{
  "type": "URL",
  "indicator": "https://legacyllcelectric.com/",
  "general": {
    "sections": [
      "general",
      "url_list",
      "http_scans",
      "screenshot"
    ],
    "indicator": "https://legacyllcelectric.com/",
    "type": "url",
    "type_title": "URL",
    "validation": [],
    "base_indicator": {
      "id": 3933418696,
      "indicator": "https://legacyllcelectric.com/",
      "type": "URL",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 6,
      "pulses": [
        {
          "id": "69a5c36b78ed73550bb0bf22",
          "name": "by Disable_Duck",
          "description": "",
          "modified": "2026-03-04T23:37:24.208000",
          "created": "2026-03-02T17:05:47.288000",
          "tags": [
            "kgs0",
            "kls0",
            "botname http",
            "entity",
            "UAlberta",
            "Telus",
            "Norton",
            "ffss",
            "Alberta",
            "AlbertaNDP",
            "InteriorHealth",
            "RCMP",
            "CrimeStoppersAB",
            "EdmontonPolice",
            "RCMP Kelowna",
            "RCMP AB",
            "TLS/SSL Crawler",
            "CVE-2026-24061 Attempt",
            "Generic IoT Default Password Attempt",
            "Cisco Prime Infrastructure CVE-2019-1821 RCE Attempt",
            "Dahua Backdoor Attempt",
            "ENV Crawler",
            "DCERPC Protocol",
            "Carries HTTP Referer",
            "GNU Inetutils Telnetd Auth Bypass",
            "ICMPv4 Protocol"
          ],
          "references": [
            "https://www.virustotal.com/graph/embed/g34c2ebfedb6c47c286431a829da992c3744ab3fab0d74008946f3b9bbeb83e23?theme=dark",
            "https://viz.greynoise.io/ip/analysis/61bb7542-40c2-448e-87d4-947a4623eada",
            "https://viz.greynoise.io/ip/analysis/7e527b44-c950-4c01-bb33-d96"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America",
            "Canada",
            "Netherlands",
            "Panama",
            "Poland",
            "United Kingdom of Great Britain and Northern Ireland",
            "Slovakia",
            "Aruba",
            "Anguilla",
            "Australia",
            "Costa Rica",
            "Guatemala",
            "Mexico",
            "Trinidad and Tobago",
            "Cura\u00e7ao",
            "Philippines",
            "Virgin Islands, U.S.",
            "Ukraine",
            "Barbados",
            "Germany",
            "Sint Maarten (Dutch part)",
            "Argentina",
            "Switzerland"
          ],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "Education",
            "Healthcare",
            "Government",
            "Technology",
            "Energy",
            "Telecommunications"
          ],
          "TLP": "white",
          "cloned_from": "6901363c4ce422f5caf0f72c",
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 2,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 3903,
            "FileHash-SHA1": 4967,
            "FileHash-SHA256": 12884,
            "URL": 996,
            "domain": 987,
            "hostname": 3306,
            "email": 4,
            "CVE": 1
          },
          "indicator_count": 27048,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 67,
          "modified_text": "88 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6901363c4ce422f5caf0f72c",
          "name": "Copy of DevT-OddTags-Browser-BasedOdditites - (L4ke.Aff3ct.216, 01.18.26)",
          "description": "Updated based on VT Graph & Tracking Spread of Cybercrime. This Pulse is mostly covering activity in the Province of Alberta Canada. Given recent news, it appears that BC Interior Health and Kelowna RCMP Detachment impacted in addition to Alberta Sectors of Education, Healthcare, and Government (Provincial & Federal - e.g. Treaty 6,7,8 as well as the Canadian CRA heavily impacted). \nEnriched a graph by vt user (L4ke.Aff3ct.216, 01.02.26)\nSubmitted IOCs to Greynoise.io (10.28.25)",
          "modified": "2026-02-18T05:00:41.494000",
          "created": "2025-10-28T21:31:40.008000",
          "tags": [
            "kgs0",
            "kls0",
            "botname http",
            "entity",
            "UAlberta",
            "Telus",
            "Norton",
            "ffss",
            "Alberta",
            "AlbertaNDP",
            "InteriorHealth",
            "RCMP",
