{
  "type": "URL",
  "indicator": "https://magento.userinfo.email",
  "general": {
    "sections": [
      "general",
      "url_list",
      "http_scans",
      "screenshot"
    ],
    "indicator": "https://magento.userinfo.email",
    "type": "url",
    "type_title": "URL",
    "validation": [],
    "base_indicator": {
      "id": 3742605172,
      "indicator": "https://magento.userinfo.email",
      "type": "URL",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 7,
      "pulses": [
        {
          "id": "66831f04ad169d3b685c9645",
          "name": "Win.exe , Bootstrapper.exe , pl.microsoft.com , microsoft.com/pki/certs/MicRooCerAut_2010",
          "description": "rule UPX { meta: author = \"kevoreilly\" description = \"UPX dump on OEP (original entry point)\" cape_options = \"bp0=$upx32+9,bp0=$upx64+11,action0=step2oep\" strings: $upx32 = {6A 00 39 C4 75 FA 83 EC ?? rule Windows_Generic_Threat_5c18a7f9 { meta: author = \"Elastic Security\" id = \"5c18a7f9-01af-468b-9a63-cfecbeb739d7\" fingerprint = \"68c9114ac342d527cf6f0cea96b63dfeb8e5d80060572fad2bbc7d287c752d4a\" creation_date = \"2024-01-21\" last_modified = \"2024-02-08\" threat_name = \"Windows.\ndca60557a1f47948d7158ba9f56ad8656bd0b343488264e23037fd66174e3cd5\nb4f7ace176d0eeba828e7c03f39befb30355223860d14e6ca4422fdb81778df7\nPr\u00f3bka Cuckoo-843b85c493b8a9048b2ab73a9d1a8.cab - polecenie Microsoft Office.\nResearchers have decoded a new set of data on how to store data in a safe and easy-to-use digital format, as well as the results of a series of tests on the subject.",
          "modified": "2024-10-14T20:36:07.924000",
          "created": "2024-07-01T21:26:27.623000",
          "tags": [
            "no expiration",
            "filehashsha256",
            "hacktool",
            "expiration",
            "win32autokms no",
            "filehashmd5",
            "filehashsha1",
            "virus",
            "sha1",
            "win32",
            "trojan",
            "ransom",
            "pejzasz",
            "vhash",
            "imphash",
            "ssdeep",
            "hash",
            "skrt",
            "y pkmsauto",
            "crlf",
            "dodaj",
            "hostsettings",
            "v wczono",
            "t regdword",
            "powershell",
            "nowy",
            "pe32",
            "intel",
            "ms windows",
            "nazwa typ",
            "md5 nazwa",
            "procesu",
            "vs2013",
            "rticon neutral",
            "compiler",
            "submission",
            "file version",
            "chi2",
            "contained",
            "authentihash",
            "pehash",
            "uacme akagi",
            "cobalt strike",
            "detects",
            "roth",
            "sliver stagers",
            "highvol",
            "detects imphash",
            "zero",
            "virustotal",
            "detection rule",
            "license",
            "arnim rupp",
            "whasz",
            "github",
            "postpuj zgodnie",
            "przegld",
            "danie id",
            "github og",
            "url https",
            "error",
            "toast",
            "clientrender",
            "date",
            "promise",
            "65536",
            "client env",
            "alloy",
            "rangeerror",
            "staff",
            "upx dump",
            "security",
            "license v2",
            "e8 ff",
            "fc ff",
            "ff ff",
            "e8 f7",
            "c3 e8",
            "e8 db",
            "f0 c9",
            "c8 ff",
            "c9 c3",
            "c4 a8",
            "a7 ff",
            "f1 e8",
            "ec c7",
            "f0 c0",
            "c1 e9",
            "ec e8",
            "ff e8",
            "a3 a4",
            "db e2",
            "b0 e9",
            "e8 ba",
            "b9 f3",
            "e4 f8",
            "ff e9",
            "eb ed",
            "b6 b3",
            "b6 bb",
            "c8 f7",
            "c6 a8",
            "f6 c1",
            "b0 d7",
            "df e0",
            "c4 f0",
            "fc e8",
            "cf e5",
            "f8 ff",
            "f7 ff",
            "cc cc",
            "c3 b8",
            "b9 ff",
            "ff f3",
            "ab aa",
            "f7 f9",
            "b8 c7",
            "be ad",
