{
  "type": "URL",
  "indicator": "https://j.leboo668.com/",
  "general": {
    "sections": [
      "general",
      "url_list",
      "http_scans",
      "screenshot"
    ],
    "indicator": "https://j.leboo668.com/",
    "type": "url",
    "type_title": "URL",
    "validation": [],
    "base_indicator": {
      "id": 3883070035,
      "indicator": "https://j.leboo668.com/",
      "type": "URL",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 3,
      "pulses": [
        {
          "id": "690e8b773dc39921d88abd44",
          "name": "Nanocore - Affected",
          "description": "- wmsspacer.gif\n| Photography: WMSspacer.gif, |[wmstransparent.org,]\n* YARA Detections : \nDotNET_Reactor\nSystem.Security.Cryptography.AesCryptoServiceProvider\nSystem.Security.Cryptography\nSystem.Security.Cryptography ~\nI CryptoTransform |\n Wmsspacer, i.g.sg.js..png.com, on-screen.|",
          "modified": "2025-12-07T23:02:29.645000",
          "created": "2025-11-08T00:14:47.600000",
          "tags": [
            "hgnvastlaiz",
            "read c",
            "medium",
            "rgba",
            "memcommit",
            "delete",
            "png image",
            "unicode",
            "dock",
            "execution",
            "malware",
            "crlf line",
            "speichermedium",
            "productversion",
            "fileversion",
            "engine dll",
            "internalname",
            "einstellungen",
            "comodo ca",
            "limited st",
            "yara detections",
            "next pe",
            "eula",
            "policy",
            "direct",
            "opencandy",
            "suspicious_write_exe",
            "network_icmp",
            "process_martian",
            "present jun",
            "present jul",
            "domain",
            "united",
            "ip address",
            "unknown ns",
            "ms windows",
            "intel",
            "verisign",
            "time stamping",
            "unknown",
            "class",
            "write",
            "markus",
            "temple",
            "msie",
            "windows nt",
            "get http",
            "lehash",
            "av detections",
            "ids detections",
            "alerts",
            "file score",
            "low risk",
            "compromised_site_redirector_fromcharcode",
            "present aug",
            "passive dns",
            "all ipv4",
            "urls",
            "files",
            "hosting",
            "america flag",
            "win32",
            "ipv4 add",
            "signed file, valid signature. revoked.",
            "united states",
            "pws",
            "atros",
            "fiha",
            "search",
            "entries",
            "present oct",
            "next associated",
            "show",
            "high",
            "wow64",
            "slcc2",
            "next",
            "domain add",
            "poland",
            "poland unknown",
            "ipv4",
            "location poland",
            "poland asn",
            "et policy",
            "pe exe",
            "dll windows",
            "amazon s3",
            "location united",
            "associated urls",
            "date checked",
            "url hostname",
            "server response",
            "google safe",
            "results feb",
            "nanocore",
            "url add",
            "http",
            "related nids",
            "files location",
            "flag united",
            "malicious image",
            "files domain",
            "files related",
            "pulses otx",
            "related tags",
            "resources whois",
            "virustotal",
            "present sep",
            "status",
            "present nov",
            "present mar",
            "trojan",
            "script script",
            "div div",
            "link",
            "a li",
            "meta",
            "sweden",
            "invalid url",
            "head title",
            "title head",
            "reference",
            "bad request",
            "server",
            "netherlands",
            "creation date",
            "date",
            "running server",
            "ahmann",
            "christopher",
            "p",
            "tam",
            "legal",
            "treece",
            "alfrey",
            "muscat",
            "adversaries",
            "cyber crime",
            "quasi",
            "government"
          ],
          "references": [
            "wmsspacer.gif : 548f2d6f4d0d820c6c5ffbeffcbd7f0e73193e2932eefe542accc84762deec87",
            "ceidg.gov.pl \u2022 https://www.csrc.gov.cn.lxcvc.com/ \u2022 www.alt.krasnopil-silrada.gov.ua",
            "http://www.mof.gov.cn.lxcvc.com/ \u2022  http://www.mohurd.gov.cn.lxcvc.com/ \u2022",
            "www.opencandy.com",
