{
  "type": "URL",
  "indicator": "https://management.inwx.de/",
  "general": {
    "sections": [
      "general",
      "url_list",
      "http_scans",
      "screenshot"
    ],
    "indicator": "https://management.inwx.de/",
    "type": "url",
    "type_title": "URL",
    "validation": [],
    "base_indicator": {
      "id": 3781005983,
      "indicator": "https://management.inwx.de/",
      "type": "URL",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 7,
      "pulses": [
        {
          "id": "69fc2ceaf9989ac75c80ac68",
          "name": "Credit [ty] OctoSeek - please follow them [Lucky Mouse APT27 | Feodo Tracker | Malicious Tor Server] - this post is so true",
          "description": "",
          "modified": "2026-05-07T06:24:09.569000",
          "created": "2026-05-07T06:10:50.373000",
          "tags": [
            "ssl certificate",
            "historical ssl",
            "communicating",
            "contacted",
            "resolutions",
            "whois record",
            "whois whois",
            "whois parent",
            "whois siblings",
            "skynet",
            "threat report",
            "ip summary",
            "url summary",
            "summary",
            "sample",
            "samples",
            "detection list",
            "blacklist",
            "cisco umbrella",
            "site",
            "safe site",
            "million",
            "team",
            "microsoft",
            "back",
            "download",
            "phishing",
            "union",
            "bank",
            "malicious site",
            "blacklist http",
            "exit",
            "traffic",
            "node tcp",
            "tor known",
            "tor relayrouter",
            "et tor",
            "known tor",
            "relayrouter",
            "anonymizer",
            "spammer",
            "malware",
            "dropped",
            "unlocker",
            "http",
            "critical risk",
            "redline stealer",
            "core",
            "hacktool",
            "execution",
            "type win32",
            "exe size",
            "first seen",
            "file name",
            "avast win32",
            "win32",
            "avg win32",
            "fortinet",
            "vitro",
            "mb first",
            "rmndrp",
            "clean mx",
            "undetected dns8",
            "undetected vx",
            "sophos",
            "vault",
            "zdb zeus",
            "cmc threat",
            "snort ip",
            "feodo tracker",
            "cybereason",
            "send bug",
            "pe yandex",
            "no data",
            "tag count",
            "count blacklist",
            "tag tag",
            "algorithm",
            "v3 serial",
            "number",
            "issuer",
            "cus cnr3",
            "olet",
            "subject public",
            "key info",
            "key algorithm",
            "key identifier",
            "first",
            "seen",
            "valid",
            "no na",
            "no no",
            "ip security",
            "cndst root",
            "ca x3",
            "ca id",
            "research group",
            "cnisrg root",
            "no expired",
            "mozilla",
            "android",
            "malicious red team",
            "tsara brashears",
            "cyber stalking",
            "malvertizing",
            "invasion of privacy",
            "threat",
            "adult content",
            "apple",
            "iphone unlocker",
            "android",
            "exploited spyware",
            "malware host",
            "brute force",
            "revenge-rat",
            "banker",
            "evasive",
            "domain",
            "redline",
            "stealer",
            "phishing",
            "ramnit",
            "unreliable subdomains",
            "dridex",
            "gating",
            "msil",
            "rat",
            "loki",
            "network",
            "hacking",
            "sinkhole",
            "azorult",
            "c2",
            "historicalandnew",
            "targeted attack",
            "puffstealer",
            "rultazo",
            "lokibot",
            "loki pws",
            "burkina",
            "banker,dde,dridex,exploit",
            "banker,dridex,evasive",
            "trickbot",
            "ransomware,torrentlocker",
            "exploit_source",
            "blacknet",
            "FileRepMalware",
            "linux agent",
            "blacknet",
            "ios",
            "phishing paypal",
            "tagging",
            "defacement",
            "hit",
            "bounty",
            "phishing site",
            "malware site",
            "malware download",
            "endangerment",
            "Malicious domain - SANS Internet Storm Center",
            "evasive,msil,rat,revenge-rat",
            "prism_setting",
            "prism_object",
            "static engine",
            "social engineering",
            "jansky",
            "worm",
            "network rat",
            "networm",
            "Loki Password Stealer (PWS)",
            "South Carolina Federal Credit Union phishing",
            "darkweb",
            "yandex",
            "redirectors",
            "blacknet threats",
            "phishing,ransomware,sinkhole",
            "wanacrypt0r,wannacry,wcry",
            "tor c++",
            "tor c++ client",
            "python user",
            "js user",
            "hacker",
            "hijacker",
            "heur",
            "maltiverse",
            "alexa top",
            "exploit",
            "riskware",
            "unsafe",
            "outbreak",
            "downer",
            "shell",
            "mediamagnet",
            "sality",
            "swrort",
            "adaptivebee",
            "unruy",
            "iobit",
            "dropper",
            "trojanx",
            "artemis",
            "installcore",
            "webshell",
            "crack",
            "webtoolbar",
            "search live",
            "api blog",
            "docs pricing",
            "november",
            "de indicators",
            "domains",
            "hashes",
            "__convergedlogin_pcustomizationloader_44b450e8d543eb53930d",
            "malicious url",
            "financial",
            "blacknet rat",
            "azorult",
            "stealer",
            "deep scan",
            "blacklist https",
            "referrer",
            "collections kp",
            "incident ip",
            "sneaky server",
            "replacement",
            "unauthorized",
            "emotet",
            "noname057",
            "generic malware",
            "engineering",
            "cyber threat",
            "facebook",
            "paypal",
            "dropbox",
            "united",
            "america",
            "banking",
            "wells fargo",
            "steam",
            "twitter",
            "sliver",
            "daum",
            "swift",
            "runescape",
            "betabot",
            "district",
            "iframe",
            "alexa",
            "downldr",
            "agent",
            "presenoker",
            "bladabindi",
            "live",
            "conduit",
            "pony",
            "covid19",
            "malicious",
            "cobalt strike",
            "suppobox",
            "ramnit",
            "meterpreter",
            "virut",
            "njrat",
            "pykspa",
            "asyncrat",
            "downloader",
            "fakealert",
            "binder",
            "virustotal",
            "formbook",
            "necurs",
            "trojan",
            "msil",
            "hiloti",
            "vawtrak",
            "simda",
            "kraken",
            "solimba",
            "icedid",
            "redirector",
            "suspic",
            "amadey",
            "raccoon",
            "nanocore rat",
            "revenge rat",
            "genkryptik",
            "fuery",
            "wacatac",
            "service",
            "cloudeye",
            "tinba",
            "domaiq",
            "ave maria",
            "zeus",
            "ransomware",
            "zbot",
            "generic",
            "trojanspy",
            "states",
            "inmortal",
            "locky",
            "strike",
            "china cobalt",
            "keybase",
            "cutwail",
            "citadel",
            "radamant",
            "kovter",
            "bradesco",
            "nymaim",
            "amonetize",
            "bondat",
            "ghost rat",
            "vjw0rm",
            "bandoo",
            "matsnu",
            "dnspionage",
            "darkgate",
            "vidar",
            "keylogger",
            "remcos",
            "agenttesla",
            "detplock",
            "win64",
            "smokeloader",
            "agent tesla",
            "kgs0",
            "kls0",
            "urls",
            "type name",
            "dns replication",
            "date",
            "domain",
            "win32 exe",
            "files",
            "detections type",
            "name",
            "drpsuinstaller",
            "vdfsurfs",
            "opera",
            "icwrmind",
            "notepad",
            "installer",
            "miner",
            "unknown",
            "networm",
            "houdini",
            "quasar rat",
            "gamehack",
            "dbatloader",
            "qakbot",
            "ursnif",
            "CVE-2005-1790",
            "CVE-2009-3672",
            "CVE-2010-3962",
            "CVE-2012-3993",
            "CVE-2014-6332",
            "CVE-2017-11882",
            "CVE-2020-0601",
            "CVE-2020-0674",
            "hallrender.com",
            "brian sabey",
            "insurance",
            "botnetwork",
            "botmaster",
            "command_and_control",
            "CVE-2021-27065",
            "CVE-2021-40444",
            "CVE-2023-4966",
            "CVE-2017-0199",
            "CVE-2018-4893",
            "CVE-2010-3333",
            "CVE-2015-1641",
            "CVE-2017-0147",
            "CVE-2017-8570",
            "CVE-2018-0802",
            "CVE-2018-8373",
            "CVE-2017-8759",
            "CVE-2018-8453",
            "CVE-2014-3153",
            "CVE-2015-1650",
            "CVE-2017-0143",
            "CVE-2017-8464",
            "Icefog",
            "Delf.NBX",
            "$WebWatson",
            "Gen:Heur.Ransom.HiddenTears",
            "mobilekey.pw",
            "bitbucket.org",
            "Anomalous.100%",
            "malware distribution site",
            "gootkit",
            "edsaid",
            "rightsaided",
            "betabot",
            "cobaltstrike4.tk",
            "mas.to",
            "BehavesLike.YahLover",
            "srdvd16010404",
            "languageenu",
            "buildno",
            "channelisales",
            "vendorname2581",
            "osregion",
            "device",
            "systemlocale",
            "majorver16",
            "quasar",
            "find",
            "lockbit",
            "chaos",
            "ransomexx",
            "grandoreiro",
            "evilnum",
            "banker"
          ],
          "references": [
            "https://hybrid-analysis.com/sample/6765f47ea77c8274c8e4973ed95aedf59e75998c62f6029e23c58cdf36ed85ba/654afdbdc621e7037801cce7",
            "20.99.186.246 exploit source",
            "fp2e7a.wpc.2be4.phicdn.net",
            "https://www.anyxxxtube.net/search-porn/tsara-brashears/ (phishing, ELF, Prism.exe found)",
            "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian (password cracker)",
            "http://182.22.25.124:7878/182.22.25.124:443     (malicious dropper)",
            "init.ess.apple.com         (malicious code script)",
            "https://www.pornhub.com/video/search?search=tsara+brashears (Malicious PW cracker | stylebk.css stylesheets - not found )",
            "https://urlscan.io/result/a328d9ff-fb49-4078-960d-a757fd41404f/#indicators",
            "VirusTotal Link: https://www.virustotal.com/gui/ip-address/20.99.186.246/detection",
            "Abuse IPDB Link: https://www.abuseipdb.com/check/20.99.186.246",
            "IPv4 45.12.253.72.            command_and_control",
            "Hostname: ddos.dnsnb8.net                        command_and_control",
            "IPv4 95.213.186.51              command_and_control",
            "Hostname: www.supernetforme.com      command_and_control",
            "IPv4 103.224.182.246        command_and_control",
            "IPv4 72.251.233.245           command_and_control",
            "IPv4 63.251.106.25             command_and_control",
            "IPv4 45.15.156.208            command_and_control",
            "IPv4 104.247.81.51             command_and_control",
            "http://ambisexual.phone-sex-blogs.com/http:/ambisexual.phone-sex-blogs.com/images/thumbnails/pic118.jpg             (phishing)",
            "https://downloaddevtools.ir/     (phishing)",
            "happylifehappywife.com",
            "apples.encryptedwork.com        (Interesting in the blacknet)",
            "https://itunes.apple.com/app/apple-store/id284815942/us/app/samsung-galaxy-watch-gear-s/id1117310635.                   (iOS unlocker and hijacker)",
            "https://www.anyxxxtube.net/media/favicon/apple              (password cracker and iOS hijacker)",
            "https://www.apple.com/shop/browse/open/country_selector     (exploit)",
            "www.norad.mil   (federal tracking tool used by attorneys, law firms, and private investigators 'licensed or unlicensed') hi!",
            "http://init-p01st.push.apple.com/bag            (malicious web creator)",
            "opencve.djgummikuh.de        (CVE dispensary)",
            "Maltiverse Research Team",
            "URLscan.io",
            "Deep Research",
            "Hybrid Analysis",
            "URLhaus Abuse.ch",
            "Cyber Threat Coalition",
            "ThreatFox Abuse.ch"
          ],
          "public": 1,
          "adversary": "Lucky Mouse APT27 | NoName057(16) |  Unnamed",
          "targeted_countries": [
            "United States of America",
            "France",
            "Spain"
          ],
          "malware_families": [
            {
              "id": "Feodo",
              "display_name": "Feodo",
              "target": null
            },
            {
              "id": "Dridex",
              "display_name": "Dridex",
              "target": null
            },
            {
              "id": "Redline Stealer",
              "display_name": "Redline Stealer",
              "target": null
            },
            {
              "id": "Ramnit.N",
              "display_name": "Ramnit.N",
              "target": null
            },
            {
              "id": "Loki Bot",
              "display_name": "Loki Bot",
              "target": null
            },
            {
              "id": "Loki Password Stealer (PWS)",
              "display_name": "Loki Password Stealer (PWS)",
              "target": null
            },
            {
              "id": "AZORult",
              "display_name": "AZORult",
              "target": null
            },
            {
              "id": "Zbd Zeus",
              "display_name": "Zbd Zeus",
              "target": null
            },
            {
              "id": "Trojan:MSIL/Burkina",
              "display_name": "Trojan:MSIL/Burkina",
              "target": "/malware/Trojan:MSIL/Burkina"
            },
            {
              "id": "Generic.TrickBot.1",
              "display_name": "Generic.TrickBot.1",
              "target": null
            },
            {
              "id": "Exploit.CVE",
              "display_name": "Exploit.CVE",
              "target": null
            },
            {
              "id": "Injector.IS.gen",
              "display_name": "Injector.IS.gen",
              "target": null
            },
            {
              "id": "Gen:Variant.Razy",
              "display_name": "Gen:Variant.Razy",
              "target": null
            },
            {
              "id": "Trojan.Androm.Gen",
              "display_name": "Trojan.Androm.Gen",
              "target": null
            },
            {
              "id": "HEUR:Trojan.Linux.Agent",
              "display_name": "HEUR:Trojan.Linux.Agent",
              "target": null
            },
            {
              "id": "BScope.Trojan",
              "display_name": "BScope.Trojan",
              "target": null
            },
            {
              "id": "VBA.Downloader",
              "display_name": "VBA.Downloader",
              "target": null
            },
            {
              "id": "Trojan.Notifier",
              "display_name": "Trojan.Notifier",
              "target": null
            },
            {
              "id": "HEUR:Trojan.MSOffice.Alien",
              "display_name": "HEUR:Trojan.MSOffice.Alien",
              "target": null
            },
            {
              "id": "Unsafe.AI_Score_100%",
              "display_name": "Unsafe.AI_Score_100%",
              "target": null
            },
            {
              "id": "Gen:Variant.Johnnie",
              "display_name": "Gen:Variant.Johnnie",
              "target": null
            },
            {
              "id": "DangerousObject.Multi",
              "display_name": "DangerousObject.Multi",
              "target": null
            },
            {
              "id": "Trojan:Python/Downldr",
              "display_name": "Trojan:Python/Downldr",
              "target": "/malware/Trojan:Python/Downldr"
            },
            {
              "id": "Trojan:Linux/Downldr",
              "display_name": "Trojan:Linux/Downldr",
              "target": "/malware/Trojan:Linux/Downldr"
            },
            {
              "id": "Trojan:VBA/Downldr",
              "display_name": "Trojan:VBA/Downldr",
              "target": "/malware/Trojan:VBA/Downldr"
            },
            {
              "id": "TrojanDownloader:Linux/Downldr",
              "display_name": "TrojanDownloader:Linux/Downldr",
              "target": "/malware/TrojanDownloader:Linux/Downldr"
            },
            {
              "id": "Kryptik.FPH.gen",
              "display_name": "Kryptik.FPH.gen",
              "target": null
            },
            {
              "id": "TROJ_FRS.VSNTFK19",
              "display_name": "TROJ_FRS.VSNTFK19",
              "target": null
            },
            {
              "id": "Trojan.Ransom.GenericKD",
              "display_name": "Trojan.Ransom.GenericKD",
              "target": null
            },
            {
              "id": "Phish.JAT",
              "display_name": "Phish.JAT",
              "target": null
            },
            {
              "id": "Phishing.HTML",
              "display_name": "Phishing.HTML",
              "target": null
            },
            {
              "id": "Generic.ASMalwS",
              "display_name": "Generic.ASMalwS",
              "target": null
            },
            {
              "id": "Phish.AB",
              "display_name": "Phish.AB",
              "target": null
            },
            {
              "id": "Generic.Malware",
              "display_name": "Generic.Malware",
              "target": null
            },
            {
              "id": "ml.Generic",
              "display_name": "ml.Generic",
              "target": null
            },
            {
              "id": "Xegumumune.8596c22f",
              "display_name": "Xegumumune.8596c22f",
              "target": null
            },
            {
              "id": "Generic.Malware.SMYB",
              "display_name": "Generic.Malware.SMYB",
              "target": null
            },
            {
              "id": "malicious.moderate.ml",
              "display_name": "malicious.moderate.ml",
              "target": null
            },
            {
              "id": "Agent.NBAE",
              "display_name": "Agent.NBAE",
              "target": null
            },
            {
              "id": "AGEN.1045227",
              "display_name": "AGEN.1045227",
              "target": null
            },
            {
              "id": "Riskware.Agent",
              "display_name": "Riskware.Agent",
              "target": null
            },
            {
              "id": "Gen:Variant.Cerbu",
              "display_name": "Gen:Variant.Cerbu",
              "target": null
            },
            {
              "id": "IL:Trojan.MSILZilla",
              "display_name": "IL:Trojan.MSILZilla",
              "target": null
            },
            {
              "id": "Dropped:Generic.Ransom.DMR",
              "display_name": "Dropped:Generic.Ransom.DMR",
              "target": null
            },
            {
              "id": "Delf.NBX",
              "display_name": "Delf.NBX",
              "target": null
            },
            {
              "id": "malicious.f01f67",
              "display_name": "malicious.f01f67",
              "target": null
            },
            {
              "id": "AGEN.1144657",
              "display_name": "AGEN.1144657",
              "target": null
            },
            {
              "id": "Trojan.Heur",
              "display_name": "Trojan.Heur",
              "target": null
            },
            {
              "id": "Trojan.Malware.300983",
              "display_name": "Trojan.Malware.300983",
              "target": null
            },
            {
              "id": "SdBot.CAOC",
              "display_name": "SdBot.CAOC",
              "target": null
            },
            {
              "id": "Trojan.DelShad",
              "display_name": "Trojan.DelShad",
              "target": null
            },
            {
              "id": "Exploit CVE-2017-11882",
              "display_name": "Exploit CVE-2017-11882",
              "target": null
            },
            {
              "id": "GameHack.NL",
              "display_name": "GameHack.NL",
              "target": null
            },
            {
              "id": "JS:Trojan.HideLink",
              "display_name": "JS:Trojan.HideLink",
              "target": null
            },
            {
              "id": "Script.Agent",
              "display_name": "Script.Agent",
              "target": null
            },
            {
              "id": "Macro.Agent",
              "display_name": "Macro.Agent",
              "target": null
            },
            {
              "id": "Macro.Downloader.AMIP",
              "display_name": "Macro.Downloader.AMIP",
              "target": null
            },
            {
              "id": "Trojan.VBA",
              "display_name": "Trojan.VBA",
              "target": null
            },
            {
              "id": "HEUR.VBA.Trojan",
              "display_name": "HEUR.VBA.Trojan",
              "target": null
            },
            {
              "id": "VB.EmoooDldr.10",
              "display_name": "VB.EmoooDldr.10",
              "target": null
            },
            {
              "id": "VB:Trojan.Valyria",
              "display_name": "VB:Trojan.Valyria",
              "target": null
            },
            {
              "id": "OpenSubtitles.A",
              "display_name": "OpenSubtitles.A",
              "target": null
            },
            {
              "id": "VB.EmoDldr.4",
              "display_name": "VB.EmoDldr.4",
              "target": null
            },
            {
              "id": "Packed-GV",
              "display_name": "Packed-GV",
              "target": null
            },
            {
              "id": "Adware.InstallMonetizer",
              "display_name": "Adware.InstallMonetizer",
              "target": null
            },
            {
              "id": "Skynet",
              "display_name": "Skynet",
              "target": null
            },
            {
              "id": "HW32.Packed",
              "display_name": "HW32.Packed",
              "target": null
            },
            {
              "id": "Zpevdo.B",
              "display_name": "Zpevdo.B",
              "target": null
            },
            {
              "id": "Presenoker",
              "display_name": "Presenoker",
              "target": null
            },
            {
              "id": "SGeneric",
              "display_name": "SGeneric",
              "target": null
            },
            {
              "id": "GameHack.DOM",
              "display_name": "GameHack.DOM",
              "target": null
            },
            {
              "id": "BehavesLike.Ransom",
              "display_name": "BehavesLike.Ransom",
              "target": null
            },
            {
              "id": "CIL.StupidCryptor",
              "display_name": "CIL.StupidCryptor",
              "target": null
            },
            {
              "id": "Gen:Heur.Ransom.MSIL",
              "display_name": "Gen:Heur.Ransom.MSIL",
              "target": null
            },
            {
              "id": "Black.Gen2",
              "display_name": "Black.Gen2",
              "target": null
            },
            {
              "id": "GameHack.CRS",
              "display_name": "GameHack.CRS",
              "target": null
            },
            {
              "id": "Trojan.HTML.PHISH",
              "display_name": "Trojan.HTML.PHISH",
              "target": null
            },
            {
              "id": "Gen:Heur.MSIL.Inject",
              "display_name": "Gen:Heur.MSIL.Inject",
              "target": null
            },
            {
              "id": "Program.Unwanted",
              "display_name": "Program.Unwanted",
              "target": null
            },
            {
              "id": "HEUR/QVM42.3.72EB.Malware",
              "display_name": "HEUR/QVM42.3.72EB.Malware",
              "target": null
            },
            {
              "id": "suspicious.low.ml",
              "display_name": "suspicious.low.ml",
              "target": null
            },
            {
              "id": "JS:Trojan.Cryxos",
              "display_name": "JS:Trojan.Cryxos",
              "target": null
            },
            {
              "id": "Suspicious_GEN.F47V0520",
              "display_name": "Suspicious_GEN.F47V0520",
              "target": null
            },
            {
              "id": "Dropper.Trojan.Generic",
              "display_name": "Dropper.Trojan.Generic",
              "target": null
            },
            {
              "id": "Trojan.TrickBot",
              "display_name": "Trojan.TrickBot",
              "target": null
            },
            {
              "id": "Malware.Tk.Generic",
              "display_name": "Malware.Tk.Generic",
              "target": null
            },
            {
              "id": "TrojanSpy.Java",
              "display_name": "TrojanSpy.Java",
              "target": null
            },
            {
              "id": "Riskware.NetFilter",
              "display_name": "Riskware.NetFilter",
              "target": null
            },
            {
              "id": "RiskWare.Crack",
              "display_name": "RiskWare.Crack",
              "target": null
            },
            {
              "id": "BehavesLike.Exploit",
              "display_name": "BehavesLike.Exploit",
              "target": null
            },
            {
              "id": "Gen:NN.ZemsilF.34128",
              "display_name": "Gen:NN.ZemsilF.34128",
              "target": null
            },
            {
              "id": "Wacapew.C",
              "display_name": "Wacapew.C",
              "target": null
            },
            {
              "id": "Trojan.Malware.121218",
              "display_name": "Trojan.Malware.121218",
              "target": null
            },
            {
              "id": "RiskWare.HackTool.Agent",
              "display_name": "RiskWare.HackTool.Agent",
              "target": null
            },
            {
              "id": "Artemis",
              "display_name": "Artemis",
              "target": null
            },
            {
              "id": "Trojan.Generic",
              "display_name": "Trojan.Generic",
              "target": null
            },
            {
              "id": "W32.Trojan",
              "display_name": "W32.Trojan",
              "target": null
            },
            {
              "id": "BScope.Riskware",
              "display_name": "BScope.Riskware",
              "target": null
            },
            {
              "id": "Gen:Variant.Bulz",
              "display_name": "Gen:Variant.Bulz",
              "target": null
            },
            {
              "id": "Ransom:Win32/CVE-2017-0147",
              "display_name": "Ransom:Win32/CVE-2017-0147",
              "target": "/malware/Ransom:Win32/CVE-2017-0147"
            },
            {
              "id": "Virus.Ramnit",
              "display_name": "Virus.Ramnit",
              "target": null
            },
            {
              "id": "Virus.Virut",
              "display_name": "Virus.Virut",
              "target": null
            },
            {
              "id": "Adware.KuziTui",
              "display_name": "Adware.KuziTui",
              "target": null
            },
            {
              "id": "AGEN.1141126",
              "display_name": "AGEN.1141126",
              "target": null
            },
            {
              "id": "W32.AIDetect",
              "display_name": "W32.AIDetect",
              "target": null
            },
            {
              "id": "Trojan.Python",
              "display_name": "Trojan.Python",
              "target": null
            },
            {
              "id": "W32.AIDetectVM",
              "display_name": "W32.AIDetectVM",
              "target": null
            },
            {
              "id": "Suspicious.Save",
              "display_name": "Suspicious.Save",
              "target": null
            },
            {
              "id": "Adware.Downware",
              "display_name": "Adware.Downware",
              "target": null
            },
            {
              "id": "Ransom.Win64.Wacatac.oa",
              "display_name": "Ransom.Win64.Wacatac.oa",
              "target": null
            },
            {
              "id": "OpenSubtitles.A",
              "display_name": "OpenSubtitles.A",
              "target": null
            },
            {
              "id": "VB.EmoDldr.4",
              "display_name": "VB.EmoDldr.4",
              "target": null
            },
            {
              "id": "Gen:Variant.Midie",
              "display_name": "Gen:Variant.Midie",
              "target": null
            },
            {
              "id": "HEUR/QVM41.2.DA9B.Malware",
              "display_name": "HEUR/QVM41.2.DA9B.Malware",
              "target": null
            },
            {
              "id": "Gen:Variant.Sirefef",
              "display_name": "Gen:Variant.Sirefef",
              "target": null
            },
            {
              "id": "Macro.Trojan.Dropperd",
              "display_name": "Macro.Trojan.Dropperd",
              "target": null
            },
            {
              "id": "BlackNET RAT",
              "display_name": "BlackNET RAT",
              "target": null
            },
            {
              "id": "Gen:Variant.Ursu",
              "display_name": "Gen:Variant.Ursu",
              "target": null
            },
            {
              "id": "Redcap.rlhse",
              "display_name": "Redcap.rlhse",
              "target": null
            },
            {
              "id": "Trojan.Trickster",
              "display_name": "Trojan.Trickster",
              "target": null
            },
            {
              "id": "HTML_REDIR.SMR",
              "display_name": "HTML_REDIR.SMR",
              "target": null
            },
            {
              "id": "TROJ_FRS.VSNTFK19",
              "display_name": "TROJ_FRS.VSNTFK19",
              "target": null
            },
            {
              "id": "Hoax.JS.Phish",
              "display_name": "Hoax.JS.Phish",
              "target": null
            },
            {
              "id": "JS:Iframe",
              "display_name": "JS:Iframe",
              "target": null
            },
            {
              "id": "Application.SQLCrack",
              "display_name": "Application.SQLCrack",
              "target": null
            },
            {
              "id": "susp.lnk",
              "display_name": "susp.lnk",
              "target": null
            },
            {
              "id": "QVM201.0.B70B.Malware",
              "display_name": "QVM201.0.B70B.Malware",
              "target": null
            },
            {
              "id": "Immortal Stealer",
              "display_name": "Immortal Stealer",
              "target": null
            },
            {
              "id": "WebMonitor RAT",
              "display_name": "WebMonitor RAT",
              "target": null
            },
            {
              "id": "Tor - S0183",
              "display_name": "Tor - S0183",
              "target": null
            },
            {
              "id": "WannaCry",
              "display_name": "WannaCry",
              "target": null
            },
            {
              "id": "WannaCryptor",
              "display_name": "WannaCryptor",
              "target": null
            },
            {
              "id": "WebToolbar",
              "display_name": "WebToolbar",
              "target": null
            },
            {
              "id": "BlackNET",
              "display_name": "BlackNET",
              "target": null
            },
            {
              "id": "DeepScan:Generic.Ransom.GandCrab5",
              "display_name": "DeepScan:Generic.Ransom.GandCrab5",
              "target": null
            },
            {
              "id": "TrojanSpy",
              "display_name": "TrojanSpy",
              "target": null
            },
            {
              "id": "States",
              "display_name": "States",
              "target": null
            },
            {
              "id": "Inmortal",
              "display_name": "Inmortal",
              "target": null
            },
            {
              "id": "Domains",
              "display_name": "Domains",
              "target": null
            },
            {
              "id": "Locky",
              "display_name": "Locky",
              "target": null
            },
            {
              "id": "Delf.NBX",
              "display_name": "Delf.NBX",
              "target": null
            },
            {
              "id": "Gen:NN.ZexaF.32515",
              "display_name": "Gen:NN.ZexaF.32515",
              "target": null
            },
            {
              "id": "FileRepMalware",
              "display_name": "FileRepMalware",
              "target": null
            },
            {
              "id": "Gen:Variant.MSILPerseus",
              "display_name": "Gen:Variant.MSILPerseus",
              "target": null
            },
            {
              "id": "Icefog",
              "display_name": "Icefog",
              "target": null
            },
            {
              "id": "$WebWatson",
              "display_name": "$WebWatson",
              "target": null
            },
            {
              "id": "Agent.AIK.gen",
              "display_name": "Agent.AIK.gen",
              "target": null
            },
            {
              "id": "Agent.AIK.genCIL.StupidCryptor",
              "display_name": "Agent.AIK.genCIL.StupidCryptor",
              "target": null
            },
            {
              "id": "Agent.YPEZ",
              "display_name": "Agent.YPEZ",
              "target": null
            },
            {
              "id": "Application.InnovativSol",
              "display_name": "Application.InnovativSol",
              "target": null
            },
            {
              "id": "Agent.ASO",
              "display_name": "Agent.ASO",
              "target": null
            },
            {
              "id": "S-b748adc5",
              "display_name": "S-b748adc5",
              "target": null
            },
            {
              "id": "W32.eHeur",
              "display_name": "W32.eHeur",
              "target": null
            },
            {
              "id": "Kryptik.GUCB",
              "display_name": "Kryptik.GUCB",
              "target": null
            },
            {
              "id": "AgentTesla",
              "display_name": "AgentTesla",
              "target": null
            },
            {
              "id": "Autoit.bimwt",
              "display_name": "Autoit.bimwt",
              "target": null
            },
            {
              "id": "HEUR:Trojan.OLE2.Alien",
              "display_name": "HEUR:Trojan.OLE2.Alien",
              "target": null
            },
            {
              "id": "AGEN.1038489",
              "display_name": "AGEN.1038489",
              "target": null
            },
            {
              "id": "Gen:Variant.Ser.Strictor",
              "display_name": "Gen:Variant.Ser.Strictor",
              "target": null
            },
            {
              "id": "Packed.Themida.Gen",
              "display_name": "Packed.Themida.Gen",
              "target": null
            },
            {
              "id": "AGEN.1043164",
              "display_name": "AGEN.1043164",
              "target": null
            },
            {
              "id": "TrickBot - S0266",
              "display_name": "TrickBot - S0266",
              "target": null
            },
            {
              "id": "Emotet",
              "display_name": "Emotet",
              "target": null
            },
            {
              "id": "Trojan.PornoAsset",
              "display_name": "Trojan.PornoAsset",
              "target": null
            },
            {
              "id": "Ransom.Win64.PORNOASSET.SM1",
              "display_name": "Ransom.Win64.PORNOASSET.SM1",
              "target": null
            },
            {
              "id": "Gen:Variant.Ulise",
              "display_name": "Gen:Variant.Ulise",
              "target": null
            },
            {
              "id": "Trojan.Win64",
              "display_name": "Trojan.Win64",
              "target": null
            },
            {
              "id": "Dropper.Trojan.Agent",
              "display_name": "Dropper.Trojan.Agent",
              "target": null
            },
            {
              "id": "Heur.BZC.YAX.Pantera.10",
              "display_name": "Heur.BZC.YAX.Pantera.10",
              "target": null
            },
            {
              "id": "malicious.high.ml",
