "name": "Akamai Popular Domain"
      },
      {
        "source": "whitelist",
        "message": "Whitelisted domain google.com",
        "name": "Whitelisted domain"
      },
      {
        "source": "majestic",
        "message": "Whitelisted domain google.com",
        "name": "Whitelisted domain"
      }
    ],
    "base_indicator": {
      "id": 314391360,
      "indicator": "https://docs.google.com/",
      "type": "URL",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 5,
      "pulses": [
        {
          "id": "69ca4a306066375786947f52",
          "name": "Who is safe?",
          "description": "<Pulses are generated by a individual, but they can be traced to a specific address and sent to the Withheld for Privacy service. and the same address as the BBC News website><.>\nhttps://www.virustotal.com/gui/file/c656b145ce73a997b6d95ec21dcfbee1ded90d7fff2ca0bc48765c4bb671d58c/behavior",
          "modified": "2026-04-30T15:30:17.242000",
          "created": "2026-03-30T10:02:24.092000",
          "tags": [
            "pulse analysis",
            "pulses otx",
            "pulses",
            "related tags",
            "email domain",
            "withheld",
            "privacy"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 170,
            "domain": 88,
            "email": 5,
            "FileHash-SHA1": 170,
            "FileHash-SHA256": 1028,
            "URL": 288,
            "hostname": 76
          },
          "indicator_count": 1825,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 68,
          "modified_text": "31 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "68adee67c08cd025b05c2ab0",
          "name": "Collection of Collections - Updated - Malicious Certificates & University of Alberta DataBreach - 09.15.25.25",
          "description": "This Pulse is an attempt to aggregate all known certificates from all sources.\n\nEncrypted Communication: The malware uses Bitcoin and Ethereum addresses for communication, allowing it to receive commands and exfiltrate data securely.\nEvasion Techniques: The malware generates long and unusual domain parts using Domain Generation Algorithms to evade detection and establish communication with its C2 server.\nData Exfiltration: The malware can exfiltrate data to cloud storage services, enabling the threat actor to steal sensitive information from the compromised system.\nRemote Access: The malware leverages bidirectional communication and system binary proxy execution techniques to enable remote access and control over the infected system.\nIngress Tool Transfer: The malware downloads executable files from URLs, indicating its ability to download additional malicious payloads or updates to enhance its capabilities.",
          "modified": "2025-10-16T05:02:02.452000",
          "created": "2025-08-26T17:27:01.650000",
          "tags": [
            "http",
            "https",
            "kgs0",
            "kls0",
            "Malcerts",
            "Certificates",
            "Alberta",
            "GovAB",
            "UAlberta",
            "Speader"
          ],
          "references": [
            "https://www.virustotal.com/graph/embed/g0cfdc207f7d14c9a9173c2f9b804dd92b17706ef2a8c41dba3e0af36353cd70b?theme=dark",
            "https://viz.greynoise.io/ip/analysis/408b56e2-1932-4975-b348-5a8a7c5991d4",
            "https://report.netcraft.com/submission/ATkcJjvq2iKUQhELceQs7q4WVU76Q8QG - Submitted IPv4s to Netcraft 08.29.25",
            "https://www.filescan.io/uploads/68b261771c81c34281d8af6d/reports/44924eb0-000d-42ad-944e-36bf849a406d/overview",
            "https://www.virustotal.com/gui/file/19ec86ce10a716e8e63804239052c96cfa0a7fb66c2820bda2e66358f622525c/community",
            "Added some URLs from FSio Report to URLScan"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America",
            "Canada",
            "Netherlands",
            "Aruba",
            "Panama",
            "Poland",
            "Ukraine",
            "United Kingdom of Great Britain and Northern Ireland",
            "Anguilla",
            "United Arab Emirates",
            "Ireland",
            "Tanzania, United Republic of",
            "Philippines",
            "Japan",
            "Guatemala",
            "Mexico",
            "Bahamas",
            "Barbados",
            "Georgia",
            "Slovakia",
            "Sint Maarten (Dutch part)",
            "Kenya"
          ],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "Education",
            "Government",
            "Technology",
            "Telecommunications",
            "Healthcare"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 25,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 2,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Disable_Duck",
            "id": "244325",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_244325/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 1639,
            "FileHash-MD5": 1481,
            "FileHash-SHA1": 1421,
            "FileHash-SHA256": 5969,
            "domain": 707,
            "hostname": 2311,
            "email": 5,