            "http://www.opencandy.com/privacy \u2022 http://www.opencandy.com/privacy-policy. \u2022  license@opencandy.com \u2022",
            "Yara Detections : compromised_site_redirector_fromcharcode",
            "Matches rule: skip20_sqllang_hook from ruleset skip20_sqllang_hook by Mathieu Tartare <mathieu.tartare@eset.com>",
            "Matches rule Adobe_XMP_Identifier from ruleset Adobe_XMP_Identifier by InQuest Labs",
            "http://pcoptimizerpro.com/eula.aspx \u2022 http://www.pcoptimizerpro.com/privacypolicy.aspx",
            "pcoptimizerpro.com \u2022 www.pcoptimizerpro.com",
            "PE EXE UpdatesDll.dll : 69081ab853021bd28bf7fb1eb4eac3199623c8ed413589e6f3898806a15f0f23",
            "YARA: DotNET_Reactor System.Security.Cryptography.AesCryptoServiceProvider System.Security.Cryptography System.Security.Cryptography ICryptoTransform",
            "https://img.fkcdn.com/image/kg8avm80/mobile/j/f/9/apple-iphone-12-dummyapplefsn-200x200-imafwg8dkyh2zgrh.jpeg",
            "https://heavyfetish.com/search/CHEESE-PIZZA-porn/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "Win.Trojan.Nanocore-5",
              "display_name": "Win.Trojan.Nanocore-5",
              "target": null
            },
            {
              "id": "Win.Trojan.Adinstall-2",
              "display_name": "Win.Trojan.Adinstall-2",
              "target": null
            },
            {
              "id": "PSW.Generic13",
              "display_name": "PSW.Generic13",
              "target": null
            },
            {
              "id": "Atros.UPK",
              "display_name": "Atros.UPK",
              "target": null
            },
            {
              "id": "Luhe.Fiha.A",
              "display_name": "Luhe.Fiha.A",
              "target": null
            },
            {
              "id": "Pua.Optimizerpro/PCOptimizerPro",
              "display_name": "Pua.Optimizerpro/PCOptimizerPro",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1053",
              "name": "Scheduled Task/Job",
              "display_name": "T1053 - Scheduled Task/Job"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1119",
              "name": "Automated Collection",
              "display_name": "T1119 - Automated Collection"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1143",
              "name": "Hidden Window",
              "display_name": "T1143 - Hidden Window"
            },
            {
              "id": "T1102",
              "name": "Web Service",
              "display_name": "T1102 - Web Service"
            },
            {
              "id": "T1491.001",
              "name": "Internal Defacement",
              "display_name": "T1491.001 - Internal Defacement"
            },
            {
              "id": "T1204.003",
              "name": "Malicious Image",
              "display_name": "T1204.003 - Malicious Image"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 12,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 1,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Q.Vashti",
            "id": "337942",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 753,
            "FileHash-SHA1": 622,
            "FileHash-SHA256": 4336,
            "URL": 2448,
            "domain": 300,
            "hostname": 788,
            "CVE": 1,
            "email": 4
          },
          "indicator_count": 9252,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 142,
          "modified_text": "174 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6650751b8dd6c7d00f0d7478",
          "name": "ET INFO Terse | Apple | Win.Trojan.Zbot-6598057-0",
          "description": "Tags, results generated by Level Blue OTX. AlienVault\nMy limited research results: \nApple | CIDR\n17.0.0.0/8\nFileHash-SHA256 d9ff17dd19a01ad64a77df6837e566319d16a235ac7223b9f565f470e57154c8 | Antivirus Detections\nWin32:Dropper-gen, Adware.Xadupi.B, Mirai, Win.Trojan.Zbot-6598057-0,\na variant of Win32/ELEX.IE potentially unwanted, Adware.Xadupi.B, Artemis!69E9EFD2E75E\nIDS Detections:\nET CURRENT_EVENTS Terse alphanumeric executable downloader high likelihood of being hostile.\nYara Detections: dbgdetect_funcs,\nAlerts: injection_runpe,\nnetwork_icmp,\nallocates_execute_remote_process,\npersistence_autorun,\ncreates_service,\ninjection_modifies_memory,\ninjection_write_memory,\nprocess_martian,\nransomware_extensions,\nransomware_mass_file_delete",
          "modified": "2024-06-23T10:00:24.005000",
          "created": "2024-05-24T11:08:10.044000",
          "tags": [
            "technology",
            "apple computer",
            "dns replication",
            "date",
            "domain",
            "lookups",
            "city",
            "apple abuse",
            "orgid",
            "rtechhandle",
            "june",
            "threat roundup",
            "triad",
            "usps",
            "us citizens",
            "data theft",
