{
  "type": "URL",
  "indicator": "https://iplogger.org/1nLz4",
  "general": {
    "sections": [
      "general",
      "url_list",
      "http_scans",
      "screenshot"
    ],
    "indicator": "https://iplogger.org/1nLz4",
    "type": "url",
    "type_title": "URL",
    "validation": [
      {
        "source": "whitelist",
        "message": "Whitelisted domain iplogger.org",
        "name": "Whitelisted domain"
      },
      {
        "source": "majestic",
        "message": "Whitelisted domain iplogger.org",
        "name": "Whitelisted domain"
      }
    ],
    "base_indicator": {
      "id": 4376692727,
      "indicator": "https://iplogger.org/1nLz4",
      "type": "URL",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 2,
      "pulses": [
        {
          "id": "6a13404a015fc885f5edb1c9",
          "name": "An error occurred: breadcrumb. IpLogger - piggy back on @skocherhan",
          "description": "[Find out the best IP logging tools and tools at  \u00c2\u00a31.5m in the UK, Ireland, Wales, Scotland and Northern Ireland on the website+ here is the full list.]",
          "modified": "2026-05-24T18:15:38.213000",
          "created": "2026-05-24T18:15:38.213000",
          "tags": [
            "::keywords_error_main",
            "sign",
            "url shortener",
            "track phone",
            "tracking pixel",
            "my ip",
            "ip counters",
            "ip generator",
            "internet",
            "best ip",
            "logger",
            "accept",
            "pe32",
            "intel",
            "ms windows",
            "win16 ne",
            "icons library",
            "os2 executable",
            "pe32 compiler",
            "exe32",
            "compiler",
            "ltcgc",
            "ascii text",
            "redacted for",
            "postal code",
            "privacy tech",
            "stateprovince",
            "server",
            "registrar abuse",
            "registrant name",
            "domain id",
            "iana id",
            "admin country",
            "date",
            "key identifier",
            "number",
            "issuer",
            "cus cnlet",
            "x3 olet",
            "subject public",
            "key info",
            "key algorithm",
            "x509v3 subject",
            "x509v3 key",
            "delegated",
            "unverified",
            "record type",
            "ttl value",
            "homenet",
            "0xf82",
            "externalnet",
            "policy ip",
            "check domain",
            "tls sni",
            "high",
            "informational",
            "registry keys",
            "nothing",
            "mutexes nothing",
            "parent pid",
            "full path",
            "command line",
            "read files",
            "apis nothing",
            "pe file",
            "performs dns",
            "network info",
            "processes extra",
            "aslr",
            "sample",
            "t1055 process",
            "overview",
            "mitre attack",
            "overview zenbox",
            "defense evasion",
            "next",
            "generic cil",
            "executable",
            "mono",
            "win32 dynamic",
            "link library",
            "pe32 library",
            "file type",
            "python script",
            "python",
            "writes shell",
            "unicode text",
            "utf8 text",
            "ascii",
            "writes",
            "persistence",
            "info",
            "Expired certificate",
            "Drops",
            "Oa auth abuse [potential]"