            "CrimeStoppersAB",
            "EdmontonPolice",
            "RCMP Kelowna",
            "RCMP AB"
          ],
          "references": [
            "https://www.virustotal.com/graph/embed/g34c2ebfedb6c47c286431a829da992c3744ab3fab0d74008946f3b9bbeb83e23?theme=dark",
            "https://viz.greynoise.io/ip/analysis/61bb7542-40c2-448e-87d4-947a4623eada"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America",
            "Canada",
            "Netherlands",
            "Panama",
            "Poland",
            "United Kingdom of Great Britain and Northern Ireland",
            "Slovakia",
            "Aruba",
            "Anguilla",
            "Australia",
            "Costa Rica",
            "Guatemala",
            "Mexico",
            "Trinidad and Tobago",
            "Cura\u00e7ao",
            "Philippines",
            "Virgin Islands, U.S.",
            "Ukraine",
            "Barbados",
            "Germany",
            "Sint Maarten (Dutch part)"
          ],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "Education",
            "Healthcare",
            "Government",
            "Technology",
            "Energy",
            "Telecommunications"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 1,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Disable_Duck",
            "id": "244325",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_244325/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 3903,
            "FileHash-SHA1": 4967,
            "FileHash-SHA256": 12884,
            "URL": 995,
            "domain": 984,
            "hostname": 3305,
            "email": 4
          },
          "indicator_count": 27042,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 129,
          "modified_text": "103 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "68b78d521f024d3a98fc79c8",
          "name": "VT Graph miniuser - Databreach IOCs & Links",
          "description": "Related to Pulse: Food for Thought (Updated 09.02.25)\n\n*Note most links are malicious",
          "modified": "2025-10-03T00:01:12.616000",
          "created": "2025-09-03T00:35:30.936000",
          "tags": [
            "kgs0",
            "kls0",
            "entity",
            "UAlberta",
            "University of Alberta",
            "Hacked",
            "DataBreach"
          ],
          "references": [
            "https://www.virustotal.com/graph/embed/g1ed56ef53af34510a0e0ee0c2d204f066a8684fa5aeb4e69aef49403742ef6a5?theme=dark"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "Canada"
          ],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "Education"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 7,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Disable_Duck",
            "id": "244325",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_244325/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 132,
            "FileHash-SHA1": 121,
            "FileHash-SHA256": 711,
            "URL": 83,
            "domain": 50,
            "hostname": 125
          },
          "indicator_count": 1222,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 129,
          "modified_text": "241 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "67b109cbfbcc6f92c399b327",
          "name": "UAlberta Breach Data - Food for thought - thoughts & input on how to 'bring some attention to this' (not enriched)",
          "description": "Just thought I'd throw thisntogether and 'see what ya'll make of it' (documents a VT graph produced and slightly modified) that pulls a lot of things together.  Highlights both 'some problems' - U of A / Gov. of AB (who are also some 'solutions'). \nIdeas on how to grab their attention and maybe bring some 'urgency' to this issue? I have a few solutions and ideas for everyone - problem: I require some folks to 'do their jobs' (there is not 10 of me). Thoughts on how to encourage them to act on these problems. Present status: Connected directly to them on other devices. Within literal 5 min walking range.",
          "modified": "2025-05-27T07:01:17.646000",
          "created": "2025-02-15T21:40:27.895000",
          "tags": [
            "kgs0",
            "kls0"
          ],
          "references": [
            "https://www.virustotal.com/graph/embed/g1ed56ef53af34510a0e0ee0c2d204f066a8684fa5aeb4e69aef49403742ef6a5?theme=dark",