            "CIDR": 13
          },
          "indicator_count": 13546,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 133,
          "modified_text": "228 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "677db8b56d3d4c3af9ebd9b5",
          "name": "hxxps://tinyurl [.] com/Pixel2 - Link to Google Drive of Malicious APKs (unenriched analysis of link to the Google Drive)",
          "description": "hxxps://tinyurl [.] com - Link to Google Drive of Malicious APKs\nIt appears a link to a Backup of Client's APKs (Telus Google Device Protected by Norton)\nDevice currently connected to the University of Alberta, Telus  Communications (ISP), Alberta Health Services (AHS) and the Government of Alberta - is apparently itself malicious (still links to Google Drive Folder of APKs - to import for analysis later).",
          "modified": "2025-02-07T05:00:08.549000",
          "created": "2025-01-07T23:28:53.566000",
          "tags": [
            "UAlberta",
            "AHS",
            "Google",
            "Telus",
            "Pixel",
            "Norton"
          ],
          "references": [
            "https://www.filescan.io/uploads/677e0e14212309a70397d357/reports/0077a75d-f7d7-4634-a1ba-6f7b0488f9da/overview",
            "https://urlquery.net/report/16d1e034-1c64-4cbe-8b58-f5926dab9001",
            "https://www.virustotal.com/gui/url/1763a71e86e74729f1e993dc2e6b5cec9d91dd51245533a5300c85c9d49bc7ef",
            "http://www.hybrid-analysis.com/sample/dc744fc325700c6fda2b8d83b39a8c241258b9305058a3402ce70c97932acc74",
            "http://www.hybrid-analysis.com/sample/dc744fc325700c6fda2b8d83b39a8c241258b9305058a3402ce70c97932acc74/677d1d5dcb161e2448026452"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "Canada",
            "United States of America"
          ],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "Healthcare",
            "Government",
            "Education"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 16,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 1,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Disable_Duck",
            "id": "244325",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_244325/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 13,
            "FileHash-MD5": 96,
            "FileHash-SHA1": 96,
            "FileHash-SHA256": 97,
            "SSLCertFingerprint": 4,
            "URL": 221,
            "hostname": 34
          },
          "indicator_count": 561,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 129,
          "modified_text": "479 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "64276a557aaf8592b056bf30",
          "name": "InQuest - 31-03-2023",
          "description": "",
          "modified": "2023-04-30T23:01:04.745000",
          "created": "2023-03-31T23:18:45.769000",
          "tags": [],
          "references": [
            "https://labs.inquest.net/iocdb"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 7,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "CyberHunterAutoFeed",
            "id": "182496",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_182496/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 297,
            "FileHash-MD5": 40,
            "URL": 1648,
            "domain": 1073,
            "hostname": 228,
            "FileHash-SHA1": 41
          },
          "indicator_count": 3327,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 1622,
          "modified_text": "1127 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "61f2cc67324e764bec0f4f9e",
          "name": "www.asurion.com (2)",
          "description": "",
          "modified": "2022-01-27T16:46:31.432000",
          "created": "2022-01-27T16:46:31.432000",
          "tags": [
            "a domains",
            "moved",
            "script domains",
            "script urls",
            "body",
            "date",
            "x cache",
            "cloudfront x",
            "hio50 c1",
            "script script",
            "meta"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 4,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Kailula4",
            "id": "131997",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 84,
            "hostname": 35,
            "domain": 4,
            "FileHash-SHA256": 276,
            "FileHash-MD5": 5,
            "FileHash-SHA1": 1
          },
          "indicator_count": 405,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 406,
          "modified_text": "1585 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "Added some URLs from FSio Report to URLScan",
        "https://www.virustotal.com/gui/file/19ec86ce10a716e8e63804239052c96cfa0a7fb66c2820bda2e66358f622525c/community",
        "https://www.filescan.io/uploads/68b261771c81c34281d8af6d/reports/44924eb0-000d-42ad-944e-36bf849a406d/overview",
        "https://www.filescan.io/uploads/677e0e14212309a70397d357/reports/0077a75d-f7d7-4634-a1ba-6f7b0488f9da/overview",
        "https://www.virustotal.com/gui/url/1763a71e86e74729f1e993dc2e6b5cec9d91dd51245533a5300c85c9d49bc7ef",