          ],
          "references": [
            "http://iplogger.org/1tnbw7%0Ahttp://gsoftclean.top/ver.txt%0Ahttp://iplogger.org/1z9A57%0Ahttp://gsoftclean.top/main.exe%0Ahttp://gsoftclean.top/aus%0Ahttp://gsoftclean.top/settings.dll%0Ahttp://iplogger.org/1nLz47%0Ahttp://iplogger.org/1z6A57%0Ahttps://iplogger.org/1z6A57%0Ahttp://iplogger.org/1PMX37%0Ahttps://iplogger.org/1nLz47",
            "https://vtbehaviour.commondatastorage.googleapis.com/e920fc67e098b7a6f3a13d99935239edc4c6c799bbaf2126c28da9b6e77fcf6f_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1779645922&Signature=JwLo32luwQokWOHR7lJz4dmUcLMQf18tKN2sLujlReeuplXL3B7kObdnC6EAKvj0%2FbPufiSY60CcdkPZ0L38f2ezSQ%2FpUd%2B9vwTI0sIkA%2BKOPYbhRV0zr7%2FH0rSo%2Fe1bb7p3YS9o0fzclIJ9iT6lWjLBnyAgZ4ZvwYmLkJk2x9beiNvBoWd5BPX2QLlZXDEzKgUbGKGGjHZQPfSIi3YI3zIRo16YJkaQzjxGBhhyGB4Ao8%2Fr",
            "https://vtbehaviour.commondatastorage.googleapis.com/e920fc67e098b7a6f3a13d99935239edc4c6c799bbaf2126c28da9b6e77fcf6f_Zenbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1779646024&Signature=GY3f%2BonWSmAE2r3xAvXp%2F0FLSZV%2B761HeH7MY%2F8jak5D8A6eAtDD6dxfY3qi8RFAYc2JIbh%2BWXZHSBZkxzZskVfm5S22fwOHMoCy9ezLI3%2BUbKxsL0uv64YuKmYd8s9FPp4wHA7tAXPPEMApUtclPZEQeo1AHVK7AN9zQZqAGYGnbfQtD1Ew5Bny5yT6axRterHcQPbXI8aPUvmJjP0131Op%2FKquhhierCzlcA3JIPWrYGomlInU9wZg",
            "https://vtbehaviour.commondatastorage.googleapis.com/8ed092fba4497e2cdde226956c589a21ccfb01c1a23305c029746d6f3f8441f2_Zenbox%20Linux.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1779646404&Signature=RAWN3ziUE4nt7cOF13GailGKiIaXg1kyzWnV3ohWPQWImilq1jkY6T9cnu7vh%2F0SwtRBev83RCV6GntS%2BJCyx7SBzUDQfqgPb3FwbcVEKgVziqaqJnxUSRgT0fWVsRCXJCisv9WjaxDGYcpAG8VMSXObs0HpYbgKvL%2FmbwN2wmzCCwSIiyGZj72303oaIQHVyqX9LoYWhs16g1xe%2B%2BXBcJaVerKyva6h3EWLVO9dkwM0cWEidZPw"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1056",
              "name": "Input Capture",
              "display_name": "T1056 - Input Capture"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1095",
              "name": "Non-Application Layer Protocol",
              "display_name": "T1095 - Non-Application Layer Protocol"
            },
            {
              "id": "T1218",
              "name": "Signed Binary Proxy Execution",
              "display_name": "T1218 - Signed Binary Proxy Execution"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1574",
              "name": "Hijack Execution Flow",
              "display_name": "T1574 - Hijack Execution Flow"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1064",
              "name": "Scripting",
              "display_name": "T1064 - Scripting"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1222",
              "name": "File and Directory Permissions Modification",
              "display_name": "T1222 - File and Directory Permissions Modification"
            },
            {
              "id": "T1518",
              "name": "Software Discovery",
              "display_name": "T1518 - Software Discovery"
            },
            {
              "id": "T1564",
              "name": "Hide Artifacts",
              "display_name": "T1564 - Hide Artifacts"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 200,
            "domain": 530,
            "hostname": 84,
            "FileHash-SHA256": 1090,
            "FileHash-MD5": 104,
            "Mutex": 2,
            "FileHash-SHA1": 97,
            "IPv4": 58,
            "email": 1,
            "CVE": 1
          },
          "indicator_count": 2167,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 66,
          "modified_text": "7 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6a1340485f49d8abce143eea",