            "<iframe   src=\"https://www.virustotal.com/graph/embed/g1ed56ef53af34510a0e0ee0c2d204f066a8684fa5aeb4e69aef49403742ef6a5?theme=dark\"   width=\"700\"   height=\"400\"> </iframe>",
            "Government of AB https://app.malcore.io/share/652553f6aec33d70a1dbbd25/67ab2665da3e8886f5e4ecce OTX AlienVault 2096",
            "UAlberta = https://app.malcore.io/share/652553f6aec33d70a1dbbd25/67ab2665da3e8886f5e4ecbe"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America",
            "Canada"
          ],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "Government",
            "Healthcare",
            "Education"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 6,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 5,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Disable_Duck",
            "id": "244325",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_244325/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 215,
            "FileHash-SHA1": 193,
            "FileHash-SHA256": 1302,
            "URL": 166,
            "domain": 100,
            "hostname": 234
          },
          "indicator_count": 2210,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 131,
          "modified_text": "370 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "678ccc91c5648de42af0d6ee",
          "name": "horselakefn[.]ca - Tc Energy, Duncan, Sturgeon Lake [& WCTC] & Treaty 6, 7, 8 & sac-isc[.]gc[.]ca -02.02.25 - quick look incomplete",
          "description": "Taking a quick look at HLFNA of WCTC & T8FNA, it apppears they along as Treaty 6 & 7 Territory (and the Alberta Regional Office for the Alberta Branch of the Government of Canada) has been hacked/breached",
          "modified": "2025-05-23T19:00:25.262000",
          "created": "2025-01-19T09:57:37.497000",
          "tags": [
            "entity"
          ],
          "references": [
            "https://www.virustotal.com/graph/embed/gd7c52fa412654cc5b239a064a9891ffeba51cfdfcfa84bf291f2745751c6a686?theme=dark",
            "https://www.virustotal.com/gui/collection/86de79c78794e2b83f5410218f1d7231b0e5acd7bd4f124186ed72d0817d6405",
            "https://www.virustotal.com/gui/collection/d176151d51c4e95353544d4c6540cdfdc49d324b47fd3eb532cbe30bcaa46792",
            "https://www.hybrid-analysis.com/sample/05af1781c1b97b7fff85d8eab5072f1fe4e6a7f6bc754c35d1d527f7ef3005c6/68093fa41e226b739d0d401b",
            "https://www.hybrid-analysis.com/sample/05af1781c1b97b7fff85d8eab5072f1fe4e6a7f6bc754c35d1d527f7ef3005c6",
            "https://www.filescan.io/uploads/68093f78218c4a98adde3f92/reports/7e5be6b9-0d5e-4a3b-bb19-4f72974b4207/overview"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "Canada"
          ],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "Government",
            "Education",
            "Healthcare",
            "Agriculture",
            "Chemical",
            "Finance",
            "Transportation"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 14,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Disable_Duck",
            "id": "244325",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_244325/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 4977,
            "FileHash-MD5": 197,
            "FileHash-SHA1": 197,
            "FileHash-SHA256": 2846,
            "domain": 2655,
            "hostname": 4019,
            "CVE": 1,
            "SSLCertFingerprint": 3,
            "email": 4
          },
          "indicator_count": 14899,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 132,
          "modified_text": "374 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "66ad3b7e51c055d13305ad52",
          "name": "treaty8[.]ca",
          "description": "Just another piece of the puzzle taking a look into",
          "modified": "2025-05-01T18:07:16.953000",
          "created": "2024-08-02T20:03:10.879000",
          "tags": [
            "UAlberta"
          ],
          "references": [
            "https://www.virustotal.com/graph/embed/g09343c2567844f43815e5e7198b28eb74ca71bfaba5244dc893156114c5943aa?theme=dark",
            "https://www.virustotal.com/gui/collection/b7ddbd785698a00d83ce3711c842493267d0b3b2ddb261d56fa5f759303c6ba8",
            "https://www.virustotal.com/gui/collection/b7ddbd785698a00d83ce3711c842493267d0b3b2ddb261d56fa5f759303c6ba8/iocs",
