{
  "type": "URL",
  "indicator": "https://img2.icson.com",
  "general": {
    "sections": [
      "general",
      "url_list",
      "http_scans",
      "screenshot"
    ],
    "indicator": "https://img2.icson.com",
    "type": "url",
    "type_title": "URL",
    "validation": [],
    "base_indicator": {
      "id": 2914911606,
      "indicator": "https://img2.icson.com",
      "type": "URL",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 7,
      "pulses": [
        {
          "id": "66ce3eb4b4f1fc9eafb4b572",
          "name": "DDoS:Linux/Lightaidra | Mirai Botnet on US a State Computer",
          "description": "*Mirai Botnet on Colorado State computer. Im starting to wonder if potential problem cases are diverted to a botnet.\n1. Overlaps with a Colorado victim. Similar issues. I Recently became a senior in expensive Colorado, never compensated for workers compensation injury exacerbated when suddenly tossed a 60 lb weighted ball under care. Denied diagnoses of severe injury after toss. Complained, case closed, lawyers denied case after accepting case. Referred to JeffCo seeking assisted living resources. Was sent various packets with a variety of phone numbers, email addresses, etc. She keeps speaking to same man no matter what option chosen. Denied workforce training due to severity of injuries, No SSI or SSDI until years later. \n2. I can't pulse half of what I've researched without using multiple resources. No more 'contacted' made when new serious issues found. Pulses being modified. I rarely modify any pulse.",
          "modified": "2024-09-26T20:01:27.723000",
          "created": "2024-08-27T21:01:40.251000",
          "tags": [
            "memcommit",
            "read c",
            "nospltezraxuf",
            "writeconsolea",
            "write",
            "CVE-2023-22518",
            "tesla",
            "ye ye",
            "incapril",
            "yed ye",
            "yet ye",
            "yexe ye",
            "security",
            "search",
            "function read",
            "dll read",
            "installer",
            "april",
            "copy",
            "win32",
            "template",
            "creation date",
            "servers",
            "passive dns",
            "urls",
            "name servers",
            "scan endpoints",
            "all scoreblue",
            "hostname",
            "pulse pulses",
            "date",
            "windows",
            "medium",
            "shellexecuteexw",
            "hash",
            "show",
            "writeconsolew",
            "entries",
            "displayname",
            "sddl",
            "service",
            "august",
            "malware",
            "url http",
            "http",
            "ip address",
            "related nids",
            "files location",
            "domain",
            "status",
            "nxdomain",
            "whitelisted",
            "certificate",
            "backdoor",
            "record value",
            "body",
            "as15133 verizon",
            "united",
            "unknown",
            "mtb aug",
            "gmt server",
            "ecacc sed5906",
            "ransom",
            "trojan",
            "high",
            "cname",
            "as8075",
            "ipv4",
            "files",
            "asn as55720",
            "date hash",
            "default",
            "delete",
            "yara detections",
            "msvisualcpp60",
            "related pulses",
            "rootkit",
            "as16276",
            "canada unknown",
            "pulses",
            "expiration date",
            "exploit",
            "showing",
            "aaaa",
            "france unknown",
            "mtb sep",
            "worm",
            "msil",
            "mirai",
            "as36081 state",
            "reverse dns",
            "port",
            "destination",
            "south korea",
            "taiwan as3462",
            "as4766 korea",
            "asnone",
            "japan as17676",
            "china as4134",
            "china as4837",
            "file samples",
            "files matching",
            "next",
            "copyright",
            "levelblue",
            "as20940",
            "as15169 google",
            "ave suite",
            "purpose p5",
            "country united",
            "code us",
            "as41231",
            "united kingdom",
            "ddos",
            "sha256",
            "filehash",
            "av detections",
            "location london",
            "great britain",
            "gnulinux apt",
            "yara rule",
            "ids detections",
            "top source",
            "address",
            "as23969",
            "thailand"
          ],
          "references": [
            "In this instance a senior citizen needing assisted living resources redirected & social engineered by addresses originated from: jefferson.co.us",
            "Noted: Calls redirected, call jumps ahead of 25+ callers in wait, keeps getting same agent, told approved for services never applied for or received",
            "Exploits: IPv4 20.99.186.246 | 52.109.0.140 | CVE CVE-2023-22518 | Trojans: AgentTesla.KM , Cobalt Strike , Ransom: WannaCrypt , Malware: Dxqo",
            "Domain Name: IUQERFSODP9IFJAPOSDFJHGOSURIJFAEWRWERGWEA.COM  Emails: BotnetSinkhole@gmail.com",
            "Emails: abuse@namecheap.com Name: Botnet Sinkhole  | Address: Botnet Sinkhole City: Los Angeles Country: USA",
            "Dnssec:Unsigned | Name Servers | BRUCE.NS.CLOUDFLARE.COM",
            "Notable: Mirai - 192.70.175.110 Security Operations (DORA?) oit_isocsecurity@state.co.us | state.co.us | Reverse DNS dns1.state.co.us",
            "Unix.Trojan.Mirai-6976991-0 : FileHash-SHA256 a282f250e59f8754335993293bfbfcc154cdb67ff0e234162f40a6cce5c4290c",
            "ELF:Mirai-AII\\ [Trj] | FileHash-SHA256 760a17dea7794ebbfb5c54e7e74d0b53fd9e079e43be0b9b6e3df7eb14a47be9",
