{
  "type": "URL",
  "indicator": "https://klingxai.com",
  "general": {
    "sections": [
      "general",
      "url_list",
      "http_scans",
      "screenshot"
    ],
    "indicator": "https://klingxai.com",
    "type": "url",
    "type_title": "URL",
    "validation": [],
    "base_indicator": {
      "id": 4071324703,
      "indicator": "https://klingxai.com",
      "type": "URL",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 2,
      "pulses": [
        {
          "id": "6836fce0d7f64f82186e780a",
          "name": "Text-to-Malware: How Cybercriminals Weaponize Fake AI-Themed Websites | Google Cloud Blog",
          "description": "A study by Mandiant Threat Defense and Google Cloud Next shows how cybercriminals are weaponizing the interest in artificial intelligence (AI) through fake websites and malicious social media ads, including Facebook and LinkedIn.",
          "modified": "2025-05-28T12:09:04.021000",
          "created": "2025-05-28T12:09:04.021000",
          "tags": [
            "protobuf",
            "hkcusoftware",
            "urls",
            "webdrivers",
            "figure",
            "threat intelligence",
            "frostrift",
            "starkveil",
            "xworm",
            "grimpull"
          ],
          "references": [
            "https://cloud.google.com/blog/topics/threat-intelligence/cybercriminals-weaponize-fake-ai-websites/"
          ],
          "public": 1,
          "adversary": "Figure",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Threat Intelligence",
              "display_name": "Threat Intelligence",
              "target": null
            },
            {
              "id": "FROSTRIFT",
              "display_name": "FROSTRIFT",
              "target": null
            },
            {
              "id": "STARKVEIL",
              "display_name": "STARKVEIL",
              "target": null
            },
            {
              "id": "XWORM",
              "display_name": "XWORM",
              "target": null
            },
            {
              "id": "GRIMPULL",
              "display_name": "GRIMPULL",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1056",
              "name": "Input Capture",
              "display_name": "T1056 - Input Capture"
            },
            {
              "id": "T1574",
              "name": "Hijack Execution Flow",
              "display_name": "T1574 - Hijack Execution Flow"
            },
            {
              "id": "T1090",
              "name": "Proxy",
              "display_name": "T1090 - Proxy"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 8,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "PetrP.73",
            "id": "154605",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 9,
            "URL": 7,
            "YARA": 2,
            "domain": 30,
            "hostname": 2
          },
          "indicator_count": 50,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 539,
          "modified_text": "367 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "68361f3322abf0f14a1dc6bb",
          "name": "Text-to-Malware: How Cybercriminals Weaponize Fake AI-Themed Websites | Google Cloud Blog",
          "description": "A study by Mandiant Threat Defense and Google Cloud Next shows how cybercriminals are weaponizing the interest in artificial intelligence (AI) through fake websites and malicious social media ads, including Facebook and LinkedIn.",
          "modified": "2025-05-27T20:23:15.312000",
          "created": "2025-05-27T20:23:15.312000",
          "tags": [
            "protobuf",
            "hkcusoftware",
            "urls",
            "webdrivers",
            "figure",
            "threat intelligence",
            "frostrift",
            "starkveil",
            "xworm",
            "grimpull"
          ],
          "references": [
            "https://cloud.google.com/blog/topics/threat-intelligence/cybercriminals-weaponize-fake-ai-websites"
          ],
          "public": 1,
          "adversary": "Figure",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Threat Intelligence",
              "display_name": "Threat Intelligence",
              "target": null
            },
            {
              "id": "FROSTRIFT",
              "display_name": "FROSTRIFT",
              "target": null
            },
            {
              "id": "STARKVEIL",
              "display_name": "STARKVEIL",
              "target": null
            },
            {
              "id": "XWORM",
              "display_name": "XWORM",
              "target": null
            },
            {
              "id": "GRIMPULL",
              "display_name": "GRIMPULL",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1056",
              "name": "Input Capture",
              "display_name": "T1056 - Input Capture"
            },
            {
              "id": "T1574",
              "name": "Hijack Execution Flow",
              "display_name": "T1574 - Hijack Execution Flow"
            },
            {
              "id": "T1090",
              "name": "Proxy",
              "display_name": "T1090 - Proxy"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 11,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "PetrP.73",
            "id": "154605",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 9,
            "URL": 7,
            "YARA": 2,
            "domain": 30,
            "hostname": 2
          },
          "indicator_count": 50,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 539,
          "modified_text": "368 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "https://cloud.google.com/blog/topics/threat-intelligence/cybercriminals-weaponize-fake-ai-websites/",
        "https://cloud.google.com/blog/topics/threat-intelligence/cybercriminals-weaponize-fake-ai-websites"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 0
