{
  "type": "URL",
  "indicator": "https://klyou.net",
  "general": {
    "sections": [
      "general",
      "url_list",
      "http_scans",
      "screenshot"
    ],
    "indicator": "https://klyou.net",
    "type": "url",
    "type_title": "URL",
    "validation": [],
    "base_indicator": {
      "id": 3918546547,
      "indicator": "https://klyou.net",
      "type": "URL",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 5,
      "pulses": [
        {
          "id": "6a19ab3077e26f1ba3c8cd51",
          "name": "Credit Q.Vashti \"Unknown - Established hacker group. Affects banking\" clone",
          "description": "",
          "modified": "2026-05-31T05:26:42.780000",
          "created": "2026-05-29T15:05:20.198000",
          "tags": [
            "united",
            "search",
            "entries",
            "unknown ns",
            "ip address",
            "creation date",
            "record value",
            "date",
            "showing",
            "moved",
            "body",
            "encrypt",
            "lowfi",
            "trojanspy",
            "checkin",
            "passive dns",
            "trojan",
            "next associated",
            "cryp",
            "win32",
            "phishing",
            "virtool",
            "hstr",
            "backdoor",
            "ipv4",
            "pulse pulses",
            "associated urls",
            "show",
            "date checked",
            "url hostname",
            "server response",
            "google safe",
            "results feb",
            "header http2",
            "accept encoding",
            "gmt related",
            "domains show",
            "domain related",
            "response ip",
            "address google",
            "safe browsing",
            "entries http",
            "scans show",
            "title",
            "link",
            "present mar",
            "meta",
            "starfield",
            "dynamicloader",
            "qaeaav12",
            "medium",
            "high",
            "malware",
            "windows wget",
            "qbeipbdii",
            "write",
            "suspicious",
            "copy",
            "yara rule",
            "gravityrat",
            "detectvm",
            "x00 x00",
            "x00x00",
            "doviacmd",
            "rootjob",
            "getfiles",
            "updateserver",
            "ethernetid",
            "unknown",
            "yara detections",
            "filehash",
            "sha256 add",
            "av detections",
            "ids detections",
            "alerts",
            "analysis date",
            "file score",
            "oinetsim",
            "oudevelopment",
            "write c",
            "demo",
            "mtb sep",
            "trojandropper",
            "cookie",
            "path max",
            "age86400 set",
            "win32qqpass sep",
            "results aug",
            "script urls",
            "script domains",
            "a domains",
            "cache control",
            "cache status",
            "fury",
            "zenedge",
            "present jun",
            "present dec",
            "present jan",
            "present nov",
            "for privacy",
            "present may",
            "name servers",
            "no expiration",
            "filehashmd5",
            "filehashsha256",
            "filehashsha1",
            "iocs",
            "extract",
            "enter source",
            "url or",
            "text drag",
            "drop or",
            "domain",
            "expiration",
            "url http",
            "hostname",
            "email abuse"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1045",
              "name": "Software Packing",
              "display_name": "T1045 - Software Packing"
            },
            {
              "id": "T1060",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1060 - Registry Run Keys / Startup Folder"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": "688f1ce317fc8b3f9d5d5f33",
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA1": 459,
            "FileHash-MD5": 553,
            "FileHash-SHA256": 1042,
            "URL": 1429,
            "hostname": 478,
            "domain": 521,
            "email": 3,
            "SSLCertFingerprint": 1,
            "JA3": 1
          },
          "indicator_count": 4487,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 67,
          "modified_text": "21 hours ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "688f1ce317fc8b3f9d5d5f33",
          "name": "Unknown  - Established hacker group. Affects banking, financial  and much more.",
          "description": "Crowdsourced. Identifies as a Dark Web gang stalking entity. Research suggests that this is a very organized, possibly quasi governmental entity with shadowy state figures that social engineer targets. Even though they have been considered scammers and they are grifters, they are very established, dangerous and a very large force with claims of military alignments which has not yet been fully confirmed.\n\nThis group is anything you want them to be, attorney, accountant, technician, nurse, uber driver.",
          "modified": "2025-09-02T08:02:34.108000",
          "created": "2025-08-03T08:25:07.135000",
          "tags": [
            "united",
            "search",
            "entries",
            "unknown ns",
            "ip address",
            "creation date",
            "record value",
            "date",
            "showing",
            "moved",
            "body",
            "encrypt",
            "lowfi",
            "trojanspy",
            "checkin",
            "passive dns",
            "trojan",
            "next associated",
            "cryp",
            "win32",
            "phishing",
            "virtool",
            "hstr",
            "backdoor",
            "ipv4",
            "pulse pulses",
            "associated urls",
            "show",
            "date checked",
            "url hostname",
            "server response",
            "google safe",
            "results feb",
            "header http2",
            "accept encoding",
            "gmt related",
            "domains show",
            "domain related",
            "response ip",
            "address google",
            "safe browsing",
            "entries http",
            "scans show",
            "title",
            "link",
            "present mar",
            "meta",
            "starfield",
            "dynamicloader",
            "qaeaav12",
            "medium",
            "high",
            "malware",
            "windows wget",
            "qbeipbdii",
            "write",
            "suspicious",
            "copy",
            "yara rule",
            "gravityrat",
            "detectvm",
            "x00 x00",
            "x00x00",
            "doviacmd",
            "rootjob",
            "getfiles",
            "updateserver",
            "ethernetid",
            "unknown",
            "yara detections",
            "filehash",
            "sha256 add",
            "av detections",
            "ids detections",
            "alerts",