            "ef be",
            "ad de",
            "e9 cd",
            "c4 f4",
            "fe ff",
            "d1 fa",
            "fa fc",
            "f3 a6",
            "fb ff",
            "fc c6",
            "fc eb",
            "e8 ed",
            "fb d1",
            "b6 f8",
            "c7 c7",
            "ec d0",
            "b6 d2",
            "ff e1",
            "c0 ac",
            "c1 e3",
            "c3 aa",
            "c2 c1",
            "d3 f7",
            "fc c7",
            "win32 cabinet",
            "selfextractor",
            "pecompact",
            "yarahub",
            "yara",
            "repository",
            "hub",
            "repo",
            "malware_onenote_delivery_jan23",
            "yara rule",
            "team",
            "sifalconteam",
            "yarahub entry",
            "rule details",
            "malpedia family",
            "rule matching",
            "content copy",
            "download rule",
            "malware",
            "cc by",
            "vbscript",
            "sub autoopen",
            "getobject",
            "batch"
          ],
          "references": [
            "https://github.githubassets.com/assets/ui_packages_react-core_create-browser-history_ts-ui_packages_safe-storage_safe-storage_ts-ui_-682c2c-2c0ad573fa49.js",
            "https://yaraify.abuse.ch/yarahub/rule/MALWARE_OneNote_Delivery_Jan23"
          ],
          "public": 1,
          "adversary": "rule MALWARE_OneNote_Delivery_Jan23 { meta: author = \"SECUINFRA Falcon Team (@SI_FalconTeam)\" descri",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 361,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Arek-BTC",
            "id": "212764",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_212764/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 14732,
            "FileHash-MD5": 4316,
            "FileHash-SHA1": 3405,
            "YARA": 181,
            "URL": 4793,
            "domain": 1717,
            "hostname": 4354,
            "IPv4": 107,
            "IPv6": 845,
            "email": 26,
            "CVE": 13,
            "FilePath": 1
          },
          "indicator_count": 34490,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 145,
          "modified_text": "593 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6570a464c07b076a6022abbe",
          "name": "Social Engineering - Anonymizer  - Qakbot \u221a",
          "description": "",
          "modified": "2023-12-06T16:42:12.952000",
          "created": "2023-12-06T16:42:12.952000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 9,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 28,
            "URL": 247,
            "FileHash-SHA256": 705,
            "hostname": 126,
            "FileHash-MD5": 17,
            "FileHash-SHA1": 13
          },
          "indicator_count": 1136,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "906 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6570a0c0b966ec5b823d2ae7",
          "name": "PROXY - Defense Evasion \u2022 Malicious Spammer",
          "description": "",
          "modified": "2023-12-06T16:26:40.335000",
          "created": "2023-12-06T16:26:40.335000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 8,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 28,
            "URL": 247,
            "FileHash-SHA256": 705,
            "hostname": 126,
            "FileHash-MD5": 17,
            "FileHash-SHA1": 13
          },
          "indicator_count": 1136,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "906 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6570a05bc6152413ed0fdbaa",
          "name": "Social Engineering -Striven Anonymizer",
          "description": "",
          "modified": "2023-12-06T16:24:59.615000",
          "created": "2023-12-06T16:24:59.615000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 8,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 28,
            "URL": 247,
            "FileHash-SHA256": 705,
            "hostname": 126,
            "FileHash-MD5": 17,
            "FileHash-SHA1": 13
          },
          "indicator_count": 1136,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "906 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "64e26c454e86439fd9462541",
          "name": "Social Engineering -Striven Anonymizer",