              "display_name": "malicious.high.ml",
              "target": null
            },
            {
              "id": "CVE-2015-1650",
              "display_name": "CVE-2015-1650",
              "target": null
            },
            {
              "id": "Worm.Win64.AutoRun",
              "display_name": "Worm.Win64.AutoRun",
              "target": null
            },
            {
              "id": "AIT.Heur.Cottonmouth.8.78F19BD7",
              "display_name": "AIT.Heur.Cottonmouth.8.78F19BD7",
              "target": null
            },
            {
              "id": "Gen:Variant.Mikey",
              "display_name": "Gen:Variant.Mikey",
              "target": null
            },
            {
              "id": "Trojan.Agent",
              "display_name": "Trojan.Agent",
              "target": null
            },
            {
              "id": "Pua.Gen",
              "display_name": "Pua.Gen",
              "target": null
            },
            {
              "id": "Trojan.Downloader.Generic",
              "display_name": "Trojan.Downloader.Generic",
              "target": null
            },
            {
              "id": "Suspected of Trojan.Downloader.gen",
              "display_name": "Suspected of Trojan.Downloader.gen",
              "target": null
            },
            {
              "id": "HEUR:RemoteAdmin.Generic",
              "display_name": "HEUR:RemoteAdmin.Generic",
              "target": null
            },
            {
              "id": "Gen:Heur.Ransom.HiddenTears",
              "display_name": "Gen:Heur.Ransom.HiddenTears",
              "target": null
            },
            {
              "id": "Nemucod.A",
              "display_name": "Nemucod.A",
              "target": null
            },
            {
              "id": "Backdoor.Hupigon",
              "display_name": "Backdoor.Hupigon",
              "target": null
            },
            {
              "id": "Trojan.Starter JS.Iframe",
              "display_name": "Trojan.Starter JS.Iframe",
              "target": null
            },
            {
              "id": "fake ,promethiumm ,strongpity",
              "display_name": "fake ,promethiumm ,strongpity",
              "target": null
            },
            {
              "id": "PUA.Reg1staid",
              "display_name": "PUA.Reg1staid",
              "target": null
            },
            {
              "id": "Malware.Heur_Generic.A",
              "display_name": "Malware.Heur_Generic.A",
              "target": null
            },
            {
              "id": "Bladabindi.Q",
              "display_name": "Bladabindi.Q",
              "target": null
            },
            {
              "id": "W32.eHeur",
              "display_name": "W32.eHeur",
              "target": null
            },
            {
              "id": "malicious.6e0700",
              "display_name": "malicious.6e0700",
              "target": null
            },
            {
              "id": "Trojan.Inject",
              "display_name": "Trojan.Inject",
              "target": null
            },
            {
              "id": "TSGeneric",
              "display_name": "TSGeneric",
              "target": null
            },
            {
              "id": "RedCap.vneda",
              "display_name": "RedCap.vneda",
              "target": null
            },
            {
              "id": "Trojan.Indiloadz",
              "display_name": "Trojan.Indiloadz",
              "target": null
            },
            {
              "id": "Trojan.Ekstak",
              "display_name": "Trojan.Ekstak",
              "target": null
            },
            {
              "id": "staticrr.paleokits.net",
              "display_name": "staticrr.paleokits.net",
              "target": null
            },
            {
              "id": "MSIL.Downloader",
              "display_name": "MSIL.Downloader",
              "target": null
            },
            {
              "id": "Trojan.Autoruns.GenericKDS",
              "display_name": "Trojan.Autoruns.GenericKDS",
              "target": null
            },
            {
              "id": "MSIL.Trojan.BSE",
              "display_name": "MSIL.Trojan.BSE",
              "target": null
            },
            {
              "id": "Adload.AD81",
              "display_name": "Adload.AD81",
              "target": null
            },
            {
              "id": "Packed.Asprotect",
              "display_name": "Packed.Asprotect",
              "target": null
            },
            {
              "id": "Gen:NN.ZemsilF.34062",
              "display_name": "Gen:NN.ZemsilF.34062",
              "target": null
            },
            {
              "id": "Evo",
              "display_name": "Evo",
              "target": null
            },
            {
              "id": "Agent.pwc",
              "display_name": "Agent.pwc",
              "target": null
            },
            {
              "id": "RiskTool.Phpw",
              "display_name": "RiskTool.Phpw",
              "target": null
            },
            {
              "id": "Gen:Variant.Symmi",
              "display_name": "Gen:Variant.Symmi",
              "target": null
            },
            {
              "id": "Trojan.PWS",
              "display_name": "Trojan.PWS",
              "target": null
            },
            {
              "id": "Generic.BitCoinMiner.3",
              "display_name": "Generic.BitCoinMiner.3",
              "target": null
            },
            {
              "id": "Trojan.Tasker",
              "display_name": "Trojan.Tasker",
              "target": null
            },
            {
              "id": "Gen:NN",
              "display_name": "Gen:NN",
              "target": null
            },
            {
              "id": "Downloader.CertutilURLCache",
              "display_name": "Downloader.CertutilURLCache",
              "target": null
            },
            {
              "id": "Elf",
              "display_name": "Elf",
              "target": null
            },
            {
              "id": "Gen:Heur.MSIL.Androm",
              "display_name": "Gen:Heur.MSIL.Androm",
              "target": null
            },
            {
              "id": "Kryptik.NRD",
              "display_name": "Kryptik.NRD",
              "target": null
            },
            {
              "id": "Riskware",
              "display_name": "Riskware",
              "target": null
            },
            {
              "id": "Kuluoz.B.gen",
              "display_name": "Kuluoz.B.gen",
              "target": null
            },
            {
              "id": "Gen:Variant.RevengeRat",
              "display_name": "Gen:Variant.RevengeRat",
              "target": null
            },
            {
              "id": "Gen:Variant.Mikey",
              "display_name": "Gen:Variant.Mikey",
              "target": null
            },
            {
              "id": "VB.Chronos.7",
              "display_name": "VB.Chronos.7",
              "target": null
            },
            {
              "id": "Kryptik.NOE",
              "display_name": "Kryptik.NOE",
              "target": null
            },
            {
              "id": "HEUR:WebToolbar.Generic",
              "display_name": "HEUR:WebToolbar.Generic",
              "target": null
            },
            {
              "id": "Gen:Variant.Barys",
              "display_name": "Gen:Variant.Barys",
              "target": null
            },
            {
              "id": "Backdoor.Xtreme",
              "display_name": "Backdoor.Xtreme",
              "target": null
            },
            {
              "id": "Trojan.MSIL",
              "display_name": "Trojan.MSIL",
              "target": null
            },
            {
              "id": "Gen:Variant.Graftor",
              "display_name": "Gen:Variant.Graftor",
              "target": null
            },
            {
              "id": "Backdoor.Agent",
              "display_name": "Backdoor.Agent",
              "target": null
            },
            {
              "id": "Unsafe",
              "display_name": "Unsafe",
              "target": null
            },
            {
              "id": "Trojan.PHP.Agent",
              "display_name": "Trojan.PHP.Agent",
              "target": null
            },
            {
              "id": "Trojan.Agent",
              "display_name": "Trojan.Agent",
              "target": null
            },
            {
              "id": "HEUR:Exploit.Generic",
              "display_name": "HEUR:Exploit.Generic",
              "target": null
            },
            {
              "id": "Ransom_WCRY.SMALYM",
              "display_name": "Ransom_WCRY.SMALYM",
              "target": null
            },
            {
              "id": "Ransom_WCRY.SMJ",
              "display_name": "Ransom_WCRY.SMJ",
              "target": null
            },
            {
              "id": "Auslogics",
              "display_name": "Auslogics",
              "target": null
            },
            {
              "id": "Gen:Variant.Jaiko",
              "display_name": "Gen:Variant.Jaiko",
              "target": null
            },
            {
              "id": "Exploit.W32.Agent",
              "display_name": "Exploit.W32.Agent",
              "target": null
            },
            {
              "id": "Trojan.Cud.Gen",
              "display_name": "Trojan.Cud.Gen",
              "target": null
            },
            {
              "id": "Trojan.DOC.Downloader",
              "display_name": "Trojan.DOC.Downloader",
              "target": null
            },
            {
              "id": "Backdoor.MSIL.Agent",
              "display_name": "Backdoor.MSIL.Agent",
              "target": null
            },
            {
              "id": "Gen:Trojan.Heur2.LPTbHW@W64.HfsAutoB",
              "display_name": "Gen:Trojan.Heur2.LPTbHW@W64.HfsAutoB",
              "target": null
            },
            {
              "id": "Gen:Variant.Kazy",
              "display_name": "Gen:Variant.Kazy",
              "target": null
            },
            {
              "id": "Gen:Variant.Zusy",
              "display_name": "Gen:Variant.Zusy",
              "target": null
            },
            {
              "id": "Ransom.WannaCrypt",
              "display_name": "Ransom.WannaCrypt",
              "target": null
            },
            {
              "id": "Generic.ServStart.A",
              "display_name": "Generic.ServStart.A",
              "target": null
            },
            {
              "id": "Trojan.Wanna",
              "display_name": "Trojan.Wanna",
              "target": null
            },
            {
              "id": "Generic.MSIL.Bladabindi",
              "display_name": "Generic.MSIL.Bladabindi",
              "target": null
            },
            {
              "id": "TROJ_GEN.R002C0OG518",
              "display_name": "TROJ_GEN.R002C0OG518",
              "target": null
            },
            {
              "id": "Trojan.Chapak",
              "display_name": "Trojan.Chapak",
              "target": null
            },
            {
              "id": "Indiloadz.BB",
              "display_name": "Indiloadz.BB",
              "target": null
            },
            {
              "id": "BehavBehavesLike.PUPXBI",
              "display_name": "BehavBehavesLike.PUPXBI",
              "target": null
            },
            {
              "id": "DeepScan:Generic.SpyAgent.6",
              "display_name": "DeepScan:Generic.SpyAgent.6",
              "target": null
            },
            {
              "id": "Python.KeyLogger",
              "display_name": "Python.KeyLogger",
              "target": null
            },
            {
              "id": "GameHack.CRS",
              "display_name": "GameHack.CRS",
              "target": null
            },
            {
              "id": "Generic.MSIL.PasswordStealer",
              "display_name": "Generic.MSIL.PasswordStealer",
              "target": null
            },
            {
              "id": "PSW.Agent",
              "display_name": "PSW.Agent",
              "target": null
            },
            {
              "id": "malicious.8c45ba",
              "display_name": "malicious.8c45ba",
              "target": null
            },
            {
              "id": "Dropper.Binder",
              "display_name": "Dropper.Binder",
              "target": null
            },
            {
              "id": "Constructor.MSIL",
              "display_name": "Constructor.MSIL",
              "target": null
            },
            {
              "id": "Linux.Agent",
              "display_name": "Linux.Agent",
              "target": null
            },
            {
              "id": "Virus.3DMax.Script",
              "display_name": "Virus.3DMax.Script",
              "target": null
            },
            {
              "id": "ScrInject.B",
              "display_name": "ScrInject.B",
              "target": null
            },
            {
              "id": "Trojan.WisdomEyes.16070401.9500",
              "display_name": "Trojan.WisdomEyes.16070401.9500",
              "target": null
            },
            {
              "id": "Application.SearchProtect",
              "display_name": "Application.SearchProtect",
              "target": null
            },
            {
              "id": "JS:Trojan.Clicker",
              "display_name": "JS:Trojan.Clicker",
              "target": null
            },
            {
              "id": "Faceliker.A",
              "display_name": "Faceliker.A",
              "target": null
            },
            {
              "id": "JS:Trojan.JS.Faceliker",
              "display_name": "JS:Trojan.JS.Faceliker",
              "target": null
            },
            {
              "id": "Constructor.MSIL  Linux.Agent",
              "display_name": "Constructor.MSIL  Linux.Agent",
              "target": null
            },
            {
              "id": "PowerShell.Trojan",
              "display_name": "PowerShell.Trojan",
              "target": null
            },
            {
              "id": "HTML:Script",
              "display_name": "HTML:Script",
              "target": null
            },
            {
              "id": "ScrInject.B",
              "display_name": "ScrInject.B",
              "target": null
            },
            {
              "id": "W32.AIDetectVM",
              "display_name": "W32.AIDetectVM",
              "target": null
            },
            {
              "id": "HackTool.CheatEngine",
              "display_name": "HackTool.CheatEngine",
              "target": null
            },
            {
              "id": "Injector.CLDS",
              "display_name": "Injector.CLDS",
              "target": null
            },
            {
              "id": "VB.Downloader.2",
              "display_name": "VB.Downloader.2",
              "target": null
            },
            {
              "id": "malicious.3e78cc",
              "display_name": "malicious.3e78cc",
              "target": null
            },
            {
              "id": "malicious.d800d6",
              "display_name": "malicious.d800d6",
              "target": null
            },
            {
              "id": "VB.PwShell.2",
              "display_name": "VB.PwShell.2",
              "target": null
            },
            {
              "id": "Backdoor.RBot",
              "display_name": "Backdoor.RBot",
              "target": null
            },
            {
              "id": "malicious.71b1a8",
              "display_name": "malicious.71b1a8",
              "target": null
            },
            {
              "id": "TrojanSpy.KeyLogger",
              "display_name": "TrojanSpy.KeyLogger",
              "target": null
            },
            {
              "id": "Injector.JDO",
              "display_name": "Injector.JDO",
              "target": null
            },
            {
              "id": "Heur.Msword.Gen",
              "display_name": "Heur.Msword.Gen",
              "target": null
            },
            {
              "id": "PSW.Discord",
              "display_name": "PSW.Discord",
              "target": null
            },
            {
              "id": "Packed.VMProtect",
              "display_name": "Packed.VMProtect",
              "target": null
            },
            {
              "id": "HEUR:AdWare.StartSurf",
              "display_name": "HEUR:AdWare.StartSurf",
              "target": null
            },
            {
              "id": "Gen:Heur.NoobyProtect",
              "display_name": "Gen:Heur.NoobyProtect",
              "target": null
            },
            {
              "id": "CIL.HeapOverride",
              "display_name": "CIL.HeapOverride",
              "target": null
            },
            {
              "id": "HEUR:Trojan.Tasker",
              "display_name": "HEUR:Trojan.Tasker",
              "target": null
            },
            {
              "id": "XLM.Trojan.Abracadabra.27",
              "display_name": "XLM.Trojan.Abracadabra.27",
              "target": null
            },
            {
              "id": "HEUR:Backdoor.MSIL.NanoBot",
              "display_name": "HEUR:Backdoor.MSIL.NanoBot",
              "target": null
            },
            {
              "id": "Trojan.PSW.Mimikatz",
              "display_name": "Trojan.PSW.Mimikatz",
              "target": null
            },
            {
              "id": "TrojanSpy.Python",
              "display_name": "TrojanSpy.Python",
              "target": null
            },
            {
              "id": "Trojan.Ole2.Vbs",
              "display_name": "Trojan.Ole2.Vbs",
              "target": null
            },
            {
              "id": "Exploit.MSOffice",
              "display_name": "Exploit.MSOffice",
              "target": null
            },
            {
              "id": "DeepScan:Generic.Ransom.AmnesiaE",
              "display_name": "DeepScan:Generic.Ransom.AmnesiaE",
              "target": null
            },
            {
              "id": "Wacatac.D6",
              "display_name": "Wacatac.D6",
              "target": null
            },
            {
              "id": "Backdoor.Androm",
              "display_name": "Backdoor.Androm",
              "target": null
            },
            {
              "id": "Packed.NetSeal",
              "display_name": "Packed.NetSeal",
              "target": null
            },
            {
              "id": "Trojan.MSIL.Injector",
              "display_name": "Trojan.MSIL.Injector",
              "target": null
            },
            {
              "id": "Trojan.PWS.Agent",
              "display_name": "Trojan.PWS.Agent",
              "target": null
            },
            {
              "id": "TScope.Trojan",
              "display_name": "TScope.Trojan",
              "target": null
            },
            {
              "id": "PSW.Stealer",
              "display_name": "PSW.Stealer",
              "target": null
            },
            {
              "id": "Trojan.PackedNET",
              "display_name": "Trojan.PackedNET",
              "target": null
            },
            {
              "id": "Trojan.Java",
              "display_name": "Trojan.Java",
              "target": null
            },
            {
              "id": "MalwareX",
              "display_name": "MalwareX",
              "target": null
            },
            {
              "id": "Trojan.PSW.Python",
              "display_name": "Trojan.PSW.Python",
              "target": null
            },
            {
              "id": "malicious.11abfc",
              "display_name": "malicious.11abfc",
              "target": null
            },
            {
              "id": "Generic.ASMalwS",
              "display_name": "Generic.ASMalwS",
              "target": null
            },
            {
              "id": "HEUR:Trojan.MSIL.Tasker",
              "display_name": "HEUR:Trojan.MSIL.Tasker",
              "target": null
            },
            {
              "id": "PossibleThreat.PALLAS",
              "display_name": "PossibleThreat.PALLAS",
              "target": null
            },
            {
              "id": "Backdoor.Poison",
              "display_name": "Backdoor.Poison",
              "target": null
            },
            {
              "id": "Generic.MSIL.LimeRAT",
              "display_name": "Generic.MSIL.LimeRAT",
              "target": null
            },
            {
              "id": "PWS-FCZZ",
              "display_name": "PWS-FCZZ",
              "target": null
            },
            {
              "id": "Trojan.Script",
              "display_name": "Trojan.Script",
              "target": null
            },
            {
              "id": "Gen:Heur.MSIL.Inject",
              "display_name": "Gen:Heur.MSIL.Inject",
              "target": null
            },
            {
              "id": "Trojan.PWS.Growtopia",
              "display_name": "Trojan.PWS.Growtopia",
              "target": null
            },
            {
              "id": "Spyware.Bobik",
              "display_name": "Spyware.Bobik",
              "target": null
            },
            {
              "id": "HackTool.BruteForce",
              "display_name": "HackTool.BruteForce",
              "target": null
            },
            {
              "id": "Hack.Patcher",
              "display_name": "Hack.Patcher",
              "target": null
            },
            {
              "id": "PWS.p",
              "display_name": "PWS.p",
              "target": null
            },
            {
              "id": "Suppobox",
              "display_name": "Suppobox",
              "target": null
            },
            {
              "id": "index.php",
              "display_name": "index.php",
              "target": null
            },
            {
              "id": "Packed.VMProtect",
              "display_name": "Packed.VMProtect",
              "target": null
            },
            {
              "id": "SmokeLoader",
              "display_name": "SmokeLoader",
              "target": null
            },
            {
              "id": "Generic.Malware",
              "display_name": "Generic.Malware",
              "target": null
            },
            {
              "id": "SNH:Script [Dropper]",
              "display_name": "SNH:Script [Dropper]",
              "target": null
            },
            {
              "id": "HEUR:Trojan.MSOffice.SAgent",
              "display_name": "HEUR:Trojan.MSOffice.SAgent",
              "target": null
            },
            {
              "id": "Script.INF",
              "display_name": "Script.INF",
              "target": null
            },
            {
              "id": "JS:Trojan.JS.Likejack",
              "display_name": "JS:Trojan.JS.Likejack",
              "target": null
            },
            {
              "id": "SNH:Script [Dropper]",
              "display_name": "SNH:Script [Dropper]",
              "target": null
            },
            {
              "id": "Trojan.JS.Agent",
              "display_name": "Trojan.JS.Agent",
              "target": null
            },
            {
              "id": "APT Notes",
              "display_name": "APT Notes",
              "target": null
            },
            {
              "id": "susp.rtf.objupdate",
              "display_name": "susp.rtf.objupdate",
              "target": null
            },
            {
              "id": "RedCap.zoohz",
              "display_name": "RedCap.zoohz",
              "target": null
            },
            {
              "id": "Trojan.Tasker",
              "display_name": "Trojan.Tasker",
              "target": null
            },
            {
              "id": "virus.office.qexvmc",
              "display_name": "virus.office.qexvmc",
              "target": null
            },
            {
              "id": "Trojan.KillProc",
              "display_name": "Trojan.KillProc",
              "target": null
            },
            {
              "id": "Generic.MSIL.GrwtpStealer.1",
              "display_name": "Generic.MSIL.GrwtpStealer.1",
              "target": null
            },
            {
              "id": "Suspicious.Cloud",
              "display_name": "Suspicious.Cloud",
              "target": null
            },
            {
              "id": "PowerShell.DownLoader",
              "display_name": "PowerShell.DownLoader",
              "target": null
            },
            {
              "id": "Downldr.gen",
              "display_name": "Downldr.gen",
              "target": null
            },
            {
              "id": "AGEN.1030939",
              "display_name": "AGEN.1030939",
              "target": null
            },
            {
              "id": "HackTool.Binder",
              "display_name": "HackTool.Binder",
              "target": null
            },
            {
              "id": "Trojan.Inject",
              "display_name": "Trojan.Inject",
              "target": null
            },
            {
              "id": "Dldr.Agent",
              "display_name": "Dldr.Agent",
              "target": null
            },
            {
              "id": "Dropper.MSIL",
              "display_name": "Dropper.MSIL",
              "target": null
            },
            {
              "id": "Trojan.VBKryjetor",
              "display_name": "Trojan.VBKryjetor",
              "target": null
            },
            {
              "id": "PWSX",
              "display_name": "PWSX",
              "target": null
            },
            {
              "id": "VB:Trojan.VBA.Agent",
              "display_name": "VB:Trojan.VBA.Agent",
              "target": null
            },
            {
              "id": "HEUR:Trojan.MSOffice.Stratos",
              "display_name": "HEUR:Trojan.MSOffice.Stratos",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1071.004",
              "name": "DNS",
              "display_name": "T1071.004 - DNS"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1059.007",
              "name": "JavaScript",
              "display_name": "T1059.007 - JavaScript"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1068",
              "name": "Exploitation for Privilege Escalation",
              "display_name": "T1068 - Exploitation for Privilege Escalation"
            },
            {
              "id": "TA0029",
              "name": "Privilege Escalation",
              "display_name": "TA0029 - Privilege Escalation"
            },
            {
              "id": "T1449",
              "name": "Exploit SS7 to Redirect Phone Calls/SMS",
              "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
            },
            {
              "id": "T1190",
              "name": "Exploit Public-Facing Application",
              "display_name": "T1190 - Exploit Public-Facing Application"
            },
            {
              "id": "T1210",
              "name": "Exploitation of Remote Services",
              "display_name": "T1210 - Exploitation of Remote Services"
            },
            {
              "id": "T1450",
              "name": "Exploit SS7 to Track Device Location",
              "display_name": "T1450 - Exploit SS7 to Track Device Location"
            },
            {
              "id": "T1211",
              "name": "Exploitation for Defense Evasion",
              "display_name": "T1211 - Exploitation for Defense Evasion"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "TA0011",
              "name": "Command and Control",
              "display_name": "TA0011 - Command and Control"
            },
            {
              "id": "T1412",
              "name": "Capture SMS Messages",
              "display_name": "T1412 - Capture SMS Messages"
            },
            {
              "id": "T1454",
              "name": "Malicious SMS Message",
              "display_name": "T1454 - Malicious SMS Message"
            },
            {
              "id": "T1001",
              "name": "Data Obfuscation",
              "display_name": "T1001 - Data Obfuscation"
            },
            {
              "id": "T1114",
              "name": "Email Collection",
              "display_name": "T1114 - Email Collection"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1498",
              "name": "Network Denial of Service",
              "display_name": "T1498 - Network Denial of Service"
            },
            {
              "id": "T1496",
              "name": "Resource Hijacking",
              "display_name": "T1496 - Resource Hijacking"
            },
            {
              "id": "T1176",
              "name": "Browser Extensions",
              "display_name": "T1176 - Browser Extensions"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": "654c597a4a45c8d84f0b15c1",
          "export_count": 3,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 1184,
            "FileHash-SHA1": 949,
            "FileHash-SHA256": 3712,
            "URL": 2927,
            "domain": 627,
            "hostname": 1320,
            "CVE": 26,
            "email": 8,
            "CIDR": 2
          },
          "indicator_count": 10755,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 68,
          "modified_text": "24 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "69fc2ce920f63f0ab26c6871",
          "name": "Credit [ty] OctoSeek - please follow them [Lucky Mouse APT27 | Feodo Tracker | Malicious Tor Server] - this post is so true",
          "description": "",
          "modified": "2026-05-07T06:22:38.844000",
          "created": "2026-05-07T06:10:49.008000",
          "tags": [
            "ssl certificate",
            "historical ssl",
            "communicating",
            "contacted",
            "resolutions",
            "whois record",
            "whois whois",
            "whois parent",
            "whois siblings",
            "skynet",
            "threat report",
            "ip summary",
            "url summary",
            "summary",
            "sample",
            "samples",
            "detection list",
            "blacklist",
            "cisco umbrella",
            "site",
            "safe site",
            "million",
            "team",
            "microsoft",
            "back",
            "download",
            "phishing",
            "union",
            "bank",
            "malicious site",
            "blacklist http",
            "exit",
            "traffic",
            "node tcp",
            "tor known",
            "tor relayrouter",
            "et tor",
            "known tor",
            "relayrouter",
            "anonymizer",
            "spammer",
            "malware",
            "dropped",
            "unlocker",
            "http",
            "critical risk",
            "redline stealer",
            "core",
            "hacktool",
            "execution",
            "type win32",
            "exe size",
            "first seen",
            "file name",
            "avast win32",
            "win32",
            "avg win32",
            "fortinet",
            "vitro",
            "mb first",
            "rmndrp",
            "clean mx",
            "undetected dns8",
            "undetected vx",
            "sophos",
            "vault",
            "zdb zeus",
            "cmc threat",
            "snort ip",
            "feodo tracker",
            "cybereason",
            "send bug",
            "pe yandex",
            "no data",
            "tag count",
            "count blacklist",
            "tag tag",
            "algorithm",
            "v3 serial",
            "number",
            "issuer",
            "cus cnr3",
            "olet",
            "subject public",
            "key info",
            "key algorithm",
            "key identifier",
            "first",
            "seen",
            "valid",
            "no na",
            "no no",
            "ip security",
            "cndst root",
            "ca x3",
            "ca id",
            "research group",
            "cnisrg root",
            "no expired",
            "mozilla",
            "android",
            "malicious red team",
            "tsara brashears",
            "cyber stalking",
            "malvertizing",
            "invasion of privacy",
            "threat",
            "adult content",
            "apple",
            "iphone unlocker",
            "android",
            "exploited spyware",
            "malware host",
            "brute force",
            "revenge-rat",
            "banker",
            "evasive",
            "domain",
            "redline",
            "stealer",
            "phishing",
            "ramnit",
            "unreliable subdomains",
            "dridex",
            "gating",
            "msil",
            "rat",
            "loki",
            "network",
            "hacking",
            "sinkhole",
            "azorult",
            "c2",
            "historicalandnew",
            "targeted attack",
            "puffstealer",
            "rultazo",
            "lokibot",
            "loki pws",
            "burkina",
            "banker,dde,dridex,exploit",
            "banker,dridex,evasive",
            "trickbot",
            "ransomware,torrentlocker",
            "exploit_source",
            "blacknet",
            "FileRepMalware",
            "linux agent",
            "blacknet",
            "ios",
            "phishing paypal",
            "tagging",
            "defacement",
            "hit",
            "bounty",
            "phishing site",
            "malware site",
            "malware download",
            "endangerment",
            "Malicious domain - SANS Internet Storm Center",
            "evasive,msil,rat,revenge-rat",
            "prism_setting",
            "prism_object",
            "static engine",
            "social engineering",
            "jansky",
            "worm",
            "network rat",
            "networm",
            "Loki Password Stealer (PWS)",
            "South Carolina Federal Credit Union phishing",
            "darkweb",
            "yandex",
            "redirectors",
            "blacknet threats",
            "phishing,ransomware,sinkhole",
            "wanacrypt0r,wannacry,wcry",
            "tor c++",
            "tor c++ client",
            "python user",
            "js user",
            "hacker",
            "hijacker",
            "heur",
            "maltiverse",
            "alexa top",
            "exploit",
            "riskware",
            "unsafe",
            "outbreak",
            "downer",
            "shell",
            "mediamagnet",
            "sality",
            "swrort",
            "adaptivebee",
            "unruy",
            "iobit",
            "dropper",
            "trojanx",
            "artemis",
            "installcore",
            "webshell",
            "crack",
            "webtoolbar",
            "search live",
            "api blog",
            "docs pricing",
            "november",
            "de indicators",
            "domains",
            "hashes",
            "__convergedlogin_pcustomizationloader_44b450e8d543eb53930d",
            "malicious url",
            "financial",
            "blacknet rat",
            "azorult",
            "stealer",
            "deep scan",
            "blacklist https",
            "referrer",
            "collections kp",
            "incident ip",
            "sneaky server",
            "replacement",
            "unauthorized",
            "emotet",
            "noname057",
            "generic malware",
            "engineering",
            "cyber threat",
            "facebook",
            "paypal",
            "dropbox",
            "united",
            "america",
            "banking",
            "wells fargo",
            "steam",
            "twitter",
            "sliver",
            "daum",
            "swift",
            "runescape",
            "betabot",
            "district",
            "iframe",
            "alexa",
            "downldr",
            "agent",
            "presenoker",
            "bladabindi",
            "live",
            "conduit",
            "pony",
            "covid19",
            "malicious",
            "cobalt strike",
            "suppobox",
            "ramnit",
            "meterpreter",
            "virut",
            "njrat",
            "pykspa",
            "asyncrat",
            "downloader",
            "fakealert",
            "binder",
            "virustotal",
            "formbook",
            "necurs",
            "trojan",
            "msil",
            "hiloti",
            "vawtrak",
            "simda",
            "kraken",
            "solimba",
            "icedid",
            "redirector",
            "suspic",
            "amadey",
            "raccoon",
            "nanocore rat",
            "revenge rat",
            "genkryptik",
            "fuery",
            "wacatac",
            "service",
            "cloudeye",
            "tinba",
            "domaiq",
            "ave maria",
            "zeus",
            "ransomware",
            "zbot",
            "generic",
            "trojanspy",
            "states",
            "inmortal",
            "locky",
            "strike",
            "china cobalt",
            "keybase",
            "cutwail",
            "citadel",
            "radamant",
            "kovter",
            "bradesco",
            "nymaim",
            "amonetize",
            "bondat",
            "ghost rat",
            "vjw0rm",
            "bandoo",
            "matsnu",
            "dnspionage",
            "darkgate",
            "vidar",
            "keylogger",
            "remcos",
            "agenttesla",
            "detplock",
            "win64",
            "smokeloader",
            "agent tesla",
            "kgs0",
            "kls0",
            "urls",
            "type name",
            "dns replication",
            "date",
            "domain",
            "win32 exe",
            "files",
            "detections type",
            "name",
            "drpsuinstaller",
            "vdfsurfs",
            "opera",
            "icwrmind",
            "notepad",
            "installer",
            "miner",
            "unknown",
            "networm",
            "houdini",
            "quasar rat",
            "gamehack",
            "dbatloader",
            "qakbot",
            "ursnif",
            "CVE-2005-1790",
            "CVE-2009-3672",
            "CVE-2010-3962",
            "CVE-2012-3993",
            "CVE-2014-6332",
            "CVE-2017-11882",
            "CVE-2020-0601",
            "CVE-2020-0674",
            "hallrender.com",
