{
  "type": "URL",
  "indicator": "https://etc.freebuf.info",
  "general": {
    "sections": [
      "general",
      "url_list",
      "http_scans",
      "screenshot"
    ],
    "indicator": "https://etc.freebuf.info",
    "type": "url",
    "type_title": "URL",
    "validation": [],
    "base_indicator": {
      "id": 2892398395,
      "indicator": "https://etc.freebuf.info",
      "type": "URL",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 3,
      "pulses": [
        {
          "id": "688f2a4444334746890f3b39",
          "name": "Bank of America Scam",
          "description": "Bank of America scams that being carried out for at least 8 years. Group able to steal your credentials, investments, insurance policies, skimming, small to large false charges, account theft. 9/2024 BoFa was investigated by me. They had experienced a major , sophisticated compromise. At least one branch is run by unfriendly investigators or authorities. All regular staff was moved to different branches. I witnessed personnel accessing a customer\u2019s account without customer presenting ID or giving name. Customer was concerned, staffer just stated he remembered their business name. Another customer was being harassed to close business account for an hour and another staffer took a consumers debit card and denied it prompting an internal investigation. Finally a \u2018manager\u2019 said they experienced a major hack. Research shows customers weren\u2019t informed. . Further research is necessary.\nAnybody? \n#theft #skimming #cancellations #false_charges #debitcardfraud #botnetcallcenter",
          "modified": "2025-09-02T08:02:34.108000",
          "created": "2025-08-03T09:22:12.846000",
          "tags": [
            "united",
            "link",
            "ip address",
            "creation date",
            "search",
            "record value",
            "showing",
            "unknown ns",
            "present mar",
            "a domains",
            "date",
            "meta",
            "starfield",
            "entries",
            "show",
            "windows",
            "msie",
            "http",
            "medium",
            "post http",
            "delete",
            "ids detections",
            "malware",
            "copy",
            "drweb",
            "write",
            "win32",
            "global",
            "present jul",
            "error",
            "lowfi",
            "trojanspy",
            "checkin",
            "passive dns",
            "trojan",
            "next associated",
            "cryp",
            "present aug",
            "urls",
            "address",
            "hostname",
            "pulse submit",
            "url analysis",
            "files",
            "domain",
            "pulse",
            "less whois",
            "registrar",
            "adylkuzz cnc",
            "beacon",
            "get http",
            "exe payload",
            "read",
            "suspicious"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1045",
              "name": "Software Packing",
              "display_name": "T1045 - Software Packing"
            },
            {
              "id": "T1053",
              "name": "Scheduled Task/Job",
              "display_name": "T1053 - Scheduled Task/Job"
            },
            {
              "id": "T1060",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1060 - Registry Run Keys / Startup Folder"
            },
            {
              "id": "T1158",
              "name": "Hidden Files and Directories",
              "display_name": "T1158 - Hidden Files and Directories"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 17,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Q.Vashti",
            "id": "337942",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 171,
            "URL": 873,
            "domain": 180,
            "hostname": 332,
            "email": 3,
            "FileHash-SHA256": 698,
            "FileHash-SHA1": 167
          },
          "indicator_count": 2424,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 141,
          "modified_text": "273 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "657096b4440900cf22fd32b0",
          "name": "B\u00e1n \u0111\u1ea5t th\u00f4n C\u1ed5 \u0110i\u1ec3n A, T\u1ee9 Hi\u1ec7p, Thanh Tr\u00ec, H\u00e0 N\u1ed9i.",
          "description": "",
          "modified": "2023-12-06T15:43:48.468000",
          "created": "2023-12-06T15:43:48.468000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 3,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 271,
            "FileHash-SHA256": 256,
            "domain": 40,
            "hostname": 111,
