{
  "type": "URL",
  "indicator": "https://gotocfr.com/cfrcareers/",
  "general": {
    "sections": [
      "general",
      "url_list",
      "http_scans",
      "screenshot"
    ],
    "indicator": "https://gotocfr.com/cfrcareers/",
    "type": "url",
    "type_title": "URL",
    "validation": [],
    "base_indicator": {
      "id": 4348858745,
      "indicator": "https://gotocfr.com/cfrcareers/",
      "type": "URL",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 3,
      "pulses": [
        {
          "id": "69fdc02a184d8d0f3370b069",
          "name": "ripe.arin.enom.cpanel.cpcalendar.iana.networksolutions.02050.webdisk.webmail.",
          "description": "interesting. 2000-06-05T14:09:35Z\nDNSSEC: unsigned\nDomain Name: GOTOCFR.COM\nDomain Status:  https://icann.org/epp#clientTransferProhibited\nName Server: NS37.WORLDNIC.COM\nName Server: NS38.WORLDNIC.COM\nRegistrant City: 3f16518cc21288a8\nRegistrant Country: US\nRegistrant Email: a07a5df6ca9e975bs@gotocfr.com\nRegistrant Fax Ext: 3432650ec337c945\nRegistrant Fax: b3c25287c0f8ed51\nRegistrant Name: 3432650ec337c945\nRegistrant Organization: 3432650ec337c945\nRegistrant Phone Ext: 3432650ec337c945\nRegistrant Phone: a8108981ed146828\nRegistrant Postal Code: 22ba98fa33e9a7d1\nRegistrant State/Province: 2f0a6dc5401e8a9a\nRegistrant Street: c4d735c293d4e708\nRegistrar Abuse Contact Email: domain.operations@web.com\nRegistrar Abuse Contact Phone: +1.8777228662\nRegistrar IANA ID: 2\nRegistrar URL: http://networksolutions.com\nRegistrar WHOIS Server: whois.networksolutions.com\nRegistrar: Network Solutions, LLC\nRegistry Domain ID: 28566423_DOMAIN_COM-VRSN\nUpdated Date: 2026-04-06T06:20:14Z",
          "modified": "2026-05-09T07:30:09.404000",
          "created": "2026-05-08T10:51:22.795000",
          "tags": [
            "msie",
            "chrome",
            "passive dns",
            "date",
            "urls",
            "fabricating and",
            "type",
            "media type",
            "gmt content",
            "certificate",
            "title",
            "body",
            "encrypt",
            "graph summary",
            "algorithm",
            "key identifier",
            "x509v3 subject",
            "v3 serial",
            "number",
            "cus olet",
            "encrypt cnr12",
            "validity",
            "subject public",
            "key info",
            "code",
            "email",
            "server",
            "admin country",
            "registrant name",
            "and repair",
            "expiration date",
            "registry domain",
            "registrar iana",
            "creation date",
            "admin city",
            "key algorithm",
            "registrar abuse",
            "dnssec",
            "domain name",
            "status",
            "city",
            "us registrant",
            "registrant fax",
            "marshfield ssl",
            "common name",
            "issued",
            "supporte",
            "charter",
            "llc united",
            "statesunited",
            "new london",
            "i20100 may",
            "diesel",
            "ripe ncc",
            "ripe network",
            "abuse contact",
            "orgid",
            "orgtechhandle",
            "address",
            "orgabuseref",
            "postalcode",
            "ripe",
            "cidr",
            "ripe database",
            "orgabuseemail",
            "orgabusehandle",
            "nethandle",
            "thumbprint",
            "handle",
            "address range",
            "network name",
            "allocation type",
            "allocated pa",
            "whois server",
            "organization",
            "please note",
            "ip address",
            "google",
            "redacted for",
            "privacy admin",
            "privacy",