            "brian sabey",
            "insurance",
            "botnetwork",
            "botmaster",
            "command_and_control",
            "CVE-2021-27065",
            "CVE-2021-40444",
            "CVE-2023-4966",
            "CVE-2017-0199",
            "CVE-2018-4893",
            "CVE-2010-3333",
            "CVE-2015-1641",
            "CVE-2017-0147",
            "CVE-2017-8570",
            "CVE-2018-0802",
            "CVE-2018-8373",
            "CVE-2017-8759",
            "CVE-2018-8453",
            "CVE-2014-3153",
            "CVE-2015-1650",
            "CVE-2017-0143",
            "CVE-2017-8464",
            "Icefog",
            "Delf.NBX",
            "$WebWatson",
            "Gen:Heur.Ransom.HiddenTears",
            "mobilekey.pw",
            "bitbucket.org",
            "Anomalous.100%",
            "malware distribution site",
            "gootkit",
            "edsaid",
            "rightsaided",
            "betabot",
            "cobaltstrike4.tk",
            "mas.to",
            "BehavesLike.YahLover",
            "srdvd16010404",
            "languageenu",
            "buildno",
            "channelisales",
            "vendorname2581",
            "osregion",
            "device",
            "systemlocale",
            "majorver16",
            "quasar",
            "find",
            "lockbit",
            "chaos",
            "ransomexx",
            "grandoreiro",
            "evilnum",
            "banker"
          ],
          "references": [
            "https://hybrid-analysis.com/sample/6765f47ea77c8274c8e4973ed95aedf59e75998c62f6029e23c58cdf36ed85ba/654afdbdc621e7037801cce7",
            "20.99.186.246 exploit source",
            "fp2e7a.wpc.2be4.phicdn.net",
            "https://www.anyxxxtube.net/search-porn/tsara-brashears/ (phishing, ELF, Prism.exe found)",
            "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian (password cracker)",
            "http://182.22.25.124:7878/182.22.25.124:443     (malicious dropper)",
            "init.ess.apple.com         (malicious code script)",
            "https://www.pornhub.com/video/search?search=tsara+brashears (Malicious PW cracker | stylebk.css stylesheets - not found )",
            "https://urlscan.io/result/a328d9ff-fb49-4078-960d-a757fd41404f/#indicators",
            "VirusTotal Link: https://www.virustotal.com/gui/ip-address/20.99.186.246/detection",
            "Abuse IPDB Link: https://www.abuseipdb.com/check/20.99.186.246",
            "IPv4 45.12.253.72.            command_and_control",
            "Hostname: ddos.dnsnb8.net                        command_and_control",
            "IPv4 95.213.186.51              command_and_control",
            "Hostname: www.supernetforme.com      command_and_control",
            "IPv4 103.224.182.246        command_and_control",
            "IPv4 72.251.233.245           command_and_control",
            "IPv4 63.251.106.25             command_and_control",
            "IPv4 45.15.156.208            command_and_control",
            "IPv4 104.247.81.51             command_and_control",
            "http://ambisexual.phone-sex-blogs.com/http:/ambisexual.phone-sex-blogs.com/images/thumbnails/pic118.jpg             (phishing)",
            "https://downloaddevtools.ir/     (phishing)",
            "happylifehappywife.com",
            "apples.encryptedwork.com        (Interesting in the blacknet)",
            "https://itunes.apple.com/app/apple-store/id284815942/us/app/samsung-galaxy-watch-gear-s/id1117310635.                   (iOS unlocker and hijacker)",
            "https://www.anyxxxtube.net/media/favicon/apple              (password cracker and iOS hijacker)",
            "https://www.apple.com/shop/browse/open/country_selector     (exploit)",
            "www.norad.mil   (federal tracking tool used by attorneys, law firms, and private investigators 'licensed or unlicensed') hi!",
            "http://init-p01st.push.apple.com/bag            (malicious web creator)",
            "opencve.djgummikuh.de        (CVE dispensary)",
            "Maltiverse Research Team",
            "URLscan.io",
            "Deep Research",
            "Hybrid Analysis",
            "URLhaus Abuse.ch",
            "Cyber Threat Coalition",
            "ThreatFox Abuse.ch"
          ],
          "public": 1,
          "adversary": "Lucky Mouse APT27 | NoName057(16) |  Unnamed",
          "targeted_countries": [
            "United States of America",
            "France",
            "Spain"
          ],
          "malware_families": [
            {
              "id": "Feodo",
              "display_name": "Feodo",
              "target": null
            },
            {
              "id": "Dridex",
              "display_name": "Dridex",
              "target": null
            },
            {
              "id": "Redline Stealer",
              "display_name": "Redline Stealer",
              "target": null
            },
            {
              "id": "Ramnit.N",
              "display_name": "Ramnit.N",
              "target": null
            },
            {
              "id": "Loki Bot",
              "display_name": "Loki Bot",
              "target": null
            },
            {
              "id": "Loki Password Stealer (PWS)",
              "display_name": "Loki Password Stealer (PWS)",
              "target": null
            },
            {
              "id": "AZORult",
              "display_name": "AZORult",
              "target": null
            },
            {
              "id": "Zbd Zeus",
              "display_name": "Zbd Zeus",
              "target": null
            },
            {
              "id": "Trojan:MSIL/Burkina",
              "display_name": "Trojan:MSIL/Burkina",
              "target": "/malware/Trojan:MSIL/Burkina"
            },
            {
              "id": "Generic.TrickBot.1",
              "display_name": "Generic.TrickBot.1",
              "target": null
            },
            {
              "id": "Exploit.CVE",
              "display_name": "Exploit.CVE",
              "target": null
            },
            {
              "id": "Injector.IS.gen",
              "display_name": "Injector.IS.gen",
              "target": null
            },
            {
              "id": "Gen:Variant.Razy",
              "display_name": "Gen:Variant.Razy",
              "target": null
            },
            {
              "id": "Trojan.Androm.Gen",
              "display_name": "Trojan.Androm.Gen",
              "target": null
            },
            {
              "id": "HEUR:Trojan.Linux.Agent",
              "display_name": "HEUR:Trojan.Linux.Agent",
              "target": null
            },
            {
              "id": "BScope.Trojan",
              "display_name": "BScope.Trojan",
              "target": null
            },
            {
              "id": "VBA.Downloader",
              "display_name": "VBA.Downloader",
              "target": null
            },
            {
              "id": "Trojan.Notifier",
              "display_name": "Trojan.Notifier",
              "target": null
            },
            {
              "id": "HEUR:Trojan.MSOffice.Alien",
              "display_name": "HEUR:Trojan.MSOffice.Alien",
              "target": null
            },
            {
              "id": "Unsafe.AI_Score_100%",
              "display_name": "Unsafe.AI_Score_100%",
              "target": null
            },
            {
              "id": "Gen:Variant.Johnnie",
              "display_name": "Gen:Variant.Johnnie",
              "target": null
            },
            {
              "id": "DangerousObject.Multi",
              "display_name": "DangerousObject.Multi",
              "target": null
            },
            {
              "id": "Trojan:Python/Downldr",
              "display_name": "Trojan:Python/Downldr",
              "target": "/malware/Trojan:Python/Downldr"
            },
            {
              "id": "Trojan:Linux/Downldr",
              "display_name": "Trojan:Linux/Downldr",
              "target": "/malware/Trojan:Linux/Downldr"
            },
            {
              "id": "Trojan:VBA/Downldr",
              "display_name": "Trojan:VBA/Downldr",
              "target": "/malware/Trojan:VBA/Downldr"
            },
            {
              "id": "TrojanDownloader:Linux/Downldr",
              "display_name": "TrojanDownloader:Linux/Downldr",
              "target": "/malware/TrojanDownloader:Linux/Downldr"
            },
            {
              "id": "Kryptik.FPH.gen",
              "display_name": "Kryptik.FPH.gen",
              "target": null
            },
            {
              "id": "TROJ_FRS.VSNTFK19",
              "display_name": "TROJ_FRS.VSNTFK19",
              "target": null
            },
            {
              "id": "Trojan.Ransom.GenericKD",
              "display_name": "Trojan.Ransom.GenericKD",
              "target": null
            },
            {
              "id": "Phish.JAT",
              "display_name": "Phish.JAT",
              "target": null
            },
            {
              "id": "Phishing.HTML",
              "display_name": "Phishing.HTML",
              "target": null
            },
            {
              "id": "Generic.ASMalwS",
              "display_name": "Generic.ASMalwS",
              "target": null
            },
            {
              "id": "Phish.AB",
              "display_name": "Phish.AB",
              "target": null
            },
            {
              "id": "Generic.Malware",
              "display_name": "Generic.Malware",
              "target": null
            },
            {
              "id": "ml.Generic",
              "display_name": "ml.Generic",
              "target": null
            },
            {
              "id": "Xegumumune.8596c22f",
              "display_name": "Xegumumune.8596c22f",
              "target": null
            },
            {
              "id": "Generic.Malware.SMYB",
              "display_name": "Generic.Malware.SMYB",
              "target": null
            },
            {
              "id": "malicious.moderate.ml",
              "display_name": "malicious.moderate.ml",
              "target": null
            },
            {
              "id": "Agent.NBAE",
              "display_name": "Agent.NBAE",
              "target": null
            },
            {
              "id": "AGEN.1045227",
              "display_name": "AGEN.1045227",
              "target": null
            },
            {
              "id": "Riskware.Agent",
              "display_name": "Riskware.Agent",
              "target": null
            },
            {
              "id": "Gen:Variant.Cerbu",
              "display_name": "Gen:Variant.Cerbu",
              "target": null
            },
            {
              "id": "IL:Trojan.MSILZilla",
              "display_name": "IL:Trojan.MSILZilla",
              "target": null
            },
            {
              "id": "Dropped:Generic.Ransom.DMR",
              "display_name": "Dropped:Generic.Ransom.DMR",
              "target": null
            },
            {
              "id": "Delf.NBX",
              "display_name": "Delf.NBX",
              "target": null
            },
            {
              "id": "malicious.f01f67",
              "display_name": "malicious.f01f67",
              "target": null
            },
            {
              "id": "AGEN.1144657",
              "display_name": "AGEN.1144657",
              "target": null
            },
            {
              "id": "Trojan.Heur",
              "display_name": "Trojan.Heur",
              "target": null
            },
            {
              "id": "Trojan.Malware.300983",
              "display_name": "Trojan.Malware.300983",
              "target": null
            },
            {
              "id": "SdBot.CAOC",
              "display_name": "SdBot.CAOC",
              "target": null
            },
            {
              "id": "Trojan.DelShad",
              "display_name": "Trojan.DelShad",
              "target": null
            },
            {
              "id": "Exploit CVE-2017-11882",
              "display_name": "Exploit CVE-2017-11882",
              "target": null
            },
            {
              "id": "GameHack.NL",
              "display_name": "GameHack.NL",
              "target": null
            },
            {
              "id": "JS:Trojan.HideLink",
              "display_name": "JS:Trojan.HideLink",
              "target": null
            },
            {
              "id": "Script.Agent",
              "display_name": "Script.Agent",
              "target": null
            },
            {
              "id": "Macro.Agent",
              "display_name": "Macro.Agent",
              "target": null
            },
            {
              "id": "Macro.Downloader.AMIP",
              "display_name": "Macro.Downloader.AMIP",
              "target": null
            },
            {
              "id": "Trojan.VBA",
              "display_name": "Trojan.VBA",
              "target": null
            },
            {
              "id": "HEUR.VBA.Trojan",
              "display_name": "HEUR.VBA.Trojan",
              "target": null
            },
            {
              "id": "VB.EmoooDldr.10",
              "display_name": "VB.EmoooDldr.10",
              "target": null
            },
            {
              "id": "VB:Trojan.Valyria",
              "display_name": "VB:Trojan.Valyria",
              "target": null
            },
            {
              "id": "OpenSubtitles.A",
              "display_name": "OpenSubtitles.A",
              "target": null
            },
            {
              "id": "VB.EmoDldr.4",
              "display_name": "VB.EmoDldr.4",
              "target": null
            },
            {
              "id": "Packed-GV",
              "display_name": "Packed-GV",
              "target": null
            },
            {
              "id": "Adware.InstallMonetizer",
              "display_name": "Adware.InstallMonetizer",
              "target": null
            },
            {
              "id": "Skynet",
              "display_name": "Skynet",
              "target": null
            },
            {
              "id": "HW32.Packed",
              "display_name": "HW32.Packed",
              "target": null
            },
            {
              "id": "Zpevdo.B",
              "display_name": "Zpevdo.B",
              "target": null
            },
            {
              "id": "Presenoker",
              "display_name": "Presenoker",
              "target": null
            },
            {
              "id": "SGeneric",
              "display_name": "SGeneric",
              "target": null
            },
            {
              "id": "GameHack.DOM",
              "display_name": "GameHack.DOM",
              "target": null
            },
            {
              "id": "BehavesLike.Ransom",
              "display_name": "BehavesLike.Ransom",
              "target": null
            },
            {
              "id": "CIL.StupidCryptor",
              "display_name": "CIL.StupidCryptor",
              "target": null
            },
            {
              "id": "Gen:Heur.Ransom.MSIL",
              "display_name": "Gen:Heur.Ransom.MSIL",
              "target": null
            },
            {
              "id": "Black.Gen2",
              "display_name": "Black.Gen2",
              "target": null
            },
            {
              "id": "GameHack.CRS",
              "display_name": "GameHack.CRS",
              "target": null
            },
            {
              "id": "Trojan.HTML.PHISH",
              "display_name": "Trojan.HTML.PHISH",
              "target": null
            },
            {
              "id": "Gen:Heur.MSIL.Inject",
              "display_name": "Gen:Heur.MSIL.Inject",
              "target": null
            },
            {
              "id": "Program.Unwanted",
              "display_name": "Program.Unwanted",
              "target": null
            },
            {
              "id": "HEUR/QVM42.3.72EB.Malware",
              "display_name": "HEUR/QVM42.3.72EB.Malware",
              "target": null
            },
            {
              "id": "suspicious.low.ml",
              "display_name": "suspicious.low.ml",
              "target": null
            },
            {
              "id": "JS:Trojan.Cryxos",
              "display_name": "JS:Trojan.Cryxos",
              "target": null
            },
            {
              "id": "Suspicious_GEN.F47V0520",
              "display_name": "Suspicious_GEN.F47V0520",
              "target": null
            },
            {
              "id": "Dropper.Trojan.Generic",
              "display_name": "Dropper.Trojan.Generic",
              "target": null
            },
            {
              "id": "Trojan.TrickBot",
              "display_name": "Trojan.TrickBot",
              "target": null
            },
            {
              "id": "Malware.Tk.Generic",
              "display_name": "Malware.Tk.Generic",
              "target": null
            },
            {
              "id": "TrojanSpy.Java",
              "display_name": "TrojanSpy.Java",
              "target": null
            },
            {
              "id": "Riskware.NetFilter",
              "display_name": "Riskware.NetFilter",
              "target": null
            },
            {
              "id": "RiskWare.Crack",
              "display_name": "RiskWare.Crack",
              "target": null
            },
            {
              "id": "BehavesLike.Exploit",
              "display_name": "BehavesLike.Exploit",
              "target": null
            },
            {
              "id": "Gen:NN.ZemsilF.34128",
              "display_name": "Gen:NN.ZemsilF.34128",
              "target": null
            },
            {
              "id": "Wacapew.C",
              "display_name": "Wacapew.C",
              "target": null
            },
            {
              "id": "Trojan.Malware.121218",
              "display_name": "Trojan.Malware.121218",
              "target": null
            },
            {
              "id": "RiskWare.HackTool.Agent",
              "display_name": "RiskWare.HackTool.Agent",
              "target": null
            },
            {
              "id": "Artemis",
              "display_name": "Artemis",
              "target": null
            },
            {
              "id": "Trojan.Generic",
              "display_name": "Trojan.Generic",
              "target": null
            },
            {
              "id": "W32.Trojan",
              "display_name": "W32.Trojan",
              "target": null
            },
            {
              "id": "BScope.Riskware",
              "display_name": "BScope.Riskware",
              "target": null
            },
            {
              "id": "Gen:Variant.Bulz",
              "display_name": "Gen:Variant.Bulz",
              "target": null
            },
            {
              "id": "Ransom:Win32/CVE-2017-0147",
              "display_name": "Ransom:Win32/CVE-2017-0147",
              "target": "/malware/Ransom:Win32/CVE-2017-0147"
            },
            {
              "id": "Virus.Ramnit",
              "display_name": "Virus.Ramnit",
              "target": null
            },
            {
              "id": "Virus.Virut",
              "display_name": "Virus.Virut",
              "target": null
            },
            {
              "id": "Adware.KuziTui",
              "display_name": "Adware.KuziTui",
              "target": null
            },
            {
              "id": "AGEN.1141126",
              "display_name": "AGEN.1141126",
              "target": null
            },
            {
              "id": "W32.AIDetect",
              "display_name": "W32.AIDetect",
              "target": null
            },
            {
              "id": "Trojan.Python",
              "display_name": "Trojan.Python",
              "target": null
            },
            {
              "id": "W32.AIDetectVM",
              "display_name": "W32.AIDetectVM",
              "target": null
            },
            {
              "id": "Suspicious.Save",
              "display_name": "Suspicious.Save",
              "target": null
            },
            {
              "id": "Adware.Downware",
              "display_name": "Adware.Downware",
              "target": null
            },
            {
              "id": "Ransom.Win64.Wacatac.oa",
              "display_name": "Ransom.Win64.Wacatac.oa",
              "target": null
            },
            {
              "id": "OpenSubtitles.A",
              "display_name": "OpenSubtitles.A",
              "target": null
            },
            {
              "id": "VB.EmoDldr.4",
              "display_name": "VB.EmoDldr.4",
              "target": null
            },
            {
              "id": "Gen:Variant.Midie",
              "display_name": "Gen:Variant.Midie",
              "target": null
            },
            {
              "id": "HEUR/QVM41.2.DA9B.Malware",
              "display_name": "HEUR/QVM41.2.DA9B.Malware",
              "target": null
            },
            {
              "id": "Gen:Variant.Sirefef",
              "display_name": "Gen:Variant.Sirefef",
              "target": null
            },
            {
              "id": "Macro.Trojan.Dropperd",
              "display_name": "Macro.Trojan.Dropperd",
              "target": null
            },
            {
              "id": "BlackNET RAT",
              "display_name": "BlackNET RAT",
              "target": null
            },
            {
              "id": "Gen:Variant.Ursu",
              "display_name": "Gen:Variant.Ursu",
              "target": null
            },
            {
              "id": "Redcap.rlhse",
              "display_name": "Redcap.rlhse",
              "target": null
            },
            {
              "id": "Trojan.Trickster",
              "display_name": "Trojan.Trickster",
              "target": null
            },
            {
              "id": "HTML_REDIR.SMR",
              "display_name": "HTML_REDIR.SMR",
              "target": null
            },
            {
              "id": "TROJ_FRS.VSNTFK19",
              "display_name": "TROJ_FRS.VSNTFK19",
              "target": null
            },
            {
              "id": "Hoax.JS.Phish",
              "display_name": "Hoax.JS.Phish",
              "target": null
            },
            {
              "id": "JS:Iframe",
              "display_name": "JS:Iframe",
              "target": null
            },
            {
              "id": "Application.SQLCrack",
              "display_name": "Application.SQLCrack",
              "target": null
            },
            {
              "id": "susp.lnk",
              "display_name": "susp.lnk",
              "target": null
            },
            {
              "id": "QVM201.0.B70B.Malware",
              "display_name": "QVM201.0.B70B.Malware",
              "target": null
            },
            {
              "id": "Immortal Stealer",
              "display_name": "Immortal Stealer",
              "target": null
            },
            {
              "id": "WebMonitor RAT",
              "display_name": "WebMonitor RAT",
              "target": null
            },
            {
              "id": "Tor - S0183",
              "display_name": "Tor - S0183",
              "target": null
            },
            {
              "id": "WannaCry",
              "display_name": "WannaCry",
              "target": null
            },
            {
              "id": "WannaCryptor",
              "display_name": "WannaCryptor",
              "target": null
            },
            {
              "id": "WebToolbar",
              "display_name": "WebToolbar",
              "target": null
            },
            {
              "id": "BlackNET",
              "display_name": "BlackNET",
              "target": null
            },
            {
              "id": "DeepScan:Generic.Ransom.GandCrab5",
              "display_name": "DeepScan:Generic.Ransom.GandCrab5",
              "target": null
            },
            {
              "id": "TrojanSpy",
              "display_name": "TrojanSpy",
              "target": null
            },
            {
              "id": "States",
              "display_name": "States",
              "target": null
            },
            {
              "id": "Inmortal",
              "display_name": "Inmortal",
              "target": null
            },
            {
              "id": "Domains",
              "display_name": "Domains",
              "target": null
            },
            {
              "id": "Locky",
              "display_name": "Locky",
              "target": null
            },
            {
              "id": "Delf.NBX",
              "display_name": "Delf.NBX",
              "target": null
            },
            {
              "id": "Gen:NN.ZexaF.32515",
              "display_name": "Gen:NN.ZexaF.32515",
              "target": null
            },
            {
              "id": "FileRepMalware",
              "display_name": "FileRepMalware",
              "target": null
            },
            {
              "id": "Gen:Variant.MSILPerseus",
              "display_name": "Gen:Variant.MSILPerseus",
              "target": null
            },
            {
              "id": "Icefog",
              "display_name": "Icefog",
              "target": null
            },
            {
              "id": "$WebWatson",
              "display_name": "$WebWatson",
              "target": null
            },
            {
              "id": "Agent.AIK.gen",
              "display_name": "Agent.AIK.gen",
              "target": null
            },
            {
              "id": "Agent.AIK.genCIL.StupidCryptor",
              "display_name": "Agent.AIK.genCIL.StupidCryptor",
              "target": null
            },
            {
              "id": "Agent.YPEZ",
              "display_name": "Agent.YPEZ",
              "target": null
            },
            {
              "id": "Application.InnovativSol",
              "display_name": "Application.InnovativSol",
              "target": null
            },
            {
              "id": "Agent.ASO",
              "display_name": "Agent.ASO",
              "target": null
            },
            {
              "id": "S-b748adc5",
              "display_name": "S-b748adc5",
              "target": null
            },
            {
              "id": "W32.eHeur",
              "display_name": "W32.eHeur",
              "target": null
            },
            {
              "id": "Kryptik.GUCB",
              "display_name": "Kryptik.GUCB",
              "target": null
            },
            {
              "id": "AgentTesla",
              "display_name": "AgentTesla",
              "target": null
            },
            {
              "id": "Autoit.bimwt",
              "display_name": "Autoit.bimwt",
              "target": null
            },
            {
              "id": "HEUR:Trojan.OLE2.Alien",
              "display_name": "HEUR:Trojan.OLE2.Alien",
              "target": null
            },
            {
              "id": "AGEN.1038489",
              "display_name": "AGEN.1038489",
              "target": null
            },
            {
              "id": "Gen:Variant.Ser.Strictor",
              "display_name": "Gen:Variant.Ser.Strictor",
              "target": null
            },
            {
              "id": "Packed.Themida.Gen",
              "display_name": "Packed.Themida.Gen",
              "target": null
            },
            {
              "id": "AGEN.1043164",
              "display_name": "AGEN.1043164",
              "target": null
            },
            {
              "id": "TrickBot - S0266",
              "display_name": "TrickBot - S0266",
              "target": null
            },
            {
              "id": "Emotet",
              "display_name": "Emotet",
              "target": null
            },
            {
              "id": "Trojan.PornoAsset",
              "display_name": "Trojan.PornoAsset",
              "target": null
            },
            {
              "id": "Ransom.Win64.PORNOASSET.SM1",
              "display_name": "Ransom.Win64.PORNOASSET.SM1",
              "target": null
            },
            {
              "id": "Gen:Variant.Ulise",
              "display_name": "Gen:Variant.Ulise",
              "target": null
            },
            {
              "id": "Trojan.Win64",
              "display_name": "Trojan.Win64",
              "target": null
            },
            {
              "id": "Dropper.Trojan.Agent",
              "display_name": "Dropper.Trojan.Agent",
              "target": null
            },
            {
              "id": "Heur.BZC.YAX.Pantera.10",
              "display_name": "Heur.BZC.YAX.Pantera.10",
              "target": null
            },
            {
              "id": "malicious.high.ml",
              "display_name": "malicious.high.ml",
              "target": null
            },
            {
              "id": "CVE-2015-1650",
              "display_name": "CVE-2015-1650",
              "target": null
            },
            {
              "id": "Worm.Win64.AutoRun",
              "display_name": "Worm.Win64.AutoRun",
              "target": null
            },
            {
              "id": "AIT.Heur.Cottonmouth.8.78F19BD7",
              "display_name": "AIT.Heur.Cottonmouth.8.78F19BD7",
              "target": null
            },
            {
              "id": "Gen:Variant.Mikey",
              "display_name": "Gen:Variant.Mikey",
              "target": null
            },
            {
              "id": "Trojan.Agent",
              "display_name": "Trojan.Agent",
              "target": null
            },
            {
              "id": "Pua.Gen",
              "display_name": "Pua.Gen",
              "target": null
            },
            {
              "id": "Trojan.Downloader.Generic",
              "display_name": "Trojan.Downloader.Generic",
              "target": null
            },
            {
              "id": "Suspected of Trojan.Downloader.gen",
              "display_name": "Suspected of Trojan.Downloader.gen",
              "target": null
            },
            {
              "id": "HEUR:RemoteAdmin.Generic",
              "display_name": "HEUR:RemoteAdmin.Generic",
              "target": null
            },
            {
              "id": "Gen:Heur.Ransom.HiddenTears",
              "display_name": "Gen:Heur.Ransom.HiddenTears",
              "target": null
            },
            {
              "id": "Nemucod.A",
              "display_name": "Nemucod.A",
              "target": null
            },
            {
              "id": "Backdoor.Hupigon",
              "display_name": "Backdoor.Hupigon",
              "target": null
            },
            {
              "id": "Trojan.Starter JS.Iframe",
              "display_name": "Trojan.Starter JS.Iframe",
              "target": null
            },
            {
              "id": "fake ,promethiumm ,strongpity",
              "display_name": "fake ,promethiumm ,strongpity",
              "target": null
            },
            {
              "id": "PUA.Reg1staid",
              "display_name": "PUA.Reg1staid",
              "target": null
            },
            {
              "id": "Malware.Heur_Generic.A",
              "display_name": "Malware.Heur_Generic.A",
              "target": null
            },
            {
              "id": "Bladabindi.Q",
              "display_name": "Bladabindi.Q",
              "target": null
            },
            {
              "id": "W32.eHeur",
              "display_name": "W32.eHeur",
              "target": null
            },
            {
              "id": "malicious.6e0700",
              "display_name": "malicious.6e0700",
              "target": null
            },
            {
              "id": "Trojan.Inject",
              "display_name": "Trojan.Inject",
              "target": null
            },
            {
              "id": "TSGeneric",
              "display_name": "TSGeneric",
              "target": null
            },
            {
              "id": "RedCap.vneda",
              "display_name": "RedCap.vneda",
              "target": null
            },
            {
              "id": "Trojan.Indiloadz",
              "display_name": "Trojan.Indiloadz",
              "target": null
            },
            {
              "id": "Trojan.Ekstak",
              "display_name": "Trojan.Ekstak",
              "target": null
            },
            {
              "id": "staticrr.paleokits.net",
              "display_name": "staticrr.paleokits.net",
              "target": null
            },
            {
              "id": "MSIL.Downloader",
              "display_name": "MSIL.Downloader",
              "target": null
            },
            {
              "id": "Trojan.Autoruns.GenericKDS",
              "display_name": "Trojan.Autoruns.GenericKDS",
              "target": null
            },
            {
              "id": "MSIL.Trojan.BSE",
              "display_name": "MSIL.Trojan.BSE",
              "target": null
            },
            {
              "id": "Adload.AD81",
              "display_name": "Adload.AD81",
              "target": null
            },
            {
              "id": "Packed.Asprotect",
              "display_name": "Packed.Asprotect",
              "target": null
            },
            {
              "id": "Gen:NN.ZemsilF.34062",
              "display_name": "Gen:NN.ZemsilF.34062",
              "target": null
            },
            {
              "id": "Evo",
              "display_name": "Evo",
              "target": null
            },
            {
              "id": "Agent.pwc",
              "display_name": "Agent.pwc",
              "target": null
            },
            {
              "id": "RiskTool.Phpw",
              "display_name": "RiskTool.Phpw",
              "target": null
            },
            {
              "id": "Gen:Variant.Symmi",
              "display_name": "Gen:Variant.Symmi",
              "target": null
            },
            {
              "id": "Trojan.PWS",
              "display_name": "Trojan.PWS",
              "target": null
            },
            {
              "id": "Generic.BitCoinMiner.3",
              "display_name": "Generic.BitCoinMiner.3",
              "target": null
            },
            {
              "id": "Trojan.Tasker",
              "display_name": "Trojan.Tasker",
              "target": null
            },
            {
              "id": "Gen:NN",
              "display_name": "Gen:NN",
              "target": null
            },
            {
              "id": "Downloader.CertutilURLCache",
              "display_name": "Downloader.CertutilURLCache",
              "target": null
            },
            {
              "id": "Elf",
              "display_name": "Elf",
              "target": null
            },
            {
              "id": "Gen:Heur.MSIL.Androm",
              "display_name": "Gen:Heur.MSIL.Androm",
              "target": null
            },
            {
              "id": "Kryptik.NRD",
              "display_name": "Kryptik.NRD",
              "target": null
            },
            {
              "id": "Riskware",
              "display_name": "Riskware",
              "target": null
            },
            {
              "id": "Kuluoz.B.gen",
              "display_name": "Kuluoz.B.gen",
              "target": null
            },
            {
              "id": "Gen:Variant.RevengeRat",
              "display_name": "Gen:Variant.RevengeRat",
              "target": null
            },
            {
              "id": "Gen:Variant.Mikey",
              "display_name": "Gen:Variant.Mikey",
              "target": null
            },
            {
              "id": "VB.Chronos.7",
              "display_name": "VB.Chronos.7",
              "target": null
            },
            {
              "id": "Kryptik.NOE",
              "display_name": "Kryptik.NOE",
              "target": null
            },
            {
              "id": "HEUR:WebToolbar.Generic",
              "display_name": "HEUR:WebToolbar.Generic",
              "target": null
            },
            {
              "id": "Gen:Variant.Barys",
              "display_name": "Gen:Variant.Barys",
              "target": null
            },
            {
              "id": "Backdoor.Xtreme",
              "display_name": "Backdoor.Xtreme",
              "target": null
            },
            {
              "id": "Trojan.MSIL",
              "display_name": "Trojan.MSIL",
              "target": null
            },
            {
              "id": "Gen:Variant.Graftor",
              "display_name": "Gen:Variant.Graftor",
              "target": null
            },
            {
              "id": "Backdoor.Agent",
              "display_name": "Backdoor.Agent",
              "target": null
            },
            {
              "id": "Unsafe",
              "display_name": "Unsafe",
              "target": null
            },
            {
              "id": "Trojan.PHP.Agent",
              "display_name": "Trojan.PHP.Agent",
              "target": null
            },
            {
              "id": "Trojan.Agent",
              "display_name": "Trojan.Agent",
              "target": null
            },
            {
              "id": "HEUR:Exploit.Generic",
              "display_name": "HEUR:Exploit.Generic",
              "target": null
            },
            {
              "id": "Ransom_WCRY.SMALYM",
              "display_name": "Ransom_WCRY.SMALYM",
              "target": null
            },
            {
              "id": "Ransom_WCRY.SMJ",
              "display_name": "Ransom_WCRY.SMJ",
              "target": null
            },
            {
              "id": "Auslogics",
              "display_name": "Auslogics",
              "target": null
            },
            {
              "id": "Gen:Variant.Jaiko",
              "display_name": "Gen:Variant.Jaiko",
              "target": null
            },
            {
              "id": "Exploit.W32.Agent",
              "display_name": "Exploit.W32.Agent",
              "target": null
            },
            {
              "id": "Trojan.Cud.Gen",
              "display_name": "Trojan.Cud.Gen",
              "target": null
            },
            {
              "id": "Trojan.DOC.Downloader",
              "display_name": "Trojan.DOC.Downloader",
              "target": null
            },
            {
              "id": "Backdoor.MSIL.Agent",
              "display_name": "Backdoor.MSIL.Agent",
