{
  "type": "URL",
  "indicator": "https://en.cube-soft.jp/entry/cubepdf-utility%",
  "general": {
    "sections": [
      "general",
      "url_list",
      "http_scans",
      "screenshot"
    ],
    "indicator": "https://en.cube-soft.jp/entry/cubepdf-utility%",
    "type": "url",
    "type_title": "URL",
    "validation": [],
    "base_indicator": {
      "id": 4042152417,
      "indicator": "https://en.cube-soft.jp/entry/cubepdf-utility%",
      "type": "URL",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 4,
      "pulses": [
        {
          "id": "69ba97dadbd6e4729709fa6d",
          "name": "pobierz.zip Sygn. akt II K 909/23 oskar clone by arek-BTC",
          "description": "",
          "modified": "2026-03-18T12:17:30.176000",
          "created": "2026-03-18T12:17:30.176000",
          "tags": [
            "typ pliku",
            "ascii",
            "sqlite",
            "tekst",
            "postscript",
            "cza typ",
            "windows",
            "152 x",
            "utf8",
            "dziennik",
            "sha1",
            "json",
            "foxpro fpt",
            "sha256",
            "mwdb",
            "bazar",
            "sha3384",
            "crc32 c69b0751",
            "gboki",
            "settings",
            "categories",
            "default",
            "toolspanose",
            "cname",
            "nova cond",
            "inprocserver32",
            "metadata",
            "lcid1033",
            "syslcid1033",
            "light"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": "67c44a6e14a21bec8ba63984",
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 210,
            "FileHash-SHA1": 53,
            "FileHash-SHA256": 599,
            "hostname": 151,
            "domain": 23,
            "URL": 233
          },
          "indicator_count": 1269,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 66,
          "modified_text": "75 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "686c5dd19c990e74486c5e1f",
          "name": "(by gameprofits.io) ? DILBOOSTENERY.COM RHORINC.COM JANUSCAPITALINC.COM BRITISH COLUMBIA",
          "description": "",
          "modified": "2025-07-07T23:52:49.965000",
          "created": "2025-07-07T23:52:49.965000",
          "tags": [
            "ip address",
            "country name",
            "gameprofitshack",
            "t'sara brashears",
            "Texas GOP Hack",
            "patent theft",
            "januscapitalinc.com hack",
            "pluspetro framing",
            "rhorinc hack"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "",
            "Video Games",
            "Petro",
            "Oil",
            "Energy",
            "telecommunications"
          ],
          "TLP": "white",
          "cloned_from": "6830a9467691823193700901",
          "export_count": 4,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 1,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Q.Vashti",
            "id": "337942",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 65,
            "URL": 315,
            "FileHash-SHA256": 84,
            "hostname": 90
          },
          "indicator_count": 554,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 143,
          "modified_text": "328 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6830a9467691823193700901",
          "name": "DILBOOSTENERY.COM RHORINC.COM JANUSCAPITALINC.COM BRITISH COLUMBIA VITCIM OF CYBERSTALKING ESPONIAGE FRAMING IP THEFT FORCED POVERTY HACKING",
          "description": "MAJOR UPDATE - \n\nCHRISTY LEE DEWALT WORKING WITH CRIMINAL ENTERPRISE PK TECHNOLOGY BEHIND  THE HACKERS ON THESE PULSES FRAMED",
          "modified": "2025-06-22T16:03:56.158000",
          "created": "2025-05-23T16:58:46.788000",
          "tags": [
            "ip address",
            "country name",
            "gameprofitshack",
            "t'sara brashears",
            "Texas GOP Hack",
            "patent theft",
            "januscapitalinc.com hack",
            "pluspetro framing",
            "rhorinc hack"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "",
            "Video Games",
            "Petro",
            "Oil",
            "Energy",
            "telecommunications"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 15,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "gameprofits.io",
            "id": "170823",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_170823/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 65,
            "URL": 315,
