{
  "type": "URL",
  "indicator": "https://doingfedtime.com/888/",
  "general": {
    "sections": [
      "general",
      "url_list",
      "http_scans",
      "screenshot"
    ],
    "indicator": "https://doingfedtime.com/888/",
    "type": "url",
    "type_title": "URL",
    "validation": [],
    "base_indicator": {
      "id": 4178074915,
      "indicator": "https://doingfedtime.com/888/",
      "type": "URL",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 1,
      "pulses": [
        {
          "id": "6965476ec00b081079a03e01",
          "name": "Doomsday for Cybercriminals Data Breach of Major Dark Web Forum",
          "description": "The data breach involving BreachForums, a prominent dark web forum, marks a significant event for cybercriminals and the broader security landscape. Historically, BreachForums acted as a successor to RaidForums, which was shut down in 2022 due to law enforcement actions. Following its own shutdown in March 2023, BreachForums attempted to continue operations under new management, but was subsequently seized again in May 2024. This forum served as a hotspot for discussions related to hacking, distribution of stolen data, and various illicit activities.",
          "modified": "2026-02-11T19:01:42.222000",
          "created": "2026-01-12T19:11:42.754000",
          "tags": [
            "breachforums",
            "eu data",
            "shinyhunters",
            "james",
            "dark web",
            "raidforums",
            "resecurity",
            "january",
            "february",
            "kuroish",
            "indra",
            "june",
            "date",
            "code",
            "april",
            "project",
            "donald",
            "ctos",
            "eternity",
            "fortune",
            "life",
            "pegasus",
            "king",
            "goma",
            "hermes",
            "jerusalem",
            "achilles",
            "evil",
            "saturn",
            "hades",
            "look",
            "dust",
            "light",
            "exploit",
            "mena",
            "loki",
            "august",
            "turkish",
            "trinity",
            "chaos"
          ],
          "references": [
            "https://www.resecurity.com/blog/article/doomsday-for-cybercriminals-data-breach-of-major-dark-web-foru"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1583.001",
              "name": "Domains",
              "display_name": "T1583.001 - Domains"
            },
            {
              "id": "T1583.004",
              "name": "Server",
              "display_name": "T1583.004 - Server"
            },
            {
              "id": "T1589",
              "name": "Gather Victim Identity Information",
              "display_name": "T1589 - Gather Victim Identity Information"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "PetrP.73",
            "id": "154605",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "CVE": 1,
            "URL": 5,
            "domain": 9,
            "email": 4,
            "hostname": 5
          },
          "indicator_count": 24,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 170,
          "modified_text": "66 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "https://www.resecurity.com/blog/article/doomsday-for-cybercriminals-data-breach-of-major-dark-web-foru"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 0
        },
        "other": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 25
        }
      }
    },
    "false_positive": [],
    "alexa": "http://www.alexa.com/siteinfo/doingfedtime.com",
    "whois": "http://whois.domaintools.com/doingfedtime.com",
    "domain": "doingfedtime.com",
    "hostname": "Unavailable"
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 1,
  "pulses": [
    {
      "id": "6965476ec00b081079a03e01",
      "name": "Doomsday for Cybercriminals Data Breach of Major Dark Web Forum",
      "description": "The data breach involving BreachForums, a prominent dark web forum, marks a significant event for cybercriminals and the broader security landscape. Historically, BreachForums acted as a successor to RaidForums, which was shut down in 2022 due to law enforcement actions. Following its own shutdown in March 2023, BreachForums attempted to continue operations under new management, but was subsequently seized again in May 2024. This forum served as a hotspot for discussions related to hacking, distribution of stolen data, and various illicit activities.",
      "modified": "2026-02-11T19:01:42.222000",
      "created": "2026-01-12T19:11:42.754000",
      "tags": [
        "breachforums",
        "eu data",
        "shinyhunters",
        "james",
        "dark web",
        "raidforums",
        "resecurity",
        "january",
        "february",
        "kuroish",
        "indra",
        "june",
        "date",
        "code",
        "april",
        "project",
        "donald",
        "ctos",
        "eternity",
        "fortune",
        "life",
        "pegasus",
        "king",
        "goma",
        "hermes",
        "jerusalem",
        "achilles",
        "evil",
        "saturn",
        "hades",
        "look",
        "dust",
        "light",
        "exploit",
        "mena",
        "loki",
        "august",
        "turkish",
        "trinity",
        "chaos"
      ],
      "references": [
        "https://www.resecurity.com/blog/article/doomsday-for-cybercriminals-data-breach-of-major-dark-web-foru"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1583.001",
          "name": "Domains",
          "display_name": "T1583.001 - Domains"
        },
        {
          "id": "T1583.004",
          "name": "Server",
          "display_name": "T1583.004 - Server"
        },
        {
          "id": "T1589",
          "name": "Gather Victim Identity Information",
          "display_name": "T1589 - Gather Victim Identity Information"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 1,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "PetrP.73",
        "id": "154605",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "CVE": 1,
        "URL": 5,
        "domain": 9,
        "email": 4,
        "hostname": 5
      },
      "indicator_count": 24,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 170,
      "modified_text": "66 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "https://doingfedtime.com/888/",
    "type": "URL"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "https://doingfedtime.com/888/",
    "type": "URL",
    "found": false,
    "verdict": "clean",
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1776611388.4041867
}