              "target": null
            },
            {
              "id": "Gen:Trojan.Heur2.LPTbHW@W64.HfsAutoB",
              "display_name": "Gen:Trojan.Heur2.LPTbHW@W64.HfsAutoB",
              "target": null
            },
            {
              "id": "Gen:Variant.Kazy",
              "display_name": "Gen:Variant.Kazy",
              "target": null
            },
            {
              "id": "Gen:Variant.Zusy",
              "display_name": "Gen:Variant.Zusy",
              "target": null
            },
            {
              "id": "Ransom.WannaCrypt",
              "display_name": "Ransom.WannaCrypt",
              "target": null
            },
            {
              "id": "Generic.ServStart.A",
              "display_name": "Generic.ServStart.A",
              "target": null
            },
            {
              "id": "Trojan.Wanna",
              "display_name": "Trojan.Wanna",
              "target": null
            },
            {
              "id": "Generic.MSIL.Bladabindi",
              "display_name": "Generic.MSIL.Bladabindi",
              "target": null
            },
            {
              "id": "TROJ_GEN.R002C0OG518",
              "display_name": "TROJ_GEN.R002C0OG518",
              "target": null
            },
            {
              "id": "Trojan.Chapak",
              "display_name": "Trojan.Chapak",
              "target": null
            },
            {
              "id": "Indiloadz.BB",
              "display_name": "Indiloadz.BB",
              "target": null
            },
            {
              "id": "BehavBehavesLike.PUPXBI",
              "display_name": "BehavBehavesLike.PUPXBI",
              "target": null
            },
            {
              "id": "DeepScan:Generic.SpyAgent.6",
              "display_name": "DeepScan:Generic.SpyAgent.6",
              "target": null
            },
            {
              "id": "Python.KeyLogger",
              "display_name": "Python.KeyLogger",
              "target": null
            },
            {
              "id": "GameHack.CRS",
              "display_name": "GameHack.CRS",
              "target": null
            },
            {
              "id": "Generic.MSIL.PasswordStealer",
              "display_name": "Generic.MSIL.PasswordStealer",
              "target": null
            },
            {
              "id": "PSW.Agent",
              "display_name": "PSW.Agent",
              "target": null
            },
            {
              "id": "malicious.8c45ba",
              "display_name": "malicious.8c45ba",
              "target": null
            },
            {
              "id": "Dropper.Binder",
              "display_name": "Dropper.Binder",
              "target": null
            },
            {
              "id": "Constructor.MSIL",
              "display_name": "Constructor.MSIL",
              "target": null
            },
            {
              "id": "Linux.Agent",
              "display_name": "Linux.Agent",
              "target": null
            },
            {
              "id": "Virus.3DMax.Script",
              "display_name": "Virus.3DMax.Script",
              "target": null
            },
            {
              "id": "ScrInject.B",
              "display_name": "ScrInject.B",
              "target": null
            },
            {
              "id": "Trojan.WisdomEyes.16070401.9500",
              "display_name": "Trojan.WisdomEyes.16070401.9500",
              "target": null
            },
            {
              "id": "Application.SearchProtect",
              "display_name": "Application.SearchProtect",
              "target": null
            },
            {
              "id": "JS:Trojan.Clicker",
              "display_name": "JS:Trojan.Clicker",
              "target": null
            },
            {
              "id": "Faceliker.A",
              "display_name": "Faceliker.A",
              "target": null
            },
            {
              "id": "JS:Trojan.JS.Faceliker",
              "display_name": "JS:Trojan.JS.Faceliker",
              "target": null
            },
            {
              "id": "Constructor.MSIL  Linux.Agent",
              "display_name": "Constructor.MSIL  Linux.Agent",
              "target": null
            },
            {
              "id": "PowerShell.Trojan",
              "display_name": "PowerShell.Trojan",
              "target": null
            },
            {
              "id": "HTML:Script",
              "display_name": "HTML:Script",
              "target": null
            },
            {
              "id": "ScrInject.B",
              "display_name": "ScrInject.B",
              "target": null
            },
            {
              "id": "W32.AIDetectVM",
              "display_name": "W32.AIDetectVM",
              "target": null
            },
            {
              "id": "HackTool.CheatEngine",
              "display_name": "HackTool.CheatEngine",
              "target": null
            },
            {
              "id": "Injector.CLDS",
              "display_name": "Injector.CLDS",
              "target": null
            },
            {
              "id": "VB.Downloader.2",
              "display_name": "VB.Downloader.2",
              "target": null
            },
            {
              "id": "malicious.3e78cc",
              "display_name": "malicious.3e78cc",
              "target": null
            },
            {
              "id": "malicious.d800d6",
              "display_name": "malicious.d800d6",
              "target": null
            },
            {
              "id": "VB.PwShell.2",
              "display_name": "VB.PwShell.2",
              "target": null
            },
            {
              "id": "Backdoor.RBot",
              "display_name": "Backdoor.RBot",
              "target": null
            },
            {
              "id": "malicious.71b1a8",
              "display_name": "malicious.71b1a8",
              "target": null
            },
            {
              "id": "TrojanSpy.KeyLogger",
              "display_name": "TrojanSpy.KeyLogger",
              "target": null
            },
            {
              "id": "Injector.JDO",
              "display_name": "Injector.JDO",
              "target": null
            },
            {
              "id": "Heur.Msword.Gen",
              "display_name": "Heur.Msword.Gen",
              "target": null
            },
            {
              "id": "PSW.Discord",
              "display_name": "PSW.Discord",
              "target": null
            },
            {
              "id": "Packed.VMProtect",
              "display_name": "Packed.VMProtect",
              "target": null
            },
            {
              "id": "HEUR:AdWare.StartSurf",
              "display_name": "HEUR:AdWare.StartSurf",
              "target": null
            },
            {
              "id": "Gen:Heur.NoobyProtect",
              "display_name": "Gen:Heur.NoobyProtect",
              "target": null
            },
            {
              "id": "CIL.HeapOverride",
              "display_name": "CIL.HeapOverride",
              "target": null
            },
            {
              "id": "HEUR:Trojan.Tasker",
              "display_name": "HEUR:Trojan.Tasker",
              "target": null
            },
            {
              "id": "XLM.Trojan.Abracadabra.27",
              "display_name": "XLM.Trojan.Abracadabra.27",
              "target": null
            },
            {
              "id": "HEUR:Backdoor.MSIL.NanoBot",
              "display_name": "HEUR:Backdoor.MSIL.NanoBot",
              "target": null
            },
            {
              "id": "Trojan.PSW.Mimikatz",
              "display_name": "Trojan.PSW.Mimikatz",
              "target": null
            },
            {
              "id": "TrojanSpy.Python",
              "display_name": "TrojanSpy.Python",
              "target": null
            },
            {
              "id": "Trojan.Ole2.Vbs",
              "display_name": "Trojan.Ole2.Vbs",
              "target": null
            },
            {
              "id": "Exploit.MSOffice",
              "display_name": "Exploit.MSOffice",
              "target": null
            },
            {
              "id": "DeepScan:Generic.Ransom.AmnesiaE",
              "display_name": "DeepScan:Generic.Ransom.AmnesiaE",
              "target": null
            },
            {
              "id": "Wacatac.D6",
              "display_name": "Wacatac.D6",
              "target": null
            },
            {
              "id": "Backdoor.Androm",
              "display_name": "Backdoor.Androm",
              "target": null
            },
            {
              "id": "Packed.NetSeal",
              "display_name": "Packed.NetSeal",
              "target": null
            },
            {
              "id": "Trojan.MSIL.Injector",
              "display_name": "Trojan.MSIL.Injector",
              "target": null
            },
            {
              "id": "Trojan.PWS.Agent",
              "display_name": "Trojan.PWS.Agent",
              "target": null
            },
            {
              "id": "TScope.Trojan",
              "display_name": "TScope.Trojan",
              "target": null
            },
            {
              "id": "PSW.Stealer",
              "display_name": "PSW.Stealer",
              "target": null
            },
            {
              "id": "Trojan.PackedNET",
              "display_name": "Trojan.PackedNET",
              "target": null
            },
            {
              "id": "Trojan.Java",
              "display_name": "Trojan.Java",
              "target": null
            },
            {
              "id": "MalwareX",
              "display_name": "MalwareX",
              "target": null
            },
            {
              "id": "Trojan.PSW.Python",
              "display_name": "Trojan.PSW.Python",
              "target": null
            },
            {
              "id": "malicious.11abfc",
              "display_name": "malicious.11abfc",
              "target": null
            },
            {
              "id": "Generic.ASMalwS",
              "display_name": "Generic.ASMalwS",
              "target": null
            },
            {
              "id": "HEUR:Trojan.MSIL.Tasker",
              "display_name": "HEUR:Trojan.MSIL.Tasker",
              "target": null
            },
            {
              "id": "PossibleThreat.PALLAS",
              "display_name": "PossibleThreat.PALLAS",
              "target": null
            },
            {
              "id": "Backdoor.Poison",
              "display_name": "Backdoor.Poison",
              "target": null
            },
            {
              "id": "Generic.MSIL.LimeRAT",
              "display_name": "Generic.MSIL.LimeRAT",
              "target": null
            },
            {
              "id": "PWS-FCZZ",
              "display_name": "PWS-FCZZ",
              "target": null
            },
            {
              "id": "Trojan.Script",
              "display_name": "Trojan.Script",
              "target": null
            },
            {
              "id": "Gen:Heur.MSIL.Inject",
              "display_name": "Gen:Heur.MSIL.Inject",
              "target": null
            },
            {
              "id": "Trojan.PWS.Growtopia",
              "display_name": "Trojan.PWS.Growtopia",
              "target": null
            },
            {
              "id": "Spyware.Bobik",
              "display_name": "Spyware.Bobik",
              "target": null
            },
            {
              "id": "HackTool.BruteForce",
              "display_name": "HackTool.BruteForce",
              "target": null
            },
            {
              "id": "Hack.Patcher",
              "display_name": "Hack.Patcher",
              "target": null
            },
            {
              "id": "PWS.p",
              "display_name": "PWS.p",
              "target": null
            },
            {
              "id": "Suppobox",
              "display_name": "Suppobox",
              "target": null
            },
            {
              "id": "index.php",
              "display_name": "index.php",
              "target": null
            },
            {
              "id": "Packed.VMProtect",
              "display_name": "Packed.VMProtect",
              "target": null
            },
            {
              "id": "SmokeLoader",
              "display_name": "SmokeLoader",
              "target": null
            },
            {
              "id": "Generic.Malware",
              "display_name": "Generic.Malware",
              "target": null
            },
            {
              "id": "SNH:Script [Dropper]",
              "display_name": "SNH:Script [Dropper]",
              "target": null
            },
            {
              "id": "HEUR:Trojan.MSOffice.SAgent",
              "display_name": "HEUR:Trojan.MSOffice.SAgent",
              "target": null
            },
            {
              "id": "Script.INF",
              "display_name": "Script.INF",
              "target": null
            },
            {
              "id": "JS:Trojan.JS.Likejack",
              "display_name": "JS:Trojan.JS.Likejack",
              "target": null
            },
            {
              "id": "SNH:Script [Dropper]",
              "display_name": "SNH:Script [Dropper]",
              "target": null
            },
            {
              "id": "Trojan.JS.Agent",
              "display_name": "Trojan.JS.Agent",
              "target": null
            },
            {
              "id": "APT Notes",
              "display_name": "APT Notes",
              "target": null
            },
            {
              "id": "susp.rtf.objupdate",
              "display_name": "susp.rtf.objupdate",
              "target": null
            },
            {
              "id": "RedCap.zoohz",
              "display_name": "RedCap.zoohz",
              "target": null
            },
            {
              "id": "Trojan.Tasker",
              "display_name": "Trojan.Tasker",
              "target": null
            },
            {
              "id": "virus.office.qexvmc",
              "display_name": "virus.office.qexvmc",
              "target": null
            },
            {
              "id": "Trojan.KillProc",
              "display_name": "Trojan.KillProc",
              "target": null
            },
            {
              "id": "Generic.MSIL.GrwtpStealer.1",
              "display_name": "Generic.MSIL.GrwtpStealer.1",
              "target": null
            },
            {
              "id": "Suspicious.Cloud",
              "display_name": "Suspicious.Cloud",
              "target": null
            },
            {
              "id": "PowerShell.DownLoader",
              "display_name": "PowerShell.DownLoader",
              "target": null
            },
            {
              "id": "Downldr.gen",
              "display_name": "Downldr.gen",
              "target": null
            },
            {
              "id": "AGEN.1030939",
              "display_name": "AGEN.1030939",
              "target": null
            },
            {
              "id": "HackTool.Binder",
              "display_name": "HackTool.Binder",
              "target": null
            },
            {
              "id": "Trojan.Inject",
              "display_name": "Trojan.Inject",
              "target": null
            },
            {
              "id": "Dldr.Agent",
              "display_name": "Dldr.Agent",
              "target": null
            },
            {
              "id": "Dropper.MSIL",
              "display_name": "Dropper.MSIL",
              "target": null
            },
            {
              "id": "Trojan.VBKryjetor",
              "display_name": "Trojan.VBKryjetor",
              "target": null
            },
            {
              "id": "PWSX",
              "display_name": "PWSX",
              "target": null
            },
            {
              "id": "VB:Trojan.VBA.Agent",
              "display_name": "VB:Trojan.VBA.Agent",
              "target": null
            },
            {
              "id": "HEUR:Trojan.MSOffice.Stratos",
              "display_name": "HEUR:Trojan.MSOffice.Stratos",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1071.004",
              "name": "DNS",
              "display_name": "T1071.004 - DNS"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1059.007",
              "name": "JavaScript",
              "display_name": "T1059.007 - JavaScript"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1068",
              "name": "Exploitation for Privilege Escalation",
              "display_name": "T1068 - Exploitation for Privilege Escalation"
            },
            {
              "id": "TA0029",
              "name": "Privilege Escalation",
              "display_name": "TA0029 - Privilege Escalation"
            },
            {
              "id": "T1449",
              "name": "Exploit SS7 to Redirect Phone Calls/SMS",
              "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
            },
            {
              "id": "T1190",
              "name": "Exploit Public-Facing Application",
              "display_name": "T1190 - Exploit Public-Facing Application"
            },
            {
              "id": "T1210",
              "name": "Exploitation of Remote Services",
              "display_name": "T1210 - Exploitation of Remote Services"
            },
            {
              "id": "T1450",
              "name": "Exploit SS7 to Track Device Location",
              "display_name": "T1450 - Exploit SS7 to Track Device Location"
            },
            {
              "id": "T1211",
              "name": "Exploitation for Defense Evasion",
              "display_name": "T1211 - Exploitation for Defense Evasion"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "TA0011",
              "name": "Command and Control",
              "display_name": "TA0011 - Command and Control"
            },
            {
              "id": "T1412",
              "name": "Capture SMS Messages",
              "display_name": "T1412 - Capture SMS Messages"
            },
            {
              "id": "T1454",
              "name": "Malicious SMS Message",
              "display_name": "T1454 - Malicious SMS Message"
            },
            {
              "id": "T1001",
              "name": "Data Obfuscation",
              "display_name": "T1001 - Data Obfuscation"
            },
            {
              "id": "T1114",
              "name": "Email Collection",
              "display_name": "T1114 - Email Collection"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1498",
              "name": "Network Denial of Service",
              "display_name": "T1498 - Network Denial of Service"
            },
            {
              "id": "T1496",
              "name": "Resource Hijacking",
              "display_name": "T1496 - Resource Hijacking"
            },
            {
              "id": "T1176",
              "name": "Browser Extensions",
              "display_name": "T1176 - Browser Extensions"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": "654c597a4a45c8d84f0b15c1",
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 1184,
            "FileHash-SHA1": 949,
            "FileHash-SHA256": 3712,
            "URL": 2927,
            "domain": 627,
            "hostname": 1320,
            "CVE": 26,
            "email": 8,
            "CIDR": 2
          },
          "indicator_count": 10755,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 67,
          "modified_text": "24 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "654c5970817e6bf8b0e5b5ff",
          "name": "Lucky Mouse APT27 | Feodo Tracker | Malicious Tor Server | Apple iOS",
          "description": "Darkside 2020 Ecosystem .BEware\nMalicious Tor server. Link found in pulse created prior. \nMalvertizing target: Tsara Brashears\nRevenge Porn.\nThere may me others. Malicious Apple activities, locating, CVE exploits, unlocking, hijacker, service transfer, spyware, malicious full auth, tracking, endless. Seems to originate from a law firm that goes to far to defend clients and silence alleged victims. \nSome State allow  the same  privileges  and tools the federal government to insurance, workers compensation, investigators and insurance company law firms for investigations. \nFear tactics they seem willing to back up. I was approached and asked about my cyber knowledge by strangers. I am followed now for using a tool properly.\nALL terms auto populated from various tools from various tools used including, State, Brian Sabey, cyber stalking. Perhaps he's made contact with target. Danger!",
          "modified": "2023-12-09T03:01:57.989000",
          "created": "2023-11-09T04:00:48.087000",
          "tags": [
            "ssl certificate",
            "historical ssl",
            "communicating",
            "contacted",
            "resolutions",
            "whois record",
            "whois whois",
            "whois parent",
            "whois siblings",
            "skynet",
            "threat report",
            "ip summary",
            "url summary",
            "summary",
            "sample",
            "samples",
            "detection list",
            "blacklist",
            "cisco umbrella",
            "site",
            "safe site",
            "million",
            "team",
            "microsoft",
            "back",
            "download",
            "phishing",
            "union",
            "bank",
            "malicious site",
            "blacklist http",
            "exit",
            "traffic",
            "node tcp",
            "tor known",
            "tor relayrouter",
            "et tor",
            "known tor",
            "relayrouter",
            "anonymizer",
            "spammer",
            "malware",
            "dropped",
            "unlocker",
            "http",
            "critical risk",
            "redline stealer",
            "core",
            "hacktool",
            "execution",
            "type win32",
            "exe size",
            "first seen",
            "file name",
            "avast win32",
            "win32",
            "avg win32",
            "fortinet",
            "vitro",
            "mb first",
            "rmndrp",
            "clean mx",
            "undetected dns8",
            "undetected vx",
            "sophos",
            "vault",
            "zdb zeus",
            "cmc threat",
            "snort ip",
            "feodo tracker",
            "cybereason",
            "send bug",
            "pe yandex",
            "no data",
            "tag count",
            "count blacklist",
            "tag tag",
            "algorithm",
            "v3 serial",
            "number",
            "issuer",
            "cus cnr3",
            "olet",
            "subject public",
            "key info",
            "key algorithm",
            "key identifier",
            "first",
            "seen",
            "valid",
            "no na",
            "no no",
            "ip security",
            "cndst root",
            "ca x3",
            "ca id",
            "research group",
            "cnisrg root",
            "no expired",
            "mozilla",
            "android",
            "malicious red team",
            "tsara brashears",
            "cyber stalking",
            "malvertizing",
            "invasion of privacy",
            "threat",
            "adult content",
            "apple",
            "iphone unlocker",
            "android",
            "exploited spyware",
            "malware host",
            "brute force",
            "revenge-rat",
            "banker",
            "evasive",
            "domain",
            "redline",
            "stealer",
            "phishing",
            "ramnit",
            "unreliable subdomains",
            "dridex",
            "gating",
            "msil",
            "rat",
            "loki",
            "network",
            "hacking",
            "sinkhole",
            "azorult",
            "c2",
            "historicalandnew",
            "targeted attack",
            "puffstealer",
            "rultazo",
            "lokibot",
            "loki pws",
            "burkina",
            "banker,dde,dridex,exploit",
            "banker,dridex,evasive",
            "trickbot",
            "ransomware,torrentlocker",
            "exploit_source",
            "blacknet",
            "FileRepMalware",
            "linux agent",
            "blacknet",
            "ios",
            "phishing paypal",
            "tagging",
            "defacement",
            "hit",
            "bounty",
            "phishing site",
            "malware site",
            "malware download",
            "endangerment",
            "Malicious domain - SANS Internet Storm Center",
            "evasive,msil,rat,revenge-rat",
            "prism_setting",
            "prism_object",
            "static engine",
            "social engineering",
            "jansky",
            "worm",
            "network rat",
            "networm",
            "Loki Password Stealer (PWS)",
            "South Carolina Federal Credit Union phishing",
            "darkweb",
            "yandex",
            "redirectors",
            "blacknet threats",
            "phishing,ransomware,sinkhole",
            "wanacrypt0r,wannacry,wcry",
            "tor c++",
            "tor c++ client",
            "python user",
            "js user",
            "hacker",
            "hijacker",
            "heur",
            "maltiverse",
            "alexa top",
            "exploit",
            "riskware",
            "unsafe",
            "outbreak",
            "downer",
            "shell",
            "mediamagnet",
            "sality",
            "swrort",
            "adaptivebee",
            "unruy",
            "iobit",
            "dropper",
            "trojanx",
            "artemis",
            "installcore",
            "webshell",
            "crack",
            "webtoolbar",
            "search live",
            "api blog",
            "docs pricing",
            "november",
            "de indicators",
            "domains",
            "hashes",
            "__convergedlogin_pcustomizationloader_44b450e8d543eb53930d",
            "malicious url",
            "financial",
            "blacknet rat",
            "azorult",
            "stealer",
            "deep scan",
            "blacklist https",
            "referrer",
            "collections kp",
            "incident ip",
            "sneaky server",
            "replacement",
            "unauthorized",
            "emotet",
            "noname057",
            "generic malware",
            "engineering",
            "cyber threat",
            "facebook",
            "paypal",
            "dropbox",
            "united",
            "america",
            "banking",
            "wells fargo",
            "steam",
            "twitter",
            "sliver",
            "daum",
            "swift",
            "runescape",
            "betabot",
            "district",
            "iframe",
            "alexa",
            "downldr",
            "agent",
            "presenoker",
            "bladabindi",
            "live",
            "conduit",
            "pony",
            "covid19",
            "malicious",
            "cobalt strike",
            "suppobox",
            "ramnit",
            "meterpreter",
            "virut",
            "njrat",
            "pykspa",
            "asyncrat",
            "downloader",
            "fakealert",
            "binder",
            "virustotal",
            "formbook",
            "necurs",
            "trojan",
            "msil",
            "hiloti",
            "vawtrak",
            "simda",
            "kraken",
            "solimba",
            "icedid",
            "redirector",
            "suspic",
            "amadey",
            "raccoon",
            "nanocore rat",
            "revenge rat",
            "genkryptik",
            "fuery",
            "wacatac",
            "service",
            "cloudeye",
            "tinba",
            "domaiq",
            "ave maria",
            "zeus",
            "ransomware",
            "zbot",
            "generic",
            "trojanspy",
            "states",
            "inmortal",
            "locky",
            "strike",
            "china cobalt",
            "keybase",
            "cutwail",
            "citadel",
            "radamant",
            "kovter",
            "bradesco",
            "nymaim",
            "amonetize",
            "bondat",
            "ghost rat",
            "vjw0rm",
            "bandoo",
            "matsnu",
            "dnspionage",
            "darkgate",
            "vidar",
            "keylogger",
            "remcos",
            "agenttesla",
            "detplock",
            "win64",
            "smokeloader",
            "agent tesla",
            "kgs0",
            "kls0",
            "urls",
            "type name",
            "dns replication",
            "date",
            "domain",
            "win32 exe",
            "files",
            "detections type",
            "name",
            "drpsuinstaller",
            "vdfsurfs",
            "opera",
            "icwrmind",
            "notepad",
            "installer",
            "miner",
            "unknown",
            "networm",
            "houdini",
            "quasar rat",
            "gamehack",
            "dbatloader",
            "qakbot",
            "ursnif",
            "CVE-2005-1790",
            "CVE-2009-3672",
            "CVE-2010-3962",
            "CVE-2012-3993",
            "CVE-2014-6332",
            "CVE-2017-11882",
            "CVE-2020-0601",
            "CVE-2020-0674",
            "hallrender.com",
            "brian sabey",
            "insurance",
            "botnetwork",
            "botmaster",
            "command_and_control",
            "CVE-2021-27065",
            "CVE-2021-40444",
            "CVE-2023-4966",
            "CVE-2017-0199",
            "CVE-2018-4893",
            "CVE-2010-3333",
            "CVE-2015-1641",
            "CVE-2017-0147",
            "CVE-2017-8570",
            "CVE-2018-0802",
            "CVE-2018-8373",
            "CVE-2017-8759",
            "CVE-2018-8453",
            "CVE-2014-3153",
            "CVE-2015-1650",
            "CVE-2017-0143",
            "CVE-2017-8464",
            "Icefog",
            "Delf.NBX",
            "$WebWatson",
            "Gen:Heur.Ransom.HiddenTears",
            "mobilekey.pw",
            "bitbucket.org",
            "Anomalous.100%",
            "malware distribution site",
            "gootkit",
            "edsaid",
            "rightsaided",
            "betabot",
            "cobaltstrike4.tk",
            "mas.to",
            "BehavesLike.YahLover",
            "srdvd16010404",
            "languageenu",
            "buildno",
            "channelisales",
            "vendorname2581",
            "osregion",
            "device",
            "systemlocale",
            "majorver16",
            "quasar",
            "find",
            "lockbit",
            "chaos",
            "ransomexx",
            "grandoreiro",
            "evilnum",
            "banker"
          ],
          "references": [
            "https://hybrid-analysis.com/sample/6765f47ea77c8274c8e4973ed95aedf59e75998c62f6029e23c58cdf36ed85ba/654afdbdc621e7037801cce7",
            "20.99.186.246 exploit source",
            "fp2e7a.wpc.2be4.phicdn.net",
            "https://www.anyxxxtube.net/search-porn/tsara-brashears/ (phishing, ELF, Prism.exe found)",
            "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian (password cracker)",
            "http://182.22.25.124:7878/182.22.25.124:443     (malicious dropper)",
            "init.ess.apple.com         (malicious code script)",
            "https://www.pornhub.com/video/search?search=tsara+brashears (Malicious PW cracker | stylebk.css stylesheets - not found )",
            "https://urlscan.io/result/a328d9ff-fb49-4078-960d-a757fd41404f/#indicators",
            "VirusTotal Link: https://www.virustotal.com/gui/ip-address/20.99.186.246/detection",
            "Abuse IPDB Link: https://www.abuseipdb.com/check/20.99.186.246",
            "IPv4 45.12.253.72.            command_and_control",
            "Hostname: ddos.dnsnb8.net                        command_and_control",
            "IPv4 95.213.186.51              command_and_control",
            "Hostname: www.supernetforme.com      command_and_control",
            "IPv4 103.224.182.246        command_and_control",
            "IPv4 72.251.233.245           command_and_control",
            "IPv4 63.251.106.25             command_and_control",
            "IPv4 45.15.156.208            command_and_control",
            "IPv4 104.247.81.51             command_and_control",
            "http://ambisexual.phone-sex-blogs.com/http:/ambisexual.phone-sex-blogs.com/images/thumbnails/pic118.jpg             (phishing)",
            "https://downloaddevtools.ir/     (phishing)",
            "happylifehappywife.com",
            "apples.encryptedwork.com        (Interesting in the blacknet)",
            "https://itunes.apple.com/app/apple-store/id284815942/us/app/samsung-galaxy-watch-gear-s/id1117310635.                   (iOS unlocker and hijacker)",
            "https://www.anyxxxtube.net/media/favicon/apple              (password cracker and iOS hijacker)",
            "https://www.apple.com/shop/browse/open/country_selector     (exploit)",
            "www.norad.mil   (federal tracking tool used by attorneys, law firms, and private investigators 'licensed or unlicensed') hi!",
            "http://init-p01st.push.apple.com/bag            (malicious web creator)",
            "opencve.djgummikuh.de        (CVE dispensary)",
            "Maltiverse Research Team",
            "URLscan.io",
            "Deep Research",
            "Hybrid Analysis",
            "URLhaus Abuse.ch",
            "Cyber Threat Coalition",
            "ThreatFox Abuse.ch"
          ],
          "public": 1,
          "adversary": "Lucky Mouse APT27 | NoName057(16) |  Unnamed",
          "targeted_countries": [
            "United States of America",
            "France",
            "Spain"
          ],
          "malware_families": [
            {
              "id": "Feodo",
              "display_name": "Feodo",
              "target": null
            },
            {
              "id": "Dridex",
              "display_name": "Dridex",
              "target": null
            },
            {
              "id": "Redline Stealer",
              "display_name": "Redline Stealer",
              "target": null
            },
            {
              "id": "Ramnit.N",
              "display_name": "Ramnit.N",
              "target": null
            },
            {
              "id": "Loki Bot",
              "display_name": "Loki Bot",
              "target": null
            },
            {
              "id": "Loki Password Stealer (PWS)",
              "display_name": "Loki Password Stealer (PWS)",
              "target": null
            },
            {
              "id": "AZORult",
              "display_name": "AZORult",
              "target": null
            },
            {
              "id": "Zbd Zeus",
              "display_name": "Zbd Zeus",
              "target": null
            },
            {
              "id": "Trojan:MSIL/Burkina",
              "display_name": "Trojan:MSIL/Burkina",
              "target": "/malware/Trojan:MSIL/Burkina"
            },
            {
              "id": "Generic.TrickBot.1",
              "display_name": "Generic.TrickBot.1",
              "target": null
            },
            {
              "id": "Exploit.CVE",
              "display_name": "Exploit.CVE",
              "target": null
            },
            {
              "id": "Injector.IS.gen",
              "display_name": "Injector.IS.gen",
              "target": null
            },
            {
              "id": "Gen:Variant.Razy",
              "display_name": "Gen:Variant.Razy",
              "target": null
            },
            {
              "id": "Trojan.Androm.Gen",
              "display_name": "Trojan.Androm.Gen",
              "target": null
            },
            {
              "id": "HEUR:Trojan.Linux.Agent",
              "display_name": "HEUR:Trojan.Linux.Agent",
              "target": null
            },
            {
              "id": "BScope.Trojan",
              "display_name": "BScope.Trojan",
              "target": null
            },
            {
              "id": "VBA.Downloader",
              "display_name": "VBA.Downloader",
              "target": null
            },
            {
              "id": "Trojan.Notifier",
              "display_name": "Trojan.Notifier",
              "target": null
            },
            {
              "id": "HEUR:Trojan.MSOffice.Alien",
              "display_name": "HEUR:Trojan.MSOffice.Alien",
              "target": null
            },
            {
              "id": "Unsafe.AI_Score_100%",
              "display_name": "Unsafe.AI_Score_100%",
              "target": null
            },
            {
              "id": "Gen:Variant.Johnnie",
              "display_name": "Gen:Variant.Johnnie",
              "target": null
            },
            {
              "id": "DangerousObject.Multi",
              "display_name": "DangerousObject.Multi",
              "target": null
            },
            {
              "id": "Trojan:Python/Downldr",
              "display_name": "Trojan:Python/Downldr",
              "target": "/malware/Trojan:Python/Downldr"
            },
            {
              "id": "Trojan:Linux/Downldr",
              "display_name": "Trojan:Linux/Downldr",
              "target": "/malware/Trojan:Linux/Downldr"
            },
            {
              "id": "Trojan:VBA/Downldr",
              "display_name": "Trojan:VBA/Downldr",
              "target": "/malware/Trojan:VBA/Downldr"
            },
            {
              "id": "TrojanDownloader:Linux/Downldr",
              "display_name": "TrojanDownloader:Linux/Downldr",
              "target": "/malware/TrojanDownloader:Linux/Downldr"
            },
            {
              "id": "Kryptik.FPH.gen",
              "display_name": "Kryptik.FPH.gen",
              "target": null
            },
            {
              "id": "TROJ_FRS.VSNTFK19",
              "display_name": "TROJ_FRS.VSNTFK19",
              "target": null
            },
            {
              "id": "Trojan.Ransom.GenericKD",
              "display_name": "Trojan.Ransom.GenericKD",
              "target": null
            },
            {
              "id": "Phish.JAT",
              "display_name": "Phish.JAT",
              "target": null