            "august",
            "apple",
            "sweet quadreams",
            "spyware vendor",
            "get http",
            "png image",
            "rgba",
            "ms windows",
            "united",
            "intel",
            "windows nt",
            "as16509",
            "pe32",
            "crlf line",
            "win32",
            "write",
            "next",
            "artemis",
            "malware",
            "copy",
            "cname",
            "unknown",
            "passive dns",
            "scan endpoints",
            "all scoreblue",
            "pulse submit",
            "url analysis",
            "urls",
            "pagewritecopy",
            "pageexecuteread",
            "nx00xffxe2",
            "nx00xc7d",
            "memcommit",
            "pagenoaccess",
            "memreserve",
            "service",
            "high process",
            "injection t1055"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1031",
              "name": "Modify Existing Service",
              "display_name": "T1031 - Modify Existing Service"
            },
            {
              "id": "T1053",
              "name": "Scheduled Task/Job",
              "display_name": "T1053 - Scheduled Task/Job"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1060",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1060 - Registry Run Keys / Startup Folder"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 20,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 1524,
            "CIDR": 1,
            "URL": 5189,
            "email": 2,
            "hostname": 867,
            "FileHash-MD5": 117,
            "FileHash-SHA1": 27,
            "domain": 403
          },
          "indicator_count": 8130,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 228,
          "modified_text": "707 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "66507a6eb3fde0552a6ebd9d",
          "name": "Sweet QuaDreams Apple | Hostile Spy campaign | Service modifier (Updated) ",
          "description": "",
          "modified": "2024-06-23T10:00:24.005000",
          "created": "2024-05-24T11:30:54.138000",
          "tags": [
            "technology",
            "apple computer",
            "dns replication",
            "date",
            "domain",
            "lookups",
            "city",
            "apple abuse",
            "orgid",
            "rtechhandle",
            "june",
            "threat roundup",
            "triad",
            "usps",
            "us citizens",
            "data theft",
            "august",
            "apple",
            "sweet quadreams",
            "spyware vendor",
            "get http",
            "png image",
            "rgba",
            "ms windows",
            "united",
            "intel",
            "windows nt",
            "as16509",
            "pe32",
            "crlf line",
            "win32",
            "write",
            "next",
            "artemis",
            "malware",
            "copy",
            "cname",
            "unknown",
            "passive dns",
            "scan endpoints",
            "all scoreblue",
            "pulse submit",
            "url analysis",
            "urls",
            "pagewritecopy",
            "pageexecuteread",
            "nx00xffxe2",
            "nx00xc7d",
            "memcommit",
            "pagenoaccess",
            "memreserve",
            "service",
            "high process",
            "injection t1055"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1031",
              "name": "Modify Existing Service",
              "display_name": "T1031 - Modify Existing Service"
            },
            {
              "id": "T1053",
              "name": "Scheduled Task/Job",
              "display_name": "T1053 - Scheduled Task/Job"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1060",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1060 - Registry Run Keys / Startup Folder"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": "6650751b8dd6c7d00f0d7478",
          "export_count": 18,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 1524,
            "CIDR": 1,
            "URL": 5189,
            "email": 2,
            "hostname": 867,
            "FileHash-MD5": 117,
            "FileHash-SHA1": 27,
            "domain": 403
          },
          "indicator_count": 8130,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 229,
          "modified_text": "707 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "Yara Detections : compromised_site_redirector_fromcharcode",
        "Matches rule Adobe_XMP_Identifier from ruleset Adobe_XMP_Identifier by InQuest Labs",
        "https://heavyfetish.com/search/CHEESE-PIZZA-porn/",
        "ceidg.gov.pl \u2022 https://www.csrc.gov.cn.lxcvc.com/ \u2022 www.alt.krasnopil-silrada.gov.ua",