          "name": "An error occurred: breadcrumb. IpLogger - piggy back on @skocherhan",
          "description": "[Find out the best IP logging tools and tools at  \u00c2\u00a31.5m in the UK, Ireland, Wales, Scotland and Northern Ireland on the website+ here is the full list.]",
          "modified": "2026-05-24T18:15:36.238000",
          "created": "2026-05-24T18:15:36.238000",
          "tags": [
            "::keywords_error_main",
            "sign",
            "url shortener",
            "track phone",
            "tracking pixel",
            "my ip",
            "ip counters",
            "ip generator",
            "internet",
            "best ip",
            "logger",
            "accept",
            "pe32",
            "intel",
            "ms windows",
            "win16 ne",
            "icons library",
            "os2 executable",
            "pe32 compiler",
            "exe32",
            "compiler",
            "ltcgc",
            "ascii text",
            "redacted for",
            "postal code",
            "privacy tech",
            "stateprovince",
            "server",
            "registrar abuse",
            "registrant name",
            "domain id",
            "iana id",
            "admin country",
            "date",
            "key identifier",
            "number",
            "issuer",
            "cus cnlet",
            "x3 olet",
            "subject public",
            "key info",
            "key algorithm",
            "x509v3 subject",
            "x509v3 key",
            "delegated",
            "unverified",
            "record type",
            "ttl value",
            "homenet",
            "0xf82",
            "externalnet",
            "policy ip",
            "check domain",
            "tls sni",
            "high",
            "informational",
            "registry keys",
            "nothing",
            "mutexes nothing",
            "parent pid",
            "full path",
            "command line",
            "read files",
            "apis nothing",
            "pe file",
            "performs dns",
            "network info",
            "processes extra",
            "aslr",
            "sample",
            "t1055 process",
            "overview",
            "mitre attack",
            "overview zenbox",
            "defense evasion",
            "next",
            "generic cil",
            "executable",
            "mono",
            "win32 dynamic",
            "link library",
            "pe32 library",
            "file type",
            "python script",
            "python",
            "writes shell",
            "unicode text",
            "utf8 text",
            "ascii",
            "writes",
            "persistence",
            "info",
            "Expired certificate",
            "Drops",
            "Oa auth abuse [potential]"
          ],
          "references": [
            "http://iplogger.org/1tnbw7%0Ahttp://gsoftclean.top/ver.txt%0Ahttp://iplogger.org/1z9A57%0Ahttp://gsoftclean.top/main.exe%0Ahttp://gsoftclean.top/aus%0Ahttp://gsoftclean.top/settings.dll%0Ahttp://iplogger.org/1nLz47%0Ahttp://iplogger.org/1z6A57%0Ahttps://iplogger.org/1z6A57%0Ahttp://iplogger.org/1PMX37%0Ahttps://iplogger.org/1nLz47",
            "https://vtbehaviour.commondatastorage.googleapis.com/e920fc67e098b7a6f3a13d99935239edc4c6c799bbaf2126c28da9b6e77fcf6f_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1779645922&Signature=JwLo32luwQokWOHR7lJz4dmUcLMQf18tKN2sLujlReeuplXL3B7kObdnC6EAKvj0%2FbPufiSY60CcdkPZ0L38f2ezSQ%2FpUd%2B9vwTI0sIkA%2BKOPYbhRV0zr7%2FH0rSo%2Fe1bb7p3YS9o0fzclIJ9iT6lWjLBnyAgZ4ZvwYmLkJk2x9beiNvBoWd5BPX2QLlZXDEzKgUbGKGGjHZQPfSIi3YI3zIRo16YJkaQzjxGBhhyGB4Ao8%2Fr",
