{
  "type": "URL",
  "indicator": "https://labtv.com/",
  "general": {
    "sections": [
      "general",
      "url_list",
      "http_scans",
      "screenshot"
    ],
    "indicator": "https://labtv.com/",
    "type": "url",
    "type_title": "URL",
    "validation": [],
    "base_indicator": {
      "id": 4104939742,
      "indicator": "https://labtv.com/",
      "type": "URL",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 1,
      "pulses": [
        {
          "id": "6885713b1663acf8f8d67256",
          "name": "Bot Joining - Ransom | Malware Packed Botnet",
          "description": "Bot joining by going to trusted names domains.\nI haven\u2019t isolated (bot joining) IoC\u2019s because the results are unsettling.\n*I realize it\u2019s important to check for an unsigned certificates, headers, redirects, and various other indications no matter how well one is secured. There are amazing hackers armed with AI who are only getting better. There software/tools will erase your security unless you\u2019re a hacker as well. IMO targeted persons should consider becoming Grey Hats on White team armed with AI knowledge.\n#Crypto_Mining_Pool\n#Bot_Joining #Malware #BotNetworking",
          "modified": "2025-08-25T23:01:42.226000",
          "created": "2025-07-27T00:22:19.267000",
          "tags": [
            "hostname",
            "domain",
            "pulses",
            "groups",
            "search filter",
            "time",
            "x show",
            "indicator type",
            "cidr",
            "email",
            "present jun",
            "body html",
            "head meta",
            "moved title",
            "head body",
            "moved",
            "a href",
            "certificate",
            "united",
            "showing",
            "date",
            "present may",
            "backdoor",
            "aaaa",
            "entries",
            "ip address",
            "search",
            "mtb jul",
            "domain add",
            "trojan",
            "error",
            "pulse pulses",
            "passive dns",
            "urls",
            "files",
            "location united",
            "asn as15169",
            "less whois",
            "registrar",
            "markmonitor",
            "crypto mining",
            "next associated",
            "files show",
            "date hash",
            "avast avg",
            "win32ellell jul",
            "lowfi",
            "ransom",
            "serialnumber",
            "html http2",
            "record value"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 16,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Q.Vashti",
            "id": "337942",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "email": 4,
            "hostname": 65,
            "FileHash-SHA256": 994,
            "FileHash-SHA1": 151,
            "domain": 61,
            "URL": 103,
            "FileHash-MD5": 151
          },
          "indicator_count": 1529,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 137,
          "modified_text": "237 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        }
      ],
      "references": [],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 0
        },
        "other": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 1541
        }
      }
    },
    "false_positive": [],
    "alexa": "http://www.alexa.com/siteinfo/labtv.com",
    "whois": "http://whois.domaintools.com/labtv.com",
    "domain": "labtv.com",
    "hostname": "Unavailable"
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 1,
  "pulses": [
    {
      "id": "6885713b1663acf8f8d67256",
      "name": "Bot Joining - Ransom | Malware Packed Botnet",
      "description": "Bot joining by going to trusted names domains.\nI haven\u2019t isolated (bot joining) IoC\u2019s because the results are unsettling.\n*I realize it\u2019s important to check for an unsigned certificates, headers, redirects, and various other indications no matter how well one is secured. There are amazing hackers armed with AI who are only getting better. There software/tools will erase your security unless you\u2019re a hacker as well. IMO targeted persons should consider becoming Grey Hats on White team armed with AI knowledge.\n#Crypto_Mining_Pool\n#Bot_Joining #Malware #BotNetworking",
      "modified": "2025-08-25T23:01:42.226000",
      "created": "2025-07-27T00:22:19.267000",
      "tags": [
        "hostname",
        "domain",
        "pulses",
        "groups",
        "search filter",
        "time",
        "x show",
        "indicator type",
        "cidr",
        "email",
        "present jun",
        "body html",
        "head meta",
        "moved title",
        "head body",
        "moved",
        "a href",
        "certificate",
        "united",
        "showing",
        "date",
        "present may",
        "backdoor",
        "aaaa",
        "entries",
        "ip address",
        "search",
        "mtb jul",
        "domain add",
        "trojan",
        "error",
        "pulse pulses",
        "passive dns",
        "urls",
        "files",
        "location united",
        "asn as15169",
        "less whois",
        "registrar",
        "markmonitor",
        "crypto mining",
        "next associated",
        "files show",
        "date hash",
        "avast avg",
        "win32ellell jul",
        "lowfi",
        "ransom",
        "serialnumber",
        "html http2",
        "record value"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 16,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Q.Vashti",
        "id": "337942",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "email": 4,
        "hostname": 65,
        "FileHash-SHA256": 994,
        "FileHash-SHA1": 151,
        "domain": 61,
        "URL": 103,
        "FileHash-MD5": 151
      },
      "indicator_count": 1529,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 137,
      "modified_text": "237 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "https://labtv.com/",
    "type": "URL"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "https://labtv.com/",
    "type": "URL",
    "found": false,
    "verdict": "clean",
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1776673552.5770018
}