{
  "type": "URL",
  "indicator": "https://i.dengi.ua",
  "general": {
    "sections": [
      "general",
      "url_list",
      "http_scans",
      "screenshot"
    ],
    "indicator": "https://i.dengi.ua",
    "type": "url",
    "type_title": "URL",
    "validation": [],
    "base_indicator": {
      "id": 2900245251,
      "indicator": "https://i.dengi.ua",
      "type": "URL",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 6,
      "pulses": [
        {
          "id": "65708e7ca78fb9ed8bda43d0",
          "name": "Part 2 of the small sub section post - This a sample of the infrastructure on the perimeter of each of those controlled websrv and devuces on home lans",
          "description": "",
          "modified": "2023-12-06T15:08:44.795000",
          "created": "2023-12-06T15:08:44.795000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "CVE": 19,
            "hostname": 404,
            "FileHash-SHA256": 1484,
            "FileHash-SHA1": 1,
            "URL": 1141,
            "domain": 202,
            "FileHash-MD5": 1
          },
          "indicator_count": 3252,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 110,
          "modified_text": "907 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "65708e7a2404c20175ed6396",
          "name": "small subsection of compromised consumer devices being abused constantly starting at ed fraud ending in ransomewwre",
          "description": "",
          "modified": "2023-12-06T15:08:40.868000",
          "created": "2023-12-06T15:08:40.868000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 152,
            "hostname": 195,
            "URL": 184,
            "domain": 10
          },
          "indicator_count": 541,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "907 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "65708e76213725cde244c32c",
          "name": "report.if.ua  212.24.97.24",
          "description": "",
          "modified": "2023-12-06T15:08:38.420000",
          "created": "2023-12-06T15:08:38.420000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 259,
            "hostname": 81,
            "URL": 217,
            "domain": 13,
            "FileHash-MD5": 1
          },
          "indicator_count": 571,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "907 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6286d559b2765afe219b32ef",
          "name": "report.if.ua  212.24.97.24",
          "description": "",
          "modified": "2022-06-19T00:05:22.053000",
          "created": "2022-05-19T23:40:09.210000",
          "tags": [
            "show",
            "download go",
            "full url",
            "reverse dns",
            "general check",
            "resource",
            "security tls",
            "get h2",
            "protocol h2",
            "software",
            "main",
            "ukraine",
            "win64",
            "212.24.97.24",
            "report.if.ua"
          ],
          "references": [
            "report.if.ua  212.24.97.24"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 3,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "dorkingbeauty1",
            "id": "80137",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 259,
            "hostname": 81,
            "domain": 13,
            "URL": 218,
            "FileHash-MD5": 1
          },
          "indicator_count": 572,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 392,
          "modified_text": "1442 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6286dcfd57ce395a51a842f1",
          "name": "small subsection of compromised consumer devices being abused constantly starting at ed fraud ending in ransomewwre",
          "description": "Firmware breaches via useand iso images of fritzbox routers. Used for management of a group of hone/mobile devices around the world via web servers set up on home lans without the knowledge or permission of consumer owner. this then allows the threats actors control all. I have absolutely witnessed with my own eyes now so much of this filth going round on a constant loop with many investigating due to infection. many of those infected are  security researchers other cyber related peeps, some very talented hackers have yet to solve this now epedemic global problem. It is a highly evasive and obsfucated bluetooth worm spreading via a very selective path",
          "modified": "2022-06-19T00:05:22.053000",
          "created": "2022-05-20T00:12:45.905000",
          "tags": [
            "germany unknown",
            "canada unknown",
            "united",
            "as3320 deutsche",
            "united kingdom",
            "spain unknown",
            "as6327 shaw",
            "as577 bell",
            "as8881",
            "as133481 ais"
          ],
          "references": [
            "remoted.com",
            "myfritz.net",
            "consumers graded and grouped in terms of personality and character traits based on certain aspects of  \"Usefulness\""
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 3,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "dorkingbeauty1",
            "id": "80137",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 152,
            "hostname": 195,
            "URL": 184,
            "domain": 10
          },
          "indicator_count": 541,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 392,
          "modified_text": "1442 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6286f196943a5ae10bc4e72c",
          "name": "Part 2 of the small sub section post - This a sample of the infrastructure on the perimeter of each of those controlled websrv and devuces on home lans",
          "description": "",
          "modified": "2022-06-19T00:05:22.053000",
          "created": "2022-05-20T01:40:38.150000",
          "tags": [],
          "references": [
            "layer 2"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 8,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "dorkingbeauty1",
            "id": "80137",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 404,
            "FileHash-SHA256": 1484,
            "URL": 1141,
            "domain": 202,
            "CVE": 19,
            "FileHash-MD5": 1,
            "FileHash-SHA1": 1
          },
          "indicator_count": 3252,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 395,
          "modified_text": "1442 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "report.if.ua  212.24.97.24",