            "https://vtbehaviour.commondatastorage.googleapis.com/e920fc67e098b7a6f3a13d99935239edc4c6c799bbaf2126c28da9b6e77fcf6f_Zenbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1779646024&Signature=GY3f%2BonWSmAE2r3xAvXp%2F0FLSZV%2B761HeH7MY%2F8jak5D8A6eAtDD6dxfY3qi8RFAYc2JIbh%2BWXZHSBZkxzZskVfm5S22fwOHMoCy9ezLI3%2BUbKxsL0uv64YuKmYd8s9FPp4wHA7tAXPPEMApUtclPZEQeo1AHVK7AN9zQZqAGYGnbfQtD1Ew5Bny5yT6axRterHcQPbXI8aPUvmJjP0131Op%2FKquhhierCzlcA3JIPWrYGomlInU9wZg",
            "https://vtbehaviour.commondatastorage.googleapis.com/8ed092fba4497e2cdde226956c589a21ccfb01c1a23305c029746d6f3f8441f2_Zenbox%20Linux.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1779646404&Signature=RAWN3ziUE4nt7cOF13GailGKiIaXg1kyzWnV3ohWPQWImilq1jkY6T9cnu7vh%2F0SwtRBev83RCV6GntS%2BJCyx7SBzUDQfqgPb3FwbcVEKgVziqaqJnxUSRgT0fWVsRCXJCisv9WjaxDGYcpAG8VMSXObs0HpYbgKvL%2FmbwN2wmzCCwSIiyGZj72303oaIQHVyqX9LoYWhs16g1xe%2B%2BXBcJaVerKyva6h3EWLVO9dkwM0cWEidZPw"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1056",
              "name": "Input Capture",
              "display_name": "T1056 - Input Capture"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1095",
              "name": "Non-Application Layer Protocol",
              "display_name": "T1095 - Non-Application Layer Protocol"
            },
            {
              "id": "T1218",
              "name": "Signed Binary Proxy Execution",
              "display_name": "T1218 - Signed Binary Proxy Execution"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1574",
              "name": "Hijack Execution Flow",
              "display_name": "T1574 - Hijack Execution Flow"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1064",
              "name": "Scripting",
              "display_name": "T1064 - Scripting"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1222",
              "name": "File and Directory Permissions Modification",
              "display_name": "T1222 - File and Directory Permissions Modification"
            },
            {
              "id": "T1518",
              "name": "Software Discovery",
              "display_name": "T1518 - Software Discovery"
            },
            {
              "id": "T1564",
              "name": "Hide Artifacts",
              "display_name": "T1564 - Hide Artifacts"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 200,
            "domain": 530,
            "hostname": 84,
            "FileHash-SHA256": 1090,
            "FileHash-MD5": 104,
            "Mutex": 2,
            "FileHash-SHA1": 97,
            "IPv4": 58,
            "email": 1,
            "CVE": 1
          },
          "indicator_count": 2167,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 66,
          "modified_text": "7 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "https://vtbehaviour.commondatastorage.googleapis.com/e920fc67e098b7a6f3a13d99935239edc4c6c799bbaf2126c28da9b6e77fcf6f_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1779645922&Signature=JwLo32luwQokWOHR7lJz4dmUcLMQf18tKN2sLujlReeuplXL3B7kObdnC6EAKvj0%2FbPufiSY60CcdkPZ0L38f2ezSQ%2FpUd%2B9vwTI0sIkA%2BKOPYbhRV0zr7%2FH0rSo%2Fe1bb7p3YS9o0fzclIJ9iT6lWjLBnyAgZ4ZvwYmLkJk2x9beiNvBoWd5BPX2QLlZXDEzKgUbGKGGjHZQPfSIi3YI3zIRo16YJkaQzjxGBhhyGB4Ao8%2Fr",
        "https://vtbehaviour.commondatastorage.googleapis.com/8ed092fba4497e2cdde226956c589a21ccfb01c1a23305c029746d6f3f8441f2_Zenbox%20Linux.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1779646404&Signature=RAWN3ziUE4nt7cOF13GailGKiIaXg1kyzWnV3ohWPQWImilq1jkY6T9cnu7vh%2F0SwtRBev83RCV6GntS%2BJCyx7SBzUDQfqgPb3FwbcVEKgVziqaqJnxUSRgT0fWVsRCXJCisv9WjaxDGYcpAG8VMSXObs0HpYbgKvL%2FmbwN2wmzCCwSIiyGZj72303oaIQHVyqX9LoYWhs16g1xe%2B%2BXBcJaVerKyva6h3EWLVO9dkwM0cWEidZPw",