          "description": "Optin Example: Affected (device w/vulnerabilities or in BotNetwork, etc) clocks on a ' Sponsored Ad' that fits search query. Will view webpage and Optin to be contacted by email and/or telephone. Both methods will likely be required by attacker. Bad actor will call immediately, quality of call can be surprisingly poor (obnoxiously noisy), BA takes assessment, quotes prices much higher than should be. You are desperate because no one else can help. Actor will demand email,  will send various attachments, all malicious. Will not look suspicious, (strategy, video introduction, proposal, etc). Once you don't respond you may  receive email contact from different email, more attachments. Follow ups...by now bad actor has full use of device. Spyware. Apps auto download, blocked  from removal. Incredible cycle.\n\n\nLogin.aspx192.118.8.10 = 192.118.8.10\niphones.orange.co.il\nhttps://www.partner.co.il/n/login?utm_source=sm",
          "modified": "2023-09-19T20:04:24.850000",
          "created": "2023-08-20T19:40:53.299000",
          "tags": [
            "qakbot",
            "string",
            "social engineering",
            "click",
            "malspam",
            "chromeua",
            "optout",
            "drmedgeua",
            "pattern match",
            "unicode",
            "optin",
            "suspicious",
            "footer",
            "ansi",
            "dropped file",
            "localappdata",
            "scam",
            "anonymizer",
            "Binary Padding",
            "Apt",
            "Defense Evasion",
            "junk files"
          ],
          "references": [
            "https://login.striven.com/Security/Login.aspx192.118.8.10",
            "MilesIT"
          ],
          "public": 1,
          "adversary": "Striven",
          "targeted_countries": [
            "United States of America",
            "Israel"
          ],
          "malware_families": [
            {
              "id": "Black Basta (ELF)",
              "display_name": "Black Basta (ELF)",
              "target": null
            },
            {
              "id": "ALF:MonitoringTool:AndroidOS/FinSpy",
              "display_name": "ALF:MonitoringTool:AndroidOS/FinSpy",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            }
          ],
          "industries": [
            "Cyber Security"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 21,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 201,
            "domain": 52,
            "URL": 443,
            "FileHash-MD5": 17,
            "FileHash-SHA256": 738,
            "FileHash-SHA1": 13
          },
          "indicator_count": 1464,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 222,
          "modified_text": "984 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "64e7c73087130803d20066ef",
          "name": "PROXY - Defense Evasion \u2022 Malicious Spammer ",
          "description": "",
          "modified": "2023-09-19T20:04:24.850000",
          "created": "2023-08-24T21:10:08.493000",
          "tags": [
            "qakbot",
            "string",
            "social engineering",
            "click",
            "malspam",
            "chromeua",
            "optout",
            "drmedgeua",
            "pattern match",
            "unicode",
            "optin",
            "suspicious",
            "footer",
            "ansi",
            "dropped file",
            "localappdata",
            "scam",
            "anonymizer",
            "Binary Padding",
            "Apt",
            "Defense Evasion",
            "junk files"
          ],
          "references": [
            "https://login.striven.com/Security/Login.aspx192.118.8.10",
            "MilesIT"
          ],
          "public": 1,
          "adversary": "Striven",
          "targeted_countries": [
            "United States of America",
            "Israel"
          ],
          "malware_families": [
            {
              "id": "Black Basta (ELF)",
              "display_name": "Black Basta (ELF)",
              "target": null
            },
            {
              "id": "ALF:MonitoringTool:AndroidOS/FinSpy",
              "display_name": "ALF:MonitoringTool:AndroidOS/FinSpy",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            }
          ],
          "industries": [
            "Cyber Security"
          ],
          "TLP": "white",
