{
  "type": "URL",
  "indicator": "https://hisxdep.ddns.ms",
  "general": {
    "sections": [
      "general",
      "url_list",
      "http_scans",
      "screenshot"
    ],
    "indicator": "https://hisxdep.ddns.ms",
    "type": "url",
    "type_title": "URL",
    "validation": [],
    "base_indicator": {
      "id": 3600812020,
      "indicator": "https://hisxdep.ddns.ms",
      "type": "URL",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 5,
      "pulses": [
        {
          "id": "65cdac3ba9d7f42c0ed9c46d",
          "name": "Emotet | POD 18447 for Cox.xls | M. Brian Sabey \u2022 HallRender \u2022 Denver",
          "description": "Researchers have identified the source of a virus that has spread around the world and is believed to be linked to a network called \"thedevilsback\" in the United States, which is currently under the control of Amazon.com.",
          "modified": "2024-03-16T05:00:42.461000",
          "created": "2024-02-15T06:16:27.967000",
          "tags": [
            "dns resolutions",
            "ip traffic",
            "hashes",
            "file type",
            "name file",
            "ip detections",
            "country",
            "search",
            "zbot type",
            "indicator role",
            "active related",
            "filehashsha256",
            "entries",
            "brian sabey",
            "ssl certificate",
            "contacted",
            "resolutions",
            "communicating",
            "referrer",
            "emotet emotet",
            "malware emotet",
            "http",
            "emotet",
            "whois record",
            "contacted urls",
            "bundled",
            "threat roundup",
            "historical ssl",
            "execution",
            "attack",
            "probe",
            "service",
            "startpage",
            "core",
            "hiddentear",
            "guid",
            "ransomexx",
            "azorult",
            "lightning",
            "ursnif",
            "agent tesla",
            "quasar",
            "trickbot",
            "project",
            "remcos",
            "evilnum",
            "asyncrat",
            "matanbuchus",
            "cobalt strike",
            "metro",
            "intel",
            "ms windows",
            "pe32",
            "show",
            "trojan",
            "copy",
            "windows",
            "read",
            "write",
            "february",
            "delphi",
            "win32",
            "ransomware",
            "united",
            "unknown",
            "as44273 host",
            "moved",
            "passive dns",
            "gmt content",
            "scan endpoints",
            "all octoseek",
            "pulse pulses",
            "urls",
            "body",
            "date",
            "encrypt",
            "trojandropper",
            "ipv4",
            "virtool",
            "junkpoly",
            "worm",
            "msie",
            "chrome",
            "status",
            "creation date",
            "servers",
            "record value",
            "javascript",
            "please",
            "june",
            "august",
            "malware",
            "whois whois",
            "njrat",
            "ransomware",
            "siblings domain",
            "tulach",
            "hallrender",
            "cyber espionage",
            "cyberstalking"
          ],
          "references": [
            "POD 18447 for Cox.xls",
            "https://apps.apple.com/us/app/gambinos-pizza/id1500338496",
            "https://www.hallrender.com/attorney/brian-sabey/ \u2022 www.hallrender.com \u2022 https://www.hallrender.com/wp-json/oembed",
            "1.download.windowsupdate.com [HiddenTear]",
            "https://tulach.cc/ \u2022 tulach.cc \u2022 thedevilsback.golf \u2022 nextcloud.tulach.cc  [phishing]",
            "https://gronthoghor.com/xoe/qbot.zip \u2022",
            "Win32:JunkPoly - Worm:Win32/Bagle.gen!C https://www.anyxxxtube.net/search-porn/tsara-brashears/ \u2022 www.metrobyt-mobile.com"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Trojan:Win32/Antavmu.D",
              "display_name": "Trojan:Win32/Antavmu.D",
              "target": "/malware/Trojan:Win32/Antavmu.D"
            },
            {
              "id": "HiddenTear",
              "display_name": "HiddenTear",
              "target": null
            },
            {
              "id": "Emotet",