        "http://iplogger.org/1tnbw7%0Ahttp://gsoftclean.top/ver.txt%0Ahttp://iplogger.org/1z9A57%0Ahttp://gsoftclean.top/main.exe%0Ahttp://gsoftclean.top/aus%0Ahttp://gsoftclean.top/settings.dll%0Ahttp://iplogger.org/1nLz47%0Ahttp://iplogger.org/1z6A57%0Ahttps://iplogger.org/1z6A57%0Ahttp://iplogger.org/1PMX37%0Ahttps://iplogger.org/1nLz47",
        "https://vtbehaviour.commondatastorage.googleapis.com/e920fc67e098b7a6f3a13d99935239edc4c6c799bbaf2126c28da9b6e77fcf6f_Zenbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1779646024&Signature=GY3f%2BonWSmAE2r3xAvXp%2F0FLSZV%2B761HeH7MY%2F8jak5D8A6eAtDD6dxfY3qi8RFAYc2JIbh%2BWXZHSBZkxzZskVfm5S22fwOHMoCy9ezLI3%2BUbKxsL0uv64YuKmYd8s9FPp4wHA7tAXPPEMApUtclPZEQeo1AHVK7AN9zQZqAGYGnbfQtD1Ew5Bny5yT6axRterHcQPbXI8aPUvmJjP0131Op%2FKquhhierCzlcA3JIPWrYGomlInU9wZg"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 0
        },
        "other": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 2171
        }
      }
    },
    "false_positive": [],
    "alexa": "http://www.alexa.com/siteinfo/iplogger.org",
    "whois": "http://whois.domaintools.com/iplogger.org",
    "domain": "iplogger.org",
    "hostname": "Unavailable"
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 2,
  "pulses": [
    {
      "id": "6a13404a015fc885f5edb1c9",
      "name": "An error occurred: breadcrumb. IpLogger - piggy back on @skocherhan",
      "description": "[Find out the best IP logging tools and tools at  \u00c2\u00a31.5m in the UK, Ireland, Wales, Scotland and Northern Ireland on the website+ here is the full list.]",
      "modified": "2026-05-24T18:15:38.213000",
      "created": "2026-05-24T18:15:38.213000",
      "tags": [
        "::keywords_error_main",
        "sign",
        "url shortener",
        "track phone",
        "tracking pixel",
        "my ip",
        "ip counters",
        "ip generator",
        "internet",
        "best ip",
        "logger",
        "accept",
        "pe32",
        "intel",
        "ms windows",
        "win16 ne",
        "icons library",
        "os2 executable",
        "pe32 compiler",
        "exe32",
        "compiler",
        "ltcgc",
        "ascii text",
        "redacted for",
        "postal code",
        "privacy tech",
        "stateprovince",
        "server",
        "registrar abuse",
        "registrant name",
        "domain id",
        "iana id",
        "admin country",
        "date",
        "key identifier",
        "number",
        "issuer",
        "cus cnlet",
        "x3 olet",
        "subject public",
        "key info",
        "key algorithm",
        "x509v3 subject",
        "x509v3 key",
        "delegated",
        "unverified",
        "record type",
        "ttl value",
        "homenet",
        "0xf82",
        "externalnet",
        "policy ip",
        "check domain",
        "tls sni",
        "high",
        "informational",
        "registry keys",
        "nothing",
        "mutexes nothing",
        "parent pid",
        "full path",
        "command line",
        "read files",
        "apis nothing",
        "pe file",
        "performs dns",
        "network info",
        "processes extra",
        "aslr",
        "sample",
        "t1055 process",
        "overview",
        "mitre attack",
        "overview zenbox",
        "defense evasion",
        "next",
        "generic cil",
        "executable",
        "mono",
        "win32 dynamic",
        "link library",
        "pe32 library",
        "file type",
        "python script",
        "python",
        "writes shell",