        "http://pcoptimizerpro.com/eula.aspx \u2022 http://www.pcoptimizerpro.com/privacypolicy.aspx",
        "PE EXE UpdatesDll.dll : 69081ab853021bd28bf7fb1eb4eac3199623c8ed413589e6f3898806a15f0f23",
        "YARA: DotNET_Reactor System.Security.Cryptography.AesCryptoServiceProvider System.Security.Cryptography System.Security.Cryptography ICryptoTransform",
        "http://www.mof.gov.cn.lxcvc.com/ \u2022  http://www.mohurd.gov.cn.lxcvc.com/ \u2022",
        "Matches rule: skip20_sqllang_hook from ruleset skip20_sqllang_hook by Mathieu Tartare <mathieu.tartare@eset.com>",
        "http://www.opencandy.com/privacy \u2022 http://www.opencandy.com/privacy-policy. \u2022  license@opencandy.com \u2022",
        "www.opencandy.com",
        "wmsspacer.gif : 548f2d6f4d0d820c6c5ffbeffcbd7f0e73193e2932eefe542accc84762deec87",
        "https://img.fkcdn.com/image/kg8avm80/mobile/j/f/9/apple-iphone-12-dummyapplefsn-200x200-imafwg8dkyh2zgrh.jpeg",
        "pcoptimizerpro.com \u2022 www.pcoptimizerpro.com"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 0
        },
        "other": {
          "adversary": [],
          "malware_families": [
            "Luhe.fiha.a",
            "Pua.optimizerpro/pcoptimizerpro",
            "Atros.upk",
            "Win.trojan.nanocore-5",
            "Psw.generic13",
            "Win.trojan.adinstall-2"
          ],
          "industries": [],
          "unique_indicators": 17505
        }
      }
    },
    "false_positive": [],
    "alexa": "http://www.alexa.com/siteinfo/leboo668.com",
    "whois": "http://whois.domaintools.com/leboo668.com",
    "domain": "leboo668.com",
    "hostname": "j.leboo668.com"
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 3,
  "pulses": [
    {
      "id": "690e8b773dc39921d88abd44",
      "name": "Nanocore - Affected",
      "description": "- wmsspacer.gif\n| Photography: WMSspacer.gif, |[wmstransparent.org,]\n* YARA Detections : \nDotNET_Reactor\nSystem.Security.Cryptography.AesCryptoServiceProvider\nSystem.Security.Cryptography\nSystem.Security.Cryptography ~\nI CryptoTransform |\n Wmsspacer, i.g.sg.js..png.com, on-screen.|",
      "modified": "2025-12-07T23:02:29.645000",
      "created": "2025-11-08T00:14:47.600000",
      "tags": [
        "hgnvastlaiz",
        "read c",
        "medium",
        "rgba",
        "memcommit",
        "delete",
        "png image",
        "unicode",
        "dock",
        "execution",
        "malware",
        "crlf line",
        "speichermedium",
        "productversion",
        "fileversion",
        "engine dll",
        "internalname",
        "einstellungen",
        "comodo ca",
        "limited st",
        "yara detections",
        "next pe",
        "eula",
        "policy",
        "direct",
        "opencandy",
        "suspicious_write_exe",
        "network_icmp",
        "process_martian",
        "present jun",
        "present jul",
        "domain",
        "united",
        "ip address",
        "unknown ns",
        "ms windows",
        "intel",
        "verisign",
        "time stamping",
        "unknown",
        "class",
        "write",
        "markus",
        "temple",
        "msie",
        "windows nt",
        "get http",
        "lehash",
        "av detections",
        "ids detections",
        "alerts",
        "file score",
        "low risk",
        "compromised_site_redirector_fromcharcode",
        "present aug",
        "passive dns",
        "all ipv4",
        "urls",
        "files",
        "hosting",
        "america flag",
        "win32",
        "ipv4 add",
        "signed file, valid signature. revoked.",
        "united states",
        "pws",
        "atros",
        "fiha",
        "search",
        "entries",
        "present oct",
        "next associated",
        "show",
        "high",
        "wow64",
        "slcc2",
        "next",
        "domain add",
        "poland",
        "poland unknown",
        "ipv4",
        "location poland",
        "poland asn",
        "et policy",
        "pe exe",
        "dll windows",
        "amazon s3",
        "location united",
        "associated urls",
        "date checked",
        "url hostname",
        "server response",
        "google safe",
        "results feb",
        "nanocore",
        "url add",
        "http",
        "related nids",
        "files location",
        "flag united",
        "malicious image",
        "files domain",
        "files related",
        "pulses otx",
        "related tags",
        "resources whois",
        "virustotal",
        "present sep",
        "status",
        "present nov",
        "present mar",
        "trojan",
        "script script",
        "div div",
        "link",
        "a li",
        "meta",
        "sweden",
        "invalid url",
        "head title",
        "title head",
        "reference",
        "bad request",
        "server",
        "netherlands",
        "creation date",
        "date",