              "display_name": "Emotet",
              "target": null
            },
            {
              "id": "ZBot",
              "display_name": "ZBot",
              "target": null
            },
            {
              "id": "QBot",
              "display_name": "QBot",
              "target": null
            },
            {
              "id": "Delphi",
              "display_name": "Delphi",
              "target": null
            }
          ],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 58,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 5573,
            "hostname": 1806,
            "FileHash-SHA256": 5748,
            "domain": 1677,
            "FileHash-MD5": 349,
            "FileHash-SHA1": 348,
            "CVE": 3,
            "email": 3
          },
          "indicator_count": 15507,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 222,
          "modified_text": "808 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "65cdac46a01234da94a42565",
          "name": "Emotet | POD 18447 for Cox.xls | M. Brian Sabey \u2022 HallRender \u2022 Denver",
          "description": "Researchers have identified the source of a virus that has spread around the world and is believed to be linked to a network called \"thedevilsback\" in the United States, which is currently under the control of Amazon.com.",
          "modified": "2024-03-16T05:00:42.461000",
          "created": "2024-02-15T06:16:38.290000",
          "tags": [
            "dns resolutions",
            "ip traffic",
            "hashes",
            "file type",
            "name file",
            "ip detections",
            "country",
            "search",
            "zbot type",
            "indicator role",
            "active related",
            "filehashsha256",
            "entries",
            "brian sabey",
            "ssl certificate",
            "contacted",
            "resolutions",
            "communicating",
            "referrer",
            "emotet emotet",
            "malware emotet",
            "http",
            "emotet",
            "whois record",
            "contacted urls",
            "bundled",
            "threat roundup",
            "historical ssl",
            "execution",
            "attack",
            "probe",
            "service",
            "startpage",
            "core",
            "hiddentear",
            "guid",
            "ransomexx",
            "azorult",
            "lightning",
            "ursnif",
            "agent tesla",
            "quasar",
            "trickbot",
            "project",
            "remcos",
            "evilnum",
            "asyncrat",
            "matanbuchus",
            "cobalt strike",
            "metro",
            "intel",
            "ms windows",
            "pe32",
            "show",
            "trojan",
            "copy",
            "windows",
            "read",
            "write",
            "february",
            "delphi",
            "win32",
            "ransomware",
            "united",
            "unknown",
            "as44273 host",
            "moved",
            "passive dns",
            "gmt content",
            "scan endpoints",
            "all octoseek",
            "pulse pulses",
            "urls",
            "body",
            "date",
            "encrypt",
            "trojandropper",
            "ipv4",
            "virtool",
            "junkpoly",
            "worm",
            "msie",
            "chrome",
            "status",
            "creation date",
            "servers",
            "record value",
            "javascript",
            "please",
            "june",
            "august",
            "malware",
            "whois whois",
            "njrat",
            "ransomware",
            "siblings domain",
            "tulach",
            "hallrender",
            "cyber espionage",
            "cyberstalking"
          ],
          "references": [
            "POD 18447 for Cox.xls",
            "https://apps.apple.com/us/app/gambinos-pizza/id1500338496",
            "https://www.hallrender.com/attorney/brian-sabey/ \u2022 www.hallrender.com \u2022 https://www.hallrender.com/wp-json/oembed",
            "1.download.windowsupdate.com [HiddenTear]",
            "https://tulach.cc/ \u2022 tulach.cc \u2022 thedevilsback.golf \u2022 nextcloud.tulach.cc  [phishing]",
            "https://gronthoghor.com/xoe/qbot.zip \u2022",