            "Overlaps: 4 others mailed information email address.",
            "Ransom:Win32/WannaCrypt.H",
            "iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com | CVE-2017-0147",
            "AS36081 State of Colorado General Government Computer",
            "Yara Detections Mirai_Botnet_Malware Alerts: dead_host network_icmp osquery_detection nolookup_communication",
            "ELF:Mirai-AII\\ [Trj]  | FileHash-SHA256:  760a17dea7794ebbfb5c54e7e74d0b53fd9e079e43be0b9b6e3df7eb14a47be9",
            "Detections Executable and linking format (ELF) file download Over HTTP |",
            "FileHash-SHA256 : 256760a17dea7794ebbfb5c54e7e74d0b53fd9e079e43be0b9b6e3df7eb14a47be9",
            "Yara Detections: UPXProtectorv10x2 ,  UPX ,  ELFHighEntropy ,  elf_empty_sections Alerts: dead_host | ELF:Mirai-AII\\ [Trj]",
            "77882 IP\u2019s Contacted: 1.1.69.67  1.10.237.208  1.101.233.31  1.102.46.59  1.103.37.126  1.105.106.252  1.106.108.182  1.106.193.143  1.109.132.165  1.11.116.209",
            "Domains Contacted: ntp.ubuntu.com | IDS Detections GNU/Linux APT User-Agent Outbound likely related to package management | 91.189.89.198",
            "Yara Detections: gafgyt IP\u2019s Contacted:  91.189.89.198 Domains Contacted :ntp.ubuntu.com",
            "FileHash-SHA256:  a0f50a7b0f9717589000b3414017bdcfcb9d3f6a3e5e03fe49c4dc8035e0d25c",
            "Related Domains: townofignacio.com | coloradoagriculture.com | coloradoworkforce.com | coworkforce.com | coloradoccjj.com | dns1.state.co.us",
            "https://www.rapidinterviews.com/api/jobs/redirect/public-transit-bus-drivers-with-utah-transit-authority-in-stansbury-park-apc-1932",
            "https://us.thebigjobsite.com/redirectfeedjob?jobid=2A5F97A6BAE0AA90DC418C2119E1E0EB&source=onestepjobsxmlus&utm_source=onestepjobsxmlus&jobSiteK",
            "redirect.wuxs.icu",
            "https://a-a.redirector.navexglobal.com/navex_hosting/404.html",
            "https://engage.navexglobal.com/topclass1/login.do?redirectTo=/expand.do?template=JasperReports&view=library"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "ALF:Trojan:MSIL/AgentTesla.KM",
              "display_name": "ALF:Trojan:MSIL/AgentTesla.KM",
              "target": null
            },
            {
              "id": "Win.Trojan.CobaltStrike-9044898-1",
              "display_name": "Win.Trojan.CobaltStrike-9044898-1",
              "target": null
            },
            {
              "id": "Win.Malware.Dxqo-6984072-0",
              "display_name": "Win.Malware.Dxqo-6984072-0",
              "target": null
            },
            {
              "id": "Ransom:Win32/WannaCrypt",
              "display_name": "Ransom:Win32/WannaCrypt",
              "target": "/malware/Ransom:Win32/WannaCrypt"
            },
            {
              "id": "Mirai",
              "display_name": "Mirai",
              "target": null
            },
            {
              "id": "Backdoor:Win32/Fynloski",
              "display_name": "Backdoor:Win32/Fynloski",
              "target": "/malware/Backdoor:Win32/Fynloski"
            },
            {
              "id": "Worm:Win32/Mofksys",
              "display_name": "Worm:Win32/Mofksys",
              "target": "/malware/Worm:Win32/Mofksys"
            },
            {
              "id": "TELPER:DDoS:Linux/Lightaidra",
              "display_name": "TELPER:DDoS:Linux/Lightaidra",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1045",
              "name": "Software Packing",
              "display_name": "T1045 - Software Packing"
            },
            {
              "id": "T1060",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1060 - Registry Run Keys / Startup Folder"
            },
            {
              "id": "T1449",
              "name": "Exploit SS7 to Redirect Phone Calls/SMS",
              "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
            },
            {
              "id": "T1410",
              "name": "Network Traffic Capture or Redirection",
              "display_name": "T1410 - Network Traffic Capture or Redirection"
            },
            {
              "id": "T1036.004",
              "name": "Masquerade Task or Service",
              "display_name": "T1036.004 - Masquerade Task or Service"
            },
            {
              "id": "T1009",
              "name": "Binary Padding",
              "display_name": "T1009 - Binary Padding"
            },
            {
              "id": "T1499",
              "name": "Endpoint Denial of Service",
              "display_name": "T1499 - Endpoint Denial of Service"
            },
            {
              "id": "T1498",
              "name": "Network Denial of Service",
              "display_name": "T1498 - Network Denial of Service"
            },
            {
              "id": "T1464",
              "name": "Jamming or Denial of Service",
              "display_name": "T1464 - Jamming or Denial of Service"
            }
          ],
          "industries": [
            "Telecom"
          ],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 18,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "CVE": 2,
            "FileHash-MD5": 675,
            "FileHash-SHA1": 664,
            "FileHash-SHA256": 3327,
            "URL": 2448,
            "domain": 656,
            "hostname": 1281,
            "email": 11
          },
          "indicator_count": 9064,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 232,
          "modified_text": "612 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "65708bf87a08635a650eeb9b",
          "name": "ctgserver.net",
          "description": "",
          "modified": "2023-12-06T14:58:00.096000",
          "created": "2023-12-06T14:58:00.096000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 1286,
            "domain": 560,
            "hostname": 1602,
            "URL": 7975,