        "running server",
        "ahmann",
        "christopher",
        "p",
        "tam",
        "legal",
        "treece",
        "alfrey",
        "muscat",
        "adversaries",
        "cyber crime",
        "quasi",
        "government"
      ],
      "references": [
        "wmsspacer.gif : 548f2d6f4d0d820c6c5ffbeffcbd7f0e73193e2932eefe542accc84762deec87",
        "ceidg.gov.pl \u2022 https://www.csrc.gov.cn.lxcvc.com/ \u2022 www.alt.krasnopil-silrada.gov.ua",
        "http://www.mof.gov.cn.lxcvc.com/ \u2022  http://www.mohurd.gov.cn.lxcvc.com/ \u2022",
        "www.opencandy.com",
        "http://www.opencandy.com/privacy \u2022 http://www.opencandy.com/privacy-policy. \u2022  license@opencandy.com \u2022",
        "Yara Detections : compromised_site_redirector_fromcharcode",
        "Matches rule: skip20_sqllang_hook from ruleset skip20_sqllang_hook by Mathieu Tartare <mathieu.tartare@eset.com>",
        "Matches rule Adobe_XMP_Identifier from ruleset Adobe_XMP_Identifier by InQuest Labs",
        "http://pcoptimizerpro.com/eula.aspx \u2022 http://www.pcoptimizerpro.com/privacypolicy.aspx",
        "pcoptimizerpro.com \u2022 www.pcoptimizerpro.com",
        "PE EXE UpdatesDll.dll : 69081ab853021bd28bf7fb1eb4eac3199623c8ed413589e6f3898806a15f0f23",
        "YARA: DotNET_Reactor System.Security.Cryptography.AesCryptoServiceProvider System.Security.Cryptography System.Security.Cryptography ICryptoTransform",
        "https://img.fkcdn.com/image/kg8avm80/mobile/j/f/9/apple-iphone-12-dummyapplefsn-200x200-imafwg8dkyh2zgrh.jpeg",
        "https://heavyfetish.com/search/CHEESE-PIZZA-porn/"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "Win.Trojan.Nanocore-5",
          "display_name": "Win.Trojan.Nanocore-5",
          "target": null
        },
        {
          "id": "Win.Trojan.Adinstall-2",
          "display_name": "Win.Trojan.Adinstall-2",
          "target": null
        },
        {
          "id": "PSW.Generic13",
          "display_name": "PSW.Generic13",
          "target": null
        },
        {
          "id": "Atros.UPK",
          "display_name": "Atros.UPK",
          "target": null
        },
        {
          "id": "Luhe.Fiha.A",
          "display_name": "Luhe.Fiha.A",
          "target": null
        },
        {
          "id": "Pua.Optimizerpro/PCOptimizerPro",
          "display_name": "Pua.Optimizerpro/PCOptimizerPro",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1053",
          "name": "Scheduled Task/Job",
          "display_name": "T1053 - Scheduled Task/Job"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1119",
          "name": "Automated Collection",
          "display_name": "T1119 - Automated Collection"
        },
        {
          "id": "T1129",
          "name": "Shared Modules",
          "display_name": "T1129 - Shared Modules"
        },
        {
          "id": "T1143",
          "name": "Hidden Window",
          "display_name": "T1143 - Hidden Window"
        },
        {
          "id": "T1102",
          "name": "Web Service",
          "display_name": "T1102 - Web Service"
        },
        {
          "id": "T1491.001",
          "name": "Internal Defacement",
          "display_name": "T1491.001 - Internal Defacement"
        },
        {
          "id": "T1204.003",
          "name": "Malicious Image",
          "display_name": "T1204.003 - Malicious Image"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 12,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 1,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Q.Vashti",
        "id": "337942",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 753,
        "FileHash-SHA1": 622,
        "FileHash-SHA256": 4336,
        "URL": 2448,
        "domain": 300,
        "hostname": 788,
        "CVE": 1,
        "email": 4
      },
      "indicator_count": 9252,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 142,
      "modified_text": "174 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6650751b8dd6c7d00f0d7478",
      "name": "ET INFO Terse | Apple | Win.Trojan.Zbot-6598057-0",
      "description": "Tags, results generated by Level Blue OTX. AlienVault\nMy limited research results: \nApple | CIDR\n17.0.0.0/8\nFileHash-SHA256 d9ff17dd19a01ad64a77df6837e566319d16a235ac7223b9f565f470e57154c8 | Antivirus Detections\nWin32:Dropper-gen, Adware.Xadupi.B, Mirai, Win.Trojan.Zbot-6598057-0,\na variant of Win32/ELEX.IE potentially unwanted, Adware.Xadupi.B, Artemis!69E9EFD2E75E\nIDS Detections:\nET CURRENT_EVENTS Terse alphanumeric executable downloader high likelihood of being hostile.\nYara Detections: dbgdetect_funcs,\nAlerts: injection_runpe,\nnetwork_icmp,\nallocates_execute_remote_process,\npersistence_autorun,\ncreates_service,\ninjection_modifies_memory,\ninjection_write_memory,\nprocess_martian,\nransomware_extensions,\nransomware_mass_file_delete",
      "modified": "2024-06-23T10:00:24.005000",
