{
  "type": "URL",
  "indicator": "https://downloads.level.io/level.msi",
  "general": {
    "sections": [
      "general",
      "url_list",
      "http_scans",
      "screenshot"
    ],
    "indicator": "https://downloads.level.io/level.msi",
    "type": "url",
    "type_title": "URL",
    "validation": [],
    "base_indicator": {
      "id": 4034406284,
      "indicator": "https://downloads.level.io/level.msi",
      "type": "URL",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 2,
      "pulses": [
        {
          "id": "6389edf4071ec7c595fc8204",
          "name": "BlackBasta ransomware",
          "description": "Members of the Conti ransomware group appear to have splintered into multiple threat groups including BlackBasta, which has become one of the most significant ransomware threats. ThreatLabz has observed more than five victims that have been compromised by BlackBasta 2.0 since the new version\u2019s release in mid-November 2022. This demonstrates that the threat group is very successful at compromising organizations and the latest version of the ransomware will likely enable them to better evade antivirus and\u00a0EDRs.",
          "modified": "2025-03-23T00:03:10.218000",
          "created": "2022-12-02T12:22:12.999000",
          "tags": [
            "blackbasta",
            "conti",
            "ransomware"
          ],
          "references": [
            "https://www.zscaler.com/blogs/security-research/back-black-basta"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Conti",
              "display_name": "Conti",
              "target": null
            },
            {
              "id": "BlackBasta",
              "display_name": "BlackBasta",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1102",
              "name": "Web Service",
              "display_name": "T1102 - Web Service"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1471",
              "name": "Data Encrypted for Impact",
              "display_name": "T1471 - Data Encrypted for Impact"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 411,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "AlienVault",
            "id": "2",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_2/resized/80/avatar_dacfad0ca8.png",
            "is_subscribed": true,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 5,
            "URL": 2,
            "domain": 2,
            "FileHash-SHA1": 3,
            "FileHash-MD5": 1
          },
          "indicator_count": 13,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 386470,
          "modified_text": "434 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6a0e5ac0047f8480b66b253f",
          "name": "Twitter Feed - smica83 - 20-05-2026",
          "description": "",
          "modified": "2026-05-21T01:07:12.983000",
          "created": "2026-05-21T01:07:12.983000",
          "tags": [],
          "references": [
            "https://x.com/smica83/status/2057054205395820933",
            "https://x.com/smica83/status/2057056208314355811",
            "https://x.com/smica83/status/2057057509479727194",
            "https://x.com/smica83/status/2057073851339506040",
            "https://x.com/smica83/status/2057180756053475604"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "CyberHunterAutoFeed",
            "id": "182496",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_182496/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 7,
            "hostname": 1,
            "URL": 2,
            "IPv4": 1
          },
          "indicator_count": 11,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 1622,
          "modified_text": "10 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "https://x.com/smica83/status/2057057509479727194",
        "https://x.com/smica83/status/2057180756053475604",
        "https://x.com/smica83/status/2057056208314355811",
        "https://www.zscaler.com/blogs/security-research/back-black-basta",
        "https://x.com/smica83/status/2057054205395820933",
        "https://x.com/smica83/status/2057073851339506040"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [
            "Blackbasta",
            "Conti"
          ],
          "industries": [],
          "unique_indicators": 16
        },
        "other": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 11
        }
      }
    },
    "false_positive": [],
    "alexa": "http://www.alexa.com/siteinfo/level.io",
    "whois": "http://whois.domaintools.com/level.io",
    "domain": "level.io",
    "hostname": "downloads.level.io"
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 2,
  "pulses": [
    {
      "id": "6389edf4071ec7c595fc8204",
      "name": "BlackBasta ransomware",
      "description": "Members of the Conti ransomware group appear to have splintered into multiple threat groups including BlackBasta, which has become one of the most significant ransomware threats. ThreatLabz has observed more than five victims that have been compromised by BlackBasta 2.0 since the new version\u2019s release in mid-November 2022. This demonstrates that the threat group is very successful at compromising organizations and the latest version of the ransomware will likely enable them to better evade antivirus and\u00a0EDRs.",
      "modified": "2025-03-23T00:03:10.218000",
      "created": "2022-12-02T12:22:12.999000",
      "tags": [
        "blackbasta",
        "conti",
        "ransomware"
      ],
      "references": [
        "https://www.zscaler.com/blogs/security-research/back-black-basta"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Conti",
          "display_name": "Conti",
          "target": null
        },
        {
          "id": "BlackBasta",
          "display_name": "BlackBasta",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1102",
          "name": "Web Service",
          "display_name": "T1102 - Web Service"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1471",
          "name": "Data Encrypted for Impact",
          "display_name": "T1471 - Data Encrypted for Impact"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 411,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "AlienVault",
        "id": "2",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_2/resized/80/avatar_dacfad0ca8.png",
        "is_subscribed": true,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 5,
        "URL": 2,
        "domain": 2,
        "FileHash-SHA1": 3,
        "FileHash-MD5": 1
      },
      "indicator_count": 13,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 386470,
      "modified_text": "434 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6a0e5ac0047f8480b66b253f",
      "name": "Twitter Feed - smica83 - 20-05-2026",
      "description": "",
      "modified": "2026-05-21T01:07:12.983000",
      "created": "2026-05-21T01:07:12.983000",
      "tags": [],
      "references": [
        "https://x.com/smica83/status/2057054205395820933",
        "https://x.com/smica83/status/2057056208314355811",
        "https://x.com/smica83/status/2057057509479727194",
        "https://x.com/smica83/status/2057073851339506040",
        "https://x.com/smica83/status/2057180756053475604"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "CyberHunterAutoFeed",
        "id": "182496",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_182496/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 7,
        "hostname": 1,
        "URL": 2,
        "IPv4": 1
      },
      "indicator_count": 11,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 1622,
      "modified_text": "10 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "https://downloads.level.io/level.msi",
    "type": "URL"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "https://downloads.level.io/level.msi",
    "type": "URL",
    "found": false,
    "verdict": "clean",
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780192209.501975
}