          "cloned_from": "64e26c454e86439fd9462541",
          "export_count": 18,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 201,
            "domain": 52,
            "URL": 443,
            "FileHash-MD5": 17,
            "FileHash-SHA256": 738,
            "FileHash-SHA1": 13
          },
          "indicator_count": 1464,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 223,
          "modified_text": "984 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6500a47dd316d0ea5616044d",
          "name": "Social Engineering - Anonymizer  - Qakbot \u221a",
          "description": "",
          "modified": "2023-09-19T20:04:24.850000",
          "created": "2023-09-12T17:48:45.349000",
          "tags": [
            "qakbot",
            "string",
            "social engineering",
            "click",
            "malspam",
            "chromeua",
            "optout",
            "drmedgeua",
            "pattern match",
            "unicode",
            "optin",
            "suspicious",
            "footer",
            "ansi",
            "dropped file",
            "localappdata",
            "scam",
            "anonymizer",
            "Binary Padding",
            "Apt",
            "Defense Evasion",
            "junk files"
          ],
          "references": [
            "https://login.striven.com/Security/Login.aspx192.118.8.10",
            "MilesIT"
          ],
          "public": 1,
          "adversary": "Striven",
          "targeted_countries": [
            "United States of America",
            "Israel"
          ],
          "malware_families": [
            {
              "id": "Black Basta (ELF)",
              "display_name": "Black Basta (ELF)",
              "target": null
            },
            {
              "id": "ALF:MonitoringTool:AndroidOS/FinSpy",
              "display_name": "ALF:MonitoringTool:AndroidOS/FinSpy",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            }
          ],
          "industries": [
            "Cyber Security"
          ],
          "TLP": "white",
          "cloned_from": "64e26c454e86439fd9462541",
          "export_count": 21,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 201,
            "domain": 52,
            "URL": 443,
            "FileHash-MD5": 17,
            "FileHash-SHA256": 738,
            "FileHash-SHA1": 13
          },
          "indicator_count": 1464,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 224,
          "modified_text": "984 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "https://github.githubassets.com/assets/ui_packages_react-core_create-browser-history_ts-ui_packages_safe-storage_safe-storage_ts-ui_-682c2c-2c0ad573fa49.js",
        "https://login.striven.com/Security/Login.aspx192.118.8.10",
        "https://yaraify.abuse.ch/yarahub/rule/MALWARE_OneNote_Delivery_Jan23",
        "MilesIT"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 0
        },
        "other": {
          "adversary": [
            "Striven",
            "rule MALWARE_OneNote_Delivery_Jan23 { meta: author = \"SECUINFRA Falcon Team (@SI_FalconTeam)\" descri"
          ],
          "malware_families": [
            "Alf:monitoringtool:androidos/finspy",
            "Black basta (elf)"
          ],
          "industries": [
            "Cyber security"
          ],
          "unique_indicators": 31957
        }
      }
    },
    "false_positive": [],
    "alexa": "http://www.alexa.com/siteinfo/userinfo.email",
    "whois": "http://whois.domaintools.com/userinfo.email",
    "domain": "userinfo.email",
    "hostname": "magento.userinfo.email"
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 7,
  "pulses": [
    {
      "id": "66831f04ad169d3b685c9645",
      "name": "Win.exe , Bootstrapper.exe , pl.microsoft.com , microsoft.com/pki/certs/MicRooCerAut_2010",
      "description": "rule UPX { meta: author = \"kevoreilly\" description = \"UPX dump on OEP (original entry point)\" cape_options = \"bp0=$upx32+9,bp0=$upx64+11,action0=step2oep\" strings: $upx32 = {6A 00 39 C4 75 FA 83 EC ?? rule Windows_Generic_Threat_5c18a7f9 { meta: author = \"Elastic Security\" id = \"5c18a7f9-01af-468b-9a63-cfecbeb739d7\" fingerprint = \"68c9114ac342d527cf6f0cea96b63dfeb8e5d80060572fad2bbc7d287c752d4a\" creation_date = \"2024-01-21\" last_modified = \"2024-02-08\" threat_name = \"Windows.\ndca60557a1f47948d7158ba9f56ad8656bd0b343488264e23037fd66174e3cd5\nb4f7ace176d0eeba828e7c03f39befb30355223860d14e6ca4422fdb81778df7\nPr\u00f3bka Cuckoo-843b85c493b8a9048b2ab73a9d1a8.cab - polecenie Microsoft Office.\nResearchers have decoded a new set of data on how to store data in a safe and easy-to-use digital format, as well as the results of a series of tests on the subject.",