            "FileHash-SHA256": 84,
            "hostname": 90
          },
          "indicator_count": 554,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 51,
          "modified_text": "344 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "67c44a6e14a21bec8ba63984",
          "name": "pobierz.zip   Sygn. akt II K 909/23 oskar\u017conego z art. 190 \u00a7 1 k.k. i inne",
          "description": "Sugerowane identyfikatory ATT&CK:\n7eab0ed0a8a050ad34f71dfd3e2109ff SHA1 c60c3d64cfa19fb1f19eabc656aafdcf12d87dd4 SHA256 3d0f3f98cea613718def2eb9dca707ad57d3d96d4e6b593aca38c8574a578905 [VT] [MWDB] [Bazar] SHA3-384 32d70abaa630d0a8e6237b1df88da306306d27096950469ff7e99d754274e28cfaa0736af43ad55f3d57fc66d9812d4d CRC32 C69B0751 TLSH T1013413B6C8A16CF2D93D2BF2D89A3715DFDAB2C28156C057EB22C09359CE5D817438D8 G\u0142\u0119boki 6144:E8FhrpzjsHyC6DgXapizwbZ8ePb85pNLmih2tC:vrpESCUgX8ikbZ8ePb8J0E",
          "modified": "2025-04-01T09:03:52.165000",
          "created": "2025-03-02T12:09:18.878000",
          "tags": [
            "typ pliku",
            "ascii",
            "sqlite",
            "tekst",
            "postscript",
            "cza typ",
            "windows",
            "152 x",
            "utf8",
            "dziennik",
            "sha1",
            "json",
            "foxpro fpt",
            "sha256",
            "mwdb",
            "bazar",
            "sha3384",
            "crc32 c69b0751",
            "gboki",
            "settings",
            "categories",
            "default",
            "toolspanose",
            "cname",
            "nova cond",
            "inprocserver32",
            "metadata",
            "lcid1033",
            "syslcid1033",
            "light"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 8,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Arek-BTC",
            "id": "212764",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_212764/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 210,
            "FileHash-SHA1": 53,
            "FileHash-SHA256": 599,
            "hostname": 151,
            "domain": 23,
            "URL": 233
          },
          "indicator_count": 1269,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 127,
          "modified_text": "426 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        }
      ],
      "references": [],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 0
        },
        "other": {
          "adversary": [],
          "malware_families": [],
          "industries": [
            "",
            "Energy",
            "Telecommunications",
            "Petro",
            "Oil",
            "Video games"
          ],
          "unique_indicators": 1762
        }
      }
    },
    "false_positive": [],
    "alexa": "http://www.alexa.com/siteinfo/cube-soft.jp",
    "whois": "http://whois.domaintools.com/cube-soft.jp",
    "domain": "cube-soft.jp",
    "hostname": "en.cube-soft.jp"
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 4,
  "pulses": [
    {
      "id": "69ba97dadbd6e4729709fa6d",
      "name": "pobierz.zip Sygn. akt II K 909/23 oskar clone by arek-BTC",
      "description": "",
      "modified": "2026-03-18T12:17:30.176000",
      "created": "2026-03-18T12:17:30.176000",
      "tags": [
        "typ pliku",
        "ascii",
        "sqlite",
        "tekst",
        "postscript",
        "cza typ",
        "windows",
        "152 x",
        "utf8",
        "dziennik",
        "sha1",
        "json",
        "foxpro fpt",
        "sha256",
        "mwdb",
        "bazar",
        "sha3384",
        "crc32 c69b0751",
        "gboki",
        "settings",
        "categories",
        "default",
        "toolspanose",
        "cname",
        "nova cond",
        "inprocserver32",
        "metadata",
        "lcid1033",
        "syslcid1033",
        "light"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": "67c44a6e14a21bec8ba63984",
      "export_count": 1,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 210,
        "FileHash-SHA1": 53,
        "FileHash-SHA256": 599,
        "hostname": 151,
        "domain": 23,
        "URL": 233
      },
      "indicator_count": 1269,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 66,
      "modified_text": "75 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "686c5dd19c990e74486c5e1f",
      "name": "(by gameprofits.io) ? DILBOOSTENERY.COM RHORINC.COM JANUSCAPITALINC.COM BRITISH COLUMBIA",
      "description": "",
      "modified": "2025-07-07T23:52:49.965000",
      "created": "2025-07-07T23:52:49.965000",