      "created": "2024-05-24T11:08:10.044000",
      "tags": [
        "technology",
        "apple computer",
        "dns replication",
        "date",
        "domain",
        "lookups",
        "city",
        "apple abuse",
        "orgid",
        "rtechhandle",
        "june",
        "threat roundup",
        "triad",
        "usps",
        "us citizens",
        "data theft",
        "august",
        "apple",
        "sweet quadreams",
        "spyware vendor",
        "get http",
        "png image",
        "rgba",
        "ms windows",
        "united",
        "intel",
        "windows nt",
        "as16509",
        "pe32",
        "crlf line",
        "win32",
        "write",
        "next",
        "artemis",
        "malware",
        "copy",
        "cname",
        "unknown",
        "passive dns",
        "scan endpoints",
        "all scoreblue",
        "pulse submit",
        "url analysis",
        "urls",
        "pagewritecopy",
        "pageexecuteread",
        "nx00xffxe2",
        "nx00xc7d",
        "memcommit",
        "pagenoaccess",
        "memreserve",
        "service",
        "high process",
        "injection t1055"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1031",
          "name": "Modify Existing Service",
          "display_name": "T1031 - Modify Existing Service"
        },
        {
          "id": "T1053",
          "name": "Scheduled Task/Job",
          "display_name": "T1053 - Scheduled Task/Job"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1060",
          "name": "Registry Run Keys / Startup Folder",
          "display_name": "T1060 - Registry Run Keys / Startup Folder"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 20,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "scoreblue",
        "id": "254100",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 1524,
        "CIDR": 1,
        "URL": 5189,
        "email": 2,
        "hostname": 867,
        "FileHash-MD5": 117,
        "FileHash-SHA1": 27,
        "domain": 403
      },
      "indicator_count": 8130,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 228,
      "modified_text": "707 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "66507a6eb3fde0552a6ebd9d",
      "name": "Sweet QuaDreams Apple | Hostile Spy campaign | Service modifier (Updated) ",
      "description": "",
      "modified": "2024-06-23T10:00:24.005000",
      "created": "2024-05-24T11:30:54.138000",
      "tags": [
        "technology",
        "apple computer",
        "dns replication",
        "date",
        "domain",
        "lookups",
        "city",
        "apple abuse",
        "orgid",
        "rtechhandle",
        "june",
        "threat roundup",
        "triad",
        "usps",
        "us citizens",
        "data theft",
        "august",
        "apple",
        "sweet quadreams",
        "spyware vendor",
        "get http",
        "png image",
        "rgba",
        "ms windows",
        "united",
        "intel",
        "windows nt",
        "as16509",
        "pe32",
        "crlf line",
        "win32",
        "write",
        "next",
        "artemis",
        "malware",
        "copy",
        "cname",
        "unknown",
        "passive dns",
        "scan endpoints",
        "all scoreblue",
        "pulse submit",
        "url analysis",
        "urls",
        "pagewritecopy",
        "pageexecuteread",
        "nx00xffxe2",
        "nx00xc7d",
        "memcommit",
        "pagenoaccess",
        "memreserve",
        "service",
        "high process",
        "injection t1055"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1031",
          "name": "Modify Existing Service",
          "display_name": "T1031 - Modify Existing Service"
        },
        {
          "id": "T1053",
          "name": "Scheduled Task/Job",
          "display_name": "T1053 - Scheduled Task/Job"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1060",
          "name": "Registry Run Keys / Startup Folder",
          "display_name": "T1060 - Registry Run Keys / Startup Folder"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": "6650751b8dd6c7d00f0d7478",
      "export_count": 18,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "scoreblue",
        "id": "254100",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 1524,
        "CIDR": 1,
        "URL": 5189,
        "email": 2,
        "hostname": 867,
        "FileHash-MD5": 117,
        "FileHash-SHA1": 27,
        "domain": 403
      },
      "indicator_count": 8130,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 229,
      "modified_text": "707 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "https://j.leboo668.com/",
    "type": "URL"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "https://j.leboo668.com/",
    "type": "URL",
    "found": false,
    "verdict": "clean",
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780225837.1822445
}