      "modified": "2024-10-14T20:36:07.924000",
      "created": "2024-07-01T21:26:27.623000",
      "tags": [
        "no expiration",
        "filehashsha256",
        "hacktool",
        "expiration",
        "win32autokms no",
        "filehashmd5",
        "filehashsha1",
        "virus",
        "sha1",
        "win32",
        "trojan",
        "ransom",
        "pejzasz",
        "vhash",
        "imphash",
        "ssdeep",
        "hash",
        "skrt",
        "y pkmsauto",
        "crlf",
        "dodaj",
        "hostsettings",
        "v wczono",
        "t regdword",
        "powershell",
        "nowy",
        "pe32",
        "intel",
        "ms windows",
        "nazwa typ",
        "md5 nazwa",
        "procesu",
        "vs2013",
        "rticon neutral",
        "compiler",
        "submission",
        "file version",
        "chi2",
        "contained",
        "authentihash",
        "pehash",
        "uacme akagi",
        "cobalt strike",
        "detects",
        "roth",
        "sliver stagers",
        "highvol",
        "detects imphash",
        "zero",
        "virustotal",
        "detection rule",
        "license",
        "arnim rupp",
        "whasz",
        "github",
        "postpuj zgodnie",
        "przegld",
        "danie id",
        "github og",
        "url https",
        "error",
        "toast",
        "clientrender",
        "date",
        "promise",
        "65536",
        "client env",
        "alloy",
        "rangeerror",
        "staff",
        "upx dump",
        "security",
        "license v2",
        "e8 ff",
        "fc ff",
        "ff ff",
        "e8 f7",
        "c3 e8",
        "e8 db",
        "f0 c9",
        "c8 ff",
        "c9 c3",
        "c4 a8",
        "a7 ff",
        "f1 e8",
        "ec c7",
        "f0 c0",
        "c1 e9",
        "ec e8",
        "ff e8",
        "a3 a4",
        "db e2",
        "b0 e9",
        "e8 ba",
        "b9 f3",
        "e4 f8",
        "ff e9",
        "eb ed",
        "b6 b3",
        "b6 bb",
        "c8 f7",
        "c6 a8",
        "f6 c1",
        "b0 d7",
        "df e0",
        "c4 f0",
        "fc e8",
        "cf e5",
        "f8 ff",
        "f7 ff",
        "cc cc",
        "c3 b8",
        "b9 ff",
        "ff f3",
        "ab aa",
        "f7 f9",
        "b8 c7",
        "be ad",
        "ef be",
        "ad de",
        "e9 cd",
        "c4 f4",
        "fe ff",
        "d1 fa",
        "fa fc",
        "f3 a6",
        "fb ff",
        "fc c6",
        "fc eb",
        "e8 ed",
        "fb d1",
        "b6 f8",
        "c7 c7",
        "ec d0",
        "b6 d2",
        "ff e1",
        "c0 ac",
        "c1 e3",
        "c3 aa",
        "c2 c1",
        "d3 f7",
        "fc c7",
        "win32 cabinet",
        "selfextractor",
        "pecompact",
        "yarahub",
        "yara",
        "repository",
        "hub",
        "repo",
        "malware_onenote_delivery_jan23",
        "yara rule",
        "team",
        "sifalconteam",
        "yarahub entry",
        "rule details",
        "malpedia family",
        "rule matching",
        "content copy",
        "download rule",
        "malware",
        "cc by",
        "vbscript",
        "sub autoopen",
        "getobject",
        "batch"
      ],
      "references": [
        "https://github.githubassets.com/assets/ui_packages_react-core_create-browser-history_ts-ui_packages_safe-storage_safe-storage_ts-ui_-682c2c-2c0ad573fa49.js",
        "https://yaraify.abuse.ch/yarahub/rule/MALWARE_OneNote_Delivery_Jan23"
      ],
      "public": 1,
      "adversary": "rule MALWARE_OneNote_Delivery_Jan23 { meta: author = \"SECUINFRA Falcon Team (@SI_FalconTeam)\" descri",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 361,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Arek-BTC",
        "id": "212764",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_212764/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 14732,
        "FileHash-MD5": 4316,
        "FileHash-SHA1": 3405,