        "unicode text",
        "utf8 text",
        "ascii",
        "writes",
        "persistence",
        "info",
        "Expired certificate",
        "Drops",
        "Oa auth abuse [potential]"
      ],
      "references": [
        "http://iplogger.org/1tnbw7%0Ahttp://gsoftclean.top/ver.txt%0Ahttp://iplogger.org/1z9A57%0Ahttp://gsoftclean.top/main.exe%0Ahttp://gsoftclean.top/aus%0Ahttp://gsoftclean.top/settings.dll%0Ahttp://iplogger.org/1nLz47%0Ahttp://iplogger.org/1z6A57%0Ahttps://iplogger.org/1z6A57%0Ahttp://iplogger.org/1PMX37%0Ahttps://iplogger.org/1nLz47",
        "https://vtbehaviour.commondatastorage.googleapis.com/e920fc67e098b7a6f3a13d99935239edc4c6c799bbaf2126c28da9b6e77fcf6f_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1779645922&Signature=JwLo32luwQokWOHR7lJz4dmUcLMQf18tKN2sLujlReeuplXL3B7kObdnC6EAKvj0%2FbPufiSY60CcdkPZ0L38f2ezSQ%2FpUd%2B9vwTI0sIkA%2BKOPYbhRV0zr7%2FH0rSo%2Fe1bb7p3YS9o0fzclIJ9iT6lWjLBnyAgZ4ZvwYmLkJk2x9beiNvBoWd5BPX2QLlZXDEzKgUbGKGGjHZQPfSIi3YI3zIRo16YJkaQzjxGBhhyGB4Ao8%2Fr",
        "https://vtbehaviour.commondatastorage.googleapis.com/e920fc67e098b7a6f3a13d99935239edc4c6c799bbaf2126c28da9b6e77fcf6f_Zenbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1779646024&Signature=GY3f%2BonWSmAE2r3xAvXp%2F0FLSZV%2B761HeH7MY%2F8jak5D8A6eAtDD6dxfY3qi8RFAYc2JIbh%2BWXZHSBZkxzZskVfm5S22fwOHMoCy9ezLI3%2BUbKxsL0uv64YuKmYd8s9FPp4wHA7tAXPPEMApUtclPZEQeo1AHVK7AN9zQZqAGYGnbfQtD1Ew5Bny5yT6axRterHcQPbXI8aPUvmJjP0131Op%2FKquhhierCzlcA3JIPWrYGomlInU9wZg",
        "https://vtbehaviour.commondatastorage.googleapis.com/8ed092fba4497e2cdde226956c589a21ccfb01c1a23305c029746d6f3f8441f2_Zenbox%20Linux.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1779646404&Signature=RAWN3ziUE4nt7cOF13GailGKiIaXg1kyzWnV3ohWPQWImilq1jkY6T9cnu7vh%2F0SwtRBev83RCV6GntS%2BJCyx7SBzUDQfqgPb3FwbcVEKgVziqaqJnxUSRgT0fWVsRCXJCisv9WjaxDGYcpAG8VMSXObs0HpYbgKvL%2FmbwN2wmzCCwSIiyGZj72303oaIQHVyqX9LoYWhs16g1xe%2B%2BXBcJaVerKyva6h3EWLVO9dkwM0cWEidZPw"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1056",
          "name": "Input Capture",
          "display_name": "T1056 - Input Capture"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1095",
          "name": "Non-Application Layer Protocol",
          "display_name": "T1095 - Non-Application Layer Protocol"
        },
        {
          "id": "T1218",
          "name": "Signed Binary Proxy Execution",
          "display_name": "T1218 - Signed Binary Proxy Execution"
        },
        {
          "id": "T1497",
          "name": "Virtualization/Sandbox Evasion",
          "display_name": "T1497 - Virtualization/Sandbox Evasion"
        },
        {
          "id": "T1574",
          "name": "Hijack Execution Flow",
          "display_name": "T1574 - Hijack Execution Flow"
        },
        {
          "id": "T1036",
          "name": "Masquerading",
          "display_name": "T1036 - Masquerading"
        },
        {
          "id": "T1064",
          "name": "Scripting",
          "display_name": "T1064 - Scripting"
        },
        {
          "id": "T1083",
          "name": "File and Directory Discovery",
          "display_name": "T1083 - File and Directory Discovery"
        },
        {
          "id": "T1222",
          "name": "File and Directory Permissions Modification",
          "display_name": "T1222 - File and Directory Permissions Modification"
        },
        {
          "id": "T1518",
          "name": "Software Discovery",
          "display_name": "T1518 - Software Discovery"
        },
        {
          "id": "T1564",
          "name": "Hide Artifacts",
          "display_name": "T1564 - Hide Artifacts"
        },
        {