            "privacy tech",
            "street",
            "stateprovince",
            "form",
            "tech"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA1": 45,
            "IPv4": 32,
            "URL": 932,
            "domain": 51,
            "email": 9,
            "hostname": 186,
            "FileHash-SHA256": 43,
            "FileHash-MD5": 3,
            "CIDR": 3
          },
          "indicator_count": 1304,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 67,
          "modified_text": "23 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "69fdc02bea1e4ec923b01688",
          "name": "ripe.arin.enom.cpanel.cpcalendar.iana.networksolutions.02050.webdisk.webmail.",
          "description": "interesting. 2000-06-05T14:09:35Z\nDNSSEC: unsigned\nDomain Name: GOTOCFR.COM\nDomain Status:  https://icann.org/epp#clientTransferProhibited\nName Server: NS37.WORLDNIC.COM\nName Server: NS38.WORLDNIC.COM\nRegistrant City: 3f16518cc21288a8\nRegistrant Country: US\nRegistrant Email: a07a5df6ca9e975bs@gotocfr.com\nRegistrant Fax Ext: 3432650ec337c945\nRegistrant Fax: b3c25287c0f8ed51\nRegistrant Name: 3432650ec337c945\nRegistrant Organization: 3432650ec337c945\nRegistrant Phone Ext: 3432650ec337c945\nRegistrant Phone: a8108981ed146828\nRegistrant Postal Code: 22ba98fa33e9a7d1\nRegistrant State/Province: 2f0a6dc5401e8a9a\nRegistrant Street: c4d735c293d4e708\nRegistrar Abuse Contact Email: domain.operations@web.com\nRegistrar Abuse Contact Phone: +1.8777228662\nRegistrar IANA ID: 2\nRegistrar URL: http://networksolutions.com\nRegistrar WHOIS Server: whois.networksolutions.com\nRegistrar: Network Solutions, LLC\nRegistry Domain ID: 28566423_DOMAIN_COM-VRSN\nUpdated Date: 2026-04-06T06:20:14Z",
          "modified": "2026-05-09T03:07:39.308000",
          "created": "2026-05-08T10:51:23.184000",
          "tags": [
            "msie",
            "chrome",
            "passive dns",
            "date",
            "urls",
            "fabricating and",
            "type",
            "media type",
            "gmt content",
            "certificate",
            "title",
            "body",
            "encrypt",
            "graph summary",
            "algorithm",
            "key identifier",
            "x509v3 subject",
            "v3 serial",
            "number",
            "cus olet",
            "encrypt cnr12",
            "validity",
            "subject public",
            "key info",
            "code",
            "email",
            "server",
            "admin country",
            "registrant name",
            "and repair",
            "expiration date",
            "registry domain",
            "registrar iana",
            "creation date",
            "admin city",
            "key algorithm",
            "registrar abuse",
            "dnssec",
            "domain name",
            "status",
            "city",
            "us registrant",
            "registrant fax",
            "marshfield ssl",
            "common name",
            "issued",
            "supporte",
            "charter",
            "llc united",
            "statesunited",
            "new london",
            "i20100 may",
            "diesel",
            "ripe ncc",
            "ripe network",
            "abuse contact",
            "orgid",
            "orgtechhandle",
            "address",
            "orgabuseref",
            "postalcode",
            "ripe",
            "cidr",
            "ripe database",
            "orgabuseemail",
            "orgabusehandle",
            "nethandle",
            "thumbprint",
            "handle",
            "address range",
            "network name",
            "allocation type",
            "allocated pa",
            "whois server",
            "organization",
            "please note",
            "ip address",
            "google",