            "Win32:JunkPoly - Worm:Win32/Bagle.gen!C https://www.anyxxxtube.net/search-porn/tsara-brashears/ \u2022 www.metrobyt-mobile.com"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Trojan:Win32/Antavmu.D",
              "display_name": "Trojan:Win32/Antavmu.D",
              "target": "/malware/Trojan:Win32/Antavmu.D"
            },
            {
              "id": "HiddenTear",
              "display_name": "HiddenTear",
              "target": null
            },
            {
              "id": "Emotet",
              "display_name": "Emotet",
              "target": null
            },
            {
              "id": "ZBot",
              "display_name": "ZBot",
              "target": null
            },
            {
              "id": "QBot",
              "display_name": "QBot",
              "target": null
            },
            {
              "id": "Delphi",
              "display_name": "Delphi",
              "target": null
            }
          ],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 60,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 1,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 5573,
            "hostname": 1806,
            "FileHash-SHA256": 5748,
            "domain": 1677,
            "FileHash-MD5": 349,
            "FileHash-SHA1": 348,
            "CVE": 3,
            "email": 3
          },
          "indicator_count": 15507,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 223,
          "modified_text": "808 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "63f16ce668c75c5ec1148e7b",
          "name": "http://vinyldevicepop.com",
          "description": "The Falcon Sandbox malware analysis service is available to download, view and download all the data on the Falcon website, including the full report on how to identify and identify the malware and tactics behind the attack.",
          "modified": "2023-03-21T00:02:57.765000",
          "created": "2023-02-19T00:27:18.058000",
          "tags": [
            "sandbox",
            "malware",
            "analysis",
            "online",
            "submit",
            "vxstream",
            "sample",
            "download",
            "trojan",
            "apt",
            "runtime data",
            "ansi",
            "localappdata",
            "unicode",
            "hash seen",
            "size",
            "runtime process",
            "sha256",
            "sha1",
            "temp",
            "entropy",
            "suspicious",
            "hybrid",
            "close",
            "click",
            "ransomware",
            "february",
            "general",
            "strings"
          ],
          "references": [
            "https://hybrid-analysis.com/sample/a575cf06662eb0972d9d0e5286382ca909ac3d4db893153ac13242e626304b1f/63f0cc25c94909360712d453"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1486",
              "name": "Data Encrypted for Impact",
              "display_name": "T1486 - Data Encrypted for Impact"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 12,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "callmeDoris",
            "id": "205385",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 98,
            "hostname": 38,
            "domain": 10,
            "FileHash-SHA256": 62,
            "FileHash-MD5": 50,
            "FileHash-SHA1": 49
          },
          "indicator_count": 307,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 90,
          "modified_text": "1169 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "63dc196ce1e419aca95e3a87",
          "name": "#039;http://147.75.3.myip.cloud.infn.it/&#039; TS=100/100 is xip.io",
          "description": "",
          "modified": "2023-03-04T00:03:25.234000",
          "created": "2023-02-02T20:13:32.980000",
          "tags": [
            "vxstream",
            "trojan",
            "apt",
            "runtime data",
            "ansi",
            "runtime process",
            "sha256",
            "unicode",
            "localappdata",
            "date",
            "entropy",
            "close",
            "click",
            "ransomware"
          ],
          "references": [
            "https://hybrid-analysis.com/sample/172ffc5c288f7a241eac43d0d98143d91bc45fb17fce1c0788b4caf462a124d1/63dbfcceab5f780bd5536d3c"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 10,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "callmeDoris",