        "YARA": 181,
        "URL": 4793,
        "domain": 1717,
        "hostname": 4354,
        "IPv4": 107,
        "IPv6": 845,
        "email": 26,
        "CVE": 13,
        "FilePath": 1
      },
      "indicator_count": 34490,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 145,
      "modified_text": "593 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6570a464c07b076a6022abbe",
      "name": "Social Engineering - Anonymizer  - Qakbot \u221a",
      "description": "",
      "modified": "2023-12-06T16:42:12.952000",
      "created": "2023-12-06T16:42:12.952000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 9,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 28,
        "URL": 247,
        "FileHash-SHA256": 705,
        "hostname": 126,
        "FileHash-MD5": 17,
        "FileHash-SHA1": 13
      },
      "indicator_count": 1136,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "906 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6570a0c0b966ec5b823d2ae7",
      "name": "PROXY - Defense Evasion \u2022 Malicious Spammer",
      "description": "",
      "modified": "2023-12-06T16:26:40.335000",
      "created": "2023-12-06T16:26:40.335000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 8,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 28,
        "URL": 247,
        "FileHash-SHA256": 705,
        "hostname": 126,
        "FileHash-MD5": 17,
        "FileHash-SHA1": 13
      },
      "indicator_count": 1136,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "906 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6570a05bc6152413ed0fdbaa",
      "name": "Social Engineering -Striven Anonymizer",
      "description": "",
      "modified": "2023-12-06T16:24:59.615000",
      "created": "2023-12-06T16:24:59.615000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 8,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 28,
        "URL": 247,
        "FileHash-SHA256": 705,
        "hostname": 126,
        "FileHash-MD5": 17,
        "FileHash-SHA1": 13
      },
      "indicator_count": 1136,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "906 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "64e26c454e86439fd9462541",
      "name": "Social Engineering -Striven Anonymizer",
      "description": "Optin Example: Affected (device w/vulnerabilities or in BotNetwork, etc) clocks on a ' Sponsored Ad' that fits search query. Will view webpage and Optin to be contacted by email and/or telephone. Both methods will likely be required by attacker. Bad actor will call immediately, quality of call can be surprisingly poor (obnoxiously noisy), BA takes assessment, quotes prices much higher than should be. You are desperate because no one else can help. Actor will demand email,  will send various attachments, all malicious. Will not look suspicious, (strategy, video introduction, proposal, etc). Once you don't respond you may  receive email contact from different email, more attachments. Follow ups...by now bad actor has full use of device. Spyware. Apps auto download, blocked  from removal. Incredible cycle.\n\n\nLogin.aspx192.118.8.10 = 192.118.8.10\niphones.orange.co.il\nhttps://www.partner.co.il/n/login?utm_source=sm",
      "modified": "2023-09-19T20:04:24.850000",
      "created": "2023-08-20T19:40:53.299000",
      "tags": [
        "qakbot",
        "string",
        "social engineering",
        "click",
        "malspam",
        "chromeua",
        "optout",
        "drmedgeua",
        "pattern match",
        "unicode",
        "optin",
        "suspicious",
        "footer",
        "ansi",
        "dropped file",
        "localappdata",
        "scam",
        "anonymizer",
        "Binary Padding",
        "Apt",
        "Defense Evasion",
        "junk files"
      ],
      "references": [
        "https://login.striven.com/Security/Login.aspx192.118.8.10",
        "MilesIT"
      ],
      "public": 1,
      "adversary": "Striven",
      "targeted_countries": [
        "United States of America",
        "Israel"
      ],
      "malware_families": [
        {
          "id": "Black Basta (ELF)",
          "display_name": "Black Basta (ELF)",
          "target": null
        },
        {
          "id": "ALF:MonitoringTool:AndroidOS/FinSpy",
          "display_name": "ALF:MonitoringTool:AndroidOS/FinSpy",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        }
      ],