            "https://www.virustotal.com/gui/collection/b7ddbd785698a00d83ce3711c842493267d0b3b2ddb261d56fa5f759303c6ba8/graph",
            "",
            "08.04.24: https://www.virustotal.com/graph/embed/gedfb3ae24ffe4a7e84ec983d5d39604f042c7d4571fe4ba98f8db7a1cb564f77?theme=dark"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America",
            "Canada"
          ],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "Education",
            "Government",
            "Healthcare",
            "Telecommunications"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 14,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Disable_Duck",
            "id": "244325",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_244325/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 211,
            "FileHash-MD5": 17,
            "FileHash-SHA1": 17,
            "FileHash-SHA256": 50,
            "hostname": 114,
            "URL": 177,
            "CVE": 8,
            "email": 76
          },
          "indicator_count": 670,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 129,
          "modified_text": "396 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "",
        "https://www.virustotal.com/graph/embed/gd7c52fa412654cc5b239a064a9891ffeba51cfdfcfa84bf291f2745751c6a686?theme=dark",
        "https://www.hybrid-analysis.com/sample/05af1781c1b97b7fff85d8eab5072f1fe4e6a7f6bc754c35d1d527f7ef3005c6",
        "https://www.virustotal.com/gui/collection/b7ddbd785698a00d83ce3711c842493267d0b3b2ddb261d56fa5f759303c6ba8/graph",
        "https://www.hybrid-analysis.com/sample/05af1781c1b97b7fff85d8eab5072f1fe4e6a7f6bc754c35d1d527f7ef3005c6/68093fa41e226b739d0d401b",
        "<iframe   src=\"https://www.virustotal.com/graph/embed/g1ed56ef53af34510a0e0ee0c2d204f066a8684fa5aeb4e69aef49403742ef6a5?theme=dark\"   width=\"700\"   height=\"400\"> </iframe>",
        "https://www.virustotal.com/gui/collection/d176151d51c4e95353544d4c6540cdfdc49d324b47fd3eb532cbe30bcaa46792",
        "https://www.virustotal.com/graph/embed/g09343c2567844f43815e5e7198b28eb74ca71bfaba5244dc893156114c5943aa?theme=dark",
        "https://www.virustotal.com/graph/embed/g34c2ebfedb6c47c286431a829da992c3744ab3fab0d74008946f3b9bbeb83e23?theme=dark",
        "08.04.24: https://www.virustotal.com/graph/embed/gedfb3ae24ffe4a7e84ec983d5d39604f042c7d4571fe4ba98f8db7a1cb564f77?theme=dark",
        "https://viz.greynoise.io/ip/analysis/7e527b44-c950-4c01-bb33-d96",
        "https://www.virustotal.com/gui/collection/b7ddbd785698a00d83ce3711c842493267d0b3b2ddb261d56fa5f759303c6ba8/iocs",
        "https://viz.greynoise.io/ip/analysis/61bb7542-40c2-448e-87d4-947a4623eada",
        "Government of AB https://app.malcore.io/share/652553f6aec33d70a1dbbd25/67ab2665da3e8886f5e4ecce OTX AlienVault 2096",
        "https://www.virustotal.com/graph/embed/g1ed56ef53af34510a0e0ee0c2d204f066a8684fa5aeb4e69aef49403742ef6a5?theme=dark",
        "https://www.virustotal.com/gui/collection/b7ddbd785698a00d83ce3711c842493267d0b3b2ddb261d56fa5f759303c6ba8",
        "https://www.filescan.io/uploads/68093f78218c4a98adde3f92/reports/7e5be6b9-0d5e-4a3b-bb19-4f72974b4207/overview",
        "https://www.virustotal.com/gui/collection/86de79c78794e2b83f5410218f1d7231b0e5acd7bd4f124186ed72d0817d6405",
        "UAlberta = https://app.malcore.io/share/652553f6aec33d70a1dbbd25/67ab2665da3e8886f5e4ecbe"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 0
        },
        "other": {
          "adversary": [],
          "malware_families": [],
          "industries": [
            "Education",
            "Government",
            "Agriculture",
            "Chemical",
            "Energy",
            "Transportation",
            "Finance",
            "Technology",
            "Healthcare",
            "Telecommunications"
          ],
          "unique_indicators": 20367
        }
      }
    },
    "false_positive": [],
    "alexa": "http://www.alexa.com/siteinfo/legacyllcelectric.com",
    "whois": "http://whois.domaintools.com/legacyllcelectric.com",
    "domain": "legacyllcelectric.com",
    "hostname": "Unavailable"
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 6,
  "pulses": [
    {
      "id": "69a5c36b78ed73550bb0bf22",
      "name": "by Disable_Duck",
      "description": "",
      "modified": "2026-03-04T23:37:24.208000",
      "created": "2026-03-02T17:05:47.288000",