            "FileHash-MD5": 3,
            "FileHash-SHA1": 3,
            "CVE": 1,
            "CIDR": 2,
            "URI": 1
          },
          "indicator_count": 688,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "909 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "63dbc224c528ffca9ac7d598",
          "name": "B\u00e1n \u0111\u1ea5t th\u00f4n C\u1ed5 \u0110i\u1ec3n A, T\u1ee9 Hi\u1ec7p, Thanh Tr\u00ec, H\u00e0 N\u1ed9i.",
          "description": "B\u00e1n nh\u00e0 t\u00e2y Ninh  B\u00e1i B\u00ecnh trong g\u00ean \u00e2'r \u00f4l \u00c2\u00a31.5m.",
          "modified": "2023-03-04T17:04:22.783000",
          "created": "2023-02-02T14:01:08.688000",
          "tags": [
            "sang nh\u01b0\u1ee3ng",
            "chuy\u1ec3n nh\u01b0\u1ee3ng",
            "mua b\u00e1n nh\u00e0 \u0111\u1ea5t",
            "b\u00e1n nh\u00e0",
            "b\u00e1n \u0111\u1ea5t",
            "khng c",
            "miu m",
            "nam t",
            "h ni",
            "ng lu",
            "ng v",
            "n nh",
            "mariot",
            "thu nh",
            "b\u00e1n",
            "\u0111\u1ea5t",
            "th\u00f4n",
            "c\u1ed5",
            "\u0111i\u1ec3n",
            "a",
            "t\u1ee9",
            "hi\u1ec7p",
            "thanh",
            "tr\u00ec",
            "h\u00e0",
            "n\u1ed9i.",
            "thanh tr",
            "bn t",
            "ngy ng",
            "khung gi",
            "loi bs",
            "t hip",
            "t thn",
            "chn theo",
            "lin h"
          ],
          "references": [
            "http://m.bds247.vn/bat-dong-san/24010/Ban-dat-thon-Co-Dien-A-Tu-Hiep-Thanh-Tri-Ha-Noi..html",
            "http://m.bds247.vn/bat-dong-san/26417/Sang-nhuong-GAP-nha-nghi-Mieu-Dam-Nam-Tu-Liem-Ha-Noi.html"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 10,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "callmeDoris",
            "id": "205385",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 299,
            "hostname": 131,
            "domain": 120,
            "CIDR": 2,
            "FileHash-SHA256": 408,
            "URI": 1,
            "FileHash-MD5": 3,
            "FileHash-SHA1": 3,
            "CVE": 1
          },
          "indicator_count": 968,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 92,
          "modified_text": "1186 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "http://m.bds247.vn/bat-dong-san/24010/Ban-dat-thon-Co-Dien-A-Tu-Hiep-Thanh-Tri-Ha-Noi..html",
        "http://m.bds247.vn/bat-dong-san/26417/Sang-nhuong-GAP-nha-nghi-Mieu-Dam-Nam-Tu-Liem-Ha-Noi.html"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 0
        },
        "other": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 3114
        }
      }
    },
    "false_positive": [],
    "alexa": "http://www.alexa.com/siteinfo/freebuf.info",
    "whois": "http://whois.domaintools.com/freebuf.info",
    "domain": "freebuf.info",
    "hostname": "etc.freebuf.info"
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 3,
  "pulses": [
    {
      "id": "688f2a4444334746890f3b39",
      "name": "Bank of America Scam",
      "description": "Bank of America scams that being carried out for at least 8 years. Group able to steal your credentials, investments, insurance policies, skimming, small to large false charges, account theft. 9/2024 BoFa was investigated by me. They had experienced a major , sophisticated compromise. At least one branch is run by unfriendly investigators or authorities. All regular staff was moved to different branches. I witnessed personnel accessing a customer\u2019s account without customer presenting ID or giving name. Customer was concerned, staffer just stated he remembered their business name. Another customer was being harassed to close business account for an hour and another staffer took a consumers debit card and denied it prompting an internal investigation. Finally a \u2018manager\u2019 said they experienced a major hack. Research shows customers weren\u2019t informed. . Further research is necessary.\nAnybody? \n#theft #skimming #cancellations #false_charges #debitcardfraud #botnetcallcenter",
      "modified": "2025-09-02T08:02:34.108000",
      "created": "2025-08-03T09:22:12.846000",
      "tags": [
        "united",
        "link",
        "ip address",
        "creation date",
        "search",
        "record value",
        "showing",
        "unknown ns",
        "present mar",
        "a domains",
        "date",
        "meta",
        "starfield",
        "entries",
        "show",
        "windows",
        "msie",
        "http",
        "medium",
        "post http",
        "delete",