        "remoted.com",
        "layer 2",
        "myfritz.net",
        "consumers graded and grouped in terms of personality and character traits based on certain aspects of  \"Usefulness\""
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 0
        },
        "other": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 3936
        }
      }
    },
    "false_positive": [],
    "alexa": "http://www.alexa.com/siteinfo/dengi.ua",
    "whois": "http://whois.domaintools.com/dengi.ua",
    "domain": "dengi.ua",
    "hostname": "i.dengi.ua"
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 6,
  "pulses": [
    {
      "id": "65708e7ca78fb9ed8bda43d0",
      "name": "Part 2 of the small sub section post - This a sample of the infrastructure on the perimeter of each of those controlled websrv and devuces on home lans",
      "description": "",
      "modified": "2023-12-06T15:08:44.795000",
      "created": "2023-12-06T15:08:44.795000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "CVE": 19,
        "hostname": 404,
        "FileHash-SHA256": 1484,
        "FileHash-SHA1": 1,
        "URL": 1141,
        "domain": 202,
        "FileHash-MD5": 1
      },
      "indicator_count": 3252,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 110,
      "modified_text": "907 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "65708e7a2404c20175ed6396",
      "name": "small subsection of compromised consumer devices being abused constantly starting at ed fraud ending in ransomewwre",
      "description": "",
      "modified": "2023-12-06T15:08:40.868000",
      "created": "2023-12-06T15:08:40.868000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 152,
        "hostname": 195,
        "URL": 184,
        "domain": 10
      },
      "indicator_count": 541,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "907 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "65708e76213725cde244c32c",
      "name": "report.if.ua  212.24.97.24",
      "description": "",
      "modified": "2023-12-06T15:08:38.420000",
      "created": "2023-12-06T15:08:38.420000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 259,
        "hostname": 81,
        "URL": 217,
        "domain": 13,
        "FileHash-MD5": 1
      },
      "indicator_count": 571,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "907 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6286d559b2765afe219b32ef",
      "name": "report.if.ua  212.24.97.24",
      "description": "",
      "modified": "2022-06-19T00:05:22.053000",
      "created": "2022-05-19T23:40:09.210000",
      "tags": [
        "show",
        "download go",
        "full url",
        "reverse dns",
        "general check",
        "resource",
        "security tls",
        "get h2",
        "protocol h2",
        "software",
        "main",
        "ukraine",
        "win64",
        "212.24.97.24",
        "report.if.ua"
      ],
      "references": [
        "report.if.ua  212.24.97.24"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 3,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "dorkingbeauty1",
        "id": "80137",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 259,
        "hostname": 81,
        "domain": 13,
        "URL": 218,
        "FileHash-MD5": 1
      },
      "indicator_count": 572,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 392,
      "modified_text": "1442 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6286dcfd57ce395a51a842f1",
      "name": "small subsection of compromised consumer devices being abused constantly starting at ed fraud ending in ransomewwre",
      "description": "Firmware breaches via useand iso images of fritzbox routers. Used for management of a group of hone/mobile devices around the world via web servers set up on home lans without the knowledge or permission of consumer owner. this then allows the threats actors control all. I have absolutely witnessed with my own eyes now so much of this filth going round on a constant loop with many investigating due to infection. many of those infected are  security researchers other cyber related peeps, some very talented hackers have yet to solve this now epedemic global problem. It is a highly evasive and obsfucated bluetooth worm spreading via a very selective path",
      "modified": "2022-06-19T00:05:22.053000",
      "created": "2022-05-20T00:12:45.905000",
      "tags": [
        "germany unknown",
        "canada unknown",
        "united",
        "as3320 deutsche",
        "united kingdom",
        "spain unknown",
        "as6327 shaw",
        "as577 bell",
        "as8881",
        "as133481 ais"
      ],
      "references": [
        "remoted.com",
        "myfritz.net",
        "consumers graded and grouped in terms of personality and character traits based on certain aspects of  \"Usefulness\""
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 3,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "dorkingbeauty1",
        "id": "80137",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 152,
        "hostname": 195,
        "URL": 184,
        "domain": 10
      },
      "indicator_count": 541,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 392,
      "modified_text": "1442 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6286f196943a5ae10bc4e72c",
      "name": "Part 2 of the small sub section post - This a sample of the infrastructure on the perimeter of each of those controlled websrv and devuces on home lans",
      "description": "",
      "modified": "2022-06-19T00:05:22.053000",
      "created": "2022-05-20T01:40:38.150000",
      "tags": [],
      "references": [
        "layer 2"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 8,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "dorkingbeauty1",
        "id": "80137",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 404,
        "FileHash-SHA256": 1484,
        "URL": 1141,
        "domain": 202,
        "CVE": 19,
        "FileHash-MD5": 1,
        "FileHash-SHA1": 1
      },
      "indicator_count": 3252,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 395,
      "modified_text": "1442 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "https://i.dengi.ua",
    "type": "URL"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "https://i.dengi.ua",
    "type": "URL",
    "found": false,
    "verdict": "clean",
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780266024.8413737
}