      "tags": [
        "ip address",
        "country name",
        "gameprofitshack",
        "t'sara brashears",
        "Texas GOP Hack",
        "patent theft",
        "januscapitalinc.com hack",
        "pluspetro framing",
        "rhorinc hack"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [
        "",
        "Video Games",
        "Petro",
        "Oil",
        "Energy",
        "telecommunications"
      ],
      "TLP": "white",
      "cloned_from": "6830a9467691823193700901",
      "export_count": 4,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 1,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Q.Vashti",
        "id": "337942",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 65,
        "URL": 315,
        "FileHash-SHA256": 84,
        "hostname": 90
      },
      "indicator_count": 554,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 143,
      "modified_text": "328 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6830a9467691823193700901",
      "name": "DILBOOSTENERY.COM RHORINC.COM JANUSCAPITALINC.COM BRITISH COLUMBIA VITCIM OF CYBERSTALKING ESPONIAGE FRAMING IP THEFT FORCED POVERTY HACKING",
      "description": "MAJOR UPDATE - \n\nCHRISTY LEE DEWALT WORKING WITH CRIMINAL ENTERPRISE PK TECHNOLOGY BEHIND  THE HACKERS ON THESE PULSES FRAMED",
      "modified": "2025-06-22T16:03:56.158000",
      "created": "2025-05-23T16:58:46.788000",
      "tags": [
        "ip address",
        "country name",
        "gameprofitshack",
        "t'sara brashears",
        "Texas GOP Hack",
        "patent theft",
        "januscapitalinc.com hack",
        "pluspetro framing",
        "rhorinc hack"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [
        "",
        "Video Games",
        "Petro",
        "Oil",
        "Energy",
        "telecommunications"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 15,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "gameprofits.io",
        "id": "170823",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_170823/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 65,
        "URL": 315,
        "FileHash-SHA256": 84,
        "hostname": 90
      },
      "indicator_count": 554,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 51,
      "modified_text": "344 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "67c44a6e14a21bec8ba63984",
      "name": "pobierz.zip   Sygn. akt II K 909/23 oskar\u017conego z art. 190 \u00a7 1 k.k. i inne",
      "description": "Sugerowane identyfikatory ATT&CK:\n7eab0ed0a8a050ad34f71dfd3e2109ff SHA1 c60c3d64cfa19fb1f19eabc656aafdcf12d87dd4 SHA256 3d0f3f98cea613718def2eb9dca707ad57d3d96d4e6b593aca38c8574a578905 [VT] [MWDB] [Bazar] SHA3-384 32d70abaa630d0a8e6237b1df88da306306d27096950469ff7e99d754274e28cfaa0736af43ad55f3d57fc66d9812d4d CRC32 C69B0751 TLSH T1013413B6C8A16CF2D93D2BF2D89A3715DFDAB2C28156C057EB22C09359CE5D817438D8 G\u0142\u0119boki 6144:E8FhrpzjsHyC6DgXapizwbZ8ePb85pNLmih2tC:vrpESCUgX8ikbZ8ePb8J0E",
      "modified": "2025-04-01T09:03:52.165000",
      "created": "2025-03-02T12:09:18.878000",
      "tags": [
        "typ pliku",
        "ascii",
        "sqlite",
        "tekst",
        "postscript",
        "cza typ",
        "windows",
        "152 x",
        "utf8",
        "dziennik",
        "sha1",
        "json",
        "foxpro fpt",
        "sha256",
        "mwdb",
        "bazar",
        "sha3384",
        "crc32 c69b0751",
        "gboki",
        "settings",
        "categories",
        "default",
        "toolspanose",
        "cname",
        "nova cond",
        "inprocserver32",
        "metadata",
        "lcid1033",
        "syslcid1033",
        "light"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 8,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Arek-BTC",
        "id": "212764",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_212764/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 210,
        "FileHash-SHA1": 53,
        "FileHash-SHA256": 599,
        "hostname": 151,
        "domain": 23,
        "URL": 233
      },
      "indicator_count": 1269,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 127,
      "modified_text": "426 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "https://en.cube-soft.jp/entry/cubepdf-utility%",
    "type": "URL"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "https://en.cube-soft.jp/entry/cubepdf-utility%",
    "type": "URL",
    "found": false,
    "verdict": "clean",
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780342300.7593753
}