            "redacted for",
            "privacy admin",
            "privacy",
            "privacy tech",
            "street",
            "stateprovince",
            "form",
            "tech"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA1": 236,
            "IPv4": 315,
            "URL": 932,
            "domain": 1040,
            "email": 65,
            "hostname": 1049,
            "FileHash-SHA256": 960,
            "FileHash-MD5": 301,
            "CIDR": 39,
            "IPv6": 68,
            "CVE": 890,
            "SSLCertFingerprint": 16
          },
          "indicator_count": 5911,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 66,
          "modified_text": "23 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "69fd8916c718cee78b1d08d1",
          "name": "CAPE Sandbox - Borland Delphi + added other malic win [exe]",
          "description": "[Malware Analysis System Evasion (MZP) report has been generated by Yara, a community-based security firm.] Delphi and other win[exe] all malicious- sandboxed runs only.",
          "modified": "2026-05-08T10:32:41.135000",
          "created": "2026-05-08T06:56:22.767000",
          "tags": [
            "url http",
            "ipv4",
            "strong",
            "library",
            "address virtual",
            "cname",
            "size",
            "file type",
            "mwdb",
            "bazaar",
            "sha3384",
            "ssdeep",
            "accept",
            "shutdown",
            "sandbox",
            "stack",
            "windows sandbox",
            "clear filters",
            "calls process",
            "pe file",
            "sample",
            "performs dns",
            "yara",
            "https",
            "urls",
            "mitre attack",
            "network info",
            "processes extra",
            "command",
            "malicious",
            "delphi",
            "defense evasion",
            "next"
          ],
          "references": [
            "https://vtbehaviour.commondatastorage.googleapis.com/561f94715c481c0e616cf1907d86e522afe9186f8365ab3a35d7872b2653580b_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1778223081&Signature=Hm63tZKeRZujdUn11Hi%2BwTAevMctFRDZDQ9GnFQsB%2BN1N%2FxQN3pkPwwuAScaiiliHBcXgCSUXI3gph1Bgmh%2BdMALu8FKmvwYRvuq4xYlXAZvyQFUN1xr4%2FxkpnRhr0tiskf4kWXDZvlBCW1H1K3mKSkT6vkjiEn6xDLVUO1Eo8ESJDnnsTshk3vIiXlAhodWtrJS8RTgA%2BjhGCgU3IruiA3O5nxWwIJSLMrM7pRI1zgAy%2BH0",
            "https://vtbehaviour.commondatastorage.googleapis.com/561f94715c481c0e616cf1907d86e522afe9186f8365ab3a35d7872b2653580b_VirusTotal%20Jujubox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1778223201&Signature=UbPDmnyT2j%2B5gbsHnwxLwuxti6r6ukPXUh%2BIz3I0VhnZa%2FV0coDJPx%2FvqkOMdu%2F8UuONZpVTl28tlerH%2FsZNK6YpFPgUmrFXYJx6c%2B6W7%2FC1yC8TeC5lN4%2F0h19KcjvCdFGNFgLhigH62wxU2GkmZT5jz8ISZhkAzkReVhdaZA7vYQnLQZvpvEQGScnuZc0PZSANsAvfN2lyqBDH%2FpGFc%2BDpfNGnnFYsjJ",
            "https://vtbehaviour.commondatastorage.googleapis.com/9d9b74f13b0001184ea51257e446bd317e5180e0ed856e7dfb7d92d1fb7c9df9_VirusTotal%20Jujubox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1778223336&Signature=avokLSiN2%2B14P94v4u5P%2FljfsWv2nqNJdQpMmRl88Esart7da%2BE4E1d0d7MXavOLWEHHt09QYchkV3iMo3Ia%2Fr49jeO5ZALtnuDrJMAvU6Js5MUrkqPT0R9LZ9b4vcG3hrHPF%2Fu9EiVhYII3bhmK5CjnHDF44L4qtE8vVkw03lOx1XpgUhdTK6rRzXALQ1tqKrDE5LUh7S9giv0VZz7aqV%2B9Ch%2Fb%2BGPU3mis2wnh",
            "https://vtbehaviour.commondatastorage.googleapis.com/9d9b74f13b0001184ea51257e446bd317e5180e0ed856e7dfb7d92d1fb7c9df9_Zenbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1778223386&Signature=0oCtLpyEmobttCQJza34xagBptN0LmmC7kxt51fgm7nEEyRcpEzZPo%2F9OF9ZpJJs%2FJTtDEqFP8FURlT79ioFjN8T2fu7lRrL2P5%2FDzcAfYlZJvnOu%2F4fFq%2FdqmL%2F6MWyaEcrew5K1Cn3RbD7cjqTe4M82GVyxYd9lWiO0ZQ2VTe9%2FLUCyFptCg7zsZk2cHhjDYTSW36tQUoEksDtMNaANFYM2mSxRPOXZ5XRzzF6WOvQjsjwrIqay2dk"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1112",