            "FileHash-MD5": 85,
            "FileHash-SHA1": 1
          },
          "indicator_count": 11509,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "907 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "65708befc4f4c7e2be4370d9",
          "name": "ctgserver.net",
          "description": "",
          "modified": "2023-12-06T14:57:51.922000",
          "created": "2023-12-06T14:57:51.922000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 1286,
            "domain": 560,
            "hostname": 1602,
            "URL": 7975,
            "FileHash-MD5": 85,
            "FileHash-SHA1": 1
          },
          "indicator_count": 11509,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "907 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "65708020538a6eb3a87d0376",
          "name": "XAPP CONNECT &#8211; MOBILE  APPS MADE EASY",
          "description": "",
          "modified": "2023-12-06T14:07:28.711000",
          "created": "2023-12-06T14:07:28.711000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 567,
            "domain": 245,
            "URL": 1993,
            "hostname": 472,
            "FileHash-MD5": 1
          },
          "indicator_count": 3278,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "907 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "625eff927c93e3e5cd50e191",
          "name": "ctgserver.net",
          "description": "var d=b.dir,e=c&&\"parentNode\"===d,f=x, f=w, b.b, and d(b) for the first time.",
          "modified": "2022-05-19T00:00:49.028000",
          "created": "2022-04-19T18:29:38.810000",
          "tags": [
            "0x1d3c",
            "function",
            "json",
            "date",
            "0x3abb84",
            "0x400e43",
            "0x4e2be0",
            "0x27ecdf",
            "this",
            "0x217f25",
            "webview",
            "array",
            "typeof e",
            "regexp",
            "null",
            "object",
            "string",
            "post",
            "typeof r",
            "error",
            "android",
            "void",
            "math",
            "k3wc3w",
            "o4wo4w",
            "b0z1",
            "a4r1",
            "b2bbbb",
            "o5r1",
            "image",
            "typeof s",
            "typeof console",
            "contenttype",
            "number",
            "60number",
            "new date",
            "close",
            "sector",
            "typeof symbol",
            "crispclient",
            "crisp im",
            "typeof b",
            "width",
            "pseudo",
            "child",
            "sufeffxa0",
            "class",
            "accept"
          ],
          "references": [
            "http://v1-ab.cdn-static.cn/editor/js/jquery.min.js",
            "https://client.crisp.chat/l.js",
            "http://www.ctgserver.net/zhuzi-statistic.js?path=http%3a%2f%2fwww.ctgserver.net%2f&siteid=68944&referer=",
            "http://sgoutong.baidu.com/embed/1649840755/asset/embed/mobilelite/main.js",
            "https://aiff.cdn.bcebos.com/sensors%2Fonline%2Fsa-sdk-javascript-1.14.24%2Fsensorsdata.min.js",
            "https://goutong.baidu.com/site/889/a8439b4fa4b46ae6d1cb7840806b342d/b.js?siteId=12877102",
            "http://push.zhanzhang.baidu.com/push.js",
            "http://api.geetest.com/gettype.php?gt=70bfe290f45725d99fae0063c5188b8f&callback=geetest_1650391760798",
            "http://static.geetest.com/static/js/geetest.6.0.9.js",
            "http://api.geetest.com/get.php?gt=70bfe290f45725d99fae0063c5188b8f&challenge=36bbdc68ea2e3279d57269471b837a6b&product=popup&width=301px&offline=false&lang=zh-cn&protocol=http://&type=slide&path=/static/js/geetest.6.0.9.js&callback=geetest_1650391756575",
            "http://sgoutong.baidu.com/embed/1649840755/asset/embed/mobile_nb.js",
            "https://sofire.bdstatic.com/js/dfxaf.js",
            "https://p.qiao.baidu.com/cps3/site/poll?cb=jsonp_bridge_1650392095190_21922384256393768&l=1&sign=&v=165039175860477407&s=12877102&e=26958486&isAFF=1&filterAdvertisement=1&dev=1&auth=%7B%22anonym%22%3A0%2C%22key%22%3A%223bfef1eb-bde9-4fbf-ba96-abad738f1775%22%2C%22sn%22%3A%22%22%2C%22id%22%3A%22165039175860477407%22%2C%22from%22%3A4%2C%22token%22%3A%22bridge%22%7D&_time=1650392095190",
            "http://www.zhuzi.me/zhuzi-statistic.js?path=http%3a%2f%2fwww.zhuzi.me%2f&siteid=62221&referer=",
            "xfe-URL-Zhuzi.me-stix2-2.1-export.json"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 3,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "adjadex1@gmail.com",
            "id": "187163",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 7975,
            "FileHash-SHA256": 1286,
            "hostname": 1602,
            "domain": 560,
            "FileHash-MD5": 85,
            "FileHash-SHA1": 1
          },
          "indicator_count": 11509,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 68,
          "modified_text": "1474 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "625effa1c4edcef37385c4eb",
          "name": "ctgserver.net",
          "description": "var d=b.dir,e=c&&\"parentNode\"===d,f=x, f=w, b.b, and d(b) for the first time.",
          "modified": "2022-05-19T00:00:49.028000",
          "created": "2022-04-19T18:29:53.960000",
          "tags": [
            "0x1d3c",
            "function",
            "json",
            "date",
            "0x3abb84",
            "0x400e43",
            "0x4e2be0",
            "0x27ecdf",
            "this",
            "0x217f25",
            "webview",
            "array",
            "typeof e",
            "regexp",
            "null",
            "object",
            "string",
            "post",
            "typeof r",
            "error",
            "android",
            "void",
            "math",
            "k3wc3w",
            "o4wo4w",
            "b0z1",
            "a4r1",
            "b2bbbb",
            "o5r1",