            "analysis date",
            "file score",
            "oinetsim",
            "oudevelopment",
            "write c",
            "demo",
            "mtb sep",
            "trojandropper",
            "cookie",
            "path max",
            "age86400 set",
            "win32qqpass sep",
            "results aug",
            "script urls",
            "script domains",
            "a domains",
            "cache control",
            "cache status",
            "fury",
            "zenedge",
            "present jun",
            "present dec",
            "present jan",
            "present nov",
            "for privacy",
            "present may",
            "name servers",
            "no expiration",
            "filehashmd5",
            "filehashsha256",
            "filehashsha1",
            "iocs",
            "extract",
            "enter source",
            "url or",
            "text drag",
            "drop or",
            "domain",
            "expiration",
            "url http",
            "hostname",
            "email abuse"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1045",
              "name": "Software Packing",
              "display_name": "T1045 - Software Packing"
            },
            {
              "id": "T1060",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1060 - Registry Run Keys / Startup Folder"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 28,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 1,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Q.Vashti",
            "id": "337942",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA1": 459,
            "FileHash-MD5": 553,
            "FileHash-SHA256": 1042,
            "URL": 1426,
            "hostname": 476,
            "domain": 521,
            "email": 3,
            "SSLCertFingerprint": 1
          },
          "indicator_count": 4481,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 143,
          "modified_text": "271 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "68899ae621ead93f10b78da8",
          "name": "Hacking activities continue to affect multi block communities",
          "description": "Multi block complex (USA) continues to be affected by hacking and espionage activities. Every time I attempt to pulse a community, pulse is reset and malicious IoC\u2019s disappear. So here\u2019s another heap. #virtool #pws #crypter #ransom #tofsee #remote_activities #adversaries #berbew #hacking #denver_communities #infostealers",
          "modified": "2025-08-29T03:04:16.203000",
          "created": "2025-07-30T04:09:10.026000",
          "tags": [
            "url https",
            "location united",
            "asn as16509",
            "et smtp",
            "message",
            "high",
            "et info",
            "domain",
            "yara detections",
            "contacted",
            "show",
            "icmp traffic",
            "irc server",
            "copy",
            "malware",
            "destination",
            "port",
            "united",
            "unknown",
            "united kingdom",
            "search",
            "entries",
            "write",
            "next",
            "google",
            "cloudflar",
            "amazon02",
            "akamaias",
            "microsoft",
            "ip address",
            "as autonomous",
            "system",
            "cdn77 dat",
            "googlecl",
            "cisco",
            "umbrella rank",
            "cisco umbrella",
            "rank",
            "date checked",
            "url hostname",
            "server response",
            "google safe",
            "results may",
            "present apr",
            "present may",
            "files show",
            "trojan",
            "error aug",
            "spain",
            "win32",
            "passive dns",
            "next associated",
            "meta name",
            "frame src",
            "ok set",
            "cookie",
            "gmt date",
            "encrypt",
            "gmt content",
            "type",
            "medium",
            "checks system",
            "total",
            "read",
            "upatre",
            "dynamicloader",
            "dynamic",
            "pcap",
            "reads",
            "pe section",
            "pe file",
            "mtb jul",
            "backdoor",
            "win32upatre jul",
            "mtb jun",
            "ipv4 add",
            "pulse pulses",
            "fakeav",
            "downloader",
            "trojandropper",
            "win32upatre jun",
            "urls",
            "script urls",
            "showing",
            "script domains",
            "meta",
            "certificate",
            "next http",
            "scans show",
            "hostname add",
            "pulse submit",
            "url analysis",
            "files",
            "files ip",
            "address",
            "hostname",
            "verdict",
            "date hash",
            "avast avg",
            "vps reverse",
            "america flag",
            "overview ip",
            "whois registrar",
            "url add",
            "http",
            "related nids",
            "files location",
            "flag united",
            "script general",
            "full url",
            "present jul",
            "aaaa",
            "present jun",
            "moved",
            "content length",
            "content type",
            "x powered",
            "date",
            "mtb may",
            "mtb sep",
            "b jan",
            "mtb jan",
            "mtb dec",
            "asn as13335",
            "creation date",
            "unknown aaaa",
            "results jul",
            "present feb",
            "present oct",
            "win32spigot jul",
            "alfper",
            "found",
            "error",
            "domain add",
            "enom",
            "urls show",
            "address domain",
            "ip related",
            "pulses none",
            "record value",
            "emails",
            "name david",
            "lex name",
            "city",
            "country ng",
            "asn as15169",
            "pulses",
            "tags",
            "all ipv4",
            "reverse dns",
            "ashburn",
            "unknown ns",
            "llc dba",
            "name servers",
            "present jan",
            "present dec",
            "service",
            "ransom",
            "new pulse",
            "existing pulse",
            "files domain",
            "files related",
            "body html",
            "lowfi",
            "worm",
            "virtool",
            "ch ua",
            "sec ch",
            "rsa tls",
            "issuing ca",
            "mtb apr",
            "yara rule",
            "hardwareid",
            "checks",
            "vmprotectsdk",
            "vmprotectstub",
            "avgetblockcc",
            "delphi",
            "vmprotect"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1045",
              "name": "Software Packing",
              "display_name": "T1045 - Software Packing"