              "name": "Modify Registry",
              "display_name": "T1112 - Modify Registry"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1574",
              "name": "Hijack Execution Flow",
              "display_name": "T1574 - Hijack Execution Flow"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1095",
              "name": "Non-Application Layer Protocol",
              "display_name": "T1095 - Non-Application Layer Protocol"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1518",
              "name": "Software Discovery",
              "display_name": "T1518 - Software Discovery"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 304,
            "FileHash-SHA1": 239,
            "FileHash-SHA256": 499,
            "IPv4": 95,
            "hostname": 326,
            "URL": 275,
            "domain": 84,
            "email": 3
          },
          "indicator_count": 1825,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 66,
          "modified_text": "23 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "https://vtbehaviour.commondatastorage.googleapis.com/561f94715c481c0e616cf1907d86e522afe9186f8365ab3a35d7872b2653580b_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1778223081&Signature=Hm63tZKeRZujdUn11Hi%2BwTAevMctFRDZDQ9GnFQsB%2BN1N%2FxQN3pkPwwuAScaiiliHBcXgCSUXI3gph1Bgmh%2BdMALu8FKmvwYRvuq4xYlXAZvyQFUN1xr4%2FxkpnRhr0tiskf4kWXDZvlBCW1H1K3mKSkT6vkjiEn6xDLVUO1Eo8ESJDnnsTshk3vIiXlAhodWtrJS8RTgA%2BjhGCgU3IruiA3O5nxWwIJSLMrM7pRI1zgAy%2BH0",
        "https://vtbehaviour.commondatastorage.googleapis.com/9d9b74f13b0001184ea51257e446bd317e5180e0ed856e7dfb7d92d1fb7c9df9_VirusTotal%20Jujubox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1778223336&Signature=avokLSiN2%2B14P94v4u5P%2FljfsWv2nqNJdQpMmRl88Esart7da%2BE4E1d0d7MXavOLWEHHt09QYchkV3iMo3Ia%2Fr49jeO5ZALtnuDrJMAvU6Js5MUrkqPT0R9LZ9b4vcG3hrHPF%2Fu9EiVhYII3bhmK5CjnHDF44L4qtE8vVkw03lOx1XpgUhdTK6rRzXALQ1tqKrDE5LUh7S9giv0VZz7aqV%2B9Ch%2Fb%2BGPU3mis2wnh",
        "https://vtbehaviour.commondatastorage.googleapis.com/9d9b74f13b0001184ea51257e446bd317e5180e0ed856e7dfb7d92d1fb7c9df9_Zenbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1778223386&Signature=0oCtLpyEmobttCQJza34xagBptN0LmmC7kxt51fgm7nEEyRcpEzZPo%2F9OF9ZpJJs%2FJTtDEqFP8FURlT79ioFjN8T2fu7lRrL2P5%2FDzcAfYlZJvnOu%2F4fFq%2FdqmL%2F6MWyaEcrew5K1Cn3RbD7cjqTe4M82GVyxYd9lWiO0ZQ2VTe9%2FLUCyFptCg7zsZk2cHhjDYTSW36tQUoEksDtMNaANFYM2mSxRPOXZ5XRzzF6WOvQjsjwrIqay2dk",
        "https://vtbehaviour.commondatastorage.googleapis.com/561f94715c481c0e616cf1907d86e522afe9186f8365ab3a35d7872b2653580b_VirusTotal%20Jujubox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1778223201&Signature=UbPDmnyT2j%2B5gbsHnwxLwuxti6r6ukPXUh%2BIz3I0VhnZa%2FV0coDJPx%2FvqkOMdu%2F8UuONZpVTl28tlerH%2FsZNK6YpFPgUmrFXYJx6c%2B6W7%2FC1yC8TeC5lN4%2F0h19KcjvCdFGNFgLhigH62wxU2GkmZT5jz8ISZhkAzkReVhdaZA7vYQnLQZvpvEQGScnuZc0PZSANsAvfN2lyqBDH%2FpGFc%2BDpfNGnnFYsjJ"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 0
        },
        "other": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 4204
        }
      }
    },
    "false_positive": [],
    "alexa": "http://www.alexa.com/siteinfo/gotocfr.com",
    "whois": "http://whois.domaintools.com/gotocfr.com",
    "domain": "gotocfr.com",
    "hostname": "Unavailable"
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 3,
  "pulses": [
    {
      "id": "69fdc02a184d8d0f3370b069",
      "name": "ripe.arin.enom.cpanel.cpcalendar.iana.networksolutions.02050.webdisk.webmail.",