            "image",
            "typeof s",
            "typeof console",
            "contenttype",
            "number",
            "60number",
            "new date",
            "close",
            "sector",
            "typeof symbol",
            "crispclient",
            "crisp im",
            "typeof b",
            "width",
            "pseudo",
            "child",
            "sufeffxa0",
            "class",
            "accept"
          ],
          "references": [
            "http://v1-ab.cdn-static.cn/editor/js/jquery.min.js",
            "https://client.crisp.chat/l.js",
            "http://www.ctgserver.net/zhuzi-statistic.js?path=http%3a%2f%2fwww.ctgserver.net%2f&siteid=68944&referer=",
            "http://sgoutong.baidu.com/embed/1649840755/asset/embed/mobilelite/main.js",
            "https://aiff.cdn.bcebos.com/sensors%2Fonline%2Fsa-sdk-javascript-1.14.24%2Fsensorsdata.min.js",
            "https://goutong.baidu.com/site/889/a8439b4fa4b46ae6d1cb7840806b342d/b.js?siteId=12877102",
            "http://push.zhanzhang.baidu.com/push.js",
            "http://api.geetest.com/gettype.php?gt=70bfe290f45725d99fae0063c5188b8f&callback=geetest_1650391760798",
            "http://static.geetest.com/static/js/geetest.6.0.9.js",
            "http://api.geetest.com/get.php?gt=70bfe290f45725d99fae0063c5188b8f&challenge=36bbdc68ea2e3279d57269471b837a6b&product=popup&width=301px&offline=false&lang=zh-cn&protocol=http://&type=slide&path=/static/js/geetest.6.0.9.js&callback=geetest_1650391756575",
            "http://sgoutong.baidu.com/embed/1649840755/asset/embed/mobile_nb.js",
            "https://sofire.bdstatic.com/js/dfxaf.js",
            "https://p.qiao.baidu.com/cps3/site/poll?cb=jsonp_bridge_1650392095190_21922384256393768&l=1&sign=&v=165039175860477407&s=12877102&e=26958486&isAFF=1&filterAdvertisement=1&dev=1&auth=%7B%22anonym%22%3A0%2C%22key%22%3A%223bfef1eb-bde9-4fbf-ba96-abad738f1775%22%2C%22sn%22%3A%22%22%2C%22id%22%3A%22165039175860477407%22%2C%22from%22%3A4%2C%22token%22%3A%22bridge%22%7D&_time=1650392095190",
            "http://www.zhuzi.me/zhuzi-statistic.js?path=http%3a%2f%2fwww.zhuzi.me%2f&siteid=62221&referer=",
            "xfe-URL-Zhuzi.me-stix2-2.1-export.json"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 4,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "adjadex1@gmail.com",
            "id": "187163",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 7975,
            "FileHash-SHA256": 1286,
            "hostname": 1602,
            "domain": 560,
            "FileHash-MD5": 85,
            "FileHash-SHA1": 1
          },
          "indicator_count": 11509,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 69,
          "modified_text": "1474 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "622135089f85564cee8930d1",
          "name": "XAPP CONNECT &#8211; MOBILE  APPS MADE EASY",
          "description": "",
          "modified": "2022-04-02T00:04:50.405000",
          "created": "2022-03-03T21:37:12.155000",
          "tags": [
            "mobile apps",
            "xapp connect",
            "contact",
            "please",
            "debugging",
            "wordpress",
            "home apps",
            "standard apps",
            "premium apps",
            "fractal apps",
            "whois record",
            "ssl certificate",
            "whois",
            "1624406887"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "dorkingbeauty1",
            "id": "80137",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 1993,
            "hostname": 472,
            "domain": 245,
            "FileHash-SHA256": 567,
            "FileHash-MD5": 1
          },
          "indicator_count": 3278,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 393,
          "modified_text": "1521 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "redirect.wuxs.icu",
        "https://www.rapidinterviews.com/api/jobs/redirect/public-transit-bus-drivers-with-utah-transit-authority-in-stansbury-park-apc-1932",
        "http://www.ctgserver.net/zhuzi-statistic.js?path=http%3a%2f%2fwww.ctgserver.net%2f&siteid=68944&referer=",
        "Related Domains: townofignacio.com | coloradoagriculture.com | coloradoworkforce.com | coworkforce.com | coloradoccjj.com | dns1.state.co.us",
        "https://aiff.cdn.bcebos.com/sensors%2Fonline%2Fsa-sdk-javascript-1.14.24%2Fsensorsdata.min.js",
        "http://api.geetest.com/gettype.php?gt=70bfe290f45725d99fae0063c5188b8f&callback=geetest_1650391760798",
        "Yara Detections: gafgyt IP\u2019s Contacted:  91.189.89.198 Domains Contacted :ntp.ubuntu.com",
        "https://a-a.redirector.navexglobal.com/navex_hosting/404.html",
        "Ransom:Win32/WannaCrypt.H",
        "Unix.Trojan.Mirai-6976991-0 : FileHash-SHA256 a282f250e59f8754335993293bfbfcc154cdb67ff0e234162f40a6cce5c4290c",
        "Domains Contacted: ntp.ubuntu.com | IDS Detections GNU/Linux APT User-Agent Outbound likely related to package management | 91.189.89.198",
        "ELF:Mirai-AII\\ [Trj]  | FileHash-SHA256:  760a17dea7794ebbfb5c54e7e74d0b53fd9e079e43be0b9b6e3df7eb14a47be9",
        "https://client.crisp.chat/l.js",
        "https://us.thebigjobsite.com/redirectfeedjob?jobid=2A5F97A6BAE0AA90DC418C2119E1E0EB&source=onestepjobsxmlus&utm_source=onestepjobsxmlus&jobSiteK",
        "FileHash-SHA256 : 256760a17dea7794ebbfb5c54e7e74d0b53fd9e079e43be0b9b6e3df7eb14a47be9",
        "https://sofire.bdstatic.com/js/dfxaf.js",
        "xfe-URL-Zhuzi.me-stix2-2.1-export.json",
        "ELF:Mirai-AII\\ [Trj] | FileHash-SHA256 760a17dea7794ebbfb5c54e7e74d0b53fd9e079e43be0b9b6e3df7eb14a47be9",
        "http://api.geetest.com/get.php?gt=70bfe290f45725d99fae0063c5188b8f&challenge=36bbdc68ea2e3279d57269471b837a6b&product=popup&width=301px&offline=false&lang=zh-cn&protocol=http://&type=slide&path=/static/js/geetest.6.0.9.js&callback=geetest_1650391756575",
        "AS36081 State of Colorado General Government Computer",