      "industries": [
        "Cyber Security"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 21,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 201,
        "domain": 52,
        "URL": 443,
        "FileHash-MD5": 17,
        "FileHash-SHA256": 738,
        "FileHash-SHA1": 13
      },
      "indicator_count": 1464,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 222,
      "modified_text": "984 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "64e7c73087130803d20066ef",
      "name": "PROXY - Defense Evasion \u2022 Malicious Spammer ",
      "description": "",
      "modified": "2023-09-19T20:04:24.850000",
      "created": "2023-08-24T21:10:08.493000",
      "tags": [
        "qakbot",
        "string",
        "social engineering",
        "click",
        "malspam",
        "chromeua",
        "optout",
        "drmedgeua",
        "pattern match",
        "unicode",
        "optin",
        "suspicious",
        "footer",
        "ansi",
        "dropped file",
        "localappdata",
        "scam",
        "anonymizer",
        "Binary Padding",
        "Apt",
        "Defense Evasion",
        "junk files"
      ],
      "references": [
        "https://login.striven.com/Security/Login.aspx192.118.8.10",
        "MilesIT"
      ],
      "public": 1,
      "adversary": "Striven",
      "targeted_countries": [
        "United States of America",
        "Israel"
      ],
      "malware_families": [
        {
          "id": "Black Basta (ELF)",
          "display_name": "Black Basta (ELF)",
          "target": null
        },
        {
          "id": "ALF:MonitoringTool:AndroidOS/FinSpy",
          "display_name": "ALF:MonitoringTool:AndroidOS/FinSpy",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        }
      ],
      "industries": [
        "Cyber Security"
      ],
      "TLP": "white",
      "cloned_from": "64e26c454e86439fd9462541",
      "export_count": 18,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 201,
        "domain": 52,
        "URL": 443,
        "FileHash-MD5": 17,
        "FileHash-SHA256": 738,
        "FileHash-SHA1": 13
      },
      "indicator_count": 1464,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 223,
      "modified_text": "984 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6500a47dd316d0ea5616044d",
      "name": "Social Engineering - Anonymizer  - Qakbot \u221a",
      "description": "",
      "modified": "2023-09-19T20:04:24.850000",
      "created": "2023-09-12T17:48:45.349000",
      "tags": [
        "qakbot",
        "string",
        "social engineering",
        "click",
        "malspam",
        "chromeua",
        "optout",
        "drmedgeua",
        "pattern match",
        "unicode",
        "optin",
        "suspicious",
        "footer",
        "ansi",
        "dropped file",
        "localappdata",
        "scam",
        "anonymizer",
        "Binary Padding",
        "Apt",
        "Defense Evasion",
        "junk files"
      ],
      "references": [
        "https://login.striven.com/Security/Login.aspx192.118.8.10",
        "MilesIT"
      ],
      "public": 1,
      "adversary": "Striven",
      "targeted_countries": [
        "United States of America",
        "Israel"
      ],
      "malware_families": [
        {
          "id": "Black Basta (ELF)",
          "display_name": "Black Basta (ELF)",
          "target": null
        },
        {
          "id": "ALF:MonitoringTool:AndroidOS/FinSpy",
          "display_name": "ALF:MonitoringTool:AndroidOS/FinSpy",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        }
      ],
      "industries": [
        "Cyber Security"
      ],
      "TLP": "white",
      "cloned_from": "64e26c454e86439fd9462541",
      "export_count": 21,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 201,
        "domain": 52,
        "URL": 443,
        "FileHash-MD5": 17,
        "FileHash-SHA256": 738,
        "FileHash-SHA1": 13
      },
      "indicator_count": 1464,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 224,
      "modified_text": "984 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "https://magento.userinfo.email",
    "type": "URL"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "https://magento.userinfo.email",
    "type": "URL",
    "found": false,
    "verdict": "clean",
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780212675.4173722
}