      "description": "interesting. 2000-06-05T14:09:35Z\nDNSSEC: unsigned\nDomain Name: GOTOCFR.COM\nDomain Status:  https://icann.org/epp#clientTransferProhibited\nName Server: NS37.WORLDNIC.COM\nName Server: NS38.WORLDNIC.COM\nRegistrant City: 3f16518cc21288a8\nRegistrant Country: US\nRegistrant Email: a07a5df6ca9e975bs@gotocfr.com\nRegistrant Fax Ext: 3432650ec337c945\nRegistrant Fax: b3c25287c0f8ed51\nRegistrant Name: 3432650ec337c945\nRegistrant Organization: 3432650ec337c945\nRegistrant Phone Ext: 3432650ec337c945\nRegistrant Phone: a8108981ed146828\nRegistrant Postal Code: 22ba98fa33e9a7d1\nRegistrant State/Province: 2f0a6dc5401e8a9a\nRegistrant Street: c4d735c293d4e708\nRegistrar Abuse Contact Email: domain.operations@web.com\nRegistrar Abuse Contact Phone: +1.8777228662\nRegistrar IANA ID: 2\nRegistrar URL: http://networksolutions.com\nRegistrar WHOIS Server: whois.networksolutions.com\nRegistrar: Network Solutions, LLC\nRegistry Domain ID: 28566423_DOMAIN_COM-VRSN\nUpdated Date: 2026-04-06T06:20:14Z",
      "modified": "2026-05-09T07:30:09.404000",
      "created": "2026-05-08T10:51:22.795000",
      "tags": [
        "msie",
        "chrome",
        "passive dns",
        "date",
        "urls",
        "fabricating and",
        "type",
        "media type",
        "gmt content",
        "certificate",
        "title",
        "body",
        "encrypt",
        "graph summary",
        "algorithm",
        "key identifier",
        "x509v3 subject",
        "v3 serial",
        "number",
        "cus olet",
        "encrypt cnr12",
        "validity",
        "subject public",
        "key info",
        "code",
        "email",
        "server",
        "admin country",
        "registrant name",
        "and repair",
        "expiration date",
        "registry domain",
        "registrar iana",
        "creation date",
        "admin city",
        "key algorithm",
        "registrar abuse",
        "dnssec",
        "domain name",
        "status",
        "city",
        "us registrant",
        "registrant fax",
        "marshfield ssl",
        "common name",
        "issued",
        "supporte",
        "charter",
        "llc united",
        "statesunited",
        "new london",
        "i20100 may",
        "diesel",
        "ripe ncc",
        "ripe network",
        "abuse contact",
        "orgid",
        "orgtechhandle",
        "address",
        "orgabuseref",
        "postalcode",
        "ripe",
        "cidr",
        "ripe database",
        "orgabuseemail",
        "orgabusehandle",
        "nethandle",
        "thumbprint",
        "handle",
        "address range",
        "network name",
        "allocation type",
        "allocated pa",
        "whois server",
        "organization",
        "please note",
        "ip address",
        "google",
        "redacted for",
        "privacy admin",
        "privacy",
        "privacy tech",
        "street",
        "stateprovince",
        "form",
        "tech"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA1": 45,
        "IPv4": 32,
        "URL": 932,
        "domain": 51,
        "email": 9,
        "hostname": 186,
        "FileHash-SHA256": 43,
        "FileHash-MD5": 3,
        "CIDR": 3
      },
      "indicator_count": 1304,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 67,
      "modified_text": "23 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "69fdc02bea1e4ec923b01688",
      "name": "ripe.arin.enom.cpanel.cpcalendar.iana.networksolutions.02050.webdisk.webmail.",
      "description": "interesting. 2000-06-05T14:09:35Z\nDNSSEC: unsigned\nDomain Name: GOTOCFR.COM\nDomain Status:  https://icann.org/epp#clientTransferProhibited\nName Server: NS37.WORLDNIC.COM\nName Server: NS38.WORLDNIC.COM\nRegistrant City: 3f16518cc21288a8\nRegistrant Country: US\nRegistrant Email: a07a5df6ca9e975bs@gotocfr.com\nRegistrant Fax Ext: 3432650ec337c945\nRegistrant Fax: b3c25287c0f8ed51\nRegistrant Name: 3432650ec337c945\nRegistrant Organization: 3432650ec337c945\nRegistrant Phone Ext: 3432650ec337c945\nRegistrant Phone: a8108981ed146828\nRegistrant Postal Code: 22ba98fa33e9a7d1\nRegistrant State/Province: 2f0a6dc5401e8a9a\nRegistrant Street: c4d735c293d4e708\nRegistrar Abuse Contact Email: domain.operations@web.com\nRegistrar Abuse Contact Phone: +1.8777228662\nRegistrar IANA ID: 2\nRegistrar URL: http://networksolutions.com\nRegistrar WHOIS Server: whois.networksolutions.com\nRegistrar: Network Solutions, LLC\nRegistry Domain ID: 28566423_DOMAIN_COM-VRSN\nUpdated Date: 2026-04-06T06:20:14Z",