        "iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com | CVE-2017-0147",
        "Emails: abuse@namecheap.com Name: Botnet Sinkhole  | Address: Botnet Sinkhole City: Los Angeles Country: USA",
        "Overlaps: 4 others mailed information email address.",
        "http://static.geetest.com/static/js/geetest.6.0.9.js",
        "http://push.zhanzhang.baidu.com/push.js",
        "Detections Executable and linking format (ELF) file download Over HTTP |",
        "https://goutong.baidu.com/site/889/a8439b4fa4b46ae6d1cb7840806b342d/b.js?siteId=12877102",
        "http://sgoutong.baidu.com/embed/1649840755/asset/embed/mobilelite/main.js",
        "Dnssec:Unsigned | Name Servers | BRUCE.NS.CLOUDFLARE.COM",
        "http://www.zhuzi.me/zhuzi-statistic.js?path=http%3a%2f%2fwww.zhuzi.me%2f&siteid=62221&referer=",
        "Noted: Calls redirected, call jumps ahead of 25+ callers in wait, keeps getting same agent, told approved for services never applied for or received",
        "Yara Detections Mirai_Botnet_Malware Alerts: dead_host network_icmp osquery_detection nolookup_communication",
        "Exploits: IPv4 20.99.186.246 | 52.109.0.140 | CVE CVE-2023-22518 | Trojans: AgentTesla.KM , Cobalt Strike , Ransom: WannaCrypt , Malware: Dxqo",
        "http://v1-ab.cdn-static.cn/editor/js/jquery.min.js",
        "https://p.qiao.baidu.com/cps3/site/poll?cb=jsonp_bridge_1650392095190_21922384256393768&l=1&sign=&v=165039175860477407&s=12877102&e=26958486&isAFF=1&filterAdvertisement=1&dev=1&auth=%7B%22anonym%22%3A0%2C%22key%22%3A%223bfef1eb-bde9-4fbf-ba96-abad738f1775%22%2C%22sn%22%3A%22%22%2C%22id%22%3A%22165039175860477407%22%2C%22from%22%3A4%2C%22token%22%3A%22bridge%22%7D&_time=1650392095190",
        "http://sgoutong.baidu.com/embed/1649840755/asset/embed/mobile_nb.js",
        "https://engage.navexglobal.com/topclass1/login.do?redirectTo=/expand.do?template=JasperReports&view=library",
        "Domain Name: IUQERFSODP9IFJAPOSDFJHGOSURIJFAEWRWERGWEA.COM  Emails: BotnetSinkhole@gmail.com",
        "In this instance a senior citizen needing assisted living resources redirected & social engineered by addresses originated from: jefferson.co.us",
        "Yara Detections: UPXProtectorv10x2 ,  UPX ,  ELFHighEntropy ,  elf_empty_sections Alerts: dead_host | ELF:Mirai-AII\\ [Trj]",
        "Notable: Mirai - 192.70.175.110 Security Operations (DORA?) oit_isocsecurity@state.co.us | state.co.us | Reverse DNS dns1.state.co.us",
        "77882 IP\u2019s Contacted: 1.1.69.67  1.10.237.208  1.101.233.31  1.102.46.59  1.103.37.126  1.105.106.252  1.106.108.182  1.106.193.143  1.109.132.165  1.11.116.209",
        "FileHash-SHA256:  a0f50a7b0f9717589000b3414017bdcfcb9d3f6a3e5e03fe49c4dc8035e0d25c"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 0
        },
        "other": {
          "adversary": [],
          "malware_families": [
            "Ransom:win32/wannacrypt",
            "Backdoor:win32/fynloski",
            "Worm:win32/mofksys",
            "Mirai",
            "Win.trojan.cobaltstrike-9044898-1",
            "Win.malware.dxqo-6984072-0",
            "Telper:ddos:linux/lightaidra",
            "Alf:trojan:msil/agenttesla.km"
          ],
          "industries": [
            "Telecom"
          ],
          "unique_indicators": 24403
        }
      }
    },
    "false_positive": [],
    "alexa": "http://www.alexa.com/siteinfo/icson.com",
    "whois": "http://whois.domaintools.com/icson.com",
    "domain": "icson.com",
    "hostname": "img2.icson.com"
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 7,
  "pulses": [
    {
      "id": "66ce3eb4b4f1fc9eafb4b572",
      "name": "DDoS:Linux/Lightaidra | Mirai Botnet on US a State Computer",
      "description": "*Mirai Botnet on Colorado State computer. Im starting to wonder if potential problem cases are diverted to a botnet.\n1. Overlaps with a Colorado victim. Similar issues. I Recently became a senior in expensive Colorado, never compensated for workers compensation injury exacerbated when suddenly tossed a 60 lb weighted ball under care. Denied diagnoses of severe injury after toss. Complained, case closed, lawyers denied case after accepting case. Referred to JeffCo seeking assisted living resources. Was sent various packets with a variety of phone numbers, email addresses, etc. She keeps speaking to same man no matter what option chosen. Denied workforce training due to severity of injuries, No SSI or SSDI until years later. \n2. I can't pulse half of what I've researched without using multiple resources. No more 'contacted' made when new serious issues found. Pulses being modified. I rarely modify any pulse.",
      "modified": "2024-09-26T20:01:27.723000",
      "created": "2024-08-27T21:01:40.251000",
      "tags": [
        "memcommit",
        "read c",
        "nospltezraxuf",
        "writeconsolea",
        "write",
        "CVE-2023-22518",
        "tesla",
        "ye ye",
        "incapril",
        "yed ye",
        "yet ye",
        "yexe ye",
        "security",
        "search",
        "function read",
        "dll read",
        "installer",
        "april",
        "copy",
        "win32",
        "template",
        "creation date",
        "servers",
        "passive dns",
        "urls",
        "name servers",
        "scan endpoints",
        "all scoreblue",
        "hostname",
        "pulse pulses",
        "date",
        "windows",
        "medium",
        "shellexecuteexw",
        "hash",
        "show",
        "writeconsolew",
        "entries",
        "displayname",
        "sddl",
        "service",
        "august",
        "malware",
        "url http",
        "http",
        "ip address",
        "related nids",
        "files location",
        "domain",
        "status",
        "nxdomain",
        "whitelisted",
        "certificate",
        "backdoor",
        "record value",
        "body",
        "as15133 verizon",
        "united",
        "unknown",
        "mtb aug",