        "http://www.hybrid-analysis.com/sample/dc744fc325700c6fda2b8d83b39a8c241258b9305058a3402ce70c97932acc74/677d1d5dcb161e2448026452",
        "https://labs.inquest.net/iocdb",
        "https://urlquery.net/report/16d1e034-1c64-4cbe-8b58-f5926dab9001",
        "https://www.virustotal.com/graph/embed/g0cfdc207f7d14c9a9173c2f9b804dd92b17706ef2a8c41dba3e0af36353cd70b?theme=dark",
        "http://www.hybrid-analysis.com/sample/dc744fc325700c6fda2b8d83b39a8c241258b9305058a3402ce70c97932acc74",
        "https://report.netcraft.com/submission/ATkcJjvq2iKUQhELceQs7q4WVU76Q8QG - Submitted IPv4s to Netcraft 08.29.25",
        "https://viz.greynoise.io/ip/analysis/408b56e2-1932-4975-b348-5a8a7c5991d4"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 0
        },
        "other": {
          "adversary": [],
          "malware_families": [],
          "industries": [
            "Government",
            "Healthcare",
            "Technology",
            "Telecommunications",
            "Education"
          ],
          "unique_indicators": 10501
        }
      }
    },
    "false_positive": [],
    "alexa": "http://www.alexa.com/siteinfo/google.com",
    "whois": "http://whois.domaintools.com/google.com",
    "domain": "google.com",
    "hostname": "docs.google.com"
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 5,
  "pulses": [
    {
      "id": "69ca4a306066375786947f52",
      "name": "Who is safe?",
      "description": "<Pulses are generated by a individual, but they can be traced to a specific address and sent to the Withheld for Privacy service. and the same address as the BBC News website><.>\nhttps://www.virustotal.com/gui/file/c656b145ce73a997b6d95ec21dcfbee1ded90d7fff2ca0bc48765c4bb671d58c/behavior",
      "modified": "2026-04-30T15:30:17.242000",
      "created": "2026-03-30T10:02:24.092000",
      "tags": [
        "pulse analysis",
        "pulses otx",
        "pulses",
        "related tags",
        "email domain",
        "withheld",
        "privacy"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 1,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 170,
        "domain": 88,
        "email": 5,
        "FileHash-SHA1": 170,
        "FileHash-SHA256": 1028,
        "URL": 288,
        "hostname": 76
      },
      "indicator_count": 1825,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 68,
      "modified_text": "31 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "68adee67c08cd025b05c2ab0",
      "name": "Collection of Collections - Updated - Malicious Certificates & University of Alberta DataBreach - 09.15.25.25",
      "description": "This Pulse is an attempt to aggregate all known certificates from all sources.\n\nEncrypted Communication: The malware uses Bitcoin and Ethereum addresses for communication, allowing it to receive commands and exfiltrate data securely.\nEvasion Techniques: The malware generates long and unusual domain parts using Domain Generation Algorithms to evade detection and establish communication with its C2 server.\nData Exfiltration: The malware can exfiltrate data to cloud storage services, enabling the threat actor to steal sensitive information from the compromised system.\nRemote Access: The malware leverages bidirectional communication and system binary proxy execution techniques to enable remote access and control over the infected system.\nIngress Tool Transfer: The malware downloads executable files from URLs, indicating its ability to download additional malicious payloads or updates to enhance its capabilities.",
      "modified": "2025-10-16T05:02:02.452000",
      "created": "2025-08-26T17:27:01.650000",
      "tags": [
        "http",
        "https",
        "kgs0",
        "kls0",
        "Malcerts",
        "Certificates",
        "Alberta",
        "GovAB",
        "UAlberta",
        "Speader"
      ],
      "references": [
        "https://www.virustotal.com/graph/embed/g0cfdc207f7d14c9a9173c2f9b804dd92b17706ef2a8c41dba3e0af36353cd70b?theme=dark",
        "https://viz.greynoise.io/ip/analysis/408b56e2-1932-4975-b348-5a8a7c5991d4",
        "https://report.netcraft.com/submission/ATkcJjvq2iKUQhELceQs7q4WVU76Q8QG - Submitted IPv4s to Netcraft 08.29.25",
        "https://www.filescan.io/uploads/68b261771c81c34281d8af6d/reports/44924eb0-000d-42ad-944e-36bf849a406d/overview",
        "https://www.virustotal.com/gui/file/19ec86ce10a716e8e63804239052c96cfa0a7fb66c2820bda2e66358f622525c/community",
        "Added some URLs from FSio Report to URLScan"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America",
        "Canada",
        "Netherlands",
        "Aruba",
        "Panama",
        "Poland",
        "Ukraine",
        "United Kingdom of Great Britain and Northern Ireland",
        "Anguilla",
        "United Arab Emirates",
        "Ireland",
        "Tanzania, United Republic of",
        "Philippines",
        "Japan",
        "Guatemala",
        "Mexico",
        "Bahamas",
        "Barbados",
        "Georgia",
        "Slovakia",
        "Sint Maarten (Dutch part)",
        "Kenya"
      ],
      "malware_families": [],
      "attack_ids": [],
      "industries": [
        "Education",