            },
            {
              "id": "Phishing.HTML",
              "display_name": "Phishing.HTML",
              "target": null
            },
            {
              "id": "Generic.ASMalwS",
              "display_name": "Generic.ASMalwS",
              "target": null
            },
            {
              "id": "Phish.AB",
              "display_name": "Phish.AB",
              "target": null
            },
            {
              "id": "Generic.Malware",
              "display_name": "Generic.Malware",
              "target": null
            },
            {
              "id": "ml.Generic",
              "display_name": "ml.Generic",
              "target": null
            },
            {
              "id": "Xegumumune.8596c22f",
              "display_name": "Xegumumune.8596c22f",
              "target": null
            },
            {
              "id": "Generic.Malware.SMYB",
              "display_name": "Generic.Malware.SMYB",
              "target": null
            },
            {
              "id": "malicious.moderate.ml",
              "display_name": "malicious.moderate.ml",
              "target": null
            },
            {
              "id": "Agent.NBAE",
              "display_name": "Agent.NBAE",
              "target": null
            },
            {
              "id": "AGEN.1045227",
              "display_name": "AGEN.1045227",
              "target": null
            },
            {
              "id": "Riskware.Agent",
              "display_name": "Riskware.Agent",
              "target": null
            },
            {
              "id": "Gen:Variant.Cerbu",
              "display_name": "Gen:Variant.Cerbu",
              "target": null
            },
            {
              "id": "IL:Trojan.MSILZilla",
              "display_name": "IL:Trojan.MSILZilla",
              "target": null
            },
            {
              "id": "Dropped:Generic.Ransom.DMR",
              "display_name": "Dropped:Generic.Ransom.DMR",
              "target": null
            },
            {
              "id": "Delf.NBX",
              "display_name": "Delf.NBX",
              "target": null
            },
            {
              "id": "malicious.f01f67",
              "display_name": "malicious.f01f67",
              "target": null
            },
            {
              "id": "AGEN.1144657",
              "display_name": "AGEN.1144657",
              "target": null
            },
            {
              "id": "Trojan.Heur",
              "display_name": "Trojan.Heur",
              "target": null
            },
            {
              "id": "Trojan.Malware.300983",
              "display_name": "Trojan.Malware.300983",
              "target": null
            },
            {
              "id": "SdBot.CAOC",
              "display_name": "SdBot.CAOC",
              "target": null
            },
            {
              "id": "Trojan.DelShad",
              "display_name": "Trojan.DelShad",
              "target": null
            },
            {
              "id": "Exploit CVE-2017-11882",
              "display_name": "Exploit CVE-2017-11882",
              "target": null
            },
            {
              "id": "GameHack.NL",
              "display_name": "GameHack.NL",
              "target": null
            },
            {
              "id": "JS:Trojan.HideLink",
              "display_name": "JS:Trojan.HideLink",
              "target": null
            },
            {
              "id": "Script.Agent",
              "display_name": "Script.Agent",
              "target": null
            },
            {
              "id": "Macro.Agent",
              "display_name": "Macro.Agent",
              "target": null
            },
            {
              "id": "Macro.Downloader.AMIP",
              "display_name": "Macro.Downloader.AMIP",
              "target": null
            },
            {
              "id": "Trojan.VBA",
              "display_name": "Trojan.VBA",
              "target": null
            },
            {
              "id": "HEUR.VBA.Trojan",
              "display_name": "HEUR.VBA.Trojan",
              "target": null
            },
            {
              "id": "VB.EmoooDldr.10",
              "display_name": "VB.EmoooDldr.10",
              "target": null
            },
            {
              "id": "VB:Trojan.Valyria",
              "display_name": "VB:Trojan.Valyria",
              "target": null
            },
            {
              "id": "OpenSubtitles.A",
              "display_name": "OpenSubtitles.A",
              "target": null
            },
            {
              "id": "VB.EmoDldr.4",
              "display_name": "VB.EmoDldr.4",
              "target": null
            },
            {
              "id": "Packed-GV",
              "display_name": "Packed-GV",
              "target": null
            },
            {
              "id": "Adware.InstallMonetizer",
              "display_name": "Adware.InstallMonetizer",
              "target": null
            },
            {
              "id": "Skynet",
              "display_name": "Skynet",
              "target": null
            },
            {
              "id": "HW32.Packed",
              "display_name": "HW32.Packed",
              "target": null
            },
            {
              "id": "Zpevdo.B",
              "display_name": "Zpevdo.B",
              "target": null
            },
            {
              "id": "Presenoker",
              "display_name": "Presenoker",
              "target": null
            },
            {
              "id": "SGeneric",
              "display_name": "SGeneric",
              "target": null
            },
            {
              "id": "GameHack.DOM",
              "display_name": "GameHack.DOM",
              "target": null
            },
            {
              "id": "BehavesLike.Ransom",
              "display_name": "BehavesLike.Ransom",
              "target": null
            },
            {
              "id": "CIL.StupidCryptor",
              "display_name": "CIL.StupidCryptor",
              "target": null
            },
            {
              "id": "Gen:Heur.Ransom.MSIL",
              "display_name": "Gen:Heur.Ransom.MSIL",
              "target": null
            },
            {
              "id": "Black.Gen2",
              "display_name": "Black.Gen2",
              "target": null
            },
            {
              "id": "GameHack.CRS",
              "display_name": "GameHack.CRS",
              "target": null
            },
            {
              "id": "Trojan.HTML.PHISH",
              "display_name": "Trojan.HTML.PHISH",
              "target": null
            },
            {
              "id": "Gen:Heur.MSIL.Inject",
              "display_name": "Gen:Heur.MSIL.Inject",
              "target": null
            },
            {
              "id": "Program.Unwanted",
              "display_name": "Program.Unwanted",
              "target": null
            },
            {
              "id": "HEUR/QVM42.3.72EB.Malware",
              "display_name": "HEUR/QVM42.3.72EB.Malware",
              "target": null
            },
            {
              "id": "suspicious.low.ml",
              "display_name": "suspicious.low.ml",
              "target": null
            },
            {
              "id": "JS:Trojan.Cryxos",
              "display_name": "JS:Trojan.Cryxos",
              "target": null
            },
            {
              "id": "Suspicious_GEN.F47V0520",
              "display_name": "Suspicious_GEN.F47V0520",
              "target": null
            },
            {
              "id": "Dropper.Trojan.Generic",
              "display_name": "Dropper.Trojan.Generic",
              "target": null
            },
            {
              "id": "Trojan.TrickBot",
              "display_name": "Trojan.TrickBot",
              "target": null
            },
            {
              "id": "Malware.Tk.Generic",
              "display_name": "Malware.Tk.Generic",
              "target": null
            },
            {
              "id": "TrojanSpy.Java",
              "display_name": "TrojanSpy.Java",
              "target": null
            },
            {
              "id": "Riskware.NetFilter",
              "display_name": "Riskware.NetFilter",
              "target": null
            },
            {
              "id": "RiskWare.Crack",
              "display_name": "RiskWare.Crack",
              "target": null
            },
            {
              "id": "BehavesLike.Exploit",
              "display_name": "BehavesLike.Exploit",
              "target": null
            },
            {
              "id": "Gen:NN.ZemsilF.34128",
              "display_name": "Gen:NN.ZemsilF.34128",
              "target": null
            },
            {
              "id": "Wacapew.C",
              "display_name": "Wacapew.C",
              "target": null
            },
            {
              "id": "Trojan.Malware.121218",
              "display_name": "Trojan.Malware.121218",
              "target": null
            },
            {
              "id": "RiskWare.HackTool.Agent",
              "display_name": "RiskWare.HackTool.Agent",
              "target": null
            },
            {
              "id": "Artemis",
              "display_name": "Artemis",
              "target": null
            },
            {
              "id": "Trojan.Generic",
              "display_name": "Trojan.Generic",
              "target": null
            },
            {
              "id": "W32.Trojan",
              "display_name": "W32.Trojan",
              "target": null
            },
            {
              "id": "BScope.Riskware",
              "display_name": "BScope.Riskware",
              "target": null
            },
            {
              "id": "Gen:Variant.Bulz",
              "display_name": "Gen:Variant.Bulz",
              "target": null
            },
            {
              "id": "Ransom:Win32/CVE-2017-0147",
              "display_name": "Ransom:Win32/CVE-2017-0147",
              "target": "/malware/Ransom:Win32/CVE-2017-0147"
            },
            {
              "id": "Virus.Ramnit",
              "display_name": "Virus.Ramnit",
              "target": null
            },
            {
              "id": "Virus.Virut",
              "display_name": "Virus.Virut",
              "target": null
            },
            {
              "id": "Adware.KuziTui",
              "display_name": "Adware.KuziTui",
              "target": null
            },
            {
              "id": "AGEN.1141126",
              "display_name": "AGEN.1141126",
              "target": null
            },
            {
              "id": "W32.AIDetect",
              "display_name": "W32.AIDetect",
              "target": null
            },
            {
              "id": "Trojan.Python",
              "display_name": "Trojan.Python",
              "target": null
            },
            {
              "id": "W32.AIDetectVM",
              "display_name": "W32.AIDetectVM",
              "target": null
            },
            {
              "id": "Suspicious.Save",
              "display_name": "Suspicious.Save",
              "target": null
            },
            {
              "id": "Adware.Downware",
              "display_name": "Adware.Downware",
              "target": null
            },
            {
              "id": "Ransom.Win64.Wacatac.oa",
              "display_name": "Ransom.Win64.Wacatac.oa",
              "target": null
            },
            {
              "id": "OpenSubtitles.A",
              "display_name": "OpenSubtitles.A",
              "target": null
            },
            {
              "id": "VB.EmoDldr.4",
              "display_name": "VB.EmoDldr.4",
              "target": null
            },
            {
              "id": "Gen:Variant.Midie",
              "display_name": "Gen:Variant.Midie",
              "target": null
            },
            {
              "id": "HEUR/QVM41.2.DA9B.Malware",
              "display_name": "HEUR/QVM41.2.DA9B.Malware",
              "target": null
            },
            {
              "id": "Gen:Variant.Sirefef",
              "display_name": "Gen:Variant.Sirefef",
              "target": null
            },
            {
              "id": "Macro.Trojan.Dropperd",
              "display_name": "Macro.Trojan.Dropperd",
              "target": null
            },
            {
              "id": "BlackNET RAT",
              "display_name": "BlackNET RAT",
              "target": null
            },
            {
              "id": "Gen:Variant.Ursu",
              "display_name": "Gen:Variant.Ursu",
              "target": null
            },
            {
              "id": "Redcap.rlhse",
              "display_name": "Redcap.rlhse",
              "target": null
            },
            {
              "id": "Trojan.Trickster",
              "display_name": "Trojan.Trickster",
              "target": null
            },
            {
              "id": "HTML_REDIR.SMR",
              "display_name": "HTML_REDIR.SMR",
              "target": null
            },
            {
              "id": "TROJ_FRS.VSNTFK19",
              "display_name": "TROJ_FRS.VSNTFK19",
              "target": null
            },
            {
              "id": "Hoax.JS.Phish",
              "display_name": "Hoax.JS.Phish",
              "target": null
            },
            {
              "id": "JS:Iframe",
              "display_name": "JS:Iframe",
              "target": null
            },
            {
              "id": "Application.SQLCrack",
              "display_name": "Application.SQLCrack",
              "target": null
            },
            {
              "id": "susp.lnk",
              "display_name": "susp.lnk",
              "target": null
            },
            {
              "id": "QVM201.0.B70B.Malware",
              "display_name": "QVM201.0.B70B.Malware",
              "target": null
            },
            {
              "id": "Immortal Stealer",
              "display_name": "Immortal Stealer",
              "target": null
            },
            {
              "id": "WebMonitor RAT",
              "display_name": "WebMonitor RAT",
              "target": null
            },
            {
              "id": "Tor - S0183",
              "display_name": "Tor - S0183",
              "target": null
            },
            {
              "id": "WannaCry",
              "display_name": "WannaCry",
              "target": null
            },
            {
              "id": "WannaCryptor",
              "display_name": "WannaCryptor",
              "target": null
            },
            {
              "id": "WebToolbar",
              "display_name": "WebToolbar",
              "target": null
            },
            {
              "id": "BlackNET",
              "display_name": "BlackNET",
              "target": null
            },
            {
              "id": "DeepScan:Generic.Ransom.GandCrab5",
              "display_name": "DeepScan:Generic.Ransom.GandCrab5",
              "target": null
            },
            {
              "id": "TrojanSpy",
              "display_name": "TrojanSpy",
              "target": null
            },
            {
              "id": "States",
              "display_name": "States",
              "target": null
            },
            {
              "id": "Inmortal",
              "display_name": "Inmortal",
              "target": null
            },
            {
              "id": "Domains",
              "display_name": "Domains",
              "target": null
            },
            {
              "id": "Locky",
              "display_name": "Locky",
              "target": null
            },
            {
              "id": "Delf.NBX",
              "display_name": "Delf.NBX",
              "target": null
            },
            {
              "id": "Gen:NN.ZexaF.32515",
              "display_name": "Gen:NN.ZexaF.32515",
              "target": null
            },
            {
              "id": "FileRepMalware",
              "display_name": "FileRepMalware",
              "target": null
            },
            {
              "id": "Gen:Variant.MSILPerseus",
              "display_name": "Gen:Variant.MSILPerseus",
              "target": null
            },
            {
              "id": "Icefog",
              "display_name": "Icefog",
              "target": null
            },
            {
              "id": "$WebWatson",
              "display_name": "$WebWatson",
              "target": null
            },
            {
              "id": "Agent.AIK.gen",
              "display_name": "Agent.AIK.gen",
              "target": null
            },
            {
              "id": "Agent.AIK.genCIL.StupidCryptor",
              "display_name": "Agent.AIK.genCIL.StupidCryptor",
              "target": null
            },
            {
              "id": "Agent.YPEZ",
              "display_name": "Agent.YPEZ",
              "target": null
            },
            {
              "id": "Application.InnovativSol",
              "display_name": "Application.InnovativSol",
              "target": null
            },
            {
              "id": "Agent.ASO",
              "display_name": "Agent.ASO",
              "target": null
            },
            {
              "id": "S-b748adc5",
              "display_name": "S-b748adc5",
              "target": null
            },
            {
              "id": "W32.eHeur",
              "display_name": "W32.eHeur",
              "target": null
            },
            {
              "id": "Kryptik.GUCB",
              "display_name": "Kryptik.GUCB",
              "target": null
            },
            {
              "id": "AgentTesla",
              "display_name": "AgentTesla",
              "target": null
            },
            {
              "id": "Autoit.bimwt",
              "display_name": "Autoit.bimwt",
              "target": null
            },
            {
              "id": "HEUR:Trojan.OLE2.Alien",
              "display_name": "HEUR:Trojan.OLE2.Alien",
              "target": null
            },
            {
              "id": "AGEN.1038489",
              "display_name": "AGEN.1038489",
              "target": null
            },
            {
              "id": "Gen:Variant.Ser.Strictor",
              "display_name": "Gen:Variant.Ser.Strictor",
              "target": null
            },
            {
              "id": "Packed.Themida.Gen",
              "display_name": "Packed.Themida.Gen",
              "target": null
            },
            {
              "id": "AGEN.1043164",
              "display_name": "AGEN.1043164",
              "target": null
            },
            {
              "id": "TrickBot - S0266",
              "display_name": "TrickBot - S0266",
              "target": null
            },
            {
              "id": "Emotet",
              "display_name": "Emotet",
              "target": null
            },
            {
              "id": "Trojan.PornoAsset",
              "display_name": "Trojan.PornoAsset",
              "target": null
            },
            {
              "id": "Ransom.Win64.PORNOASSET.SM1",
              "display_name": "Ransom.Win64.PORNOASSET.SM1",
              "target": null
            },
            {
              "id": "Gen:Variant.Ulise",
              "display_name": "Gen:Variant.Ulise",
              "target": null
            },
            {
              "id": "Trojan.Win64",
              "display_name": "Trojan.Win64",
              "target": null
            },
            {
              "id": "Dropper.Trojan.Agent",
              "display_name": "Dropper.Trojan.Agent",
              "target": null
            },
            {
              "id": "Heur.BZC.YAX.Pantera.10",
              "display_name": "Heur.BZC.YAX.Pantera.10",
              "target": null
            },
            {
              "id": "malicious.high.ml",
              "display_name": "malicious.high.ml",
              "target": null
            },
            {
              "id": "CVE-2015-1650",
              "display_name": "CVE-2015-1650",
              "target": null
            },
            {
              "id": "Worm.Win64.AutoRun",
              "display_name": "Worm.Win64.AutoRun",
              "target": null
            },
            {
              "id": "AIT.Heur.Cottonmouth.8.78F19BD7",
              "display_name": "AIT.Heur.Cottonmouth.8.78F19BD7",
              "target": null
            },
            {
              "id": "Gen:Variant.Mikey",
              "display_name": "Gen:Variant.Mikey",
              "target": null
            },
            {
              "id": "Trojan.Agent",
              "display_name": "Trojan.Agent",
              "target": null
            },
            {
              "id": "Pua.Gen",
              "display_name": "Pua.Gen",
              "target": null
            },
            {
              "id": "Trojan.Downloader.Generic",
              "display_name": "Trojan.Downloader.Generic",
              "target": null
            },
            {
              "id": "Suspected of Trojan.Downloader.gen",
              "display_name": "Suspected of Trojan.Downloader.gen",
              "target": null
            },
            {
              "id": "HEUR:RemoteAdmin.Generic",
              "display_name": "HEUR:RemoteAdmin.Generic",
              "target": null
            },
            {
              "id": "Gen:Heur.Ransom.HiddenTears",
              "display_name": "Gen:Heur.Ransom.HiddenTears",
              "target": null
            },
            {
              "id": "Nemucod.A",
              "display_name": "Nemucod.A",
              "target": null
            },
            {
              "id": "Backdoor.Hupigon",
              "display_name": "Backdoor.Hupigon",
              "target": null
            },
            {
              "id": "Trojan.Starter JS.Iframe",
              "display_name": "Trojan.Starter JS.Iframe",
              "target": null
            },
            {
              "id": "fake ,promethiumm ,strongpity",
              "display_name": "fake ,promethiumm ,strongpity",
              "target": null
            },
            {
              "id": "PUA.Reg1staid",
              "display_name": "PUA.Reg1staid",
              "target": null
            },
            {
              "id": "Malware.Heur_Generic.A",
              "display_name": "Malware.Heur_Generic.A",
              "target": null
            },
            {
              "id": "Bladabindi.Q",
              "display_name": "Bladabindi.Q",
              "target": null
            },
            {
              "id": "W32.eHeur",
              "display_name": "W32.eHeur",
              "target": null
            },
            {
              "id": "malicious.6e0700",
              "display_name": "malicious.6e0700",
              "target": null
            },
            {
              "id": "Trojan.Inject",
              "display_name": "Trojan.Inject",
              "target": null
            },
            {
              "id": "TSGeneric",
              "display_name": "TSGeneric",
              "target": null
            },
            {
              "id": "RedCap.vneda",
              "display_name": "RedCap.vneda",
              "target": null
            },
            {
              "id": "Trojan.Indiloadz",
              "display_name": "Trojan.Indiloadz",
              "target": null
            },
            {
              "id": "Trojan.Ekstak",
              "display_name": "Trojan.Ekstak",
              "target": null
            },
            {
              "id": "staticrr.paleokits.net",
              "display_name": "staticrr.paleokits.net",
              "target": null
            },
            {
              "id": "MSIL.Downloader",
              "display_name": "MSIL.Downloader",
              "target": null
            },
            {
              "id": "Trojan.Autoruns.GenericKDS",
              "display_name": "Trojan.Autoruns.GenericKDS",
              "target": null
            },
            {
              "id": "MSIL.Trojan.BSE",
              "display_name": "MSIL.Trojan.BSE",
              "target": null
            },
            {
              "id": "Adload.AD81",
              "display_name": "Adload.AD81",
              "target": null
            },
            {
              "id": "Packed.Asprotect",
              "display_name": "Packed.Asprotect",
              "target": null
            },
            {
              "id": "Gen:NN.ZemsilF.34062",
              "display_name": "Gen:NN.ZemsilF.34062",
              "target": null
            },
            {
              "id": "Evo",
              "display_name": "Evo",
              "target": null
            },
            {
              "id": "Agent.pwc",
              "display_name": "Agent.pwc",
              "target": null
            },
            {
              "id": "RiskTool.Phpw",
              "display_name": "RiskTool.Phpw",
              "target": null
            },
            {
              "id": "Gen:Variant.Symmi",
              "display_name": "Gen:Variant.Symmi",
              "target": null
            },
            {
              "id": "Trojan.PWS",
              "display_name": "Trojan.PWS",
              "target": null
            },
            {
              "id": "Generic.BitCoinMiner.3",
              "display_name": "Generic.BitCoinMiner.3",
              "target": null
            },
            {
              "id": "Trojan.Tasker",
              "display_name": "Trojan.Tasker",
              "target": null
            },
            {
              "id": "Gen:NN",
              "display_name": "Gen:NN",
              "target": null
            },
            {
              "id": "Downloader.CertutilURLCache",
              "display_name": "Downloader.CertutilURLCache",
              "target": null
            },
            {
              "id": "Elf",
              "display_name": "Elf",
              "target": null
            },
            {
              "id": "Gen:Heur.MSIL.Androm",
              "display_name": "Gen:Heur.MSIL.Androm",
              "target": null
            },
            {
              "id": "Kryptik.NRD",
              "display_name": "Kryptik.NRD",
              "target": null
            },
            {
              "id": "Riskware",
              "display_name": "Riskware",
              "target": null
            },
            {
              "id": "Kuluoz.B.gen",
              "display_name": "Kuluoz.B.gen",
              "target": null
            },
            {
              "id": "Gen:Variant.RevengeRat",
              "display_name": "Gen:Variant.RevengeRat",
              "target": null
            },
            {
              "id": "Gen:Variant.Mikey",
              "display_name": "Gen:Variant.Mikey",
              "target": null
            },
            {
              "id": "VB.Chronos.7",
              "display_name": "VB.Chronos.7",
              "target": null
            },
            {
              "id": "Kryptik.NOE",
              "display_name": "Kryptik.NOE",
              "target": null
            },
            {
              "id": "HEUR:WebToolbar.Generic",
              "display_name": "HEUR:WebToolbar.Generic",
              "target": null
            },
            {
              "id": "Gen:Variant.Barys",
              "display_name": "Gen:Variant.Barys",
              "target": null
            },
            {
              "id": "Backdoor.Xtreme",
              "display_name": "Backdoor.Xtreme",
              "target": null
            },
            {
              "id": "Trojan.MSIL",
              "display_name": "Trojan.MSIL",
              "target": null
            },
            {
              "id": "Gen:Variant.Graftor",
              "display_name": "Gen:Variant.Graftor",
              "target": null
            },
            {
              "id": "Backdoor.Agent",
              "display_name": "Backdoor.Agent",
              "target": null
            },
            {
              "id": "Unsafe",
              "display_name": "Unsafe",
              "target": null
            },
            {
              "id": "Trojan.PHP.Agent",
              "display_name": "Trojan.PHP.Agent",
              "target": null
            },
            {
              "id": "Trojan.Agent",
              "display_name": "Trojan.Agent",
              "target": null
            },
            {
              "id": "HEUR:Exploit.Generic",
              "display_name": "HEUR:Exploit.Generic",
              "target": null
            },
            {
              "id": "Ransom_WCRY.SMALYM",
              "display_name": "Ransom_WCRY.SMALYM",
              "target": null
            },
            {
              "id": "Ransom_WCRY.SMJ",
              "display_name": "Ransom_WCRY.SMJ",
              "target": null
            },
            {
              "id": "Auslogics",
              "display_name": "Auslogics",
              "target": null
            },
            {
              "id": "Gen:Variant.Jaiko",
              "display_name": "Gen:Variant.Jaiko",
              "target": null
            },
            {
              "id": "Exploit.W32.Agent",
              "display_name": "Exploit.W32.Agent",
              "target": null
            },
            {
              "id": "Trojan.Cud.Gen",
              "display_name": "Trojan.Cud.Gen",
              "target": null
            },
            {
              "id": "Trojan.DOC.Downloader",
              "display_name": "Trojan.DOC.Downloader",
              "target": null
            },
            {
              "id": "Backdoor.MSIL.Agent",
              "display_name": "Backdoor.MSIL.Agent",
              "target": null
            },
            {
              "id": "Gen:Trojan.Heur2.LPTbHW@W64.HfsAutoB",
              "display_name": "Gen:Trojan.Heur2.LPTbHW@W64.HfsAutoB",
              "target": null
            },
            {
              "id": "Gen:Variant.Kazy",
              "display_name": "Gen:Variant.Kazy",
              "target": null
            },
            {
              "id": "Gen:Variant.Zusy",
              "display_name": "Gen:Variant.Zusy",
              "target": null
            },
            {
              "id": "Ransom.WannaCrypt",
              "display_name": "Ransom.WannaCrypt",
              "target": null
            },
            {
              "id": "Generic.ServStart.A",
              "display_name": "Generic.ServStart.A",
              "target": null
            },
            {
              "id": "Trojan.Wanna",
              "display_name": "Trojan.Wanna",
              "target": null
            },
            {
              "id": "Generic.MSIL.Bladabindi",
              "display_name": "Generic.MSIL.Bladabindi",
              "target": null
            },
            {
              "id": "TROJ_GEN.R002C0OG518",
              "display_name": "TROJ_GEN.R002C0OG518",
              "target": null
            },
            {
              "id": "Trojan.Chapak",
              "display_name": "Trojan.Chapak",
              "target": null
            },
            {
              "id": "Indiloadz.BB",
              "display_name": "Indiloadz.BB",
              "target": null
            },
            {
              "id": "BehavBehavesLike.PUPXBI",
              "display_name": "BehavBehavesLike.PUPXBI",
              "target": null
            },
            {
              "id": "DeepScan:Generic.SpyAgent.6",
              "display_name": "DeepScan:Generic.SpyAgent.6",
              "target": null
            },
            {
              "id": "Python.KeyLogger",
              "display_name": "Python.KeyLogger",
              "target": null
            },
            {
              "id": "GameHack.CRS",
              "display_name": "GameHack.CRS",
              "target": null
            },
            {
              "id": "Generic.MSIL.PasswordStealer",
              "display_name": "Generic.MSIL.PasswordStealer",
              "target": null
            },
            {
              "id": "PSW.Agent",
              "display_name": "PSW.Agent",
              "target": null
            },
            {
              "id": "malicious.8c45ba",
              "display_name": "malicious.8c45ba",
              "target": null
            },
            {
              "id": "Dropper.Binder",
              "display_name": "Dropper.Binder",
              "target": null
            },
            {
              "id": "Constructor.MSIL",
              "display_name": "Constructor.MSIL",
              "target": null
            },
            {
              "id": "Linux.Agent",
              "display_name": "Linux.Agent",
              "target": null
            },
            {
              "id": "Virus.3DMax.Script",
              "display_name": "Virus.3DMax.Script",
              "target": null
            },
            {
              "id": "ScrInject.B",
              "display_name": "ScrInject.B",
              "target": null
            },
            {
              "id": "Trojan.WisdomEyes.16070401.9500",
              "display_name": "Trojan.WisdomEyes.16070401.9500",
              "target": null
            },
            {
              "id": "Application.SearchProtect",
              "display_name": "Application.SearchProtect",
              "target": null
            },
            {
              "id": "JS:Trojan.Clicker",
              "display_name": "JS:Trojan.Clicker",
              "target": null
            },
            {
              "id": "Faceliker.A",
              "display_name": "Faceliker.A",
              "target": null
            },
            {
              "id": "JS:Trojan.JS.Faceliker",
              "display_name": "JS:Trojan.JS.Faceliker",
              "target": null
            },
            {
              "id": "Constructor.MSIL  Linux.Agent",
              "display_name": "Constructor.MSIL  Linux.Agent",
              "target": null
            },
            {
              "id": "PowerShell.Trojan",
              "display_name": "PowerShell.Trojan",
              "target": null
            },
            {
              "id": "HTML:Script",
              "display_name": "HTML:Script",
              "target": null
            },
            {
              "id": "ScrInject.B",
              "display_name": "ScrInject.B",
              "target": null
            },
            {
              "id": "W32.AIDetectVM",
              "display_name": "W32.AIDetectVM",
              "target": null
            },
            {
              "id": "HackTool.CheatEngine",
              "display_name": "HackTool.CheatEngine",
              "target": null
            },
            {
              "id": "Injector.CLDS",
              "display_name": "Injector.CLDS",
              "target": null
            },
            {
              "id": "VB.Downloader.2",
              "display_name": "VB.Downloader.2",
              "target": null
            },
            {
              "id": "malicious.3e78cc",
              "display_name": "malicious.3e78cc",
              "target": null
            },
            {
              "id": "malicious.d800d6",
              "display_name": "malicious.d800d6",
              "target": null
            },
            {
              "id": "VB.PwShell.2",
              "display_name": "VB.PwShell.2",
              "target": null
            },
            {
              "id": "Backdoor.RBot",
              "display_name": "Backdoor.RBot",
              "target": null
            },
            {
              "id": "malicious.71b1a8",
              "display_name": "malicious.71b1a8",
              "target": null
            },
            {
              "id": "TrojanSpy.KeyLogger",
              "display_name": "TrojanSpy.KeyLogger",
              "target": null
            },
            {
              "id": "Injector.JDO",
              "display_name": "Injector.JDO",
              "target": null
            },
            {
              "id": "Heur.Msword.Gen",
              "display_name": "Heur.Msword.Gen",
              "target": null
            },
            {
              "id": "PSW.Discord",
              "display_name": "PSW.Discord",
              "target": null
            },
            {
              "id": "Packed.VMProtect",
              "display_name": "Packed.VMProtect",
              "target": null
            },
            {
              "id": "HEUR:AdWare.StartSurf",
              "display_name": "HEUR:AdWare.StartSurf",
              "target": null
            },
            {
              "id": "Gen:Heur.NoobyProtect",
              "display_name": "Gen:Heur.NoobyProtect",
              "target": null
            },
            {
              "id": "CIL.HeapOverride",
              "display_name": "CIL.HeapOverride",
              "target": null
            },
            {
              "id": "HEUR:Trojan.Tasker",
              "display_name": "HEUR:Trojan.Tasker",
              "target": null
            },
            {
              "id": "XLM.Trojan.Abracadabra.27",
              "display_name": "XLM.Trojan.Abracadabra.27",
              "target": null
            },
            {
              "id": "HEUR:Backdoor.MSIL.NanoBot",
              "display_name": "HEUR:Backdoor.MSIL.NanoBot",
              "target": null
            },
            {
              "id": "Trojan.PSW.Mimikatz",
              "display_name": "Trojan.PSW.Mimikatz",
              "target": null
            },
            {
              "id": "TrojanSpy.Python",
              "display_name": "TrojanSpy.Python",
              "target": null
            },
            {
              "id": "Trojan.Ole2.Vbs",
              "display_name": "Trojan.Ole2.Vbs",
              "target": null
            },
            {
              "id": "Exploit.MSOffice",
              "display_name": "Exploit.MSOffice",
              "target": null
            },
            {
              "id": "DeepScan:Generic.Ransom.AmnesiaE",
              "display_name": "DeepScan:Generic.Ransom.AmnesiaE",
              "target": null
            },
            {
              "id": "Wacatac.D6",
              "display_name": "Wacatac.D6",
              "target": null
            },
            {
              "id": "Backdoor.Androm",
              "display_name": "Backdoor.Androm",
              "target": null
            },
            {
              "id": "Packed.NetSeal",
              "display_name": "Packed.NetSeal",
              "target": null
            },
            {
              "id": "Trojan.MSIL.Injector",
              "display_name": "Trojan.MSIL.Injector",
              "target": null
            },
            {
              "id": "Trojan.PWS.Agent",