            "id": "205385",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 98,
            "hostname": 41,
            "domain": 9,
            "FileHash-SHA256": 84,
            "FileHash-MD5": 61,
            "FileHash-SHA1": 60
          },
          "indicator_count": 353,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 90,
          "modified_text": "1186 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "63994429139dc965346ecad6",
          "name": "think of it like supply chain but using consumer infrastructure instead of corp data",
          "description": "[object Object",
          "modified": "2023-01-13T00:01:55.237000",
          "created": "2022-12-14T03:34:01.804000",
          "tags": [
            "sandbox",
            "malware",
            "analysis",
            "online",
            "submit",
            "vxstream",
            "sample",
            "download",
            "trojan",
            "apt",
            "runtime data",
            "ansi",
            "localappdata",
            "unicode",
            "hash seen",
            "size",
            "runtime process",
            "temp",
            "sha256",
            "sha1",
            "hybrid",
            "close",
            "click",
            "hosts",
            "ransomware",
            "general",
            "strings",
            "suspicious",
            "hybrid analysis",
            "api key",
            "vetting process",
            "please note",
            "please"
          ],
          "references": [
            "https://hybrid-analysis.com/sample/5e5db92f90d6ccdd7dc1eca0c1a9cd6b54493e873d07c90f72da6478ac5f24cb",
            "https://hybrid-analysis.com/sample/5e5db92f90d6ccdd7dc1eca0c1a9cd6b54493e873d07c90f72da6478ac5f24cb/6398ed7852c7e131d0022430"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 16,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "callmeDoris",
            "id": "205385",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 576,
            "hostname": 282,
            "domain": 51,
            "FileHash-SHA256": 85,
            "FileHash-MD5": 51,
            "FileHash-SHA1": 50,
            "email": 2
          },
          "indicator_count": 1097,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 90,
          "modified_text": "1236 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "https://hybrid-analysis.com/sample/5e5db92f90d6ccdd7dc1eca0c1a9cd6b54493e873d07c90f72da6478ac5f24cb",
        "https://hybrid-analysis.com/sample/a575cf06662eb0972d9d0e5286382ca909ac3d4db893153ac13242e626304b1f/63f0cc25c94909360712d453",
        "https://apps.apple.com/us/app/gambinos-pizza/id1500338496",
        "https://hybrid-analysis.com/sample/5e5db92f90d6ccdd7dc1eca0c1a9cd6b54493e873d07c90f72da6478ac5f24cb/6398ed7852c7e131d0022430",
        "https://tulach.cc/ \u2022 tulach.cc \u2022 thedevilsback.golf \u2022 nextcloud.tulach.cc  [phishing]",
        "POD 18447 for Cox.xls",
        "https://www.hallrender.com/attorney/brian-sabey/ \u2022 www.hallrender.com \u2022 https://www.hallrender.com/wp-json/oembed",
        "https://gronthoghor.com/xoe/qbot.zip \u2022",
        "1.download.windowsupdate.com [HiddenTear]",
        "Win32:JunkPoly - Worm:Win32/Bagle.gen!C https://www.anyxxxtube.net/search-porn/tsara-brashears/ \u2022 www.metrobyt-mobile.com",
        "https://hybrid-analysis.com/sample/172ffc5c288f7a241eac43d0d98143d91bc45fb17fce1c0788b4caf462a124d1/63dbfcceab5f780bd5536d3c"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 0
        },
        "other": {
          "adversary": [],
          "malware_families": [
            "Hiddentear",
            "Trojan:win32/antavmu.d",
            "Zbot",
            "Delphi",
            "Qbot",
            "Emotet"
          ],
          "industries": [],
          "unique_indicators": 17320
        }
      }
    },
    "false_positive": [],
    "alexa": "http://www.alexa.com/siteinfo/ddns.ms",
    "whois": "http://whois.domaintools.com/ddns.ms",
    "domain": "ddns.ms",
    "hostname": "hisxdep.ddns.ms"
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 5,
  "pulses": [
    {
      "id": "65cdac3ba9d7f42c0ed9c46d",
      "name": "Emotet | POD 18447 for Cox.xls | M. Brian Sabey \u2022 HallRender \u2022 Denver",
      "description": "Researchers have identified the source of a virus that has spread around the world and is believed to be linked to a network called \"thedevilsback\" in the United States, which is currently under the control of Amazon.com.",