      "tags": [
        "kgs0",
        "kls0",
        "botname http",
        "entity",
        "UAlberta",
        "Telus",
        "Norton",
        "ffss",
        "Alberta",
        "AlbertaNDP",
        "InteriorHealth",
        "RCMP",
        "CrimeStoppersAB",
        "EdmontonPolice",
        "RCMP Kelowna",
        "RCMP AB",
        "TLS/SSL Crawler",
        "CVE-2026-24061 Attempt",
        "Generic IoT Default Password Attempt",
        "Cisco Prime Infrastructure CVE-2019-1821 RCE Attempt",
        "Dahua Backdoor Attempt",
        "ENV Crawler",
        "DCERPC Protocol",
        "Carries HTTP Referer",
        "GNU Inetutils Telnetd Auth Bypass",
        "ICMPv4 Protocol"
      ],
      "references": [
        "https://www.virustotal.com/graph/embed/g34c2ebfedb6c47c286431a829da992c3744ab3fab0d74008946f3b9bbeb83e23?theme=dark",
        "https://viz.greynoise.io/ip/analysis/61bb7542-40c2-448e-87d4-947a4623eada",
        "https://viz.greynoise.io/ip/analysis/7e527b44-c950-4c01-bb33-d96"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America",
        "Canada",
        "Netherlands",
        "Panama",
        "Poland",
        "United Kingdom of Great Britain and Northern Ireland",
        "Slovakia",
        "Aruba",
        "Anguilla",
        "Australia",
        "Costa Rica",
        "Guatemala",
        "Mexico",
        "Trinidad and Tobago",
        "Cura\u00e7ao",
        "Philippines",
        "Virgin Islands, U.S.",
        "Ukraine",
        "Barbados",
        "Germany",
        "Sint Maarten (Dutch part)",
        "Argentina",
        "Switzerland"
      ],
      "malware_families": [],
      "attack_ids": [],
      "industries": [
        "Education",
        "Healthcare",
        "Government",
        "Technology",
        "Energy",
        "Telecommunications"
      ],
      "TLP": "white",
      "cloned_from": "6901363c4ce422f5caf0f72c",
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 2,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 3903,
        "FileHash-SHA1": 4967,
        "FileHash-SHA256": 12884,
        "URL": 996,
        "domain": 987,
        "hostname": 3306,
        "email": 4,
        "CVE": 1
      },
      "indicator_count": 27048,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 67,
      "modified_text": "88 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6901363c4ce422f5caf0f72c",
      "name": "Copy of DevT-OddTags-Browser-BasedOdditites - (L4ke.Aff3ct.216, 01.18.26)",
      "description": "Updated based on VT Graph & Tracking Spread of Cybercrime. This Pulse is mostly covering activity in the Province of Alberta Canada. Given recent news, it appears that BC Interior Health and Kelowna RCMP Detachment impacted in addition to Alberta Sectors of Education, Healthcare, and Government (Provincial & Federal - e.g. Treaty 6,7,8 as well as the Canadian CRA heavily impacted). \nEnriched a graph by vt user (L4ke.Aff3ct.216, 01.02.26)\nSubmitted IOCs to Greynoise.io (10.28.25)",
      "modified": "2026-02-18T05:00:41.494000",
      "created": "2025-10-28T21:31:40.008000",
      "tags": [
        "kgs0",
        "kls0",
        "botname http",
        "entity",
        "UAlberta",
        "Telus",
        "Norton",
        "ffss",
        "Alberta",
        "AlbertaNDP",
        "InteriorHealth",
        "RCMP",
        "CrimeStoppersAB",
        "EdmontonPolice",
        "RCMP Kelowna",
        "RCMP AB"
      ],
      "references": [
        "https://www.virustotal.com/graph/embed/g34c2ebfedb6c47c286431a829da992c3744ab3fab0d74008946f3b9bbeb83e23?theme=dark",
        "https://viz.greynoise.io/ip/analysis/61bb7542-40c2-448e-87d4-947a4623eada"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America",
        "Canada",
        "Netherlands",
        "Panama",
        "Poland",
        "United Kingdom of Great Britain and Northern Ireland",
        "Slovakia",
        "Aruba",
        "Anguilla",
        "Australia",
        "Costa Rica",
        "Guatemala",
        "Mexico",
        "Trinidad and Tobago",
        "Cura\u00e7ao",
        "Philippines",
        "Virgin Islands, U.S.",
        "Ukraine",
        "Barbados",
        "Germany",
        "Sint Maarten (Dutch part)"
      ],
      "malware_families": [],
      "attack_ids": [],
      "industries": [
        "Education",
        "Healthcare",
        "Government",