        "Government",
        "Technology",
        "Telecommunications",
        "Healthcare"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 25,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 2,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Disable_Duck",
        "id": "244325",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_244325/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 1639,
        "FileHash-MD5": 1481,
        "FileHash-SHA1": 1421,
        "FileHash-SHA256": 5969,
        "domain": 707,
        "hostname": 2311,
        "email": 5,
        "CIDR": 13
      },
      "indicator_count": 13546,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 133,
      "modified_text": "228 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "677db8b56d3d4c3af9ebd9b5",
      "name": "hxxps://tinyurl [.] com/Pixel2 - Link to Google Drive of Malicious APKs (unenriched analysis of link to the Google Drive)",
      "description": "hxxps://tinyurl [.] com - Link to Google Drive of Malicious APKs\nIt appears a link to a Backup of Client's APKs (Telus Google Device Protected by Norton)\nDevice currently connected to the University of Alberta, Telus  Communications (ISP), Alberta Health Services (AHS) and the Government of Alberta - is apparently itself malicious (still links to Google Drive Folder of APKs - to import for analysis later).",
      "modified": "2025-02-07T05:00:08.549000",
      "created": "2025-01-07T23:28:53.566000",
      "tags": [
        "UAlberta",
        "AHS",
        "Google",
        "Telus",
        "Pixel",
        "Norton"
      ],
      "references": [
        "https://www.filescan.io/uploads/677e0e14212309a70397d357/reports/0077a75d-f7d7-4634-a1ba-6f7b0488f9da/overview",
        "https://urlquery.net/report/16d1e034-1c64-4cbe-8b58-f5926dab9001",
        "https://www.virustotal.com/gui/url/1763a71e86e74729f1e993dc2e6b5cec9d91dd51245533a5300c85c9d49bc7ef",
        "http://www.hybrid-analysis.com/sample/dc744fc325700c6fda2b8d83b39a8c241258b9305058a3402ce70c97932acc74",
        "http://www.hybrid-analysis.com/sample/dc744fc325700c6fda2b8d83b39a8c241258b9305058a3402ce70c97932acc74/677d1d5dcb161e2448026452"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "Canada",
        "United States of America"
      ],
      "malware_families": [],
      "attack_ids": [],
      "industries": [
        "Healthcare",
        "Government",
        "Education"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 16,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 1,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Disable_Duck",
        "id": "244325",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_244325/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 13,
        "FileHash-MD5": 96,
        "FileHash-SHA1": 96,
        "FileHash-SHA256": 97,
        "SSLCertFingerprint": 4,
        "URL": 221,
        "hostname": 34
      },
      "indicator_count": 561,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 129,
      "modified_text": "479 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "64276a557aaf8592b056bf30",
      "name": "InQuest - 31-03-2023",
      "description": "",
      "modified": "2023-04-30T23:01:04.745000",
      "created": "2023-03-31T23:18:45.769000",
      "tags": [],
      "references": [
        "https://labs.inquest.net/iocdb"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 7,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "CyberHunterAutoFeed",
        "id": "182496",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_182496/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 297,
        "FileHash-MD5": 40,
        "URL": 1648,
        "domain": 1073,
        "hostname": 228,
        "FileHash-SHA1": 41
      },
      "indicator_count": 3327,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 1622,
      "modified_text": "1127 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "61f2cc67324e764bec0f4f9e",
      "name": "www.asurion.com (2)",
      "description": "",
      "modified": "2022-01-27T16:46:31.432000",
      "created": "2022-01-27T16:46:31.432000",
      "tags": [
        "a domains",
        "moved",
        "script domains",
        "script urls",
        "body",
        "date",
        "x cache",
        "cloudfront x",
        "hio50 c1",
        "script script",
        "meta"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 4,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Kailula4",
        "id": "131997",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 84,
        "hostname": 35,
        "domain": 4,
        "FileHash-SHA256": 276,
        "FileHash-MD5": 5,
        "FileHash-SHA1": 1
      },
      "indicator_count": 405,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 406,
      "modified_text": "1585 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "https://docs.google.com/",
    "type": "URL"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "https://docs.google.com/",
    "type": "URL",
    "found": false,
    "verdict": "clean",
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780290740.499096
}