          "id": "T1573",
          "name": "Encrypted Channel",
          "display_name": "T1573 - Encrypted Channel"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 200,
        "domain": 530,
        "hostname": 84,
        "FileHash-SHA256": 1090,
        "FileHash-MD5": 104,
        "Mutex": 2,
        "FileHash-SHA1": 97,
        "IPv4": 58,
        "email": 1,
        "CVE": 1
      },
      "indicator_count": 2167,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 66,
      "modified_text": "7 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6a1340485f49d8abce143eea",
      "name": "An error occurred: breadcrumb. IpLogger - piggy back on @skocherhan",
      "description": "[Find out the best IP logging tools and tools at  \u00c2\u00a31.5m in the UK, Ireland, Wales, Scotland and Northern Ireland on the website+ here is the full list.]",
      "modified": "2026-05-24T18:15:36.238000",
      "created": "2026-05-24T18:15:36.238000",
      "tags": [
        "::keywords_error_main",
        "sign",
        "url shortener",
        "track phone",
        "tracking pixel",
        "my ip",
        "ip counters",
        "ip generator",
        "internet",
        "best ip",
        "logger",
        "accept",
        "pe32",
        "intel",
        "ms windows",
        "win16 ne",
        "icons library",
        "os2 executable",
        "pe32 compiler",
        "exe32",
        "compiler",
        "ltcgc",
        "ascii text",
        "redacted for",
        "postal code",
        "privacy tech",
        "stateprovince",
        "server",
        "registrar abuse",
        "registrant name",
        "domain id",
        "iana id",
        "admin country",
        "date",
        "key identifier",
        "number",
        "issuer",
        "cus cnlet",
        "x3 olet",
        "subject public",
        "key info",
        "key algorithm",
        "x509v3 subject",
        "x509v3 key",
        "delegated",
        "unverified",
        "record type",
        "ttl value",
        "homenet",
        "0xf82",
        "externalnet",
        "policy ip",
        "check domain",
        "tls sni",
        "high",
        "informational",
        "registry keys",
        "nothing",
        "mutexes nothing",
        "parent pid",
        "full path",
        "command line",
        "read files",
        "apis nothing",
        "pe file",
        "performs dns",
        "network info",
        "processes extra",
        "aslr",
        "sample",
        "t1055 process",
        "overview",
        "mitre attack",
        "overview zenbox",
        "defense evasion",
        "next",
        "generic cil",
        "executable",
        "mono",
        "win32 dynamic",
        "link library",
        "pe32 library",
        "file type",
        "python script",
        "python",
        "writes shell",
        "unicode text",
        "utf8 text",
        "ascii",
        "writes",
        "persistence",
        "info",
        "Expired certificate",
        "Drops",
        "Oa auth abuse [potential]"
      ],
      "references": [
        "http://iplogger.org/1tnbw7%0Ahttp://gsoftclean.top/ver.txt%0Ahttp://iplogger.org/1z9A57%0Ahttp://gsoftclean.top/main.exe%0Ahttp://gsoftclean.top/aus%0Ahttp://gsoftclean.top/settings.dll%0Ahttp://iplogger.org/1nLz47%0Ahttp://iplogger.org/1z6A57%0Ahttps://iplogger.org/1z6A57%0Ahttp://iplogger.org/1PMX37%0Ahttps://iplogger.org/1nLz47",
        "https://vtbehaviour.commondatastorage.googleapis.com/e920fc67e098b7a6f3a13d99935239edc4c6c799bbaf2126c28da9b6e77fcf6f_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1779645922&Signature=JwLo32luwQokWOHR7lJz4dmUcLMQf18tKN2sLujlReeuplXL3B7kObdnC6EAKvj0%2FbPufiSY60CcdkPZ0L38f2ezSQ%2FpUd%2B9vwTI0sIkA%2BKOPYbhRV0zr7%2FH0rSo%2Fe1bb7p3YS9o0fzclIJ9iT6lWjLBnyAgZ4ZvwYmLkJk2x9beiNvBoWd5BPX2QLlZXDEzKgUbGKGGjHZQPfSIi3YI3zIRo16YJkaQzjxGBhhyGB4Ao8%2Fr",