      "modified": "2026-05-09T03:07:39.308000",
      "created": "2026-05-08T10:51:23.184000",
      "tags": [
        "msie",
        "chrome",
        "passive dns",
        "date",
        "urls",
        "fabricating and",
        "type",
        "media type",
        "gmt content",
        "certificate",
        "title",
        "body",
        "encrypt",
        "graph summary",
        "algorithm",
        "key identifier",
        "x509v3 subject",
        "v3 serial",
        "number",
        "cus olet",
        "encrypt cnr12",
        "validity",
        "subject public",
        "key info",
        "code",
        "email",
        "server",
        "admin country",
        "registrant name",
        "and repair",
        "expiration date",
        "registry domain",
        "registrar iana",
        "creation date",
        "admin city",
        "key algorithm",
        "registrar abuse",
        "dnssec",
        "domain name",
        "status",
        "city",
        "us registrant",
        "registrant fax",
        "marshfield ssl",
        "common name",
        "issued",
        "supporte",
        "charter",
        "llc united",
        "statesunited",
        "new london",
        "i20100 may",
        "diesel",
        "ripe ncc",
        "ripe network",
        "abuse contact",
        "orgid",
        "orgtechhandle",
        "address",
        "orgabuseref",
        "postalcode",
        "ripe",
        "cidr",
        "ripe database",
        "orgabuseemail",
        "orgabusehandle",
        "nethandle",
        "thumbprint",
        "handle",
        "address range",
        "network name",
        "allocation type",
        "allocated pa",
        "whois server",
        "organization",
        "please note",
        "ip address",
        "google",
        "redacted for",
        "privacy admin",
        "privacy",
        "privacy tech",
        "street",
        "stateprovince",
        "form",
        "tech"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA1": 236,
        "IPv4": 315,
        "URL": 932,
        "domain": 1040,
        "email": 65,
        "hostname": 1049,
        "FileHash-SHA256": 960,
        "FileHash-MD5": 301,
        "CIDR": 39,
        "IPv6": 68,
        "CVE": 890,
        "SSLCertFingerprint": 16
      },
      "indicator_count": 5911,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 66,
      "modified_text": "23 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "69fd8916c718cee78b1d08d1",
      "name": "CAPE Sandbox - Borland Delphi + added other malic win [exe]",
      "description": "[Malware Analysis System Evasion (MZP) report has been generated by Yara, a community-based security firm.] Delphi and other win[exe] all malicious- sandboxed runs only.",
      "modified": "2026-05-08T10:32:41.135000",
      "created": "2026-05-08T06:56:22.767000",
      "tags": [
        "url http",
        "ipv4",
        "strong",
        "library",
        "address virtual",
        "cname",
        "size",
        "file type",
        "mwdb",
        "bazaar",
        "sha3384",
        "ssdeep",
        "accept",
        "shutdown",
        "sandbox",
        "stack",
        "windows sandbox",
        "clear filters",
        "calls process",
        "pe file",
        "sample",
        "performs dns",
        "yara",
        "https",
        "urls",
        "mitre attack",
        "network info",
        "processes extra",
        "command",
        "malicious",
        "delphi",
        "defense evasion",