            },
            {
              "id": "T1060",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1060 - Registry Run Keys / Startup Folder"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 19,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Q.Vashti",
            "id": "337942",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 3262,
            "hostname": 3139,
            "FileHash-SHA256": 2614,
            "URL": 3078,
            "FileHash-MD5": 515,
            "FileHash-SHA1": 517,
            "email": 6,
            "CVE": 1
          },
          "indicator_count": 13132,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 144,
          "modified_text": "275 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "66ae21418ee5c4ef2c847a09",
          "name": "server.wojcieszyce.pl   Email:   info@wojcieszyce.pl",
          "description": "aaf8324ca0b6fb26f66dcf30f3d95491 SHA-1 f88f78f2b158c1e9df115b477509f140a1fb67d6 SHA-256 eb050903bbc118520a8889bd2fb0176262af63b6b34b9762cbfdec11bcf48f80 Vhash 1fb0238141c442bee60860692e8228f8 SSDEEP 393216:SXUROas78y5sf0Xin76QKRu8vxoX0PllhjKNeNOZYASi6:KiMhjiOka TLSH T127B76A56F211ACB0CFA2453940AB5505A23C76434FC2F9E4B72D808E6FAD58F66326FD File type Google Chrome Extension crx chrome extension browser Magic Zip archive data, at least v1.0 to extract",
          "modified": "2025-05-01T08:50:16.800000",
          "created": "2024-08-03T12:23:29.055000",
          "tags": [
            "sha256",
            "office open",
            "xml document",
            "ms word",
            "document",
            "google chrome",
            "extension",
            "strong",
            "korzystania z",
            "ciasteczka",
            "godziny",
            "jeleniogrska",
            "wojcieszyce",
            "naszej strony",
            "korzystanie z",
            "en de",
            "menu imprezy",
            "flash",
            "vhash",
            "ssdeep",
            "file type",
            "ini text",
            "magic generic",
            "magika txt",
            "file size",
            "text c",
            "javascript c",
            "peexe c",
            "doscom c",
            "tekst c",
            "javascript",
            "rgba",
            "unicode",
            "z bom",
            "dane obrazu",
            "tekst utf8",
            "crlf",
            "skrt",
            "v2 dokument",
            "dane",
            "jpeg",
            "kimhjioka tlsh",
            "magic zip",
            "magic elf",
            "sysv",
            "adres url",
            "strona",
            "zaloguj",
            "date thu",
            "connection",
            "server nginx",
            "gmt etag",
            "expires sat",
            "expires fri",
            "contentlength",
            "server",
            "gmt contenttype",
            "cachecontrol",
            "png image",
            "crlf line",
            "document file",
            "v2 document",
            "type md5",
            "process name",
            "cr line",
            "ikona rt",
            "neutralny",
            "entropia chi2",
            "typ pliku",
            "typ jzyk",
            "png ikona",
            "rt neutralny",
            "rticon neutral",
            "ico rtgroupicon",
            "neutral",
            "whasz",
            "oszczdno",
            "logowanie",
            "zagroenia",
            "dane publiczne",
            "zoliwy dane",
            "historia wpisu",
            "reagowania",
            "sha1",
            "virustotal",
            "html internet",
            "magic html",
            "unicode text",
            "please",
            "pehash"
          ],
          "references": [
            "http://www.wojcieszyce.pl/",
            "https://www.wojcieszyce.pl/",
            "https://wojcieszyce.pl/",
            "http://wojcieszyce.pl/",
            "https://www.virustotal.com/gui/search/entity%253Afile%2520tag%253Apdf"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Wojcieszyce",
              "display_name": "Wojcieszyce",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1176",
              "name": "Browser Extensions",
              "display_name": "T1176 - Browser Extensions"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 11,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Arek-BTC",
            "id": "212764",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_212764/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA1": 908,
            "FileHash-SHA256": 2450,
            "FileHash-MD5": 968,
            "URL": 373,
            "hostname": 144,
            "IPv4": 8,
            "domain": 15,
            "email": 7,
            "CVE": 16
          },
          "indicator_count": 4889,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 125,
          "modified_text": "395 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "668cebf4b3498d2f9b9e9596",
          "name": "Trojan:Win32/Predator - walmartmobile.cn",
          "description": "Monitoring, invalid URLs, malicious redirects, cams,cyber crime, red team contract. Collects targets, calls, photos, network, dns, disables proxy, movies services,, messages, shopping habits, contacts. Intrusive as always.",
          "modified": "2024-08-08T07:05:50.946000",
          "created": "2024-07-09T07:51:16.371000",
          "tags": [
            "popularity",
            "ingestion time",
            "utc cisco",
            "umbrella",
            "utc statvoo",
            "record type",
            "server",
            "dnssec",
            "email",
            "dns replication",
            "android",
            "files",
            "china unknown",
            "as4837 china",
            "aaaa",
            "search",
            "moved",
            "net technology",
            "for privacy",
            "name servers",
            "redacted for",
            "encrypt",
            "body",
            "next",
            "passive dns",
            "urls",
            "scan endpoints",
            "all scoreblue",
            "url http",
            "http",
            "ip address",
            "related nids",
            "files location",
            "ipv4",
            "url analysis",
            "location china",
            "script script",
            "td tr",
            "please",
            "please enter",
            "za z0",
            "server ca",
            "meta",
            "a li",
            "a domains",
            "ul div",
            "443 ma2592000",
            "gmt content",
            "servers",
            "https",
            "self",
            "hostname",
            "window",
            "icloud_apple_id",
            "apple",
            "apple ios",
            "apple id",
            "apple message",
            "msie",
            "chrome",
            "title",
            "head body",
            "center hr",
            "united",
            "unknown",
            "as32934",
            "as13414 twitter",
            "as19679 dropbox",
            "as20940",
            "kos",
            "walmart",
            "calls",
            "checking",
            "latest version",