        "gmt server",
        "ecacc sed5906",
        "ransom",
        "trojan",
        "high",
        "cname",
        "as8075",
        "ipv4",
        "files",
        "asn as55720",
        "date hash",
        "default",
        "delete",
        "yara detections",
        "msvisualcpp60",
        "related pulses",
        "rootkit",
        "as16276",
        "canada unknown",
        "pulses",
        "expiration date",
        "exploit",
        "showing",
        "aaaa",
        "france unknown",
        "mtb sep",
        "worm",
        "msil",
        "mirai",
        "as36081 state",
        "reverse dns",
        "port",
        "destination",
        "south korea",
        "taiwan as3462",
        "as4766 korea",
        "asnone",
        "japan as17676",
        "china as4134",
        "china as4837",
        "file samples",
        "files matching",
        "next",
        "copyright",
        "levelblue",
        "as20940",
        "as15169 google",
        "ave suite",
        "purpose p5",
        "country united",
        "code us",
        "as41231",
        "united kingdom",
        "ddos",
        "sha256",
        "filehash",
        "av detections",
        "location london",
        "great britain",
        "gnulinux apt",
        "yara rule",
        "ids detections",
        "top source",
        "address",
        "as23969",
        "thailand"
      ],
      "references": [
        "In this instance a senior citizen needing assisted living resources redirected & social engineered by addresses originated from: jefferson.co.us",
        "Noted: Calls redirected, call jumps ahead of 25+ callers in wait, keeps getting same agent, told approved for services never applied for or received",
        "Exploits: IPv4 20.99.186.246 | 52.109.0.140 | CVE CVE-2023-22518 | Trojans: AgentTesla.KM , Cobalt Strike , Ransom: WannaCrypt , Malware: Dxqo",
        "Domain Name: IUQERFSODP9IFJAPOSDFJHGOSURIJFAEWRWERGWEA.COM  Emails: BotnetSinkhole@gmail.com",
        "Emails: abuse@namecheap.com Name: Botnet Sinkhole  | Address: Botnet Sinkhole City: Los Angeles Country: USA",
        "Dnssec:Unsigned | Name Servers | BRUCE.NS.CLOUDFLARE.COM",
        "Notable: Mirai - 192.70.175.110 Security Operations (DORA?) oit_isocsecurity@state.co.us | state.co.us | Reverse DNS dns1.state.co.us",
        "Unix.Trojan.Mirai-6976991-0 : FileHash-SHA256 a282f250e59f8754335993293bfbfcc154cdb67ff0e234162f40a6cce5c4290c",
        "ELF:Mirai-AII\\ [Trj] | FileHash-SHA256 760a17dea7794ebbfb5c54e7e74d0b53fd9e079e43be0b9b6e3df7eb14a47be9",
        "Overlaps: 4 others mailed information email address.",
        "Ransom:Win32/WannaCrypt.H",
        "iuqerfsodp9ifjaposdfjhgosurijfaewrwergwea.com | CVE-2017-0147",
        "AS36081 State of Colorado General Government Computer",
        "Yara Detections Mirai_Botnet_Malware Alerts: dead_host network_icmp osquery_detection nolookup_communication",
        "ELF:Mirai-AII\\ [Trj]  | FileHash-SHA256:  760a17dea7794ebbfb5c54e7e74d0b53fd9e079e43be0b9b6e3df7eb14a47be9",
        "Detections Executable and linking format (ELF) file download Over HTTP |",
        "FileHash-SHA256 : 256760a17dea7794ebbfb5c54e7e74d0b53fd9e079e43be0b9b6e3df7eb14a47be9",
        "Yara Detections: UPXProtectorv10x2 ,  UPX ,  ELFHighEntropy ,  elf_empty_sections Alerts: dead_host | ELF:Mirai-AII\\ [Trj]",
        "77882 IP\u2019s Contacted: 1.1.69.67  1.10.237.208  1.101.233.31  1.102.46.59  1.103.37.126  1.105.106.252  1.106.108.182  1.106.193.143  1.109.132.165  1.11.116.209",
        "Domains Contacted: ntp.ubuntu.com | IDS Detections GNU/Linux APT User-Agent Outbound likely related to package management | 91.189.89.198",
        "Yara Detections: gafgyt IP\u2019s Contacted:  91.189.89.198 Domains Contacted :ntp.ubuntu.com",
        "FileHash-SHA256:  a0f50a7b0f9717589000b3414017bdcfcb9d3f6a3e5e03fe49c4dc8035e0d25c",
        "Related Domains: townofignacio.com | coloradoagriculture.com | coloradoworkforce.com | coworkforce.com | coloradoccjj.com | dns1.state.co.us",
        "https://www.rapidinterviews.com/api/jobs/redirect/public-transit-bus-drivers-with-utah-transit-authority-in-stansbury-park-apc-1932",
        "https://us.thebigjobsite.com/redirectfeedjob?jobid=2A5F97A6BAE0AA90DC418C2119E1E0EB&source=onestepjobsxmlus&utm_source=onestepjobsxmlus&jobSiteK",
        "redirect.wuxs.icu",
        "https://a-a.redirector.navexglobal.com/navex_hosting/404.html",
        "https://engage.navexglobal.com/topclass1/login.do?redirectTo=/expand.do?template=JasperReports&view=library"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "ALF:Trojan:MSIL/AgentTesla.KM",
          "display_name": "ALF:Trojan:MSIL/AgentTesla.KM",
          "target": null
        },
        {
          "id": "Win.Trojan.CobaltStrike-9044898-1",
          "display_name": "Win.Trojan.CobaltStrike-9044898-1",
          "target": null
        },
        {
          "id": "Win.Malware.Dxqo-6984072-0",
          "display_name": "Win.Malware.Dxqo-6984072-0",
          "target": null
        },
        {
          "id": "Ransom:Win32/WannaCrypt",
          "display_name": "Ransom:Win32/WannaCrypt",
          "target": "/malware/Ransom:Win32/WannaCrypt"
        },
        {
          "id": "Mirai",
          "display_name": "Mirai",
          "target": null
        },
        {
          "id": "Backdoor:Win32/Fynloski",
          "display_name": "Backdoor:Win32/Fynloski",
          "target": "/malware/Backdoor:Win32/Fynloski"
        },
        {
          "id": "Worm:Win32/Mofksys",
          "display_name": "Worm:Win32/Mofksys",
          "target": "/malware/Worm:Win32/Mofksys"
        },
        {
          "id": "TELPER:DDoS:Linux/Lightaidra",
          "display_name": "TELPER:DDoS:Linux/Lightaidra",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1129",
          "name": "Shared Modules",
          "display_name": "T1129 - Shared Modules"
        },
        {
          "id": "T1045",