        "next"
      ],
      "references": [
        "https://vtbehaviour.commondatastorage.googleapis.com/561f94715c481c0e616cf1907d86e522afe9186f8365ab3a35d7872b2653580b_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1778223081&Signature=Hm63tZKeRZujdUn11Hi%2BwTAevMctFRDZDQ9GnFQsB%2BN1N%2FxQN3pkPwwuAScaiiliHBcXgCSUXI3gph1Bgmh%2BdMALu8FKmvwYRvuq4xYlXAZvyQFUN1xr4%2FxkpnRhr0tiskf4kWXDZvlBCW1H1K3mKSkT6vkjiEn6xDLVUO1Eo8ESJDnnsTshk3vIiXlAhodWtrJS8RTgA%2BjhGCgU3IruiA3O5nxWwIJSLMrM7pRI1zgAy%2BH0",
        "https://vtbehaviour.commondatastorage.googleapis.com/561f94715c481c0e616cf1907d86e522afe9186f8365ab3a35d7872b2653580b_VirusTotal%20Jujubox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1778223201&Signature=UbPDmnyT2j%2B5gbsHnwxLwuxti6r6ukPXUh%2BIz3I0VhnZa%2FV0coDJPx%2FvqkOMdu%2F8UuONZpVTl28tlerH%2FsZNK6YpFPgUmrFXYJx6c%2B6W7%2FC1yC8TeC5lN4%2F0h19KcjvCdFGNFgLhigH62wxU2GkmZT5jz8ISZhkAzkReVhdaZA7vYQnLQZvpvEQGScnuZc0PZSANsAvfN2lyqBDH%2FpGFc%2BDpfNGnnFYsjJ",
        "https://vtbehaviour.commondatastorage.googleapis.com/9d9b74f13b0001184ea51257e446bd317e5180e0ed856e7dfb7d92d1fb7c9df9_VirusTotal%20Jujubox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1778223336&Signature=avokLSiN2%2B14P94v4u5P%2FljfsWv2nqNJdQpMmRl88Esart7da%2BE4E1d0d7MXavOLWEHHt09QYchkV3iMo3Ia%2Fr49jeO5ZALtnuDrJMAvU6Js5MUrkqPT0R9LZ9b4vcG3hrHPF%2Fu9EiVhYII3bhmK5CjnHDF44L4qtE8vVkw03lOx1XpgUhdTK6rRzXALQ1tqKrDE5LUh7S9giv0VZz7aqV%2B9Ch%2Fb%2BGPU3mis2wnh",
        "https://vtbehaviour.commondatastorage.googleapis.com/9d9b74f13b0001184ea51257e446bd317e5180e0ed856e7dfb7d92d1fb7c9df9_Zenbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1778223386&Signature=0oCtLpyEmobttCQJza34xagBptN0LmmC7kxt51fgm7nEEyRcpEzZPo%2F9OF9ZpJJs%2FJTtDEqFP8FURlT79ioFjN8T2fu7lRrL2P5%2FDzcAfYlZJvnOu%2F4fFq%2FdqmL%2F6MWyaEcrew5K1Cn3RbD7cjqTe4M82GVyxYd9lWiO0ZQ2VTe9%2FLUCyFptCg7zsZk2cHhjDYTSW36tQUoEksDtMNaANFYM2mSxRPOXZ5XRzzF6WOvQjsjwrIqay2dk"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1083",
          "name": "File and Directory Discovery",
          "display_name": "T1083 - File and Directory Discovery"
        },
        {
          "id": "T1112",
          "name": "Modify Registry",
          "display_name": "T1112 - Modify Registry"
        },
        {
          "id": "T1553",
          "name": "Subvert Trust Controls",
          "display_name": "T1553 - Subvert Trust Controls"
        },
        {
          "id": "T1574",
          "name": "Hijack Execution Flow",
          "display_name": "T1574 - Hijack Execution Flow"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1095",
          "name": "Non-Application Layer Protocol",
          "display_name": "T1095 - Non-Application Layer Protocol"
        },
        {
          "id": "T1497",
          "name": "Virtualization/Sandbox Evasion",
          "display_name": "T1497 - Virtualization/Sandbox Evasion"
        },
        {
          "id": "T1518",
          "name": "Software Discovery",
          "display_name": "T1518 - Software Discovery"
        },
        {
          "id": "T1573",
          "name": "Encrypted Channel",
          "display_name": "T1573 - Encrypted Channel"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 1,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 304,
        "FileHash-SHA1": 239,
        "FileHash-SHA256": 499,
        "IPv4": 95,
        "hostname": 326,
        "URL": 275,
        "domain": 84,
        "email": 3
      },
      "indicator_count": 1825,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 66,
      "modified_text": "23 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "https://gotocfr.com/cfrcareers/",
    "type": "URL"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "https://gotocfr.com/cfrcareers/",
    "type": "URL",
    "found": false,
    "verdict": "clean",
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780306853.809067
}