        "Technology",
        "Energy",
        "Telecommunications"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 1,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 1,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Disable_Duck",
        "id": "244325",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_244325/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 3903,
        "FileHash-SHA1": 4967,
        "FileHash-SHA256": 12884,
        "URL": 995,
        "domain": 984,
        "hostname": 3305,
        "email": 4
      },
      "indicator_count": 27042,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 129,
      "modified_text": "103 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "68b78d521f024d3a98fc79c8",
      "name": "VT Graph miniuser - Databreach IOCs & Links",
      "description": "Related to Pulse: Food for Thought (Updated 09.02.25)\n\n*Note most links are malicious",
      "modified": "2025-10-03T00:01:12.616000",
      "created": "2025-09-03T00:35:30.936000",
      "tags": [
        "kgs0",
        "kls0",
        "entity",
        "UAlberta",
        "University of Alberta",
        "Hacked",
        "DataBreach"
      ],
      "references": [
        "https://www.virustotal.com/graph/embed/g1ed56ef53af34510a0e0ee0c2d204f066a8684fa5aeb4e69aef49403742ef6a5?theme=dark"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "Canada"
      ],
      "malware_families": [],
      "attack_ids": [],
      "industries": [
        "Education"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 7,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Disable_Duck",
        "id": "244325",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_244325/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 132,
        "FileHash-SHA1": 121,
        "FileHash-SHA256": 711,
        "URL": 83,
        "domain": 50,
        "hostname": 125
      },
      "indicator_count": 1222,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 129,
      "modified_text": "241 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "67b109cbfbcc6f92c399b327",
      "name": "UAlberta Breach Data - Food for thought - thoughts & input on how to 'bring some attention to this' (not enriched)",
      "description": "Just thought I'd throw thisntogether and 'see what ya'll make of it' (documents a VT graph produced and slightly modified) that pulls a lot of things together.  Highlights both 'some problems' - U of A / Gov. of AB (who are also some 'solutions'). \nIdeas on how to grab their attention and maybe bring some 'urgency' to this issue? I have a few solutions and ideas for everyone - problem: I require some folks to 'do their jobs' (there is not 10 of me). Thoughts on how to encourage them to act on these problems. Present status: Connected directly to them on other devices. Within literal 5 min walking range.",
      "modified": "2025-05-27T07:01:17.646000",
      "created": "2025-02-15T21:40:27.895000",
      "tags": [
        "kgs0",
        "kls0"
      ],
      "references": [
        "https://www.virustotal.com/graph/embed/g1ed56ef53af34510a0e0ee0c2d204f066a8684fa5aeb4e69aef49403742ef6a5?theme=dark",
        "<iframe   src=\"https://www.virustotal.com/graph/embed/g1ed56ef53af34510a0e0ee0c2d204f066a8684fa5aeb4e69aef49403742ef6a5?theme=dark\"   width=\"700\"   height=\"400\"> </iframe>",
        "Government of AB https://app.malcore.io/share/652553f6aec33d70a1dbbd25/67ab2665da3e8886f5e4ecce OTX AlienVault 2096",
        "UAlberta = https://app.malcore.io/share/652553f6aec33d70a1dbbd25/67ab2665da3e8886f5e4ecbe"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America",
        "Canada"
      ],
      "malware_families": [],
      "attack_ids": [],
      "industries": [
        "Government",
        "Healthcare",
        "Education"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 6,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 5,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Disable_Duck",
        "id": "244325",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_244325/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 215,
        "FileHash-SHA1": 193,
        "FileHash-SHA256": 1302,
        "URL": 166,
        "domain": 100,
        "hostname": 234
      },
      "indicator_count": 2210,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 131,