          "name": "Software Packing",
          "display_name": "T1045 - Software Packing"
        },
        {
          "id": "T1060",
          "name": "Registry Run Keys / Startup Folder",
          "display_name": "T1060 - Registry Run Keys / Startup Folder"
        },
        {
          "id": "T1449",
          "name": "Exploit SS7 to Redirect Phone Calls/SMS",
          "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
        },
        {
          "id": "T1410",
          "name": "Network Traffic Capture or Redirection",
          "display_name": "T1410 - Network Traffic Capture or Redirection"
        },
        {
          "id": "T1036.004",
          "name": "Masquerade Task or Service",
          "display_name": "T1036.004 - Masquerade Task or Service"
        },
        {
          "id": "T1009",
          "name": "Binary Padding",
          "display_name": "T1009 - Binary Padding"
        },
        {
          "id": "T1499",
          "name": "Endpoint Denial of Service",
          "display_name": "T1499 - Endpoint Denial of Service"
        },
        {
          "id": "T1498",
          "name": "Network Denial of Service",
          "display_name": "T1498 - Network Denial of Service"
        },
        {
          "id": "T1464",
          "name": "Jamming or Denial of Service",
          "display_name": "T1464 - Jamming or Denial of Service"
        }
      ],
      "industries": [
        "Telecom"
      ],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 18,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "scoreblue",
        "id": "254100",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "CVE": 2,
        "FileHash-MD5": 675,
        "FileHash-SHA1": 664,
        "FileHash-SHA256": 3327,
        "URL": 2448,
        "domain": 656,
        "hostname": 1281,
        "email": 11
      },
      "indicator_count": 9064,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 232,
      "modified_text": "612 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "65708bf87a08635a650eeb9b",
      "name": "ctgserver.net",
      "description": "",
      "modified": "2023-12-06T14:58:00.096000",
      "created": "2023-12-06T14:58:00.096000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 1286,
        "domain": 560,
        "hostname": 1602,
        "URL": 7975,
        "FileHash-MD5": 85,
        "FileHash-SHA1": 1
      },
      "indicator_count": 11509,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "907 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "65708befc4f4c7e2be4370d9",
      "name": "ctgserver.net",
      "description": "",
      "modified": "2023-12-06T14:57:51.922000",
      "created": "2023-12-06T14:57:51.922000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 1286,
        "domain": 560,
        "hostname": 1602,
        "URL": 7975,
        "FileHash-MD5": 85,
        "FileHash-SHA1": 1
      },
      "indicator_count": 11509,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "907 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "65708020538a6eb3a87d0376",
      "name": "XAPP CONNECT &#8211; MOBILE  APPS MADE EASY",
      "description": "",
      "modified": "2023-12-06T14:07:28.711000",
      "created": "2023-12-06T14:07:28.711000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 567,
        "domain": 245,
        "URL": 1993,
        "hostname": 472,
        "FileHash-MD5": 1
      },
      "indicator_count": 3278,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "907 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "625eff927c93e3e5cd50e191",
      "name": "ctgserver.net",
      "description": "var d=b.dir,e=c&&\"parentNode\"===d,f=x, f=w, b.b, and d(b) for the first time.",
      "modified": "2022-05-19T00:00:49.028000",
      "created": "2022-04-19T18:29:38.810000",
      "tags": [
        "0x1d3c",
        "function",
        "json",
        "date",
        "0x3abb84",
        "0x400e43",
        "0x4e2be0",
        "0x27ecdf",
        "this",
        "0x217f25",
        "webview",
        "array",
        "typeof e",
        "regexp",
        "null",
        "object",
        "string",
        "post",
        "typeof r",
        "error",
        "android",
        "void",
        "math",
        "k3wc3w",
        "o4wo4w",
        "b0z1",
        "a4r1",
        "b2bbbb",
        "o5r1",
        "image",
        "typeof s",
        "typeof console",
        "contenttype",
        "number",
        "60number",
        "new date",
        "close",
        "sector",
        "typeof symbol",
        "crispclient",
        "crisp im",
        "typeof b",
        "width",
        "pseudo",
        "child",
        "sufeffxa0",
        "class",
        "accept"
      ],
      "references": [
        "http://v1-ab.cdn-static.cn/editor/js/jquery.min.js",
        "https://client.crisp.chat/l.js",
        "http://www.ctgserver.net/zhuzi-statistic.js?path=http%3a%2f%2fwww.ctgserver.net%2f&siteid=68944&referer=",
        "http://sgoutong.baidu.com/embed/1649840755/asset/embed/mobilelite/main.js",
        "https://aiff.cdn.bcebos.com/sensors%2Fonline%2Fsa-sdk-javascript-1.14.24%2Fsensorsdata.min.js",
        "https://goutong.baidu.com/site/889/a8439b4fa4b46ae6d1cb7840806b342d/b.js?siteId=12877102",
        "http://push.zhanzhang.baidu.com/push.js",
        "http://api.geetest.com/gettype.php?gt=70bfe290f45725d99fae0063c5188b8f&callback=geetest_1650391760798",
        "http://static.geetest.com/static/js/geetest.6.0.9.js",
        "http://api.geetest.com/get.php?gt=70bfe290f45725d99fae0063c5188b8f&challenge=36bbdc68ea2e3279d57269471b837a6b&product=popup&width=301px&offline=false&lang=zh-cn&protocol=http://&type=slide&path=/static/js/geetest.6.0.9.js&callback=geetest_1650391756575",
        "http://sgoutong.baidu.com/embed/1649840755/asset/embed/mobile_nb.js",
        "https://sofire.bdstatic.com/js/dfxaf.js",