              "display_name": "Trojan.PWS.Agent",
              "target": null
            },
            {
              "id": "TScope.Trojan",
              "display_name": "TScope.Trojan",
              "target": null
            },
            {
              "id": "PSW.Stealer",
              "display_name": "PSW.Stealer",
              "target": null
            },
            {
              "id": "Trojan.PackedNET",
              "display_name": "Trojan.PackedNET",
              "target": null
            },
            {
              "id": "Trojan.Java",
              "display_name": "Trojan.Java",
              "target": null
            },
            {
              "id": "MalwareX",
              "display_name": "MalwareX",
              "target": null
            },
            {
              "id": "Trojan.PSW.Python",
              "display_name": "Trojan.PSW.Python",
              "target": null
            },
            {
              "id": "malicious.11abfc",
              "display_name": "malicious.11abfc",
              "target": null
            },
            {
              "id": "Generic.ASMalwS",
              "display_name": "Generic.ASMalwS",
              "target": null
            },
            {
              "id": "HEUR:Trojan.MSIL.Tasker",
              "display_name": "HEUR:Trojan.MSIL.Tasker",
              "target": null
            },
            {
              "id": "PossibleThreat.PALLAS",
              "display_name": "PossibleThreat.PALLAS",
              "target": null
            },
            {
              "id": "Backdoor.Poison",
              "display_name": "Backdoor.Poison",
              "target": null
            },
            {
              "id": "Generic.MSIL.LimeRAT",
              "display_name": "Generic.MSIL.LimeRAT",
              "target": null
            },
            {
              "id": "PWS-FCZZ",
              "display_name": "PWS-FCZZ",
              "target": null
            },
            {
              "id": "Trojan.Script",
              "display_name": "Trojan.Script",
              "target": null
            },
            {
              "id": "Gen:Heur.MSIL.Inject",
              "display_name": "Gen:Heur.MSIL.Inject",
              "target": null
            },
            {
              "id": "Trojan.PWS.Growtopia",
              "display_name": "Trojan.PWS.Growtopia",
              "target": null
            },
            {
              "id": "Spyware.Bobik",
              "display_name": "Spyware.Bobik",
              "target": null
            },
            {
              "id": "HackTool.BruteForce",
              "display_name": "HackTool.BruteForce",
              "target": null
            },
            {
              "id": "Hack.Patcher",
              "display_name": "Hack.Patcher",
              "target": null
            },
            {
              "id": "PWS.p",
              "display_name": "PWS.p",
              "target": null
            },
            {
              "id": "Suppobox",
              "display_name": "Suppobox",
              "target": null
            },
            {
              "id": "index.php",
              "display_name": "index.php",
              "target": null
            },
            {
              "id": "Packed.VMProtect",
              "display_name": "Packed.VMProtect",
              "target": null
            },
            {
              "id": "SmokeLoader",
              "display_name": "SmokeLoader",
              "target": null
            },
            {
              "id": "Generic.Malware",
              "display_name": "Generic.Malware",
              "target": null
            },
            {
              "id": "SNH:Script [Dropper]",
              "display_name": "SNH:Script [Dropper]",
              "target": null
            },
            {
              "id": "HEUR:Trojan.MSOffice.SAgent",
              "display_name": "HEUR:Trojan.MSOffice.SAgent",
              "target": null
            },
            {
              "id": "Script.INF",
              "display_name": "Script.INF",
              "target": null
            },
            {
              "id": "JS:Trojan.JS.Likejack",
              "display_name": "JS:Trojan.JS.Likejack",
              "target": null
            },
            {
              "id": "SNH:Script [Dropper]",
              "display_name": "SNH:Script [Dropper]",
              "target": null
            },
            {
              "id": "Trojan.JS.Agent",
              "display_name": "Trojan.JS.Agent",
              "target": null
            },
            {
              "id": "APT Notes",
              "display_name": "APT Notes",
              "target": null
            },
            {
              "id": "susp.rtf.objupdate",
              "display_name": "susp.rtf.objupdate",
              "target": null
            },
            {
              "id": "RedCap.zoohz",
              "display_name": "RedCap.zoohz",
              "target": null
            },
            {
              "id": "Trojan.Tasker",
              "display_name": "Trojan.Tasker",
              "target": null
            },
            {
              "id": "virus.office.qexvmc",
              "display_name": "virus.office.qexvmc",
              "target": null
            },
            {
              "id": "Trojan.KillProc",
              "display_name": "Trojan.KillProc",
              "target": null
            },
            {
              "id": "Generic.MSIL.GrwtpStealer.1",
              "display_name": "Generic.MSIL.GrwtpStealer.1",
              "target": null
            },
            {
              "id": "Suspicious.Cloud",
              "display_name": "Suspicious.Cloud",
              "target": null
            },
            {
              "id": "PowerShell.DownLoader",
              "display_name": "PowerShell.DownLoader",
              "target": null
            },
            {
              "id": "Downldr.gen",
              "display_name": "Downldr.gen",
              "target": null
            },
            {
              "id": "AGEN.1030939",
              "display_name": "AGEN.1030939",
              "target": null
            },
            {
              "id": "HackTool.Binder",
              "display_name": "HackTool.Binder",
              "target": null
            },
            {
              "id": "Trojan.Inject",
              "display_name": "Trojan.Inject",
              "target": null
            },
            {
              "id": "Dldr.Agent",
              "display_name": "Dldr.Agent",
              "target": null
            },
            {
              "id": "Dropper.MSIL",
              "display_name": "Dropper.MSIL",
              "target": null
            },
            {
              "id": "Trojan.VBKryjetor",
              "display_name": "Trojan.VBKryjetor",
              "target": null
            },
            {
              "id": "PWSX",
              "display_name": "PWSX",
              "target": null
            },
            {
              "id": "VB:Trojan.VBA.Agent",
              "display_name": "VB:Trojan.VBA.Agent",
              "target": null
            },
            {
              "id": "HEUR:Trojan.MSOffice.Stratos",
              "display_name": "HEUR:Trojan.MSOffice.Stratos",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1071.004",
              "name": "DNS",
              "display_name": "T1071.004 - DNS"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1059.007",
              "name": "JavaScript",
              "display_name": "T1059.007 - JavaScript"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1068",
              "name": "Exploitation for Privilege Escalation",
              "display_name": "T1068 - Exploitation for Privilege Escalation"
            },
            {
              "id": "TA0029",
              "name": "Privilege Escalation",
              "display_name": "TA0029 - Privilege Escalation"
            },
            {
              "id": "T1449",
              "name": "Exploit SS7 to Redirect Phone Calls/SMS",
              "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
            },
            {
              "id": "T1190",
              "name": "Exploit Public-Facing Application",
              "display_name": "T1190 - Exploit Public-Facing Application"
            },
            {
              "id": "T1210",
              "name": "Exploitation of Remote Services",
              "display_name": "T1210 - Exploitation of Remote Services"
            },
            {
              "id": "T1450",
              "name": "Exploit SS7 to Track Device Location",
              "display_name": "T1450 - Exploit SS7 to Track Device Location"
            },
            {
              "id": "T1211",
              "name": "Exploitation for Defense Evasion",
              "display_name": "T1211 - Exploitation for Defense Evasion"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "TA0011",
              "name": "Command and Control",
              "display_name": "TA0011 - Command and Control"
            },
            {
              "id": "T1412",
              "name": "Capture SMS Messages",
              "display_name": "T1412 - Capture SMS Messages"
            },
            {
              "id": "T1454",
              "name": "Malicious SMS Message",
              "display_name": "T1454 - Malicious SMS Message"
            },
            {
              "id": "T1001",
              "name": "Data Obfuscation",
              "display_name": "T1001 - Data Obfuscation"
            },
            {
              "id": "T1114",
              "name": "Email Collection",
              "display_name": "T1114 - Email Collection"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1498",
              "name": "Network Denial of Service",
              "display_name": "T1498 - Network Denial of Service"
            },
            {
              "id": "T1496",
              "name": "Resource Hijacking",
              "display_name": "T1496 - Resource Hijacking"
            },
            {
              "id": "T1176",
              "name": "Browser Extensions",
              "display_name": "T1176 - Browser Extensions"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 339,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 1184,
            "FileHash-SHA1": 949,
            "FileHash-SHA256": 3712,
            "URL": 2925,
            "domain": 627,
            "hostname": 1319,
            "CVE": 26,
            "email": 8,
            "CIDR": 2
          },
          "indicator_count": 10752,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 222,
          "modified_text": "904 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "654c597a4a45c8d84f0b15c1",
          "name": "Lucky Mouse APT27 | Feodo Tracker | Malicious Tor Server | Apple iOS",
          "description": "Darkside 2020 Ecosystem .BEware\nMalicious Tor server. Link found in pulse created prior. \nMalvertizing target: Tsara Brashears\nRevenge Porn.\nThere may me others. Malicious Apple activities, locating, CVE exploits, unlocking, hijacker, service transfer, spyware, malicious full auth, tracking, endless. Seems to originate from a law firm that goes to far to defend clients and silence alleged victims. \nSome State allow  the same  privileges  and tools the federal government to insurance, workers compensation, investigators and insurance company law firms for investigations. \nFear tactics they seem willing to back up. I was approached and asked about my cyber knowledge by strangers. I am followed now for using a tool properly.\nALL terms auto populated from various tools from various tools used including, State, Brian Sabey, cyber stalking. Perhaps he's made contact with target. Danger!",
          "modified": "2023-12-09T03:01:57.989000",
          "created": "2023-11-09T04:00:58.166000",
          "tags": [
            "ssl certificate",
            "historical ssl",
            "communicating",
            "contacted",
            "resolutions",
            "whois record",
            "whois whois",
            "whois parent",
            "whois siblings",
            "skynet",
            "threat report",
            "ip summary",
            "url summary",
            "summary",
            "sample",
            "samples",
            "detection list",
            "blacklist",
            "cisco umbrella",
            "site",
            "safe site",
            "million",
            "team",
            "microsoft",
            "back",
            "download",
            "phishing",
            "union",
            "bank",
            "malicious site",
            "blacklist http",
            "exit",
            "traffic",
            "node tcp",
            "tor known",
            "tor relayrouter",
            "et tor",
            "known tor",
            "relayrouter",
            "anonymizer",
            "spammer",
            "malware",
            "dropped",
            "unlocker",
            "http",
            "critical risk",
            "redline stealer",
            "core",
            "hacktool",
            "execution",
            "type win32",
            "exe size",
            "first seen",
            "file name",
            "avast win32",
            "win32",
            "avg win32",
            "fortinet",
            "vitro",
            "mb first",
            "rmndrp",
            "clean mx",
            "undetected dns8",
            "undetected vx",
            "sophos",
            "vault",
            "zdb zeus",
            "cmc threat",
            "snort ip",
            "feodo tracker",
            "cybereason",
            "send bug",
            "pe yandex",
            "no data",
            "tag count",
            "count blacklist",
            "tag tag",
            "algorithm",
            "v3 serial",
            "number",
            "issuer",
            "cus cnr3",
            "olet",
            "subject public",
            "key info",
            "key algorithm",
            "key identifier",
            "first",
            "seen",
            "valid",
            "no na",
            "no no",
            "ip security",
            "cndst root",
            "ca x3",
            "ca id",
            "research group",
            "cnisrg root",
            "no expired",
            "mozilla",
            "android",
            "malicious red team",
            "tsara brashears",
            "cyber stalking",
            "malvertizing",
            "invasion of privacy",
            "threat",
            "adult content",
            "apple",
            "iphone unlocker",
            "android",
            "exploited spyware",
            "malware host",
            "brute force",
            "revenge-rat",
            "banker",
            "evasive",
            "domain",
            "redline",
            "stealer",
            "phishing",
            "ramnit",
            "unreliable subdomains",
            "dridex",
            "gating",
            "msil",
            "rat",
            "loki",
            "network",
            "hacking",
            "sinkhole",
            "azorult",
            "c2",
            "historicalandnew",
            "targeted attack",
            "puffstealer",
            "rultazo",
            "lokibot",
            "loki pws",
            "burkina",
            "banker,dde,dridex,exploit",
            "banker,dridex,evasive",
            "trickbot",
            "ransomware,torrentlocker",
            "exploit_source",
            "blacknet",
            "FileRepMalware",
            "linux agent",
            "blacknet",
            "ios",
            "phishing paypal",
            "tagging",
            "defacement",
            "hit",
            "bounty",
            "phishing site",
            "malware site",
            "malware download",
            "endangerment",
            "Malicious domain - SANS Internet Storm Center",
            "evasive,msil,rat,revenge-rat",
            "prism_setting",
            "prism_object",
            "static engine",
            "social engineering",
            "jansky",
            "worm",
            "network rat",
            "networm",
            "Loki Password Stealer (PWS)",
            "South Carolina Federal Credit Union phishing",
            "darkweb",
            "yandex",
            "redirectors",
            "blacknet threats",
            "phishing,ransomware,sinkhole",
            "wanacrypt0r,wannacry,wcry",
            "tor c++",
            "tor c++ client",
            "python user",
            "js user",
            "hacker",
            "hijacker",
            "heur",
            "maltiverse",
            "alexa top",
            "exploit",
            "riskware",
            "unsafe",
            "outbreak",
            "downer",
            "shell",
            "mediamagnet",
            "sality",
            "swrort",
            "adaptivebee",
            "unruy",
            "iobit",
            "dropper",
            "trojanx",
            "artemis",
            "installcore",
            "webshell",
            "crack",
            "webtoolbar",
            "search live",
            "api blog",
            "docs pricing",
            "november",
            "de indicators",
            "domains",
            "hashes",
            "__convergedlogin_pcustomizationloader_44b450e8d543eb53930d",
            "malicious url",
            "financial",
            "blacknet rat",
            "azorult",
            "stealer",
            "deep scan",
            "blacklist https",
            "referrer",
            "collections kp",
            "incident ip",
            "sneaky server",
            "replacement",
            "unauthorized",
            "emotet",
            "noname057",
            "generic malware",
            "engineering",
            "cyber threat",
            "facebook",
            "paypal",
            "dropbox",
            "united",
            "america",
            "banking",
            "wells fargo",
            "steam",
            "twitter",
            "sliver",
            "daum",
            "swift",
            "runescape",
            "betabot",
            "district",
            "iframe",
            "alexa",
            "downldr",
            "agent",
            "presenoker",
            "bladabindi",
            "live",
            "conduit",
            "pony",
            "covid19",
            "malicious",
            "cobalt strike",
            "suppobox",
            "ramnit",
            "meterpreter",
            "virut",
            "njrat",
            "pykspa",
            "asyncrat",
            "downloader",
            "fakealert",
            "binder",
            "virustotal",
            "formbook",
            "necurs",
            "trojan",
            "msil",
            "hiloti",
            "vawtrak",
            "simda",
            "kraken",
            "solimba",
            "icedid",
            "redirector",
            "suspic",
            "amadey",
            "raccoon",
            "nanocore rat",
            "revenge rat",
            "genkryptik",
            "fuery",
            "wacatac",
            "service",
            "cloudeye",
            "tinba",
            "domaiq",
            "ave maria",
            "zeus",
            "ransomware",
            "zbot",
            "generic",
            "trojanspy",
            "states",
            "inmortal",
            "locky",
            "strike",
            "china cobalt",
            "keybase",
            "cutwail",
            "citadel",
            "radamant",
            "kovter",
            "bradesco",
            "nymaim",
            "amonetize",
            "bondat",
            "ghost rat",
            "vjw0rm",
            "bandoo",
            "matsnu",
            "dnspionage",
            "darkgate",
            "vidar",
            "keylogger",
            "remcos",
            "agenttesla",
            "detplock",
            "win64",
            "smokeloader",
            "agent tesla",
            "kgs0",
            "kls0",
            "urls",
            "type name",
            "dns replication",
            "date",
            "domain",
            "win32 exe",
            "files",
            "detections type",
            "name",
            "drpsuinstaller",
            "vdfsurfs",
            "opera",
            "icwrmind",
            "notepad",
            "installer",
            "miner",
            "unknown",
            "networm",
            "houdini",
            "quasar rat",
            "gamehack",
            "dbatloader",
            "qakbot",
            "ursnif",
            "CVE-2005-1790",
            "CVE-2009-3672",
            "CVE-2010-3962",
            "CVE-2012-3993",
            "CVE-2014-6332",
            "CVE-2017-11882",
            "CVE-2020-0601",
            "CVE-2020-0674",
            "hallrender.com",
            "brian sabey",
            "insurance",
            "botnetwork",
            "botmaster",
            "command_and_control",
            "CVE-2021-27065",
            "CVE-2021-40444",
            "CVE-2023-4966",
            "CVE-2017-0199",
            "CVE-2018-4893",
            "CVE-2010-3333",
            "CVE-2015-1641",
            "CVE-2017-0147",
            "CVE-2017-8570",
            "CVE-2018-0802",
            "CVE-2018-8373",
            "CVE-2017-8759",
            "CVE-2018-8453",
            "CVE-2014-3153",
            "CVE-2015-1650",
            "CVE-2017-0143",
            "CVE-2017-8464",
            "Icefog",
            "Delf.NBX",
            "$WebWatson",
            "Gen:Heur.Ransom.HiddenTears",
            "mobilekey.pw",
            "bitbucket.org",
            "Anomalous.100%",
            "malware distribution site",
            "gootkit",
            "edsaid",
            "rightsaided",
            "betabot",
            "cobaltstrike4.tk",
            "mas.to",
            "BehavesLike.YahLover",
            "srdvd16010404",
            "languageenu",
            "buildno",
            "channelisales",
            "vendorname2581",
            "osregion",
            "device",
            "systemlocale",
            "majorver16",
            "quasar",
            "find",
            "lockbit",
            "chaos",
            "ransomexx",
            "grandoreiro",
            "evilnum",
            "banker"
          ],
          "references": [
            "https://hybrid-analysis.com/sample/6765f47ea77c8274c8e4973ed95aedf59e75998c62f6029e23c58cdf36ed85ba/654afdbdc621e7037801cce7",
            "20.99.186.246 exploit source",
            "fp2e7a.wpc.2be4.phicdn.net",
            "https://www.anyxxxtube.net/search-porn/tsara-brashears/ (phishing, ELF, Prism.exe found)",
            "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian (password cracker)",
            "http://182.22.25.124:7878/182.22.25.124:443     (malicious dropper)",
            "init.ess.apple.com         (malicious code script)",
            "https://www.pornhub.com/video/search?search=tsara+brashears (Malicious PW cracker | stylebk.css stylesheets - not found )",
            "https://urlscan.io/result/a328d9ff-fb49-4078-960d-a757fd41404f/#indicators",
            "VirusTotal Link: https://www.virustotal.com/gui/ip-address/20.99.186.246/detection",
            "Abuse IPDB Link: https://www.abuseipdb.com/check/20.99.186.246",
            "IPv4 45.12.253.72.            command_and_control",
            "Hostname: ddos.dnsnb8.net                        command_and_control",
            "IPv4 95.213.186.51              command_and_control",
            "Hostname: www.supernetforme.com      command_and_control",
            "IPv4 103.224.182.246        command_and_control",
            "IPv4 72.251.233.245           command_and_control",
            "IPv4 63.251.106.25             command_and_control",
            "IPv4 45.15.156.208            command_and_control",
            "IPv4 104.247.81.51             command_and_control",
            "http://ambisexual.phone-sex-blogs.com/http:/ambisexual.phone-sex-blogs.com/images/thumbnails/pic118.jpg             (phishing)",
            "https://downloaddevtools.ir/     (phishing)",
            "happylifehappywife.com",
            "apples.encryptedwork.com        (Interesting in the blacknet)",
            "https://itunes.apple.com/app/apple-store/id284815942/us/app/samsung-galaxy-watch-gear-s/id1117310635.                   (iOS unlocker and hijacker)",
            "https://www.anyxxxtube.net/media/favicon/apple              (password cracker and iOS hijacker)",
            "https://www.apple.com/shop/browse/open/country_selector     (exploit)",
            "www.norad.mil   (federal tracking tool used by attorneys, law firms, and private investigators 'licensed or unlicensed') hi!",
            "http://init-p01st.push.apple.com/bag            (malicious web creator)",
            "opencve.djgummikuh.de        (CVE dispensary)",
            "Maltiverse Research Team",
            "URLscan.io",
            "Deep Research",
            "Hybrid Analysis",
            "URLhaus Abuse.ch",
            "Cyber Threat Coalition",
            "ThreatFox Abuse.ch"
          ],
          "public": 1,
          "adversary": "Lucky Mouse APT27 | NoName057(16) |  Unnamed",
          "targeted_countries": [
            "United States of America",
            "France",
            "Spain"
          ],
          "malware_families": [
            {
              "id": "Feodo",
              "display_name": "Feodo",
              "target": null
            },
            {
              "id": "Dridex",
              "display_name": "Dridex",
              "target": null
            },
            {
              "id": "Redline Stealer",
              "display_name": "Redline Stealer",
              "target": null
            },
            {
              "id": "Ramnit.N",
              "display_name": "Ramnit.N",
              "target": null
            },
            {
              "id": "Loki Bot",
              "display_name": "Loki Bot",
              "target": null
            },
            {
              "id": "Loki Password Stealer (PWS)",
              "display_name": "Loki Password Stealer (PWS)",
              "target": null
            },
            {
              "id": "AZORult",
              "display_name": "AZORult",
              "target": null
            },
            {
              "id": "Zbd Zeus",
              "display_name": "Zbd Zeus",
              "target": null
            },
            {
              "id": "Trojan:MSIL/Burkina",
              "display_name": "Trojan:MSIL/Burkina",
              "target": "/malware/Trojan:MSIL/Burkina"
            },
            {
              "id": "Generic.TrickBot.1",
              "display_name": "Generic.TrickBot.1",
              "target": null
            },
            {
              "id": "Exploit.CVE",
              "display_name": "Exploit.CVE",
              "target": null
            },
            {
              "id": "Injector.IS.gen",
              "display_name": "Injector.IS.gen",
              "target": null
            },
            {
              "id": "Gen:Variant.Razy",
              "display_name": "Gen:Variant.Razy",
              "target": null
            },
            {
              "id": "Trojan.Androm.Gen",
              "display_name": "Trojan.Androm.Gen",
              "target": null
            },
            {
              "id": "HEUR:Trojan.Linux.Agent",
              "display_name": "HEUR:Trojan.Linux.Agent",
              "target": null
            },
            {
              "id": "BScope.Trojan",
              "display_name": "BScope.Trojan",
              "target": null
            },
            {
              "id": "VBA.Downloader",
              "display_name": "VBA.Downloader",
              "target": null
            },
            {
              "id": "Trojan.Notifier",
              "display_name": "Trojan.Notifier",
              "target": null
            },
            {
              "id": "HEUR:Trojan.MSOffice.Alien",
              "display_name": "HEUR:Trojan.MSOffice.Alien",
              "target": null
            },
            {
              "id": "Unsafe.AI_Score_100%",
              "display_name": "Unsafe.AI_Score_100%",
              "target": null
            },
            {
              "id": "Gen:Variant.Johnnie",
              "display_name": "Gen:Variant.Johnnie",
              "target": null
            },
            {
              "id": "DangerousObject.Multi",
              "display_name": "DangerousObject.Multi",
              "target": null
            },
            {
              "id": "Trojan:Python/Downldr",
              "display_name": "Trojan:Python/Downldr",
              "target": "/malware/Trojan:Python/Downldr"
            },
            {
              "id": "Trojan:Linux/Downldr",
              "display_name": "Trojan:Linux/Downldr",
              "target": "/malware/Trojan:Linux/Downldr"
            },
            {
              "id": "Trojan:VBA/Downldr",
              "display_name": "Trojan:VBA/Downldr",
              "target": "/malware/Trojan:VBA/Downldr"
            },
            {
              "id": "TrojanDownloader:Linux/Downldr",
              "display_name": "TrojanDownloader:Linux/Downldr",
              "target": "/malware/TrojanDownloader:Linux/Downldr"
            },
            {
              "id": "Kryptik.FPH.gen",
              "display_name": "Kryptik.FPH.gen",
              "target": null
            },
            {
              "id": "TROJ_FRS.VSNTFK19",
              "display_name": "TROJ_FRS.VSNTFK19",
              "target": null
            },
            {
              "id": "Trojan.Ransom.GenericKD",
              "display_name": "Trojan.Ransom.GenericKD",
              "target": null
            },
            {
              "id": "Phish.JAT",
              "display_name": "Phish.JAT",
              "target": null
            },
            {
              "id": "Phishing.HTML",
              "display_name": "Phishing.HTML",
              "target": null
            },
            {
              "id": "Generic.ASMalwS",
              "display_name": "Generic.ASMalwS",
              "target": null
            },
            {
              "id": "Phish.AB",
              "display_name": "Phish.AB",
              "target": null
            },
            {
              "id": "Generic.Malware",
              "display_name": "Generic.Malware",
              "target": null
            },
            {
              "id": "ml.Generic",
              "display_name": "ml.Generic",
              "target": null
            },
            {
              "id": "Xegumumune.8596c22f",
              "display_name": "Xegumumune.8596c22f",
              "target": null
            },
            {
              "id": "Generic.Malware.SMYB",
              "display_name": "Generic.Malware.SMYB",
              "target": null
            },
            {
              "id": "malicious.moderate.ml",
              "display_name": "malicious.moderate.ml",
              "target": null
            },
            {
              "id": "Agent.NBAE",
              "display_name": "Agent.NBAE",
              "target": null
            },
            {
              "id": "AGEN.1045227",
              "display_name": "AGEN.1045227",
              "target": null
            },
            {
              "id": "Riskware.Agent",
              "display_name": "Riskware.Agent",
              "target": null
            },
            {
              "id": "Gen:Variant.Cerbu",
              "display_name": "Gen:Variant.Cerbu",
              "target": null
            },
            {
              "id": "IL:Trojan.MSILZilla",
              "display_name": "IL:Trojan.MSILZilla",
              "target": null
            },
            {
              "id": "Dropped:Generic.Ransom.DMR",
              "display_name": "Dropped:Generic.Ransom.DMR",
              "target": null
            },
            {
              "id": "Delf.NBX",
              "display_name": "Delf.NBX",
              "target": null
            },
            {
              "id": "malicious.f01f67",
              "display_name": "malicious.f01f67",
              "target": null
            },
            {
              "id": "AGEN.1144657",
              "display_name": "AGEN.1144657",
              "target": null
            },
            {
              "id": "Trojan.Heur",
              "display_name": "Trojan.Heur",
              "target": null
            },
            {
              "id": "Trojan.Malware.300983",
              "display_name": "Trojan.Malware.300983",
              "target": null
            },
            {
              "id": "SdBot.CAOC",
              "display_name": "SdBot.CAOC",
              "target": null
            },
            {
              "id": "Trojan.DelShad",
              "display_name": "Trojan.DelShad",
              "target": null
            },
            {
              "id": "Exploit CVE-2017-11882",
              "display_name": "Exploit CVE-2017-11882",
              "target": null
            },
            {
              "id": "GameHack.NL",
              "display_name": "GameHack.NL",
              "target": null
            },
            {
              "id": "JS:Trojan.HideLink",
              "display_name": "JS:Trojan.HideLink",
              "target": null
            },
            {
              "id": "Script.Agent",
              "display_name": "Script.Agent",
              "target": null
            },
            {
              "id": "Macro.Agent",
              "display_name": "Macro.Agent",
              "target": null
            },
            {
              "id": "Macro.Downloader.AMIP",
              "display_name": "Macro.Downloader.AMIP",
              "target": null
            },
            {
              "id": "Trojan.VBA",
              "display_name": "Trojan.VBA",
              "target": null
            },
            {
              "id": "HEUR.VBA.Trojan",
              "display_name": "HEUR.VBA.Trojan",
              "target": null
            },
            {
              "id": "VB.EmoooDldr.10",
              "display_name": "VB.EmoooDldr.10",
              "target": null
            },
            {
              "id": "VB:Trojan.Valyria",
              "display_name": "VB:Trojan.Valyria",
              "target": null
            },
            {
              "id": "OpenSubtitles.A",
              "display_name": "OpenSubtitles.A",
              "target": null
            },
            {
              "id": "VB.EmoDldr.4",
              "display_name": "VB.EmoDldr.4",
              "target": null
            },
            {
              "id": "Packed-GV",
              "display_name": "Packed-GV",
              "target": null
            },
            {
              "id": "Adware.InstallMonetizer",
              "display_name": "Adware.InstallMonetizer",
              "target": null
            },
            {
              "id": "Skynet",
              "display_name": "Skynet",
              "target": null
            },
            {
              "id": "HW32.Packed",
              "display_name": "HW32.Packed",
              "target": null
            },
            {
              "id": "Zpevdo.B",
              "display_name": "Zpevdo.B",
              "target": null
            },
            {
              "id": "Presenoker",
              "display_name": "Presenoker",
              "target": null
            },
            {
              "id": "SGeneric",
              "display_name": "SGeneric",
              "target": null
            },
            {
              "id": "GameHack.DOM",
              "display_name": "GameHack.DOM",
              "target": null
            },
            {
              "id": "BehavesLike.Ransom",
              "display_name": "BehavesLike.Ransom",
              "target": null
            },
            {
              "id": "CIL.StupidCryptor",
              "display_name": "CIL.StupidCryptor",
              "target": null
            },
            {
              "id": "Gen:Heur.Ransom.MSIL",
              "display_name": "Gen:Heur.Ransom.MSIL",
              "target": null
            },
            {
              "id": "Black.Gen2",
              "display_name": "Black.Gen2",
              "target": null
            },
            {
              "id": "GameHack.CRS",
              "display_name": "GameHack.CRS",
              "target": null
            },
            {
              "id": "Trojan.HTML.PHISH",
              "display_name": "Trojan.HTML.PHISH",
              "target": null
            },
            {
              "id": "Gen:Heur.MSIL.Inject",
              "display_name": "Gen:Heur.MSIL.Inject",
              "target": null
            },
            {
              "id": "Program.Unwanted",
              "display_name": "Program.Unwanted",
              "target": null
            },
            {
              "id": "HEUR/QVM42.3.72EB.Malware",
              "display_name": "HEUR/QVM42.3.72EB.Malware",
              "target": null
            },
            {
              "id": "suspicious.low.ml",
              "display_name": "suspicious.low.ml",
              "target": null
            },
            {
              "id": "JS:Trojan.Cryxos",
              "display_name": "JS:Trojan.Cryxos",
              "target": null
            },
            {
              "id": "Suspicious_GEN.F47V0520",
              "display_name": "Suspicious_GEN.F47V0520",
              "target": null
            },
            {
              "id": "Dropper.Trojan.Generic",
              "display_name": "Dropper.Trojan.Generic",
              "target": null
            },
            {
              "id": "Trojan.TrickBot",
              "display_name": "Trojan.TrickBot",
              "target": null
            },
            {
              "id": "Malware.Tk.Generic",
              "display_name": "Malware.Tk.Generic",
              "target": null
            },
            {
              "id": "TrojanSpy.Java",
              "display_name": "TrojanSpy.Java",
              "target": null
            },
            {
              "id": "Riskware.NetFilter",
              "display_name": "Riskware.NetFilter",
              "target": null
            },
            {
              "id": "RiskWare.Crack",
              "display_name": "RiskWare.Crack",
              "target": null
            },
            {
              "id": "BehavesLike.Exploit",
              "display_name": "BehavesLike.Exploit",
              "target": null
            },
            {
              "id": "Gen:NN.ZemsilF.34128",
              "display_name": "Gen:NN.ZemsilF.34128",
              "target": null
            },
            {
              "id": "Wacapew.C",
              "display_name": "Wacapew.C",
              "target": null
            },
            {
              "id": "Trojan.Malware.121218",
              "display_name": "Trojan.Malware.121218",