      "modified": "2024-03-16T05:00:42.461000",
      "created": "2024-02-15T06:16:27.967000",
      "tags": [
        "dns resolutions",
        "ip traffic",
        "hashes",
        "file type",
        "name file",
        "ip detections",
        "country",
        "search",
        "zbot type",
        "indicator role",
        "active related",
        "filehashsha256",
        "entries",
        "brian sabey",
        "ssl certificate",
        "contacted",
        "resolutions",
        "communicating",
        "referrer",
        "emotet emotet",
        "malware emotet",
        "http",
        "emotet",
        "whois record",
        "contacted urls",
        "bundled",
        "threat roundup",
        "historical ssl",
        "execution",
        "attack",
        "probe",
        "service",
        "startpage",
        "core",
        "hiddentear",
        "guid",
        "ransomexx",
        "azorult",
        "lightning",
        "ursnif",
        "agent tesla",
        "quasar",
        "trickbot",
        "project",
        "remcos",
        "evilnum",
        "asyncrat",
        "matanbuchus",
        "cobalt strike",
        "metro",
        "intel",
        "ms windows",
        "pe32",
        "show",
        "trojan",
        "copy",
        "windows",
        "read",
        "write",
        "february",
        "delphi",
        "win32",
        "ransomware",
        "united",
        "unknown",
        "as44273 host",
        "moved",
        "passive dns",
        "gmt content",
        "scan endpoints",
        "all octoseek",
        "pulse pulses",
        "urls",
        "body",
        "date",
        "encrypt",
        "trojandropper",
        "ipv4",
        "virtool",
        "junkpoly",
        "worm",
        "msie",
        "chrome",
        "status",
        "creation date",
        "servers",
        "record value",
        "javascript",
        "please",
        "june",
        "august",
        "malware",
        "whois whois",
        "njrat",
        "ransomware",
        "siblings domain",
        "tulach",
        "hallrender",
        "cyber espionage",
        "cyberstalking"
      ],
      "references": [
        "POD 18447 for Cox.xls",
        "https://apps.apple.com/us/app/gambinos-pizza/id1500338496",
        "https://www.hallrender.com/attorney/brian-sabey/ \u2022 www.hallrender.com \u2022 https://www.hallrender.com/wp-json/oembed",
        "1.download.windowsupdate.com [HiddenTear]",
        "https://tulach.cc/ \u2022 tulach.cc \u2022 thedevilsback.golf \u2022 nextcloud.tulach.cc  [phishing]",
        "https://gronthoghor.com/xoe/qbot.zip \u2022",
        "Win32:JunkPoly - Worm:Win32/Bagle.gen!C https://www.anyxxxtube.net/search-porn/tsara-brashears/ \u2022 www.metrobyt-mobile.com"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Trojan:Win32/Antavmu.D",
          "display_name": "Trojan:Win32/Antavmu.D",
          "target": "/malware/Trojan:Win32/Antavmu.D"
        },
        {
          "id": "HiddenTear",
          "display_name": "HiddenTear",
          "target": null
        },
        {
          "id": "Emotet",
          "display_name": "Emotet",
          "target": null
        },
        {
          "id": "ZBot",
          "display_name": "ZBot",
          "target": null
        },
        {
          "id": "QBot",
          "display_name": "QBot",
          "target": null
        },
        {
          "id": "Delphi",
          "display_name": "Delphi",
          "target": null
        }
      ],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 58,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 5573,
        "hostname": 1806,
        "FileHash-SHA256": 5748,
        "domain": 1677,
        "FileHash-MD5": 349,
        "FileHash-SHA1": 348,
        "CVE": 3,
        "email": 3
      },
      "indicator_count": 15507,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 222,
      "modified_text": "808 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "65cdac46a01234da94a42565",
      "name": "Emotet | POD 18447 for Cox.xls | M. Brian Sabey \u2022 HallRender \u2022 Denver",
      "description": "Researchers have identified the source of a virus that has spread around the world and is believed to be linked to a network called \"thedevilsback\" in the United States, which is currently under the control of Amazon.com.",
      "modified": "2024-03-16T05:00:42.461000",
      "created": "2024-02-15T06:16:38.290000",
      "tags": [