            "invoked methods",
            "highlighted",
            "shell commands",
            "written",
            "files deleted",
            "files copied",
            "file",
            "process",
            "post http",
            "request",
            "get http",
            "dns resolutions",
            "ip traffic",
            "process32nextw",
            "shellexecuteexw",
            "get na",
            "entries",
            "medium",
            "show",
            "china as4837",
            "yara detections",
            "regsetvalueexw",
            "dock",
            "write",
            "win32",
            "persistence",
            "execution",
            "copy",
            "cname",
            "asnone united",
            "registrar",
            "as2914 ntt",
            "hichina",
            "certificate",
            "showing",
            "as142403 yisu",
            "china asn",
            "suspicious",
            "open",
            "write c",
            "create c",
            "read c",
            "windows nt",
            "wow64",
            "slcc2",
            "media center",
            "default",
            "discovery",
            "xebrbxeax1ezxf0",
            "sxe0x0cx1cxf8",
            "invalid url",
            "status",
            "reflection",
            "telephony",
            "yuming",
            "domain",
            "expiration date",
            "div div",
            "a div",
            "span a",
            "script urls",
            "p span",
            "pragma",
            "trident",
            "form",
            "applei_imessage_ios",
            "as4134 chinanet",
            "as3356 level",
            "asnone china",
            "date",
            "tsara brashears",
            "rwi dtools",
            "pyinstaller",
            "password",
            "cybercrime",
            "valid from",
            "number",
            "thumbprint",
            "ipwnderv1",
            "hacktool",
            "phishing",
            "facebook",
            "all search",
            "otx scoreblue",
            "pulse submit",
            "injection",
            "mobile",
            "tmobile"
          ],
          "references": [
            "walmartmobile.cn",
            "malware_hosting IP's:42.177.83.115 | IPv4 42.177.83.134 malware_hosting",
            "Apple Spy: iphone-say.com apple-prompt-iphone.com  http://www.apple-prompt-iphone.com/",
            "Apple Spy: 113-dd-hppg.redirectme.netiphonepofentrydstaging2zsendlabstryd.0-enakamai-lanwpradiocen6.ali.zomans.com",
            "Apple Spy: cmlinki-img-3radio-iphone-web-cmlinki3-iphone-web-cmlinkiradio.redirectme.netoppofentryd.0-iphone-web-cmlinkiradio-iphone-web-cm",
            "Apple Spy:  redirectme.netiphonepofentrydstaging2znetoppofindlabstryd.netoppofindhypernova.ali.zomans.com",
            "Apple Spy:  113-dd-hppg.redirectme.netiphonepofentrydiotging2znetoppofindlabstryd.0-enakamai-lanwpradiocen6.ali.zomans.com",
            "Trojan:Win32/Predator!: FileHash-SHA256 1cf6574bb7edda08a539fdb2885a959071b60d9c9bfb44ee1b9912b3864ff758",
            "Trojan:Win32/Predator!: FileHash-SHA256 493323dd39ebb91b861e63c7341d037877886bc3a6cf4deaef08ef76bb9db15e",
            "Trojan:Win32/Predator!: FileHash-SHA256 f7da3472e0f81fa37ea05cc91338b6a693a1fcd4d30025fdfbfc7f2f0119fa20",
            "traceability-qa.walmartmobile.cn",
            "http://img01.mifile.cn/m/apk/mishop_3.0.20141212_1.1.1.apk",
            "http://tshop.doido.com",
            "Antivirus Detections Win32:Malware-gen: Yara Detections: stack_string",
            "Alerts: dead_host network_icmp antivm_generic_services creates_largekey disables_proxy dumped_buffer network_cnc_http",
            "Alerts: network_http allocates_rwx stealth_window injection_process_search process_interest",
            "Antivirus Detections: ALF:HeraklezEval:Trojan:Win32/Asacky!rfn ,  ALF:HeraklezEval:Trojan:Win32/Predator!rfn ,   Win.Trojan.Generic-9789164-0",
            "IDS Detections: : Suspicious User-Agent (HTTP Downloader) Suspicious User-Agent containing Loader Observed",
            "Unique antivirus detections for files communicating with IP address",
            "hpcc-page.cnc.ccgslb.com.cn 121.30.192.9 58.20.206.154 139.209.89.125 124.67.23.253 61.180.227.172 61.162.172.185 IP Traffic",
            "TCP 123.125.159.119:80 (gad.page.cnc.ccgslb.com.cn) TCP 121.30.192.9:80 (hpcc-page.cnc.ccgslb.com.cn) TCP 121.30.193.30: Technique ID: T1140 Technique Name: Deobfuscate/Decode Files or Information  Medium { \"families\": [], \"description\": \"One or more potentially interesting buffers were extracted, these generally contain injected code, configuration data, etc.\", Technique ID: T1055 Technique Name: Process Injection  A common use for this is when applications run in the system tray, but don't also want to sh"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America",
            "Singapore",
            "Brazil",
            "Ireland",
            "Germany",
            "Chile",
            "China",
            "Switzerland"
          ],
          "malware_families": [
            {
              "id": "RiskTool.AndroidOS.beto",
              "display_name": "RiskTool.AndroidOS.beto",
              "target": null
            },
            {
              "id": "Trojan.TrojanBanker.Android",
              "display_name": "Trojan.TrojanBanker.Android",
              "target": null
            },
            {
              "id": "ALF:HeraklezEval:Trojan:Win32/Predator!rfn",
              "display_name": "ALF:HeraklezEval:Trojan:Win32/Predator!rfn",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1007",
              "name": "System Service Discovery",
              "display_name": "T1007 - System Service Discovery"
            },
            {
              "id": "T1040",
              "name": "Network Sniffing",
              "display_name": "T1040 - Network Sniffing"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1112",
              "name": "Modify Registry",
              "display_name": "T1112 - Modify Registry"
            },
            {
              "id": "T1143",
              "name": "Hidden Window",
              "display_name": "T1143 - Hidden Window"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1031",
              "name": "Modify Existing Service",
              "display_name": "T1031 - Modify Existing Service"
            },
            {
              "id": "T1598",
              "name": "Phishing for Information",
              "display_name": "T1598 - Phishing for Information"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 9,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 1737,
            "hostname": 4754,
            "URL": 11496,
            "FileHash-MD5": 96,
            "FileHash-SHA1": 79,
            "FileHash-SHA256": 2457,
            "email": 11,
            "SSLCertFingerprint": 2
          },
          "indicator_count": 20632,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 229,
          "modified_text": "661 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "walmartmobile.cn",