        "https://vtbehaviour.commondatastorage.googleapis.com/e920fc67e098b7a6f3a13d99935239edc4c6c799bbaf2126c28da9b6e77fcf6f_Zenbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1779646024&Signature=GY3f%2BonWSmAE2r3xAvXp%2F0FLSZV%2B761HeH7MY%2F8jak5D8A6eAtDD6dxfY3qi8RFAYc2JIbh%2BWXZHSBZkxzZskVfm5S22fwOHMoCy9ezLI3%2BUbKxsL0uv64YuKmYd8s9FPp4wHA7tAXPPEMApUtclPZEQeo1AHVK7AN9zQZqAGYGnbfQtD1Ew5Bny5yT6axRterHcQPbXI8aPUvmJjP0131Op%2FKquhhierCzlcA3JIPWrYGomlInU9wZg",
        "https://vtbehaviour.commondatastorage.googleapis.com/8ed092fba4497e2cdde226956c589a21ccfb01c1a23305c029746d6f3f8441f2_Zenbox%20Linux.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1779646404&Signature=RAWN3ziUE4nt7cOF13GailGKiIaXg1kyzWnV3ohWPQWImilq1jkY6T9cnu7vh%2F0SwtRBev83RCV6GntS%2BJCyx7SBzUDQfqgPb3FwbcVEKgVziqaqJnxUSRgT0fWVsRCXJCisv9WjaxDGYcpAG8VMSXObs0HpYbgKvL%2FmbwN2wmzCCwSIiyGZj72303oaIQHVyqX9LoYWhs16g1xe%2B%2BXBcJaVerKyva6h3EWLVO9dkwM0cWEidZPw"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1056",
          "name": "Input Capture",
          "display_name": "T1056 - Input Capture"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1095",
          "name": "Non-Application Layer Protocol",
          "display_name": "T1095 - Non-Application Layer Protocol"
        },
        {
          "id": "T1218",
          "name": "Signed Binary Proxy Execution",
          "display_name": "T1218 - Signed Binary Proxy Execution"
        },
        {
          "id": "T1497",
          "name": "Virtualization/Sandbox Evasion",
          "display_name": "T1497 - Virtualization/Sandbox Evasion"
        },
        {
          "id": "T1574",
          "name": "Hijack Execution Flow",
          "display_name": "T1574 - Hijack Execution Flow"
        },
        {
          "id": "T1036",
          "name": "Masquerading",
          "display_name": "T1036 - Masquerading"
        },
        {
          "id": "T1064",
          "name": "Scripting",
          "display_name": "T1064 - Scripting"
        },
        {
          "id": "T1083",
          "name": "File and Directory Discovery",
          "display_name": "T1083 - File and Directory Discovery"
        },
        {
          "id": "T1222",
          "name": "File and Directory Permissions Modification",
          "display_name": "T1222 - File and Directory Permissions Modification"
        },
        {
          "id": "T1518",
          "name": "Software Discovery",
          "display_name": "T1518 - Software Discovery"
        },
        {
          "id": "T1564",
          "name": "Hide Artifacts",
          "display_name": "T1564 - Hide Artifacts"
        },
        {
          "id": "T1573",
          "name": "Encrypted Channel",
          "display_name": "T1573 - Encrypted Channel"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 200,
        "domain": 530,
        "hostname": 84,
        "FileHash-SHA256": 1090,
        "FileHash-MD5": 104,
        "Mutex": 2,
        "FileHash-SHA1": 97,
        "IPv4": 58,
        "email": 1,
        "CVE": 1
      },
      "indicator_count": 2167,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 66,
      "modified_text": "7 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "https://iplogger.org/1nLz4",
    "type": "URL"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "https://iplogger.org/1nLz4",
    "type": "URL",
    "found": false,
    "verdict": "clean",
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780255521.8144505
}