        },
        "other": {
          "adversary": [
            "Figure"
          ],
          "malware_families": [
            "Threat intelligence",
            "Xworm",
            "Frostrift",
            "Grimpull",
            "Starkveil"
          ],
          "industries": [],
          "unique_indicators": 50
        }
      }
    },
    "false_positive": [],
    "alexa": "http://www.alexa.com/siteinfo/klingxai.com",
    "whois": "http://whois.domaintools.com/klingxai.com",
    "domain": "klingxai.com",
    "hostname": "Unavailable"
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 2,
  "pulses": [
    {
      "id": "6836fce0d7f64f82186e780a",
      "name": "Text-to-Malware: How Cybercriminals Weaponize Fake AI-Themed Websites | Google Cloud Blog",
      "description": "A study by Mandiant Threat Defense and Google Cloud Next shows how cybercriminals are weaponizing the interest in artificial intelligence (AI) through fake websites and malicious social media ads, including Facebook and LinkedIn.",
      "modified": "2025-05-28T12:09:04.021000",
      "created": "2025-05-28T12:09:04.021000",
      "tags": [
        "protobuf",
        "hkcusoftware",
        "urls",
        "webdrivers",
        "figure",
        "threat intelligence",
        "frostrift",
        "starkveil",
        "xworm",
        "grimpull"
      ],
      "references": [
        "https://cloud.google.com/blog/topics/threat-intelligence/cybercriminals-weaponize-fake-ai-websites/"
      ],
      "public": 1,
      "adversary": "Figure",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Threat Intelligence",
          "display_name": "Threat Intelligence",
          "target": null
        },
        {
          "id": "FROSTRIFT",
          "display_name": "FROSTRIFT",
          "target": null
        },
        {
          "id": "STARKVEIL",
          "display_name": "STARKVEIL",
          "target": null
        },
        {
          "id": "XWORM",
          "display_name": "XWORM",
          "target": null
        },
        {
          "id": "GRIMPULL",
          "display_name": "GRIMPULL",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1056",
          "name": "Input Capture",
          "display_name": "T1056 - Input Capture"
        },
        {
          "id": "T1574",
          "name": "Hijack Execution Flow",
          "display_name": "T1574 - Hijack Execution Flow"
        },
        {
          "id": "T1090",
          "name": "Proxy",
          "display_name": "T1090 - Proxy"
        },
        {
          "id": "T1036",
          "name": "Masquerading",
          "display_name": "T1036 - Masquerading"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 8,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "PetrP.73",
        "id": "154605",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 9,
        "URL": 7,
        "YARA": 2,
        "domain": 30,
        "hostname": 2
      },
      "indicator_count": 50,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 539,
      "modified_text": "367 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "68361f3322abf0f14a1dc6bb",
      "name": "Text-to-Malware: How Cybercriminals Weaponize Fake AI-Themed Websites | Google Cloud Blog",
      "description": "A study by Mandiant Threat Defense and Google Cloud Next shows how cybercriminals are weaponizing the interest in artificial intelligence (AI) through fake websites and malicious social media ads, including Facebook and LinkedIn.",
      "modified": "2025-05-27T20:23:15.312000",
      "created": "2025-05-27T20:23:15.312000",
      "tags": [
        "protobuf",
        "hkcusoftware",
        "urls",
        "webdrivers",
        "figure",
        "threat intelligence",
        "frostrift",
        "starkveil",
        "xworm",
        "grimpull"
      ],
      "references": [
        "https://cloud.google.com/blog/topics/threat-intelligence/cybercriminals-weaponize-fake-ai-websites"
      ],
      "public": 1,
      "adversary": "Figure",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Threat Intelligence",
          "display_name": "Threat Intelligence",
          "target": null
        },
        {
          "id": "FROSTRIFT",
          "display_name": "FROSTRIFT",
          "target": null
        },
        {
          "id": "STARKVEIL",
          "display_name": "STARKVEIL",
          "target": null
        },
        {
          "id": "XWORM",
          "display_name": "XWORM",
          "target": null
        },
        {
          "id": "GRIMPULL",
          "display_name": "GRIMPULL",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1056",
          "name": "Input Capture",
          "display_name": "T1056 - Input Capture"
        },
        {
          "id": "T1574",
          "name": "Hijack Execution Flow",
          "display_name": "T1574 - Hijack Execution Flow"
        },
        {
          "id": "T1090",
          "name": "Proxy",
          "display_name": "T1090 - Proxy"
        },
        {
          "id": "T1036",
          "name": "Masquerading",
          "display_name": "T1036 - Masquerading"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 11,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "PetrP.73",
        "id": "154605",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 9,
        "URL": 7,
        "YARA": 2,
        "domain": 30,
        "hostname": 2
      },
      "indicator_count": 50,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 539,
      "modified_text": "368 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "https://klingxai.com",
    "type": "URL"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "https://klingxai.com",
    "type": "URL",
    "found": false,
    "verdict": "clean",
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780224186.1372454
}