        "TCP 123.125.159.119:80 (gad.page.cnc.ccgslb.com.cn) TCP 121.30.192.9:80 (hpcc-page.cnc.ccgslb.com.cn) TCP 121.30.193.30: Technique ID: T1140 Technique Name: Deobfuscate/Decode Files or Information  Medium { \"families\": [], \"description\": \"One or more potentially interesting buffers were extracted, these generally contain injected code, configuration data, etc.\", Technique ID: T1055 Technique Name: Process Injection  A common use for this is when applications run in the system tray, but don't also want to sh",
        "Antivirus Detections Win32:Malware-gen: Yara Detections: stack_string",
        "Apple Spy:  113-dd-hppg.redirectme.netiphonepofentrydiotging2znetoppofindlabstryd.0-enakamai-lanwpradiocen6.ali.zomans.com",
        "Apple Spy: 113-dd-hppg.redirectme.netiphonepofentrydstaging2zsendlabstryd.0-enakamai-lanwpradiocen6.ali.zomans.com",
        "http://tshop.doido.com",
        "Apple Spy:  redirectme.netiphonepofentrydstaging2znetoppofindlabstryd.netoppofindhypernova.ali.zomans.com",
        "Trojan:Win32/Predator!: FileHash-SHA256 1cf6574bb7edda08a539fdb2885a959071b60d9c9bfb44ee1b9912b3864ff758",
        "https://wojcieszyce.pl/",
        "http://wojcieszyce.pl/",
        "malware_hosting IP's:42.177.83.115 | IPv4 42.177.83.134 malware_hosting",
        "hpcc-page.cnc.ccgslb.com.cn 121.30.192.9 58.20.206.154 139.209.89.125 124.67.23.253 61.180.227.172 61.162.172.185 IP Traffic",
        "http://img01.mifile.cn/m/apk/mishop_3.0.20141212_1.1.1.apk",
        "IDS Detections: : Suspicious User-Agent (HTTP Downloader) Suspicious User-Agent containing Loader Observed",
        "Antivirus Detections: ALF:HeraklezEval:Trojan:Win32/Asacky!rfn ,  ALF:HeraklezEval:Trojan:Win32/Predator!rfn ,   Win.Trojan.Generic-9789164-0",
        "Alerts: network_http allocates_rwx stealth_window injection_process_search process_interest",
        "Unique antivirus detections for files communicating with IP address",
        "traceability-qa.walmartmobile.cn",
        "Apple Spy: iphone-say.com apple-prompt-iphone.com  http://www.apple-prompt-iphone.com/",
        "http://www.wojcieszyce.pl/",
        "https://www.wojcieszyce.pl/",
        "https://www.virustotal.com/gui/search/entity%253Afile%2520tag%253Apdf",
        "Alerts: dead_host network_icmp antivm_generic_services creates_largekey disables_proxy dumped_buffer network_cnc_http",
        "Trojan:Win32/Predator!: FileHash-SHA256 f7da3472e0f81fa37ea05cc91338b6a693a1fcd4d30025fdfbfc7f2f0119fa20",
        "Trojan:Win32/Predator!: FileHash-SHA256 493323dd39ebb91b861e63c7341d037877886bc3a6cf4deaef08ef76bb9db15e",
        "Apple Spy: cmlinki-img-3radio-iphone-web-cmlinki3-iphone-web-cmlinkiradio.redirectme.netoppofentryd.0-iphone-web-cmlinkiradio-iphone-web-cm"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 0
        },
        "other": {
          "adversary": [],
          "malware_families": [
            "Alf:heraklezeval:trojan:win32/predator!rfn",
            "Risktool.androidos.beto",
            "Wojcieszyce",
            "Trojan.trojanbanker.android"
          ],
          "industries": [],
          "unique_indicators": 43788
        }
      }
    },
    "false_positive": [],
    "alexa": "http://www.alexa.com/siteinfo/klyou.net",
    "whois": "http://whois.domaintools.com/klyou.net",
    "domain": "klyou.net",
    "hostname": "Unavailable"
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 5,
  "pulses": [
    {
      "id": "6a19ab3077e26f1ba3c8cd51",
      "name": "Credit Q.Vashti \"Unknown - Established hacker group. Affects banking\" clone",
      "description": "",
      "modified": "2026-05-31T05:26:42.780000",
      "created": "2026-05-29T15:05:20.198000",
      "tags": [
        "united",
        "search",
        "entries",
        "unknown ns",
        "ip address",
        "creation date",
        "record value",
        "date",
        "showing",
        "moved",
        "body",
        "encrypt",
        "lowfi",
        "trojanspy",
        "checkin",
        "passive dns",
        "trojan",
        "next associated",
        "cryp",
        "win32",
        "phishing",
        "virtool",
        "hstr",
        "backdoor",
        "ipv4",
        "pulse pulses",
        "associated urls",
        "show",
        "date checked",
        "url hostname",
        "server response",
        "google safe",
        "results feb",
        "header http2",
        "accept encoding",
        "gmt related",
        "domains show",
        "domain related",
        "response ip",
        "address google",
        "safe browsing",
        "entries http",
        "scans show",
        "title",
        "link",
        "present mar",
        "meta",
        "starfield",
        "dynamicloader",
        "qaeaav12",
        "medium",
        "high",
        "malware",
        "windows wget",
        "qbeipbdii",
        "write",
        "suspicious",
        "copy",
        "yara rule",
        "gravityrat",
        "detectvm",
        "x00 x00",
        "x00x00",
        "doviacmd",
        "rootjob",
        "getfiles",
        "updateserver",
        "ethernetid",
        "unknown",
        "yara detections",
        "filehash",
        "sha256 add",
        "av detections",
        "ids detections",
        "alerts",
        "analysis date",
        "file score",
        "oinetsim",
        "oudevelopment",
        "write c",
        "demo",
        "mtb sep",
        "trojandropper",
        "cookie",
        "path max",
        "age86400 set",
        "win32qqpass sep",
        "results aug",
        "script urls",
        "script domains",
        "a domains",
        "cache control",
        "cache status",
        "fury",
        "zenedge",
        "present jun",
        "present dec",
        "present jan",
        "present nov",
        "for privacy",
        "present may",
        "name servers",
        "no expiration",
        "filehashmd5",
        "filehashsha256",
        "filehashsha1",
        "iocs",
        "extract",
        "enter source",
        "url or",
        "text drag",
        "drop or",
        "domain",
        "expiration",
        "url http",
        "hostname",
        "email abuse"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1045",
          "name": "Software Packing",
          "display_name": "T1045 - Software Packing"
        },
        {
          "id": "T1060",
          "name": "Registry Run Keys / Startup Folder",
          "display_name": "T1060 - Registry Run Keys / Startup Folder"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": "688f1ce317fc8b3f9d5d5f33",
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA1": 459,
        "FileHash-MD5": 553,
        "FileHash-SHA256": 1042,
        "URL": 1429,
        "hostname": 478,
        "domain": 521,
        "email": 3,
        "SSLCertFingerprint": 1,
        "JA3": 1
      },
      "indicator_count": 4487,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 67,
      "modified_text": "21 hours ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "688f1ce317fc8b3f9d5d5f33",
      "name": "Unknown  - Established hacker group. Affects banking, financial  and much more.",