              "target": null
            },
            {
              "id": "RiskWare.HackTool.Agent",
              "display_name": "RiskWare.HackTool.Agent",
              "target": null
            },
            {
              "id": "Artemis",
              "display_name": "Artemis",
              "target": null
            },
            {
              "id": "Trojan.Generic",
              "display_name": "Trojan.Generic",
              "target": null
            },
            {
              "id": "W32.Trojan",
              "display_name": "W32.Trojan",
              "target": null
            },
            {
              "id": "BScope.Riskware",
              "display_name": "BScope.Riskware",
              "target": null
            },
            {
              "id": "Gen:Variant.Bulz",
              "display_name": "Gen:Variant.Bulz",
              "target": null
            },
            {
              "id": "Ransom:Win32/CVE-2017-0147",
              "display_name": "Ransom:Win32/CVE-2017-0147",
              "target": "/malware/Ransom:Win32/CVE-2017-0147"
            },
            {
              "id": "Virus.Ramnit",
              "display_name": "Virus.Ramnit",
              "target": null
            },
            {
              "id": "Virus.Virut",
              "display_name": "Virus.Virut",
              "target": null
            },
            {
              "id": "Adware.KuziTui",
              "display_name": "Adware.KuziTui",
              "target": null
            },
            {
              "id": "AGEN.1141126",
              "display_name": "AGEN.1141126",
              "target": null
            },
            {
              "id": "W32.AIDetect",
              "display_name": "W32.AIDetect",
              "target": null
            },
            {
              "id": "Trojan.Python",
              "display_name": "Trojan.Python",
              "target": null
            },
            {
              "id": "W32.AIDetectVM",
              "display_name": "W32.AIDetectVM",
              "target": null
            },
            {
              "id": "Suspicious.Save",
              "display_name": "Suspicious.Save",
              "target": null
            },
            {
              "id": "Adware.Downware",
              "display_name": "Adware.Downware",
              "target": null
            },
            {
              "id": "Ransom.Win64.Wacatac.oa",
              "display_name": "Ransom.Win64.Wacatac.oa",
              "target": null
            },
            {
              "id": "OpenSubtitles.A",
              "display_name": "OpenSubtitles.A",
              "target": null
            },
            {
              "id": "VB.EmoDldr.4",
              "display_name": "VB.EmoDldr.4",
              "target": null
            },
            {
              "id": "Gen:Variant.Midie",
              "display_name": "Gen:Variant.Midie",
              "target": null
            },
            {
              "id": "HEUR/QVM41.2.DA9B.Malware",
              "display_name": "HEUR/QVM41.2.DA9B.Malware",
              "target": null
            },
            {
              "id": "Gen:Variant.Sirefef",
              "display_name": "Gen:Variant.Sirefef",
              "target": null
            },
            {
              "id": "Macro.Trojan.Dropperd",
              "display_name": "Macro.Trojan.Dropperd",
              "target": null
            },
            {
              "id": "BlackNET RAT",
              "display_name": "BlackNET RAT",
              "target": null
            },
            {
              "id": "Gen:Variant.Ursu",
              "display_name": "Gen:Variant.Ursu",
              "target": null
            },
            {
              "id": "Redcap.rlhse",
              "display_name": "Redcap.rlhse",
              "target": null
            },
            {
              "id": "Trojan.Trickster",
              "display_name": "Trojan.Trickster",
              "target": null
            },
            {
              "id": "HTML_REDIR.SMR",
              "display_name": "HTML_REDIR.SMR",
              "target": null
            },
            {
              "id": "TROJ_FRS.VSNTFK19",
              "display_name": "TROJ_FRS.VSNTFK19",
              "target": null
            },
            {
              "id": "Hoax.JS.Phish",
              "display_name": "Hoax.JS.Phish",
              "target": null
            },
            {
              "id": "JS:Iframe",
              "display_name": "JS:Iframe",
              "target": null
            },
            {
              "id": "Application.SQLCrack",
              "display_name": "Application.SQLCrack",
              "target": null
            },
            {
              "id": "susp.lnk",
              "display_name": "susp.lnk",
              "target": null
            },
            {
              "id": "QVM201.0.B70B.Malware",
              "display_name": "QVM201.0.B70B.Malware",
              "target": null
            },
            {
              "id": "Immortal Stealer",
              "display_name": "Immortal Stealer",
              "target": null
            },
            {
              "id": "WebMonitor RAT",
              "display_name": "WebMonitor RAT",
              "target": null
            },
            {
              "id": "Tor - S0183",
              "display_name": "Tor - S0183",
              "target": null
            },
            {
              "id": "WannaCry",
              "display_name": "WannaCry",
              "target": null
            },
            {
              "id": "WannaCryptor",
              "display_name": "WannaCryptor",
              "target": null
            },
            {
              "id": "WebToolbar",
              "display_name": "WebToolbar",
              "target": null
            },
            {
              "id": "BlackNET",
              "display_name": "BlackNET",
              "target": null
            },
            {
              "id": "DeepScan:Generic.Ransom.GandCrab5",
              "display_name": "DeepScan:Generic.Ransom.GandCrab5",
              "target": null
            },
            {
              "id": "TrojanSpy",
              "display_name": "TrojanSpy",
              "target": null
            },
            {
              "id": "States",
              "display_name": "States",
              "target": null
            },
            {
              "id": "Inmortal",
              "display_name": "Inmortal",
              "target": null
            },
            {
              "id": "Domains",
              "display_name": "Domains",
              "target": null
            },
            {
              "id": "Locky",
              "display_name": "Locky",
              "target": null
            },
            {
              "id": "Delf.NBX",
              "display_name": "Delf.NBX",
              "target": null
            },
            {
              "id": "Gen:NN.ZexaF.32515",
              "display_name": "Gen:NN.ZexaF.32515",
              "target": null
            },
            {
              "id": "FileRepMalware",
              "display_name": "FileRepMalware",
              "target": null
            },
            {
              "id": "Gen:Variant.MSILPerseus",
              "display_name": "Gen:Variant.MSILPerseus",
              "target": null
            },
            {
              "id": "Icefog",
              "display_name": "Icefog",
              "target": null
            },
            {
              "id": "$WebWatson",
              "display_name": "$WebWatson",
              "target": null
            },
            {
              "id": "Agent.AIK.gen",
              "display_name": "Agent.AIK.gen",
              "target": null
            },
            {
              "id": "Agent.AIK.genCIL.StupidCryptor",
              "display_name": "Agent.AIK.genCIL.StupidCryptor",
              "target": null
            },
            {
              "id": "Agent.YPEZ",
              "display_name": "Agent.YPEZ",
              "target": null
            },
            {
              "id": "Application.InnovativSol",
              "display_name": "Application.InnovativSol",
              "target": null
            },
            {
              "id": "Agent.ASO",
              "display_name": "Agent.ASO",
              "target": null
            },
            {
              "id": "S-b748adc5",
              "display_name": "S-b748adc5",
              "target": null
            },
            {
              "id": "W32.eHeur",
              "display_name": "W32.eHeur",
              "target": null
            },
            {
              "id": "Kryptik.GUCB",
              "display_name": "Kryptik.GUCB",
              "target": null
            },
            {
              "id": "AgentTesla",
              "display_name": "AgentTesla",
              "target": null
            },
            {
              "id": "Autoit.bimwt",
              "display_name": "Autoit.bimwt",
              "target": null
            },
            {
              "id": "HEUR:Trojan.OLE2.Alien",
              "display_name": "HEUR:Trojan.OLE2.Alien",
              "target": null
            },
            {
              "id": "AGEN.1038489",
              "display_name": "AGEN.1038489",
              "target": null
            },
            {
              "id": "Gen:Variant.Ser.Strictor",
              "display_name": "Gen:Variant.Ser.Strictor",
              "target": null
            },
            {
              "id": "Packed.Themida.Gen",
              "display_name": "Packed.Themida.Gen",
              "target": null
            },
            {
              "id": "AGEN.1043164",
              "display_name": "AGEN.1043164",
              "target": null
            },
            {
              "id": "TrickBot - S0266",
              "display_name": "TrickBot - S0266",
              "target": null
            },
            {
              "id": "Emotet",
              "display_name": "Emotet",
              "target": null
            },
            {
              "id": "Trojan.PornoAsset",
              "display_name": "Trojan.PornoAsset",
              "target": null
            },
            {
              "id": "Ransom.Win64.PORNOASSET.SM1",
              "display_name": "Ransom.Win64.PORNOASSET.SM1",
              "target": null
            },
            {
              "id": "Gen:Variant.Ulise",
              "display_name": "Gen:Variant.Ulise",
              "target": null
            },
            {
              "id": "Trojan.Win64",
              "display_name": "Trojan.Win64",
              "target": null
            },
            {
              "id": "Dropper.Trojan.Agent",
              "display_name": "Dropper.Trojan.Agent",
              "target": null
            },
            {
              "id": "Heur.BZC.YAX.Pantera.10",
              "display_name": "Heur.BZC.YAX.Pantera.10",
              "target": null
            },
            {
              "id": "malicious.high.ml",
              "display_name": "malicious.high.ml",
              "target": null
            },
            {
              "id": "CVE-2015-1650",
              "display_name": "CVE-2015-1650",
              "target": null
            },
            {
              "id": "Worm.Win64.AutoRun",
              "display_name": "Worm.Win64.AutoRun",
              "target": null
            },
            {
              "id": "AIT.Heur.Cottonmouth.8.78F19BD7",
              "display_name": "AIT.Heur.Cottonmouth.8.78F19BD7",
              "target": null
            },
            {
              "id": "Gen:Variant.Mikey",
              "display_name": "Gen:Variant.Mikey",
              "target": null
            },
            {
              "id": "Trojan.Agent",
              "display_name": "Trojan.Agent",
              "target": null
            },
            {
              "id": "Pua.Gen",
              "display_name": "Pua.Gen",
              "target": null
            },
            {
              "id": "Trojan.Downloader.Generic",
              "display_name": "Trojan.Downloader.Generic",
              "target": null
            },
            {
              "id": "Suspected of Trojan.Downloader.gen",
              "display_name": "Suspected of Trojan.Downloader.gen",
              "target": null
            },
            {
              "id": "HEUR:RemoteAdmin.Generic",
              "display_name": "HEUR:RemoteAdmin.Generic",
              "target": null
            },
            {
              "id": "Gen:Heur.Ransom.HiddenTears",
              "display_name": "Gen:Heur.Ransom.HiddenTears",
              "target": null
            },
            {
              "id": "Nemucod.A",
              "display_name": "Nemucod.A",
              "target": null
            },
            {
              "id": "Backdoor.Hupigon",
              "display_name": "Backdoor.Hupigon",
              "target": null
            },
            {
              "id": "Trojan.Starter JS.Iframe",
              "display_name": "Trojan.Starter JS.Iframe",
              "target": null
            },
            {
              "id": "fake ,promethiumm ,strongpity",
              "display_name": "fake ,promethiumm ,strongpity",
              "target": null
            },
            {
              "id": "PUA.Reg1staid",
              "display_name": "PUA.Reg1staid",
              "target": null
            },
            {
              "id": "Malware.Heur_Generic.A",
              "display_name": "Malware.Heur_Generic.A",
              "target": null
            },
            {
              "id": "Bladabindi.Q",
              "display_name": "Bladabindi.Q",
              "target": null
            },
            {
              "id": "W32.eHeur",
              "display_name": "W32.eHeur",
              "target": null
            },
            {
              "id": "malicious.6e0700",
              "display_name": "malicious.6e0700",
              "target": null
            },
            {
              "id": "Trojan.Inject",
              "display_name": "Trojan.Inject",
              "target": null
            },
            {
              "id": "TSGeneric",
              "display_name": "TSGeneric",
              "target": null
            },
            {
              "id": "RedCap.vneda",
              "display_name": "RedCap.vneda",
              "target": null
            },
            {
              "id": "Trojan.Indiloadz",
              "display_name": "Trojan.Indiloadz",
              "target": null
            },
            {
              "id": "Trojan.Ekstak",
              "display_name": "Trojan.Ekstak",
              "target": null
            },
            {
              "id": "staticrr.paleokits.net",
              "display_name": "staticrr.paleokits.net",
              "target": null
            },
            {
              "id": "MSIL.Downloader",
              "display_name": "MSIL.Downloader",
              "target": null
            },
            {
              "id": "Trojan.Autoruns.GenericKDS",
              "display_name": "Trojan.Autoruns.GenericKDS",
              "target": null
            },
            {
              "id": "MSIL.Trojan.BSE",
              "display_name": "MSIL.Trojan.BSE",
              "target": null
            },
            {
              "id": "Adload.AD81",
              "display_name": "Adload.AD81",
              "target": null
            },
            {
              "id": "Packed.Asprotect",
              "display_name": "Packed.Asprotect",
              "target": null
            },
            {
              "id": "Gen:NN.ZemsilF.34062",
              "display_name": "Gen:NN.ZemsilF.34062",
              "target": null
            },
            {
              "id": "Evo",
              "display_name": "Evo",
              "target": null
            },
            {
              "id": "Agent.pwc",
              "display_name": "Agent.pwc",
              "target": null
            },
            {
              "id": "RiskTool.Phpw",
              "display_name": "RiskTool.Phpw",
              "target": null
            },
            {
              "id": "Gen:Variant.Symmi",
              "display_name": "Gen:Variant.Symmi",
              "target": null
            },
            {
              "id": "Trojan.PWS",
              "display_name": "Trojan.PWS",
              "target": null
            },
            {
              "id": "Generic.BitCoinMiner.3",
              "display_name": "Generic.BitCoinMiner.3",
              "target": null
            },
            {
              "id": "Trojan.Tasker",
              "display_name": "Trojan.Tasker",
              "target": null
            },
            {
              "id": "Gen:NN",
              "display_name": "Gen:NN",
              "target": null
            },
            {
              "id": "Downloader.CertutilURLCache",
              "display_name": "Downloader.CertutilURLCache",
              "target": null
            },
            {
              "id": "Elf",
              "display_name": "Elf",
              "target": null
            },
            {
              "id": "Gen:Heur.MSIL.Androm",
              "display_name": "Gen:Heur.MSIL.Androm",
              "target": null
            },
            {
              "id": "Kryptik.NRD",
              "display_name": "Kryptik.NRD",
              "target": null
            },
            {
              "id": "Riskware",
              "display_name": "Riskware",
              "target": null
            },
            {
              "id": "Kuluoz.B.gen",
              "display_name": "Kuluoz.B.gen",
              "target": null
            },
            {
              "id": "Gen:Variant.RevengeRat",
              "display_name": "Gen:Variant.RevengeRat",
              "target": null
            },
            {
              "id": "Gen:Variant.Mikey",
              "display_name": "Gen:Variant.Mikey",
              "target": null
            },
            {
              "id": "VB.Chronos.7",
              "display_name": "VB.Chronos.7",
              "target": null
            },
            {
              "id": "Kryptik.NOE",
              "display_name": "Kryptik.NOE",
              "target": null
            },
            {
              "id": "HEUR:WebToolbar.Generic",
              "display_name": "HEUR:WebToolbar.Generic",
              "target": null
            },
            {
              "id": "Gen:Variant.Barys",
              "display_name": "Gen:Variant.Barys",
              "target": null
            },
            {
              "id": "Backdoor.Xtreme",
              "display_name": "Backdoor.Xtreme",
              "target": null
            },
            {
              "id": "Trojan.MSIL",
              "display_name": "Trojan.MSIL",
              "target": null
            },
            {
              "id": "Gen:Variant.Graftor",
              "display_name": "Gen:Variant.Graftor",
              "target": null
            },
            {
              "id": "Backdoor.Agent",
              "display_name": "Backdoor.Agent",
              "target": null
            },
            {
              "id": "Unsafe",
              "display_name": "Unsafe",
              "target": null
            },
            {
              "id": "Trojan.PHP.Agent",
              "display_name": "Trojan.PHP.Agent",
              "target": null
            },
            {
              "id": "Trojan.Agent",
              "display_name": "Trojan.Agent",
              "target": null
            },
            {
              "id": "HEUR:Exploit.Generic",
              "display_name": "HEUR:Exploit.Generic",
              "target": null
            },
            {
              "id": "Ransom_WCRY.SMALYM",
              "display_name": "Ransom_WCRY.SMALYM",
              "target": null
            },
            {
              "id": "Ransom_WCRY.SMJ",
              "display_name": "Ransom_WCRY.SMJ",
              "target": null
            },
            {
              "id": "Auslogics",
              "display_name": "Auslogics",
              "target": null
            },
            {
              "id": "Gen:Variant.Jaiko",
              "display_name": "Gen:Variant.Jaiko",
              "target": null
            },
            {
              "id": "Exploit.W32.Agent",
              "display_name": "Exploit.W32.Agent",
              "target": null
            },
            {
              "id": "Trojan.Cud.Gen",
              "display_name": "Trojan.Cud.Gen",
              "target": null
            },
            {
              "id": "Trojan.DOC.Downloader",
              "display_name": "Trojan.DOC.Downloader",
              "target": null
            },
            {
              "id": "Backdoor.MSIL.Agent",
              "display_name": "Backdoor.MSIL.Agent",
              "target": null
            },
            {
              "id": "Gen:Trojan.Heur2.LPTbHW@W64.HfsAutoB",
              "display_name": "Gen:Trojan.Heur2.LPTbHW@W64.HfsAutoB",
              "target": null
            },
            {
              "id": "Gen:Variant.Kazy",
              "display_name": "Gen:Variant.Kazy",
              "target": null
            },
            {
              "id": "Gen:Variant.Zusy",
              "display_name": "Gen:Variant.Zusy",
              "target": null
            },
            {
              "id": "Ransom.WannaCrypt",
              "display_name": "Ransom.WannaCrypt",
              "target": null
            },
            {
              "id": "Generic.ServStart.A",
              "display_name": "Generic.ServStart.A",
              "target": null
            },
            {
              "id": "Trojan.Wanna",
              "display_name": "Trojan.Wanna",
              "target": null
            },
            {
              "id": "Generic.MSIL.Bladabindi",
              "display_name": "Generic.MSIL.Bladabindi",
              "target": null
            },
            {
              "id": "TROJ_GEN.R002C0OG518",
              "display_name": "TROJ_GEN.R002C0OG518",
              "target": null
            },
            {
              "id": "Trojan.Chapak",
              "display_name": "Trojan.Chapak",
              "target": null
            },
            {
              "id": "Indiloadz.BB",
              "display_name": "Indiloadz.BB",
              "target": null
            },
            {
              "id": "BehavBehavesLike.PUPXBI",
              "display_name": "BehavBehavesLike.PUPXBI",
              "target": null
            },
            {
              "id": "DeepScan:Generic.SpyAgent.6",
              "display_name": "DeepScan:Generic.SpyAgent.6",
              "target": null
            },
            {
              "id": "Python.KeyLogger",
              "display_name": "Python.KeyLogger",
              "target": null
            },
            {
              "id": "GameHack.CRS",
              "display_name": "GameHack.CRS",
              "target": null
            },
            {
              "id": "Generic.MSIL.PasswordStealer",
              "display_name": "Generic.MSIL.PasswordStealer",
              "target": null
            },
            {
              "id": "PSW.Agent",
              "display_name": "PSW.Agent",
              "target": null
            },
            {
              "id": "malicious.8c45ba",
              "display_name": "malicious.8c45ba",
              "target": null
            },
            {
              "id": "Dropper.Binder",
              "display_name": "Dropper.Binder",
              "target": null
            },
            {
              "id": "Constructor.MSIL",
              "display_name": "Constructor.MSIL",
              "target": null
            },
            {
              "id": "Linux.Agent",
              "display_name": "Linux.Agent",
              "target": null
            },
            {
              "id": "Virus.3DMax.Script",
              "display_name": "Virus.3DMax.Script",
              "target": null
            },
            {
              "id": "ScrInject.B",
              "display_name": "ScrInject.B",
              "target": null
            },
            {
              "id": "Trojan.WisdomEyes.16070401.9500",
              "display_name": "Trojan.WisdomEyes.16070401.9500",
              "target": null
            },
            {
              "id": "Application.SearchProtect",
              "display_name": "Application.SearchProtect",
              "target": null
            },
            {
              "id": "JS:Trojan.Clicker",
              "display_name": "JS:Trojan.Clicker",
              "target": null
            },
            {
              "id": "Faceliker.A",
              "display_name": "Faceliker.A",
              "target": null
            },
            {
              "id": "JS:Trojan.JS.Faceliker",
              "display_name": "JS:Trojan.JS.Faceliker",
              "target": null
            },
            {
              "id": "Constructor.MSIL  Linux.Agent",
              "display_name": "Constructor.MSIL  Linux.Agent",
              "target": null
            },
            {
              "id": "PowerShell.Trojan",
              "display_name": "PowerShell.Trojan",
              "target": null
            },
            {
              "id": "HTML:Script",
              "display_name": "HTML:Script",
              "target": null
            },
            {
              "id": "ScrInject.B",
              "display_name": "ScrInject.B",
              "target": null
            },
            {
              "id": "W32.AIDetectVM",
              "display_name": "W32.AIDetectVM",
              "target": null
            },
            {
              "id": "HackTool.CheatEngine",
              "display_name": "HackTool.CheatEngine",
              "target": null
            },
            {
              "id": "Injector.CLDS",
              "display_name": "Injector.CLDS",
              "target": null
            },
            {
              "id": "VB.Downloader.2",
              "display_name": "VB.Downloader.2",
              "target": null
            },
            {
              "id": "malicious.3e78cc",
              "display_name": "malicious.3e78cc",
              "target": null
            },
            {
              "id": "malicious.d800d6",
              "display_name": "malicious.d800d6",
              "target": null
            },
            {
              "id": "VB.PwShell.2",
              "display_name": "VB.PwShell.2",
              "target": null
            },
            {
              "id": "Backdoor.RBot",
              "display_name": "Backdoor.RBot",
              "target": null
            },
            {
              "id": "malicious.71b1a8",
              "display_name": "malicious.71b1a8",
              "target": null
            },
            {
              "id": "TrojanSpy.KeyLogger",
              "display_name": "TrojanSpy.KeyLogger",
              "target": null
            },
            {
              "id": "Injector.JDO",
              "display_name": "Injector.JDO",
              "target": null
            },
            {
              "id": "Heur.Msword.Gen",
              "display_name": "Heur.Msword.Gen",
              "target": null
            },
            {
              "id": "PSW.Discord",
              "display_name": "PSW.Discord",
              "target": null
            },
            {
              "id": "Packed.VMProtect",
              "display_name": "Packed.VMProtect",
              "target": null
            },
            {
              "id": "HEUR:AdWare.StartSurf",
              "display_name": "HEUR:AdWare.StartSurf",
              "target": null
            },
            {
              "id": "Gen:Heur.NoobyProtect",
              "display_name": "Gen:Heur.NoobyProtect",
              "target": null
            },
            {
              "id": "CIL.HeapOverride",
              "display_name": "CIL.HeapOverride",
              "target": null
            },
            {
              "id": "HEUR:Trojan.Tasker",
              "display_name": "HEUR:Trojan.Tasker",
              "target": null
            },
            {
              "id": "XLM.Trojan.Abracadabra.27",
              "display_name": "XLM.Trojan.Abracadabra.27",
              "target": null
            },
            {
              "id": "HEUR:Backdoor.MSIL.NanoBot",
              "display_name": "HEUR:Backdoor.MSIL.NanoBot",
              "target": null
            },
            {
              "id": "Trojan.PSW.Mimikatz",
              "display_name": "Trojan.PSW.Mimikatz",
              "target": null
            },
            {
              "id": "TrojanSpy.Python",
              "display_name": "TrojanSpy.Python",
              "target": null
            },
            {
              "id": "Trojan.Ole2.Vbs",
              "display_name": "Trojan.Ole2.Vbs",
              "target": null
            },
            {
              "id": "Exploit.MSOffice",
              "display_name": "Exploit.MSOffice",
              "target": null
            },
            {
              "id": "DeepScan:Generic.Ransom.AmnesiaE",
              "display_name": "DeepScan:Generic.Ransom.AmnesiaE",
              "target": null
            },
            {
              "id": "Wacatac.D6",
              "display_name": "Wacatac.D6",
              "target": null
            },
            {
              "id": "Backdoor.Androm",
              "display_name": "Backdoor.Androm",
              "target": null
            },
            {
              "id": "Packed.NetSeal",
              "display_name": "Packed.NetSeal",
              "target": null
            },
            {
              "id": "Trojan.MSIL.Injector",
              "display_name": "Trojan.MSIL.Injector",
              "target": null
            },
            {
              "id": "Trojan.PWS.Agent",
              "display_name": "Trojan.PWS.Agent",
              "target": null
            },
            {
              "id": "TScope.Trojan",
              "display_name": "TScope.Trojan",
              "target": null
            },
            {
              "id": "PSW.Stealer",
              "display_name": "PSW.Stealer",
              "target": null
            },
            {
              "id": "Trojan.PackedNET",
              "display_name": "Trojan.PackedNET",
              "target": null
            },
            {
              "id": "Trojan.Java",
              "display_name": "Trojan.Java",
              "target": null
            },
            {
              "id": "MalwareX",
              "display_name": "MalwareX",
              "target": null
            },
            {
              "id": "Trojan.PSW.Python",
              "display_name": "Trojan.PSW.Python",
              "target": null
            },
            {
              "id": "malicious.11abfc",
              "display_name": "malicious.11abfc",
              "target": null
            },
            {
              "id": "Generic.ASMalwS",
              "display_name": "Generic.ASMalwS",
              "target": null
            },
            {
              "id": "HEUR:Trojan.MSIL.Tasker",
              "display_name": "HEUR:Trojan.MSIL.Tasker",
              "target": null
            },
            {
              "id": "PossibleThreat.PALLAS",
              "display_name": "PossibleThreat.PALLAS",
              "target": null
            },
            {
              "id": "Backdoor.Poison",
              "display_name": "Backdoor.Poison",
              "target": null
            },
            {
              "id": "Generic.MSIL.LimeRAT",
              "display_name": "Generic.MSIL.LimeRAT",
              "target": null
            },
            {
              "id": "PWS-FCZZ",
              "display_name": "PWS-FCZZ",
              "target": null
            },
            {
              "id": "Trojan.Script",
              "display_name": "Trojan.Script",
              "target": null
            },
            {
              "id": "Gen:Heur.MSIL.Inject",
              "display_name": "Gen:Heur.MSIL.Inject",
              "target": null
            },
            {
              "id": "Trojan.PWS.Growtopia",
              "display_name": "Trojan.PWS.Growtopia",
              "target": null
            },
            {
              "id": "Spyware.Bobik",
              "display_name": "Spyware.Bobik",
              "target": null
            },
            {
              "id": "HackTool.BruteForce",
              "display_name": "HackTool.BruteForce",
              "target": null
            },
            {
              "id": "Hack.Patcher",
              "display_name": "Hack.Patcher",
              "target": null
            },
            {
              "id": "PWS.p",
              "display_name": "PWS.p",
              "target": null
            },
            {
              "id": "Suppobox",
              "display_name": "Suppobox",
              "target": null
            },
            {
              "id": "index.php",
              "display_name": "index.php",
              "target": null
            },
            {
              "id": "Packed.VMProtect",
              "display_name": "Packed.VMProtect",
              "target": null
            },
            {
              "id": "SmokeLoader",
              "display_name": "SmokeLoader",
              "target": null
            },
            {
              "id": "Generic.Malware",
              "display_name": "Generic.Malware",
              "target": null
            },
            {
              "id": "SNH:Script [Dropper]",
              "display_name": "SNH:Script [Dropper]",
              "target": null
            },
            {
              "id": "HEUR:Trojan.MSOffice.SAgent",
              "display_name": "HEUR:Trojan.MSOffice.SAgent",
              "target": null
            },
            {
              "id": "Script.INF",
              "display_name": "Script.INF",
              "target": null
            },
            {
              "id": "JS:Trojan.JS.Likejack",
              "display_name": "JS:Trojan.JS.Likejack",
              "target": null
            },
            {
              "id": "SNH:Script [Dropper]",
              "display_name": "SNH:Script [Dropper]",
              "target": null
            },
            {
              "id": "Trojan.JS.Agent",
              "display_name": "Trojan.JS.Agent",
              "target": null
            },
            {
              "id": "APT Notes",
              "display_name": "APT Notes",
              "target": null
            },
            {
              "id": "susp.rtf.objupdate",
              "display_name": "susp.rtf.objupdate",
              "target": null
            },
            {
              "id": "RedCap.zoohz",
              "display_name": "RedCap.zoohz",
              "target": null
            },
            {
              "id": "Trojan.Tasker",
              "display_name": "Trojan.Tasker",
              "target": null
            },
            {
              "id": "virus.office.qexvmc",
              "display_name": "virus.office.qexvmc",
              "target": null
            },
            {
              "id": "Trojan.KillProc",
              "display_name": "Trojan.KillProc",
              "target": null
            },
            {
              "id": "Generic.MSIL.GrwtpStealer.1",
              "display_name": "Generic.MSIL.GrwtpStealer.1",
              "target": null
            },
            {
              "id": "Suspicious.Cloud",
              "display_name": "Suspicious.Cloud",
              "target": null
            },
            {
              "id": "PowerShell.DownLoader",
              "display_name": "PowerShell.DownLoader",
              "target": null
            },
            {
              "id": "Downldr.gen",
              "display_name": "Downldr.gen",
              "target": null
            },
            {
              "id": "AGEN.1030939",
              "display_name": "AGEN.1030939",
              "target": null
            },
            {
              "id": "HackTool.Binder",
              "display_name": "HackTool.Binder",
              "target": null
            },
            {
              "id": "Trojan.Inject",
              "display_name": "Trojan.Inject",
              "target": null
            },
            {
              "id": "Dldr.Agent",
              "display_name": "Dldr.Agent",
              "target": null
            },
            {
              "id": "Dropper.MSIL",
              "display_name": "Dropper.MSIL",
              "target": null
            },
            {
              "id": "Trojan.VBKryjetor",
              "display_name": "Trojan.VBKryjetor",
              "target": null
            },
            {
              "id": "PWSX",
              "display_name": "PWSX",
              "target": null
            },
            {
              "id": "VB:Trojan.VBA.Agent",
              "display_name": "VB:Trojan.VBA.Agent",
              "target": null
            },
            {
              "id": "HEUR:Trojan.MSOffice.Stratos",
              "display_name": "HEUR:Trojan.MSOffice.Stratos",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1071.004",
              "name": "DNS",
              "display_name": "T1071.004 - DNS"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1059.007",
              "name": "JavaScript",
              "display_name": "T1059.007 - JavaScript"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1068",
              "name": "Exploitation for Privilege Escalation",
              "display_name": "T1068 - Exploitation for Privilege Escalation"
            },
            {
              "id": "TA0029",
              "name": "Privilege Escalation",
              "display_name": "TA0029 - Privilege Escalation"
            },
            {
              "id": "T1449",
              "name": "Exploit SS7 to Redirect Phone Calls/SMS",
              "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
            },
            {
              "id": "T1190",
              "name": "Exploit Public-Facing Application",
              "display_name": "T1190 - Exploit Public-Facing Application"
            },
            {
              "id": "T1210",
              "name": "Exploitation of Remote Services",
              "display_name": "T1210 - Exploitation of Remote Services"
            },
            {
              "id": "T1450",
              "name": "Exploit SS7 to Track Device Location",
              "display_name": "T1450 - Exploit SS7 to Track Device Location"
            },
            {
              "id": "T1211",
              "name": "Exploitation for Defense Evasion",
              "display_name": "T1211 - Exploitation for Defense Evasion"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "TA0011",
              "name": "Command and Control",
              "display_name": "TA0011 - Command and Control"