        "https://p.qiao.baidu.com/cps3/site/poll?cb=jsonp_bridge_1650392095190_21922384256393768&l=1&sign=&v=165039175860477407&s=12877102&e=26958486&isAFF=1&filterAdvertisement=1&dev=1&auth=%7B%22anonym%22%3A0%2C%22key%22%3A%223bfef1eb-bde9-4fbf-ba96-abad738f1775%22%2C%22sn%22%3A%22%22%2C%22id%22%3A%22165039175860477407%22%2C%22from%22%3A4%2C%22token%22%3A%22bridge%22%7D&_time=1650392095190",
        "http://www.zhuzi.me/zhuzi-statistic.js?path=http%3a%2f%2fwww.zhuzi.me%2f&siteid=62221&referer=",
        "xfe-URL-Zhuzi.me-stix2-2.1-export.json"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1547",
          "name": "Boot or Logon Autostart Execution",
          "display_name": "T1547 - Boot or Logon Autostart Execution"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 3,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "adjadex1@gmail.com",
        "id": "187163",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 7975,
        "FileHash-SHA256": 1286,
        "hostname": 1602,
        "domain": 560,
        "FileHash-MD5": 85,
        "FileHash-SHA1": 1
      },
      "indicator_count": 11509,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 68,
      "modified_text": "1474 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "625effa1c4edcef37385c4eb",
      "name": "ctgserver.net",
      "description": "var d=b.dir,e=c&&\"parentNode\"===d,f=x, f=w, b.b, and d(b) for the first time.",
      "modified": "2022-05-19T00:00:49.028000",
      "created": "2022-04-19T18:29:53.960000",
      "tags": [
        "0x1d3c",
        "function",
        "json",
        "date",
        "0x3abb84",
        "0x400e43",
        "0x4e2be0",
        "0x27ecdf",
        "this",
        "0x217f25",
        "webview",
        "array",
        "typeof e",
        "regexp",
        "null",
        "object",
        "string",
        "post",
        "typeof r",
        "error",
        "android",
        "void",
        "math",
        "k3wc3w",
        "o4wo4w",
        "b0z1",
        "a4r1",
        "b2bbbb",
        "o5r1",
        "image",
        "typeof s",
        "typeof console",
        "contenttype",
        "number",
        "60number",
        "new date",
        "close",
        "sector",
        "typeof symbol",
        "crispclient",
        "crisp im",
        "typeof b",
        "width",
        "pseudo",
        "child",
        "sufeffxa0",
        "class",
        "accept"
      ],
      "references": [
        "http://v1-ab.cdn-static.cn/editor/js/jquery.min.js",
        "https://client.crisp.chat/l.js",
        "http://www.ctgserver.net/zhuzi-statistic.js?path=http%3a%2f%2fwww.ctgserver.net%2f&siteid=68944&referer=",
        "http://sgoutong.baidu.com/embed/1649840755/asset/embed/mobilelite/main.js",
        "https://aiff.cdn.bcebos.com/sensors%2Fonline%2Fsa-sdk-javascript-1.14.24%2Fsensorsdata.min.js",
        "https://goutong.baidu.com/site/889/a8439b4fa4b46ae6d1cb7840806b342d/b.js?siteId=12877102",
        "http://push.zhanzhang.baidu.com/push.js",
        "http://api.geetest.com/gettype.php?gt=70bfe290f45725d99fae0063c5188b8f&callback=geetest_1650391760798",
        "http://static.geetest.com/static/js/geetest.6.0.9.js",
        "http://api.geetest.com/get.php?gt=70bfe290f45725d99fae0063c5188b8f&challenge=36bbdc68ea2e3279d57269471b837a6b&product=popup&width=301px&offline=false&lang=zh-cn&protocol=http://&type=slide&path=/static/js/geetest.6.0.9.js&callback=geetest_1650391756575",
        "http://sgoutong.baidu.com/embed/1649840755/asset/embed/mobile_nb.js",
        "https://sofire.bdstatic.com/js/dfxaf.js",
        "https://p.qiao.baidu.com/cps3/site/poll?cb=jsonp_bridge_1650392095190_21922384256393768&l=1&sign=&v=165039175860477407&s=12877102&e=26958486&isAFF=1&filterAdvertisement=1&dev=1&auth=%7B%22anonym%22%3A0%2C%22key%22%3A%223bfef1eb-bde9-4fbf-ba96-abad738f1775%22%2C%22sn%22%3A%22%22%2C%22id%22%3A%22165039175860477407%22%2C%22from%22%3A4%2C%22token%22%3A%22bridge%22%7D&_time=1650392095190",
        "http://www.zhuzi.me/zhuzi-statistic.js?path=http%3a%2f%2fwww.zhuzi.me%2f&siteid=62221&referer=",
        "xfe-URL-Zhuzi.me-stix2-2.1-export.json"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1547",
          "name": "Boot or Logon Autostart Execution",
          "display_name": "T1547 - Boot or Logon Autostart Execution"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 4,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "adjadex1@gmail.com",
        "id": "187163",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 7975,
        "FileHash-SHA256": 1286,
        "hostname": 1602,
        "domain": 560,
        "FileHash-MD5": 85,
        "FileHash-SHA1": 1
      },
      "indicator_count": 11509,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 69,
      "modified_text": "1474 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "622135089f85564cee8930d1",
      "name": "XAPP CONNECT &#8211; MOBILE  APPS MADE EASY",
      "description": "",
      "modified": "2022-04-02T00:04:50.405000",
      "created": "2022-03-03T21:37:12.155000",
      "tags": [
        "mobile apps",
        "xapp connect",
        "contact",
        "please",
        "debugging",
        "wordpress",
        "home apps",
        "standard apps",
        "premium apps",
        "fractal apps",
        "whois record",
        "ssl certificate",
        "whois",
        "1624406887"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "dorkingbeauty1",
        "id": "80137",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 1993,
        "hostname": 472,
        "domain": 245,
        "FileHash-SHA256": 567,
        "FileHash-MD5": 1
      },
      "indicator_count": 3278,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 393,
      "modified_text": "1521 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "https://img2.icson.com",
    "type": "URL"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "https://img2.icson.com",
    "type": "URL",
    "found": false,
    "verdict": "clean",
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780281523.3125207
}