      "description": "Crowdsourced. Identifies as a Dark Web gang stalking entity. Research suggests that this is a very organized, possibly quasi governmental entity with shadowy state figures that social engineer targets. Even though they have been considered scammers and they are grifters, they are very established, dangerous and a very large force with claims of military alignments which has not yet been fully confirmed.\n\nThis group is anything you want them to be, attorney, accountant, technician, nurse, uber driver.",
      "modified": "2025-09-02T08:02:34.108000",
      "created": "2025-08-03T08:25:07.135000",
      "tags": [
        "united",
        "search",
        "entries",
        "unknown ns",
        "ip address",
        "creation date",
        "record value",
        "date",
        "showing",
        "moved",
        "body",
        "encrypt",
        "lowfi",
        "trojanspy",
        "checkin",
        "passive dns",
        "trojan",
        "next associated",
        "cryp",
        "win32",
        "phishing",
        "virtool",
        "hstr",
        "backdoor",
        "ipv4",
        "pulse pulses",
        "associated urls",
        "show",
        "date checked",
        "url hostname",
        "server response",
        "google safe",
        "results feb",
        "header http2",
        "accept encoding",
        "gmt related",
        "domains show",
        "domain related",
        "response ip",
        "address google",
        "safe browsing",
        "entries http",
        "scans show",
        "title",
        "link",
        "present mar",
        "meta",
        "starfield",
        "dynamicloader",
        "qaeaav12",
        "medium",
        "high",
        "malware",
        "windows wget",
        "qbeipbdii",
        "write",
        "suspicious",
        "copy",
        "yara rule",
        "gravityrat",
        "detectvm",
        "x00 x00",
        "x00x00",
        "doviacmd",
        "rootjob",
        "getfiles",
        "updateserver",
        "ethernetid",
        "unknown",
        "yara detections",
        "filehash",
        "sha256 add",
        "av detections",
        "ids detections",
        "alerts",
        "analysis date",
        "file score",
        "oinetsim",
        "oudevelopment",
        "write c",
        "demo",
        "mtb sep",
        "trojandropper",
        "cookie",
        "path max",
        "age86400 set",
        "win32qqpass sep",
        "results aug",
        "script urls",
        "script domains",
        "a domains",
        "cache control",
        "cache status",
        "fury",
        "zenedge",
        "present jun",
        "present dec",
        "present jan",
        "present nov",
        "for privacy",
        "present may",
        "name servers",
        "no expiration",
        "filehashmd5",
        "filehashsha256",
        "filehashsha1",
        "iocs",
        "extract",
        "enter source",
        "url or",
        "text drag",
        "drop or",
        "domain",
        "expiration",
        "url http",
        "hostname",
        "email abuse"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1045",
          "name": "Software Packing",
          "display_name": "T1045 - Software Packing"
        },
        {
          "id": "T1060",
          "name": "Registry Run Keys / Startup Folder",
          "display_name": "T1060 - Registry Run Keys / Startup Folder"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 28,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 1,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Q.Vashti",
        "id": "337942",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA1": 459,
        "FileHash-MD5": 553,
        "FileHash-SHA256": 1042,
        "URL": 1426,
        "hostname": 476,
        "domain": 521,
        "email": 3,
        "SSLCertFingerprint": 1
      },
      "indicator_count": 4481,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 143,
      "modified_text": "271 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "68899ae621ead93f10b78da8",
      "name": "Hacking activities continue to affect multi block communities",
      "description": "Multi block complex (USA) continues to be affected by hacking and espionage activities. Every time I attempt to pulse a community, pulse is reset and malicious IoC\u2019s disappear. So here\u2019s another heap. #virtool #pws #crypter #ransom #tofsee #remote_activities #adversaries #berbew #hacking #denver_communities #infostealers",
      "modified": "2025-08-29T03:04:16.203000",
      "created": "2025-07-30T04:09:10.026000",
      "tags": [
        "url https",
        "location united",
        "asn as16509",
        "et smtp",
        "message",
        "high",
        "et info",
        "domain",
        "yara detections",
        "contacted",
        "show",
        "icmp traffic",
        "irc server",
        "copy",
        "malware",
        "destination",
        "port",
        "united",
        "unknown",
        "united kingdom",
        "search",
        "entries",
        "write",
        "next",
        "google",
        "cloudflar",
        "amazon02",
        "akamaias",
        "microsoft",
        "ip address",
        "as autonomous",
        "system",
        "cdn77 dat",
        "googlecl",
        "cisco",
        "umbrella rank",
        "cisco umbrella",
        "rank",
        "date checked",
        "url hostname",
        "server response",
        "google safe",
        "results may",
        "present apr",
        "present may",
        "files show",
        "trojan",
        "error aug",
        "spain",
        "win32",
        "passive dns",
        "next associated",
        "meta name",
        "frame src",
        "ok set",
        "cookie",
        "gmt date",
        "encrypt",
        "gmt content",
        "type",
        "medium",
        "checks system",
        "total",
        "read",
        "upatre",
        "dynamicloader",
        "dynamic",
        "pcap",
        "reads",
        "pe section",
        "pe file",
        "mtb jul",
        "backdoor",
        "win32upatre jul",
        "mtb jun",
        "ipv4 add",
        "pulse pulses",
        "fakeav",
        "downloader",
        "trojandropper",
        "win32upatre jun",
        "urls",
        "script urls",
        "showing",
        "script domains",
        "meta",
        "certificate",
        "next http",
        "scans show",
        "hostname add",
        "pulse submit",
        "url analysis",
        "files",
        "files ip",
        "address",
        "hostname",
        "verdict",
        "date hash",
        "avast avg",
        "vps reverse",
        "america flag",
        "overview ip",
        "whois registrar",
        "url add",
        "http",
        "related nids",
        "files location",
        "flag united",
        "script general",
        "full url",
        "present jul",
        "aaaa",
        "present jun",
        "moved",
        "content length",
        "content type",
        "x powered",
        "date",
        "mtb may",
        "mtb sep",
        "b jan",
        "mtb jan",
        "mtb dec",
        "asn as13335",
        "creation date",
        "unknown aaaa",
        "results jul",
        "present feb",
        "present oct",
        "win32spigot jul",
        "alfper",
        "found",
        "error",