        "dns resolutions",
        "ip traffic",
        "hashes",
        "file type",
        "name file",
        "ip detections",
        "country",
        "search",
        "zbot type",
        "indicator role",
        "active related",
        "filehashsha256",
        "entries",
        "brian sabey",
        "ssl certificate",
        "contacted",
        "resolutions",
        "communicating",
        "referrer",
        "emotet emotet",
        "malware emotet",
        "http",
        "emotet",
        "whois record",
        "contacted urls",
        "bundled",
        "threat roundup",
        "historical ssl",
        "execution",
        "attack",
        "probe",
        "service",
        "startpage",
        "core",
        "hiddentear",
        "guid",
        "ransomexx",
        "azorult",
        "lightning",
        "ursnif",
        "agent tesla",
        "quasar",
        "trickbot",
        "project",
        "remcos",
        "evilnum",
        "asyncrat",
        "matanbuchus",
        "cobalt strike",
        "metro",
        "intel",
        "ms windows",
        "pe32",
        "show",
        "trojan",
        "copy",
        "windows",
        "read",
        "write",
        "february",
        "delphi",
        "win32",
        "ransomware",
        "united",
        "unknown",
        "as44273 host",
        "moved",
        "passive dns",
        "gmt content",
        "scan endpoints",
        "all octoseek",
        "pulse pulses",
        "urls",
        "body",
        "date",
        "encrypt",
        "trojandropper",
        "ipv4",
        "virtool",
        "junkpoly",
        "worm",
        "msie",
        "chrome",
        "status",
        "creation date",
        "servers",
        "record value",
        "javascript",
        "please",
        "june",
        "august",
        "malware",
        "whois whois",
        "njrat",
        "ransomware",
        "siblings domain",
        "tulach",
        "hallrender",
        "cyber espionage",
        "cyberstalking"
      ],
      "references": [
        "POD 18447 for Cox.xls",
        "https://apps.apple.com/us/app/gambinos-pizza/id1500338496",
        "https://www.hallrender.com/attorney/brian-sabey/ \u2022 www.hallrender.com \u2022 https://www.hallrender.com/wp-json/oembed",
        "1.download.windowsupdate.com [HiddenTear]",
        "https://tulach.cc/ \u2022 tulach.cc \u2022 thedevilsback.golf \u2022 nextcloud.tulach.cc  [phishing]",
        "https://gronthoghor.com/xoe/qbot.zip \u2022",
        "Win32:JunkPoly - Worm:Win32/Bagle.gen!C https://www.anyxxxtube.net/search-porn/tsara-brashears/ \u2022 www.metrobyt-mobile.com"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Trojan:Win32/Antavmu.D",
          "display_name": "Trojan:Win32/Antavmu.D",
          "target": "/malware/Trojan:Win32/Antavmu.D"
        },
        {
          "id": "HiddenTear",
          "display_name": "HiddenTear",
          "target": null
        },
        {
          "id": "Emotet",
          "display_name": "Emotet",
          "target": null
        },
        {
          "id": "ZBot",
          "display_name": "ZBot",
          "target": null
        },
        {
          "id": "QBot",
          "display_name": "QBot",
          "target": null
        },
        {
          "id": "Delphi",
          "display_name": "Delphi",
          "target": null
        }
      ],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 60,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 1,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 5573,
        "hostname": 1806,
        "FileHash-SHA256": 5748,
        "domain": 1677,
        "FileHash-MD5": 349,
        "FileHash-SHA1": 348,
        "CVE": 3,
        "email": 3
      },
      "indicator_count": 15507,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 223,
      "modified_text": "808 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "63f16ce668c75c5ec1148e7b",
      "name": "http://vinyldevicepop.com",
      "description": "The Falcon Sandbox malware analysis service is available to download, view and download all the data on the Falcon website, including the full report on how to identify and identify the malware and tactics behind the attack.",
      "modified": "2023-03-21T00:02:57.765000",
      "created": "2023-02-19T00:27:18.058000",
      "tags": [
        "sandbox",
        "malware",
        "analysis",
        "online",
        "submit",
        "vxstream",