        "ids detections",
        "malware",
        "copy",
        "drweb",
        "write",
        "win32",
        "global",
        "present jul",
        "error",
        "lowfi",
        "trojanspy",
        "checkin",
        "passive dns",
        "trojan",
        "next associated",
        "cryp",
        "present aug",
        "urls",
        "address",
        "hostname",
        "pulse submit",
        "url analysis",
        "files",
        "domain",
        "pulse",
        "less whois",
        "registrar",
        "adylkuzz cnc",
        "beacon",
        "get http",
        "exe payload",
        "read",
        "suspicious"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1045",
          "name": "Software Packing",
          "display_name": "T1045 - Software Packing"
        },
        {
          "id": "T1053",
          "name": "Scheduled Task/Job",
          "display_name": "T1053 - Scheduled Task/Job"
        },
        {
          "id": "T1060",
          "name": "Registry Run Keys / Startup Folder",
          "display_name": "T1060 - Registry Run Keys / Startup Folder"
        },
        {
          "id": "T1158",
          "name": "Hidden Files and Directories",
          "display_name": "T1158 - Hidden Files and Directories"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 17,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Q.Vashti",
        "id": "337942",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 171,
        "URL": 873,
        "domain": 180,
        "hostname": 332,
        "email": 3,
        "FileHash-SHA256": 698,
        "FileHash-SHA1": 167
      },
      "indicator_count": 2424,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 141,
      "modified_text": "273 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "657096b4440900cf22fd32b0",
      "name": "B\u00e1n \u0111\u1ea5t th\u00f4n C\u1ed5 \u0110i\u1ec3n A, T\u1ee9 Hi\u1ec7p, Thanh Tr\u00ec, H\u00e0 N\u1ed9i.",
      "description": "",
      "modified": "2023-12-06T15:43:48.468000",
      "created": "2023-12-06T15:43:48.468000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 3,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 271,
        "FileHash-SHA256": 256,
        "domain": 40,
        "hostname": 111,
        "FileHash-MD5": 3,
        "FileHash-SHA1": 3,
        "CVE": 1,
        "CIDR": 2,
        "URI": 1
      },
      "indicator_count": 688,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "909 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "63dbc224c528ffca9ac7d598",
      "name": "B\u00e1n \u0111\u1ea5t th\u00f4n C\u1ed5 \u0110i\u1ec3n A, T\u1ee9 Hi\u1ec7p, Thanh Tr\u00ec, H\u00e0 N\u1ed9i.",
      "description": "B\u00e1n nh\u00e0 t\u00e2y Ninh  B\u00e1i B\u00ecnh trong g\u00ean \u00e2'r \u00f4l \u00c2\u00a31.5m.",
      "modified": "2023-03-04T17:04:22.783000",
      "created": "2023-02-02T14:01:08.688000",
      "tags": [
        "sang nh\u01b0\u1ee3ng",
        "chuy\u1ec3n nh\u01b0\u1ee3ng",
        "mua b\u00e1n nh\u00e0 \u0111\u1ea5t",
        "b\u00e1n nh\u00e0",
        "b\u00e1n \u0111\u1ea5t",
        "khng c",
        "miu m",
        "nam t",
        "h ni",
        "ng lu",
        "ng v",
        "n nh",
        "mariot",
        "thu nh",
        "b\u00e1n",
        "\u0111\u1ea5t",
        "th\u00f4n",
        "c\u1ed5",
        "\u0111i\u1ec3n",
        "a",
        "t\u1ee9",
        "hi\u1ec7p",
        "thanh",
        "tr\u00ec",
        "h\u00e0",
        "n\u1ed9i.",
        "thanh tr",
        "bn t",
        "ngy ng",
        "khung gi",
        "loi bs",
        "t hip",
        "t thn",
        "chn theo",
        "lin h"
      ],
      "references": [
        "http://m.bds247.vn/bat-dong-san/24010/Ban-dat-thon-Co-Dien-A-Tu-Hiep-Thanh-Tri-Ha-Noi..html",
        "http://m.bds247.vn/bat-dong-san/26417/Sang-nhuong-GAP-nha-nghi-Mieu-Dam-Nam-Tu-Liem-Ha-Noi.html"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 10,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "callmeDoris",
        "id": "205385",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 299,
        "hostname": 131,
        "domain": 120,
        "CIDR": 2,
        "FileHash-SHA256": 408,
        "URI": 1,
        "FileHash-MD5": 3,
        "FileHash-SHA1": 3,
        "CVE": 1
      },
      "indicator_count": 968,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 92,
      "modified_text": "1186 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "https://etc.freebuf.info",
    "type": "URL"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "https://etc.freebuf.info",
    "type": "URL",
    "found": false,
    "verdict": "clean",
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780422448.4043088
}