        "domain add",
        "enom",
        "urls show",
        "address domain",
        "ip related",
        "pulses none",
        "record value",
        "emails",
        "name david",
        "lex name",
        "city",
        "country ng",
        "asn as15169",
        "pulses",
        "tags",
        "all ipv4",
        "reverse dns",
        "ashburn",
        "unknown ns",
        "llc dba",
        "name servers",
        "present jan",
        "present dec",
        "service",
        "ransom",
        "new pulse",
        "existing pulse",
        "files domain",
        "files related",
        "body html",
        "lowfi",
        "worm",
        "virtool",
        "ch ua",
        "sec ch",
        "rsa tls",
        "issuing ca",
        "mtb apr",
        "yara rule",
        "hardwareid",
        "checks",
        "vmprotectsdk",
        "vmprotectstub",
        "avgetblockcc",
        "delphi",
        "vmprotect"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1045",
          "name": "Software Packing",
          "display_name": "T1045 - Software Packing"
        },
        {
          "id": "T1060",
          "name": "Registry Run Keys / Startup Folder",
          "display_name": "T1060 - Registry Run Keys / Startup Folder"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 19,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Q.Vashti",
        "id": "337942",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 3262,
        "hostname": 3139,
        "FileHash-SHA256": 2614,
        "URL": 3078,
        "FileHash-MD5": 515,
        "FileHash-SHA1": 517,
        "email": 6,
        "CVE": 1
      },
      "indicator_count": 13132,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 144,
      "modified_text": "275 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "66ae21418ee5c4ef2c847a09",
      "name": "server.wojcieszyce.pl   Email:   info@wojcieszyce.pl",
      "description": "aaf8324ca0b6fb26f66dcf30f3d95491 SHA-1 f88f78f2b158c1e9df115b477509f140a1fb67d6 SHA-256 eb050903bbc118520a8889bd2fb0176262af63b6b34b9762cbfdec11bcf48f80 Vhash 1fb0238141c442bee60860692e8228f8 SSDEEP 393216:SXUROas78y5sf0Xin76QKRu8vxoX0PllhjKNeNOZYASi6:KiMhjiOka TLSH T127B76A56F211ACB0CFA2453940AB5505A23C76434FC2F9E4B72D808E6FAD58F66326FD File type Google Chrome Extension crx chrome extension browser Magic Zip archive data, at least v1.0 to extract",
      "modified": "2025-05-01T08:50:16.800000",
      "created": "2024-08-03T12:23:29.055000",
      "tags": [
        "sha256",
        "office open",
        "xml document",
        "ms word",
        "document",
        "google chrome",
        "extension",
        "strong",
        "korzystania z",
        "ciasteczka",
        "godziny",
        "jeleniogrska",
        "wojcieszyce",
        "naszej strony",
        "korzystanie z",
        "en de",
        "menu imprezy",
        "flash",
        "vhash",
        "ssdeep",
        "file type",
        "ini text",
        "magic generic",
        "magika txt",
        "file size",
        "text c",
        "javascript c",
        "peexe c",
        "doscom c",
        "tekst c",
        "javascript",
        "rgba",
        "unicode",
        "z bom",
        "dane obrazu",
        "tekst utf8",
        "crlf",
        "skrt",
        "v2 dokument",
        "dane",
        "jpeg",
        "kimhjioka tlsh",
        "magic zip",
        "magic elf",
        "sysv",
        "adres url",
        "strona",
        "zaloguj",
        "date thu",
        "connection",
        "server nginx",
        "gmt etag",
        "expires sat",
        "expires fri",
        "contentlength",
        "server",
        "gmt contenttype",
        "cachecontrol",
        "png image",
        "crlf line",
        "document file",
        "v2 document",
        "type md5",
        "process name",
        "cr line",
        "ikona rt",
        "neutralny",
        "entropia chi2",
        "typ pliku",
        "typ jzyk",
        "png ikona",
        "rt neutralny",
        "rticon neutral",
        "ico rtgroupicon",
        "neutral",
        "whasz",
        "oszczdno",
        "logowanie",
        "zagroenia",
        "dane publiczne",
        "zoliwy dane",
        "historia wpisu",
        "reagowania",
        "sha1",
        "virustotal",
        "html internet",
        "magic html",
        "unicode text",
        "please",
        "pehash"
      ],
      "references": [
        "http://www.wojcieszyce.pl/",
        "https://www.wojcieszyce.pl/",
        "https://wojcieszyce.pl/",
        "http://wojcieszyce.pl/",
        "https://www.virustotal.com/gui/search/entity%253Afile%2520tag%253Apdf"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Wojcieszyce",
          "display_name": "Wojcieszyce",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1176",
          "name": "Browser Extensions",
          "display_name": "T1176 - Browser Extensions"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 11,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Arek-BTC",
        "id": "212764",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_212764/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA1": 908,
        "FileHash-SHA256": 2450,
        "FileHash-MD5": 968,
        "URL": 373,
        "hostname": 144,
        "IPv4": 8,
        "domain": 15,
        "email": 7,
        "CVE": 16
      },
      "indicator_count": 4889,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 125,
      "modified_text": "395 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "668cebf4b3498d2f9b9e9596",
      "name": "Trojan:Win32/Predator - walmartmobile.cn",
      "description": "Monitoring, invalid URLs, malicious redirects, cams,cyber crime, red team contract. Collects targets, calls, photos, network, dns, disables proxy, movies services,, messages, shopping habits, contacts. Intrusive as always.",
      "modified": "2024-08-08T07:05:50.946000",
      "created": "2024-07-09T07:51:16.371000",
      "tags": [
        "popularity",
        "ingestion time",
        "utc cisco",
        "umbrella",
        "utc statvoo",
        "record type",
        "server",
        "dnssec",
        "email",
        "dns replication",
        "android",
        "files",
        "china unknown",
        "as4837 china",
        "aaaa",
        "search",
        "moved",
        "net technology",
        "for privacy",
        "name servers",
        "redacted for",
        "encrypt",
        "body",
        "next",
        "passive dns",
        "urls",
        "scan endpoints",
        "all scoreblue",
        "url http",
        "http",
        "ip address",
        "related nids",
        "files location",
        "ipv4",
        "url analysis",
        "location china",
        "script script",
        "td tr",
        "please",
        "please enter",
        "za z0",
        "server ca",
        "meta",
        "a li",
        "a domains",
        "ul div",
        "443 ma2592000",
        "gmt content",
        "servers",
        "https",
        "self",
        "hostname",
        "window",
        "icloud_apple_id",
        "apple",
        "apple ios",
        "apple id",
        "apple message",
        "msie",
        "chrome",