        "sample",
        "download",
        "trojan",
        "apt",
        "runtime data",
        "ansi",
        "localappdata",
        "unicode",
        "hash seen",
        "size",
        "runtime process",
        "sha256",
        "sha1",
        "temp",
        "entropy",
        "suspicious",
        "hybrid",
        "close",
        "click",
        "ransomware",
        "february",
        "general",
        "strings"
      ],
      "references": [
        "https://hybrid-analysis.com/sample/a575cf06662eb0972d9d0e5286382ca909ac3d4db893153ac13242e626304b1f/63f0cc25c94909360712d453"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1486",
          "name": "Data Encrypted for Impact",
          "display_name": "T1486 - Data Encrypted for Impact"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 12,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "callmeDoris",
        "id": "205385",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 98,
        "hostname": 38,
        "domain": 10,
        "FileHash-SHA256": 62,
        "FileHash-MD5": 50,
        "FileHash-SHA1": 49
      },
      "indicator_count": 307,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 90,
      "modified_text": "1169 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "63dc196ce1e419aca95e3a87",
      "name": "#039;http://147.75.3.myip.cloud.infn.it/&#039; TS=100/100 is xip.io",
      "description": "",
      "modified": "2023-03-04T00:03:25.234000",
      "created": "2023-02-02T20:13:32.980000",
      "tags": [
        "vxstream",
        "trojan",
        "apt",
        "runtime data",
        "ansi",
        "runtime process",
        "sha256",
        "unicode",
        "localappdata",
        "date",
        "entropy",
        "close",
        "click",
        "ransomware"
      ],
      "references": [
        "https://hybrid-analysis.com/sample/172ffc5c288f7a241eac43d0d98143d91bc45fb17fce1c0788b4caf462a124d1/63dbfcceab5f780bd5536d3c"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 10,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "callmeDoris",
        "id": "205385",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 98,
        "hostname": 41,
        "domain": 9,
        "FileHash-SHA256": 84,
        "FileHash-MD5": 61,
        "FileHash-SHA1": 60
      },
      "indicator_count": 353,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 90,
      "modified_text": "1186 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "63994429139dc965346ecad6",
      "name": "think of it like supply chain but using consumer infrastructure instead of corp data",
      "description": "[object Object",
      "modified": "2023-01-13T00:01:55.237000",
      "created": "2022-12-14T03:34:01.804000",
      "tags": [
        "sandbox",
        "malware",
        "analysis",
        "online",
        "submit",
        "vxstream",
        "sample",
        "download",
        "trojan",
        "apt",
        "runtime data",
        "ansi",
        "localappdata",
        "unicode",
        "hash seen",
        "size",
        "runtime process",
        "temp",
        "sha256",
        "sha1",
        "hybrid",
        "close",
        "click",
        "hosts",
        "ransomware",
        "general",
        "strings",
        "suspicious",
        "hybrid analysis",
        "api key",
        "vetting process",
        "please note",
        "please"
      ],
      "references": [
        "https://hybrid-analysis.com/sample/5e5db92f90d6ccdd7dc1eca0c1a9cd6b54493e873d07c90f72da6478ac5f24cb",
        "https://hybrid-analysis.com/sample/5e5db92f90d6ccdd7dc1eca0c1a9cd6b54493e873d07c90f72da6478ac5f24cb/6398ed7852c7e131d0022430"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 16,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "callmeDoris",
        "id": "205385",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 576,
        "hostname": 282,
        "domain": 51,
        "FileHash-SHA256": 85,
        "FileHash-MD5": 51,
        "FileHash-SHA1": 50,
        "email": 2
      },
      "indicator_count": 1097,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 90,
      "modified_text": "1236 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "https://hisxdep.ddns.ms",
    "type": "URL"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "https://hisxdep.ddns.ms",
    "type": "URL",
    "found": false,
    "verdict": "clean",
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780415065.4444678
}