      "modified_text": "370 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "678ccc91c5648de42af0d6ee",
      "name": "horselakefn[.]ca - Tc Energy, Duncan, Sturgeon Lake [& WCTC] & Treaty 6, 7, 8 & sac-isc[.]gc[.]ca -02.02.25 - quick look incomplete",
      "description": "Taking a quick look at HLFNA of WCTC & T8FNA, it apppears they along as Treaty 6 & 7 Territory (and the Alberta Regional Office for the Alberta Branch of the Government of Canada) has been hacked/breached",
      "modified": "2025-05-23T19:00:25.262000",
      "created": "2025-01-19T09:57:37.497000",
      "tags": [
        "entity"
      ],
      "references": [
        "https://www.virustotal.com/graph/embed/gd7c52fa412654cc5b239a064a9891ffeba51cfdfcfa84bf291f2745751c6a686?theme=dark",
        "https://www.virustotal.com/gui/collection/86de79c78794e2b83f5410218f1d7231b0e5acd7bd4f124186ed72d0817d6405",
        "https://www.virustotal.com/gui/collection/d176151d51c4e95353544d4c6540cdfdc49d324b47fd3eb532cbe30bcaa46792",
        "https://www.hybrid-analysis.com/sample/05af1781c1b97b7fff85d8eab5072f1fe4e6a7f6bc754c35d1d527f7ef3005c6/68093fa41e226b739d0d401b",
        "https://www.hybrid-analysis.com/sample/05af1781c1b97b7fff85d8eab5072f1fe4e6a7f6bc754c35d1d527f7ef3005c6",
        "https://www.filescan.io/uploads/68093f78218c4a98adde3f92/reports/7e5be6b9-0d5e-4a3b-bb19-4f72974b4207/overview"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "Canada"
      ],
      "malware_families": [],
      "attack_ids": [],
      "industries": [
        "Government",
        "Education",
        "Healthcare",
        "Agriculture",
        "Chemical",
        "Finance",
        "Transportation"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 14,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Disable_Duck",
        "id": "244325",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_244325/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 4977,
        "FileHash-MD5": 197,
        "FileHash-SHA1": 197,
        "FileHash-SHA256": 2846,
        "domain": 2655,
        "hostname": 4019,
        "CVE": 1,
        "SSLCertFingerprint": 3,
        "email": 4
      },
      "indicator_count": 14899,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 132,
      "modified_text": "374 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "66ad3b7e51c055d13305ad52",
      "name": "treaty8[.]ca",
      "description": "Just another piece of the puzzle taking a look into",
      "modified": "2025-05-01T18:07:16.953000",
      "created": "2024-08-02T20:03:10.879000",
      "tags": [
        "UAlberta"
      ],
      "references": [
        "https://www.virustotal.com/graph/embed/g09343c2567844f43815e5e7198b28eb74ca71bfaba5244dc893156114c5943aa?theme=dark",
        "https://www.virustotal.com/gui/collection/b7ddbd785698a00d83ce3711c842493267d0b3b2ddb261d56fa5f759303c6ba8",
        "https://www.virustotal.com/gui/collection/b7ddbd785698a00d83ce3711c842493267d0b3b2ddb261d56fa5f759303c6ba8/iocs",
        "https://www.virustotal.com/gui/collection/b7ddbd785698a00d83ce3711c842493267d0b3b2ddb261d56fa5f759303c6ba8/graph",
        "",
        "08.04.24: https://www.virustotal.com/graph/embed/gedfb3ae24ffe4a7e84ec983d5d39604f042c7d4571fe4ba98f8db7a1cb564f77?theme=dark"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America",
        "Canada"
      ],
      "malware_families": [],
      "attack_ids": [],
      "industries": [
        "Education",
        "Government",
        "Healthcare",
        "Telecommunications"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 14,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Disable_Duck",
        "id": "244325",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_244325/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 211,
        "FileHash-MD5": 17,
        "FileHash-SHA1": 17,
        "FileHash-SHA256": 50,
        "hostname": 114,
        "URL": 177,
        "CVE": 8,
        "email": 76
      },
      "indicator_count": 670,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 129,
      "modified_text": "396 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "https://legacyllcelectric.com/",
    "type": "URL"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "https://legacyllcelectric.com/",
    "type": "URL",
    "found": false,
    "verdict": "clean",
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780356842.4298487
}