        "title",
        "head body",
        "center hr",
        "united",
        "unknown",
        "as32934",
        "as13414 twitter",
        "as19679 dropbox",
        "as20940",
        "kos",
        "walmart",
        "calls",
        "checking",
        "latest version",
        "invoked methods",
        "highlighted",
        "shell commands",
        "written",
        "files deleted",
        "files copied",
        "file",
        "process",
        "post http",
        "request",
        "get http",
        "dns resolutions",
        "ip traffic",
        "process32nextw",
        "shellexecuteexw",
        "get na",
        "entries",
        "medium",
        "show",
        "china as4837",
        "yara detections",
        "regsetvalueexw",
        "dock",
        "write",
        "win32",
        "persistence",
        "execution",
        "copy",
        "cname",
        "asnone united",
        "registrar",
        "as2914 ntt",
        "hichina",
        "certificate",
        "showing",
        "as142403 yisu",
        "china asn",
        "suspicious",
        "open",
        "write c",
        "create c",
        "read c",
        "windows nt",
        "wow64",
        "slcc2",
        "media center",
        "default",
        "discovery",
        "xebrbxeax1ezxf0",
        "sxe0x0cx1cxf8",
        "invalid url",
        "status",
        "reflection",
        "telephony",
        "yuming",
        "domain",
        "expiration date",
        "div div",
        "a div",
        "span a",
        "script urls",
        "p span",
        "pragma",
        "trident",
        "form",
        "applei_imessage_ios",
        "as4134 chinanet",
        "as3356 level",
        "asnone china",
        "date",
        "tsara brashears",
        "rwi dtools",
        "pyinstaller",
        "password",
        "cybercrime",
        "valid from",
        "number",
        "thumbprint",
        "ipwnderv1",
        "hacktool",
        "phishing",
        "facebook",
        "all search",
        "otx scoreblue",
        "pulse submit",
        "injection",
        "mobile",
        "tmobile"
      ],
      "references": [
        "walmartmobile.cn",
        "malware_hosting IP's:42.177.83.115 | IPv4 42.177.83.134 malware_hosting",
        "Apple Spy: iphone-say.com apple-prompt-iphone.com  http://www.apple-prompt-iphone.com/",
        "Apple Spy: 113-dd-hppg.redirectme.netiphonepofentrydstaging2zsendlabstryd.0-enakamai-lanwpradiocen6.ali.zomans.com",
        "Apple Spy: cmlinki-img-3radio-iphone-web-cmlinki3-iphone-web-cmlinkiradio.redirectme.netoppofentryd.0-iphone-web-cmlinkiradio-iphone-web-cm",
        "Apple Spy:  redirectme.netiphonepofentrydstaging2znetoppofindlabstryd.netoppofindhypernova.ali.zomans.com",
        "Apple Spy:  113-dd-hppg.redirectme.netiphonepofentrydiotging2znetoppofindlabstryd.0-enakamai-lanwpradiocen6.ali.zomans.com",
        "Trojan:Win32/Predator!: FileHash-SHA256 1cf6574bb7edda08a539fdb2885a959071b60d9c9bfb44ee1b9912b3864ff758",
        "Trojan:Win32/Predator!: FileHash-SHA256 493323dd39ebb91b861e63c7341d037877886bc3a6cf4deaef08ef76bb9db15e",
        "Trojan:Win32/Predator!: FileHash-SHA256 f7da3472e0f81fa37ea05cc91338b6a693a1fcd4d30025fdfbfc7f2f0119fa20",
        "traceability-qa.walmartmobile.cn",
        "http://img01.mifile.cn/m/apk/mishop_3.0.20141212_1.1.1.apk",
        "http://tshop.doido.com",
        "Antivirus Detections Win32:Malware-gen: Yara Detections: stack_string",
        "Alerts: dead_host network_icmp antivm_generic_services creates_largekey disables_proxy dumped_buffer network_cnc_http",
        "Alerts: network_http allocates_rwx stealth_window injection_process_search process_interest",
        "Antivirus Detections: ALF:HeraklezEval:Trojan:Win32/Asacky!rfn ,  ALF:HeraklezEval:Trojan:Win32/Predator!rfn ,   Win.Trojan.Generic-9789164-0",
        "IDS Detections: : Suspicious User-Agent (HTTP Downloader) Suspicious User-Agent containing Loader Observed",
        "Unique antivirus detections for files communicating with IP address",
        "hpcc-page.cnc.ccgslb.com.cn 121.30.192.9 58.20.206.154 139.209.89.125 124.67.23.253 61.180.227.172 61.162.172.185 IP Traffic",
        "TCP 123.125.159.119:80 (gad.page.cnc.ccgslb.com.cn) TCP 121.30.192.9:80 (hpcc-page.cnc.ccgslb.com.cn) TCP 121.30.193.30: Technique ID: T1140 Technique Name: Deobfuscate/Decode Files or Information  Medium { \"families\": [], \"description\": \"One or more potentially interesting buffers were extracted, these generally contain injected code, configuration data, etc.\", Technique ID: T1055 Technique Name: Process Injection  A common use for this is when applications run in the system tray, but don't also want to sh"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America",
        "Singapore",
        "Brazil",
        "Ireland",
        "Germany",
        "Chile",
        "China",
        "Switzerland"
      ],
      "malware_families": [
        {
          "id": "RiskTool.AndroidOS.beto",
          "display_name": "RiskTool.AndroidOS.beto",
          "target": null
        },
        {
          "id": "Trojan.TrojanBanker.Android",
          "display_name": "Trojan.TrojanBanker.Android",
          "target": null
        },
        {
          "id": "ALF:HeraklezEval:Trojan:Win32/Predator!rfn",
          "display_name": "ALF:HeraklezEval:Trojan:Win32/Predator!rfn",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1007",
          "name": "System Service Discovery",
          "display_name": "T1007 - System Service Discovery"
        },
        {
          "id": "T1040",
          "name": "Network Sniffing",
          "display_name": "T1040 - Network Sniffing"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1112",
          "name": "Modify Registry",
          "display_name": "T1112 - Modify Registry"
        },
        {
          "id": "T1143",
          "name": "Hidden Window",
          "display_name": "T1143 - Hidden Window"
        },
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1106",
          "name": "Native API",
          "display_name": "T1106 - Native API"
        },
        {
          "id": "T1031",
          "name": "Modify Existing Service",
          "display_name": "T1031 - Modify Existing Service"
        },
        {
          "id": "T1598",
          "name": "Phishing for Information",
          "display_name": "T1598 - Phishing for Information"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 9,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "scoreblue",
        "id": "254100",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 1737,
        "hostname": 4754,
        "URL": 11496,
        "FileHash-MD5": 96,
        "FileHash-SHA1": 79,
        "FileHash-SHA256": 2457,
        "email": 11,
        "SSLCertFingerprint": 2
      },
      "indicator_count": 20632,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 229,
      "modified_text": "661 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "https://klyou.net",
    "type": "URL"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "https://klyou.net",
    "type": "URL",
    "found": false,
    "verdict": "clean",
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780281509.81785
}