            },
            {
              "id": "T1412",
              "name": "Capture SMS Messages",
              "display_name": "T1412 - Capture SMS Messages"
            },
            {
              "id": "T1454",
              "name": "Malicious SMS Message",
              "display_name": "T1454 - Malicious SMS Message"
            },
            {
              "id": "T1001",
              "name": "Data Obfuscation",
              "display_name": "T1001 - Data Obfuscation"
            },
            {
              "id": "T1114",
              "name": "Email Collection",
              "display_name": "T1114 - Email Collection"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1498",
              "name": "Network Denial of Service",
              "display_name": "T1498 - Network Denial of Service"
            },
            {
              "id": "T1496",
              "name": "Resource Hijacking",
              "display_name": "T1496 - Resource Hijacking"
            },
            {
              "id": "T1176",
              "name": "Browser Extensions",
              "display_name": "T1176 - Browser Extensions"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 338,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 1184,
            "FileHash-SHA1": 949,
            "FileHash-SHA256": 3712,
            "URL": 2925,
            "domain": 627,
            "hostname": 1319,
            "CVE": 26,
            "email": 8,
            "CIDR": 2
          },
          "indicator_count": 10752,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 223,
          "modified_text": "904 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "654c606d74f82e547c77ad89",
          "name": "Ransom.Win64.PORNOASSET.SM1 | DeepScan:Generic.Ransom.GandCrab5",
          "description": "Ransom.Win64.PORNOASSET.SM1 DeepScan:Generic.Ransom.GandCrab5\nBlackNET RAT $WebWatson\nAuto generated results from a variety of tools.",
          "modified": "2023-12-09T03:01:57.989000",
          "created": "2023-11-09T04:30:37.089000",
          "tags": [
            "ssl certificate",
            "historical ssl",
            "communicating",
            "contacted",
            "resolutions",
            "whois record",
            "whois whois",
            "whois parent",
            "whois siblings",
            "skynet",
            "threat report",
            "ip summary",
            "url summary",
            "summary",
            "sample",
            "samples",
            "detection list",
            "blacklist",
            "cisco umbrella",
            "site",
            "safe site",
            "million",
            "team",
            "microsoft",
            "back",
            "download",
            "phishing",
            "union",
            "bank",
            "malicious site",
            "blacklist http",
            "exit",
            "traffic",
            "node tcp",
            "tor known",
            "tor relayrouter",
            "et tor",
            "known tor",
            "relayrouter",
            "anonymizer",
            "spammer",
            "malware",
            "dropped",
            "unlocker",
            "http",
            "critical risk",
            "redline stealer",
            "core",
            "hacktool",
            "execution",
            "type win32",
            "exe size",
            "first seen",
            "file name",
            "avast win32",
            "win32",
            "avg win32",
            "fortinet",
            "vitro",
            "mb first",
            "rmndrp",
            "clean mx",
            "undetected dns8",
            "undetected vx",
            "sophos",
            "vault",
            "zdb zeus",
            "cmc threat",
            "snort ip",
            "feodo tracker",
            "cybereason",
            "send bug",
            "pe yandex",
            "no data",
            "tag count",
            "count blacklist",
            "tag tag",
            "algorithm",
            "v3 serial",
            "number",
            "issuer",
            "cus cnr3",
            "olet",
            "subject public",
            "key info",
            "key algorithm",
            "key identifier",
            "first",
            "seen",
            "valid",
            "no na",
            "no no",
            "ip security",
            "cndst root",
            "ca x3",
            "ca id",
            "research group",
            "cnisrg root",
            "no expired",
            "mozilla",
            "android",
            "malicious red team",
            "tsara brashears",
            "cyber stalking",
            "malvertizing",
            "invasion of privacy",
            "threat",
            "adult content",
            "apple",
            "iphone unlocker",
            "android",
            "exploited spyware",
            "malware host",
            "brute force",
            "revenge-rat",
            "banker",
            "evasive",
            "domain",
            "redline",
            "stealer",
            "phishing",
            "ramnit",
            "unreliable subdomains",
            "dridex",
            "gating",
            "msil",
            "rat",
            "loki",
            "network",
            "hacking",
            "sinkhole",
            "azorult",
            "c2",
            "historicalandnew",
            "targeted attack",
            "puffstealer",
            "rultazo",
            "lokibot",
            "loki pws",
            "burkina",
            "banker,dde,dridex,exploit",
            "banker,dridex,evasive",
            "trickbot",
            "ransomware,torrentlocker",
            "exploit_source",
            "blacknet",
            "FileRepMalware",
            "linux agent",
            "blacknet",
            "ios",
            "phishing paypal",
            "tagging",
            "defacement",
            "hit",
            "bounty",
            "phishing site",
            "malware site",
            "malware download",
            "endangerment",
            "Malicious domain - SANS Internet Storm Center",
            "evasive,msil,rat,revenge-rat",
            "prism_setting",
            "prism_object",
            "static engine",
            "social engineering",
            "jansky",
            "worm",
            "network rat",
            "networm",
            "Loki Password Stealer (PWS)",
            "South Carolina Federal Credit Union phishing",
            "darkweb",
            "yandex",
            "redirectors",
            "blacknet threats",
            "phishing,ransomware,sinkhole",
            "wanacrypt0r,wannacry,wcry",
            "tor c++",
            "tor c++ client",
            "python user",
            "js user",
            "hacker",
            "hijacker",
            "heur",
            "maltiverse",
            "alexa top",
            "exploit",
            "riskware",
            "unsafe",
            "outbreak",
            "downer",
            "shell",
            "mediamagnet",
            "sality",
            "swrort",
            "adaptivebee",
            "unruy",
            "iobit",
            "dropper",
            "trojanx",
            "artemis",
            "installcore",
            "webshell",
            "crack",
            "webtoolbar",
            "search live",
            "api blog",
            "docs pricing",
            "november",
            "de indicators",
            "domains",
            "hashes",
            "__convergedlogin_pcustomizationloader_44b450e8d543eb53930d",
            "malicious url",
            "financial",
            "blacknet rat",
            "azorult",
            "stealer",
            "deep scan",
            "blacklist https",
            "referrer",
            "collections kp",
            "incident ip",
            "sneaky server",
            "replacement",
            "unauthorized",
            "emotet",
            "noname057",
            "generic malware",
            "engineering",
            "cyber threat",
            "facebook",
            "paypal",
            "dropbox",
            "united",
            "america",
            "banking",
            "wells fargo",
            "steam",
            "twitter",
            "sliver",
            "daum",
            "swift",
            "runescape",
            "betabot",
            "district",
            "iframe",
            "alexa",
            "downldr",
            "agent",
            "presenoker",
            "bladabindi",
            "live",
            "conduit",
            "pony",
            "covid19",
            "malicious",
            "cobalt strike",
            "suppobox",
            "ramnit",
            "meterpreter",
            "virut",
            "njrat",
            "pykspa",
            "asyncrat",
            "downloader",
            "fakealert",
            "binder",
            "virustotal",
            "formbook",
            "necurs",
            "trojan",
            "msil",
            "hiloti",
            "vawtrak",
            "simda",
            "kraken",
            "solimba",
            "icedid",
            "redirector",
            "suspic",
            "amadey",
            "raccoon",
            "nanocore rat",
            "revenge rat",
            "genkryptik",
            "fuery",
            "wacatac",
            "service",
            "cloudeye",
            "tinba",
            "domaiq",
            "ave maria",
            "zeus",
            "ransomware",
            "zbot",
            "generic",
            "trojanspy",
            "states",
            "inmortal",
            "locky",
            "strike",
            "china cobalt",
            "keybase",
            "cutwail",
            "citadel",
            "radamant",
            "kovter",
            "bradesco",
            "nymaim",
            "amonetize",
            "bondat",
            "ghost rat",
            "vjw0rm",
            "bandoo",
            "matsnu",
            "dnspionage",
            "darkgate",
            "vidar",
            "keylogger",
            "remcos",
            "agenttesla",
            "detplock",
            "win64",
            "smokeloader",
            "agent tesla",
            "kgs0",
            "kls0",
            "urls",
            "type name",
            "dns replication",
            "date",
            "domain",
            "win32 exe",
            "files",
            "detections type",
            "name",
            "drpsuinstaller",
            "vdfsurfs",
            "opera",
            "icwrmind",
            "notepad",
            "installer",
            "miner",
            "unknown",
            "networm",
            "houdini",
            "quasar rat",
            "gamehack",
            "dbatloader",
            "qakbot",
            "ursnif",
            "CVE-2005-1790",
            "CVE-2009-3672",
            "CVE-2010-3962",
            "CVE-2012-3993",
            "CVE-2014-6332",
            "CVE-2017-11882",
            "CVE-2020-0601",
            "CVE-2020-0674",
            "hallrender.com",
            "brian sabey",
            "insurance",
            "botnetwork",
            "botmaster",
            "command_and_control",
            "CVE-2021-27065",
            "CVE-2021-40444",
            "CVE-2023-4966",
            "CVE-2017-0199",
            "CVE-2018-4893",
            "CVE-2010-3333",
            "CVE-2015-1641",
            "CVE-2017-0147",
            "CVE-2017-8570",
            "CVE-2018-0802",
            "CVE-2018-8373",
            "CVE-2017-8759",
            "CVE-2018-8453",
            "CVE-2014-3153",
            "CVE-2015-1650",
            "CVE-2017-0143",
            "CVE-2017-8464",
            "Icefog",
            "Delf.NBX",
            "$WebWatson",
            "Gen:Heur.Ransom.HiddenTears",
            "mobilekey.pw",
            "bitbucket.org",
            "Anomalous.100%",
            "malware distribution site",
            "gootkit",
            "edsaid",
            "rightsaided",
            "betabot",
            "cobaltstrike4.tk",
            "mas.to",
            "BehavesLike.YahLover",
            "srdvd16010404",
            "languageenu",
            "buildno",
            "channelisales",
            "vendorname2581",
            "osregion",
            "device",
            "systemlocale",
            "majorver16",
            "quasar",
            "find",
            "lockbit",
            "chaos",
            "ransomexx",
            "grandoreiro",
            "evilnum",
            "banker"
          ],
          "references": [
            "https://hybrid-analysis.com/sample/6765f47ea77c8274c8e4973ed95aedf59e75998c62f6029e23c58cdf36ed85ba/654afdbdc621e7037801cce7",
            "20.99.186.246 exploit source",
            "fp2e7a.wpc.2be4.phicdn.net",
            "https://www.anyxxxtube.net/search-porn/tsara-brashears/ (phishing, ELF, Prism.exe found)",
            "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian (password cracker)",
            "http://182.22.25.124:7878/182.22.25.124:443     (malicious dropper)",
            "init.ess.apple.com         (malicious code script)",
            "https://www.pornhub.com/video/search?search=tsara+brashears (Malicious PW cracker | stylebk.css stylesheets - not found )",
            "https://urlscan.io/result/a328d9ff-fb49-4078-960d-a757fd41404f/#indicators",
            "VirusTotal Link: https://www.virustotal.com/gui/ip-address/20.99.186.246/detection",
            "Abuse IPDB Link: https://www.abuseipdb.com/check/20.99.186.246",
            "IPv4 45.12.253.72.            command_and_control",
            "Hostname: ddos.dnsnb8.net                        command_and_control",
            "IPv4 95.213.186.51              command_and_control",
            "Hostname: www.supernetforme.com      command_and_control",
            "IPv4 103.224.182.246        command_and_control",
            "IPv4 72.251.233.245           command_and_control",
            "IPv4 63.251.106.25             command_and_control",
            "IPv4 45.15.156.208            command_and_control",
            "IPv4 104.247.81.51             command_and_control",
            "http://ambisexual.phone-sex-blogs.com/http:/ambisexual.phone-sex-blogs.com/images/thumbnails/pic118.jpg             (phishing)",
            "https://downloaddevtools.ir/     (phishing)",
            "happylifehappywife.com",
            "apples.encryptedwork.com        (Interesting in the blacknet)",
            "https://itunes.apple.com/app/apple-store/id284815942/us/app/samsung-galaxy-watch-gear-s/id1117310635.                   (iOS unlocker and hijacker)",
            "https://www.anyxxxtube.net/media/favicon/apple              (password cracker and iOS hijacker)",
            "https://www.apple.com/shop/browse/open/country_selector     (exploit)",
            "www.norad.mil   (federal tracking tool used by attorneys, law firms, and private investigators 'licensed or unlicensed') hi!",
            "http://init-p01st.push.apple.com/bag            (malicious web creator)",
            "opencve.djgummikuh.de        (CVE dispensary)",
            "Maltiverse Research Team",
            "URLscan.io",
            "Deep Research",
            "Hybrid Analysis",
            "URLhaus Abuse.ch",
            "Cyber Threat Coalition",
            "ThreatFox Abuse.ch"
          ],
          "public": 1,
          "adversary": "Lucky Mouse APT27 | NoName057(16) |  Unnamed",
          "targeted_countries": [
            "United States of America",
            "France",
            "Spain"
          ],
          "malware_families": [
            {
              "id": "Feodo",
              "display_name": "Feodo",
              "target": null
            },
            {
              "id": "Dridex",
              "display_name": "Dridex",
              "target": null
            },
            {
              "id": "Redline Stealer",
              "display_name": "Redline Stealer",
              "target": null
            },
            {
              "id": "Ramnit.N",
              "display_name": "Ramnit.N",
              "target": null
            },
            {
              "id": "Loki Bot",
              "display_name": "Loki Bot",
              "target": null
            },
            {
              "id": "Loki Password Stealer (PWS)",
              "display_name": "Loki Password Stealer (PWS)",
              "target": null
            },
            {
              "id": "AZORult",
              "display_name": "AZORult",
              "target": null
            },
            {
              "id": "Zbd Zeus",
              "display_name": "Zbd Zeus",
              "target": null
            },
            {
              "id": "Trojan:MSIL/Burkina",
              "display_name": "Trojan:MSIL/Burkina",
              "target": "/malware/Trojan:MSIL/Burkina"
            },
            {
              "id": "Generic.TrickBot.1",
              "display_name": "Generic.TrickBot.1",
              "target": null
            },
            {
              "id": "Exploit.CVE",
              "display_name": "Exploit.CVE",
              "target": null
            },
            {
              "id": "Injector.IS.gen",
              "display_name": "Injector.IS.gen",
              "target": null
            },
            {
              "id": "Gen:Variant.Razy",
              "display_name": "Gen:Variant.Razy",
              "target": null
            },
            {
              "id": "Trojan.Androm.Gen",
              "display_name": "Trojan.Androm.Gen",
              "target": null
            },
            {
              "id": "HEUR:Trojan.Linux.Agent",
              "display_name": "HEUR:Trojan.Linux.Agent",
              "target": null
            },
            {
              "id": "BScope.Trojan",
              "display_name": "BScope.Trojan",
              "target": null
            },
            {
              "id": "VBA.Downloader",
              "display_name": "VBA.Downloader",
              "target": null
            },
            {
              "id": "Trojan.Notifier",
              "display_name": "Trojan.Notifier",
              "target": null
            },
            {
              "id": "HEUR:Trojan.MSOffice.Alien",
              "display_name": "HEUR:Trojan.MSOffice.Alien",
              "target": null
            },
            {
              "id": "Unsafe.AI_Score_100%",
              "display_name": "Unsafe.AI_Score_100%",
              "target": null
            },
            {
              "id": "Gen:Variant.Johnnie",
              "display_name": "Gen:Variant.Johnnie",
              "target": null
            },
            {
              "id": "DangerousObject.Multi",
              "display_name": "DangerousObject.Multi",
              "target": null
            },
            {
              "id": "Trojan:Python/Downldr",
              "display_name": "Trojan:Python/Downldr",
              "target": "/malware/Trojan:Python/Downldr"
            },
            {
              "id": "Trojan:Linux/Downldr",
              "display_name": "Trojan:Linux/Downldr",
              "target": "/malware/Trojan:Linux/Downldr"
            },
            {
              "id": "Trojan:VBA/Downldr",
              "display_name": "Trojan:VBA/Downldr",
              "target": "/malware/Trojan:VBA/Downldr"
            },
            {
              "id": "TrojanDownloader:Linux/Downldr",
              "display_name": "TrojanDownloader:Linux/Downldr",
              "target": "/malware/TrojanDownloader:Linux/Downldr"
            },
            {
              "id": "Kryptik.FPH.gen",
              "display_name": "Kryptik.FPH.gen",
              "target": null
            },
            {
              "id": "TROJ_FRS.VSNTFK19",
              "display_name": "TROJ_FRS.VSNTFK19",
              "target": null
            },
            {
              "id": "Trojan.Ransom.GenericKD",
              "display_name": "Trojan.Ransom.GenericKD",
              "target": null
            },
            {
              "id": "Phish.JAT",
              "display_name": "Phish.JAT",
              "target": null
            },
            {
              "id": "Phishing.HTML",
              "display_name": "Phishing.HTML",
              "target": null
            },
            {
              "id": "Generic.ASMalwS",
              "display_name": "Generic.ASMalwS",
              "target": null
            },
            {
              "id": "Phish.AB",
              "display_name": "Phish.AB",
              "target": null
            },
            {
              "id": "Generic.Malware",
              "display_name": "Generic.Malware",
              "target": null
            },
            {
              "id": "ml.Generic",
              "display_name": "ml.Generic",
              "target": null
            },
            {
              "id": "Xegumumune.8596c22f",
              "display_name": "Xegumumune.8596c22f",
              "target": null
            },
            {
              "id": "Generic.Malware.SMYB",
              "display_name": "Generic.Malware.SMYB",
              "target": null
            },
            {
              "id": "malicious.moderate.ml",
              "display_name": "malicious.moderate.ml",
              "target": null
            },
            {
              "id": "Agent.NBAE",
              "display_name": "Agent.NBAE",
              "target": null
            },
            {
              "id": "AGEN.1045227",
              "display_name": "AGEN.1045227",
              "target": null
            },
            {
              "id": "Riskware.Agent",
              "display_name": "Riskware.Agent",
              "target": null
            },
            {
              "id": "Gen:Variant.Cerbu",
              "display_name": "Gen:Variant.Cerbu",
              "target": null
            },
            {
              "id": "IL:Trojan.MSILZilla",
              "display_name": "IL:Trojan.MSILZilla",
              "target": null
            },
            {
              "id": "Dropped:Generic.Ransom.DMR",
              "display_name": "Dropped:Generic.Ransom.DMR",
              "target": null
            },
            {
              "id": "Delf.NBX",
              "display_name": "Delf.NBX",
              "target": null
            },
            {
              "id": "malicious.f01f67",
              "display_name": "malicious.f01f67",
              "target": null
            },
            {
              "id": "AGEN.1144657",
              "display_name": "AGEN.1144657",
              "target": null
            },
            {
              "id": "Trojan.Heur",
              "display_name": "Trojan.Heur",
              "target": null
            },
            {
              "id": "Trojan.Malware.300983",
              "display_name": "Trojan.Malware.300983",
              "target": null
            },
            {
              "id": "SdBot.CAOC",
              "display_name": "SdBot.CAOC",
              "target": null
            },
            {
              "id": "Trojan.DelShad",
              "display_name": "Trojan.DelShad",
              "target": null
            },
            {
              "id": "Exploit CVE-2017-11882",
              "display_name": "Exploit CVE-2017-11882",
              "target": null
            },
            {
              "id": "GameHack.NL",
              "display_name": "GameHack.NL",
              "target": null
            },
            {
              "id": "JS:Trojan.HideLink",
              "display_name": "JS:Trojan.HideLink",
              "target": null
            },
            {
              "id": "Script.Agent",
              "display_name": "Script.Agent",
              "target": null
            },
            {
              "id": "Macro.Agent",
              "display_name": "Macro.Agent",
              "target": null
            },
            {
              "id": "Macro.Downloader.AMIP",
              "display_name": "Macro.Downloader.AMIP",
              "target": null
            },
            {
              "id": "Trojan.VBA",
              "display_name": "Trojan.VBA",
              "target": null
            },
            {
              "id": "HEUR.VBA.Trojan",
              "display_name": "HEUR.VBA.Trojan",
              "target": null
            },
            {
              "id": "VB.EmoooDldr.10",
              "display_name": "VB.EmoooDldr.10",
              "target": null
            },
            {
              "id": "VB:Trojan.Valyria",
              "display_name": "VB:Trojan.Valyria",
              "target": null
            },
            {
              "id": "OpenSubtitles.A",
              "display_name": "OpenSubtitles.A",
              "target": null
            },
            {
              "id": "VB.EmoDldr.4",
              "display_name": "VB.EmoDldr.4",
              "target": null
            },
            {
              "id": "Packed-GV",
              "display_name": "Packed-GV",
              "target": null
            },
            {
              "id": "Adware.InstallMonetizer",
              "display_name": "Adware.InstallMonetizer",
              "target": null
            },
            {
              "id": "Skynet",
              "display_name": "Skynet",
              "target": null
            },
            {
              "id": "HW32.Packed",
              "display_name": "HW32.Packed",
              "target": null
            },
            {
              "id": "Zpevdo.B",
              "display_name": "Zpevdo.B",
              "target": null
            },
            {
              "id": "Presenoker",
              "display_name": "Presenoker",
              "target": null
            },
            {
              "id": "SGeneric",
              "display_name": "SGeneric",
              "target": null
            },
            {
              "id": "GameHack.DOM",
              "display_name": "GameHack.DOM",
              "target": null
            },
            {
              "id": "BehavesLike.Ransom",
              "display_name": "BehavesLike.Ransom",
              "target": null
            },
            {
              "id": "CIL.StupidCryptor",
              "display_name": "CIL.StupidCryptor",
              "target": null
            },
            {
              "id": "Gen:Heur.Ransom.MSIL",
              "display_name": "Gen:Heur.Ransom.MSIL",
              "target": null
            },
            {
              "id": "Black.Gen2",
              "display_name": "Black.Gen2",
              "target": null
            },
            {
              "id": "GameHack.CRS",
              "display_name": "GameHack.CRS",
              "target": null
            },
            {
              "id": "Trojan.HTML.PHISH",
              "display_name": "Trojan.HTML.PHISH",
              "target": null
            },
            {
              "id": "Gen:Heur.MSIL.Inject",
              "display_name": "Gen:Heur.MSIL.Inject",
              "target": null
            },
            {
              "id": "Program.Unwanted",
              "display_name": "Program.Unwanted",
              "target": null
            },
            {
              "id": "HEUR/QVM42.3.72EB.Malware",
              "display_name": "HEUR/QVM42.3.72EB.Malware",
              "target": null
            },
            {
              "id": "suspicious.low.ml",
              "display_name": "suspicious.low.ml",
              "target": null
            },
            {
              "id": "JS:Trojan.Cryxos",
              "display_name": "JS:Trojan.Cryxos",
              "target": null
            },
            {
              "id": "Suspicious_GEN.F47V0520",
              "display_name": "Suspicious_GEN.F47V0520",
              "target": null
            },
            {
              "id": "Dropper.Trojan.Generic",
              "display_name": "Dropper.Trojan.Generic",
              "target": null
            },
            {
              "id": "Trojan.TrickBot",
              "display_name": "Trojan.TrickBot",
              "target": null
            },
            {
              "id": "Malware.Tk.Generic",
              "display_name": "Malware.Tk.Generic",
              "target": null
            },
            {
              "id": "TrojanSpy.Java",
              "display_name": "TrojanSpy.Java",
              "target": null
            },
            {
              "id": "Riskware.NetFilter",
              "display_name": "Riskware.NetFilter",
              "target": null
            },
            {
              "id": "RiskWare.Crack",
              "display_name": "RiskWare.Crack",
              "target": null
            },
            {
              "id": "BehavesLike.Exploit",
              "display_name": "BehavesLike.Exploit",
              "target": null
            },
            {
              "id": "Gen:NN.ZemsilF.34128",
              "display_name": "Gen:NN.ZemsilF.34128",
              "target": null
            },
            {
              "id": "Wacapew.C",
              "display_name": "Wacapew.C",
              "target": null
            },
            {
              "id": "Trojan.Malware.121218",
              "display_name": "Trojan.Malware.121218",
              "target": null
            },
            {
              "id": "RiskWare.HackTool.Agent",
              "display_name": "RiskWare.HackTool.Agent",
              "target": null
            },
            {
              "id": "Artemis",
              "display_name": "Artemis",
              "target": null
            },
            {
              "id": "Trojan.Generic",
              "display_name": "Trojan.Generic",
              "target": null
            },
            {
              "id": "W32.Trojan",
              "display_name": "W32.Trojan",
              "target": null
            },
            {
              "id": "BScope.Riskware",
              "display_name": "BScope.Riskware",
              "target": null
            },
            {
              "id": "Gen:Variant.Bulz",
              "display_name": "Gen:Variant.Bulz",
              "target": null
            },
            {
              "id": "Ransom:Win32/CVE-2017-0147",
              "display_name": "Ransom:Win32/CVE-2017-0147",
              "target": "/malware/Ransom:Win32/CVE-2017-0147"
            },
            {
              "id": "Virus.Ramnit",
              "display_name": "Virus.Ramnit",
              "target": null
            },
            {
              "id": "Virus.Virut",
              "display_name": "Virus.Virut",
              "target": null
            },
            {
              "id": "Adware.KuziTui",
              "display_name": "Adware.KuziTui",
              "target": null
            },
            {
              "id": "AGEN.1141126",
              "display_name": "AGEN.1141126",
              "target": null
            },
            {
              "id": "W32.AIDetect",
              "display_name": "W32.AIDetect",
              "target": null
            },
            {
              "id": "Trojan.Python",
              "display_name": "Trojan.Python",
              "target": null
            },
            {
              "id": "W32.AIDetectVM",
              "display_name": "W32.AIDetectVM",
              "target": null
            },
            {
              "id": "Suspicious.Save",
              "display_name": "Suspicious.Save",
              "target": null
            },
            {
              "id": "Adware.Downware",
              "display_name": "Adware.Downware",
              "target": null
            },
            {
              "id": "Ransom.Win64.Wacatac.oa",
              "display_name": "Ransom.Win64.Wacatac.oa",
              "target": null
            },
            {
              "id": "OpenSubtitles.A",
              "display_name": "OpenSubtitles.A",
              "target": null
            },
            {
              "id": "VB.EmoDldr.4",
              "display_name": "VB.EmoDldr.4",
              "target": null
            },
            {
              "id": "Gen:Variant.Midie",
              "display_name": "Gen:Variant.Midie",
              "target": null
            },
            {
              "id": "HEUR/QVM41.2.DA9B.Malware",
              "display_name": "HEUR/QVM41.2.DA9B.Malware",
              "target": null
            },
            {
              "id": "Gen:Variant.Sirefef",
              "display_name": "Gen:Variant.Sirefef",
              "target": null
            },
            {
              "id": "Macro.Trojan.Dropperd",
              "display_name": "Macro.Trojan.Dropperd",
              "target": null
            },
            {
              "id": "BlackNET RAT",
              "display_name": "BlackNET RAT",
              "target": null
            },
            {
              "id": "Gen:Variant.Ursu",
              "display_name": "Gen:Variant.Ursu",
              "target": null
            },
            {
              "id": "Redcap.rlhse",
              "display_name": "Redcap.rlhse",
              "target": null
            },
            {
              "id": "Trojan.Trickster",
              "display_name": "Trojan.Trickster",
              "target": null
            },
            {
              "id": "HTML_REDIR.SMR",
              "display_name": "HTML_REDIR.SMR",
              "target": null
            },
            {
              "id": "TROJ_FRS.VSNTFK19",
              "display_name": "TROJ_FRS.VSNTFK19",
              "target": null
            },
            {
              "id": "Hoax.JS.Phish",
              "display_name": "Hoax.JS.Phish",
              "target": null
            },
            {
              "id": "JS:Iframe",
              "display_name": "JS:Iframe",
              "target": null
            },
            {
              "id": "Application.SQLCrack",
              "display_name": "Application.SQLCrack",
              "target": null
            },
            {
              "id": "susp.lnk",
              "display_name": "susp.lnk",
              "target": null
            },
            {
              "id": "QVM201.0.B70B.Malware",
              "display_name": "QVM201.0.B70B.Malware",
              "target": null
            },
            {
              "id": "Immortal Stealer",
              "display_name": "Immortal Stealer",
              "target": null
            },
            {
              "id": "WebMonitor RAT",
              "display_name": "WebMonitor RAT",
              "target": null
            },
            {
              "id": "Tor - S0183",
              "display_name": "Tor - S0183",
              "target": null
            },
            {
              "id": "WannaCry",
              "display_name": "WannaCry",
              "target": null
            },
            {
              "id": "WannaCryptor",
              "display_name": "WannaCryptor",
              "target": null
            },
            {
              "id": "WebToolbar",
              "display_name": "WebToolbar",
              "target": null
            },
            {
              "id": "BlackNET",
              "display_name": "BlackNET",
              "target": null
            },
            {
              "id": "DeepScan:Generic.Ransom.GandCrab5",
              "display_name": "DeepScan:Generic.Ransom.GandCrab5",
              "target": null
            },
            {
              "id": "TrojanSpy",
              "display_name": "TrojanSpy",
              "target": null
            },
            {
              "id": "States",
              "display_name": "States",
              "target": null
            },
            {
              "id": "Inmortal",
              "display_name": "Inmortal",
              "target": null
            },
            {
              "id": "Domains",
              "display_name": "Domains",
              "target": null
            },
            {
              "id": "Locky",
              "display_name": "Locky",
              "target": null
            },
            {
              "id": "Delf.NBX",
              "display_name": "Delf.NBX",
              "target": null
            },
            {
              "id": "Gen:NN.ZexaF.32515",
              "display_name": "Gen:NN.ZexaF.32515",
              "target": null
            },
            {
              "id": "FileRepMalware",
              "display_name": "FileRepMalware",
              "target": null
            },
            {
              "id": "Gen:Variant.MSILPerseus",
              "display_name": "Gen:Variant.MSILPerseus",
              "target": null
            },
            {
              "id": "Icefog",
              "display_name": "Icefog",
              "target": null
            },
            {
              "id": "$WebWatson",
              "display_name": "$WebWatson",
              "target": null
            },
            {
              "id": "Agent.AIK.gen",
              "display_name": "Agent.AIK.gen",
              "target": null
            },
            {
              "id": "Agent.AIK.genCIL.StupidCryptor",
              "display_name": "Agent.AIK.genCIL.StupidCryptor",
              "target": null
            },
            {
              "id": "Agent.YPEZ",
              "display_name": "Agent.YPEZ",
              "target": null
            },
            {
              "id": "Application.InnovativSol",
              "display_name": "Application.InnovativSol",
              "target": null
            },
            {
              "id": "Agent.ASO",
              "display_name": "Agent.ASO",
              "target": null
            },
            {
              "id": "S-b748adc5",
              "display_name": "S-b748adc5",
              "target": null
            },
            {
              "id": "W32.eHeur",
              "display_name": "W32.eHeur",
              "target": null
            },
            {
              "id": "Kryptik.GUCB",
              "display_name": "Kryptik.GUCB",
              "target": null
            },
            {
              "id": "AgentTesla",
              "display_name": "AgentTesla",
              "target": null
            },
            {
              "id": "Autoit.bimwt",
              "display_name": "Autoit.bimwt",
              "target": null
            },
            {
              "id": "HEUR:Trojan.OLE2.Alien",
              "display_name": "HEUR:Trojan.OLE2.Alien",
              "target": null
            },
            {
              "id": "AGEN.1038489",
              "display_name": "AGEN.1038489",
              "target": null
            },
            {
              "id": "Gen:Variant.Ser.Strictor",
              "display_name": "Gen:Variant.Ser.Strictor",
              "target": null
            },
            {
              "id": "Packed.Themida.Gen",
              "display_name": "Packed.Themida.Gen",
              "target": null
            },
            {
              "id": "AGEN.1043164",
              "display_name": "AGEN.1043164",
              "target": null
            },
            {
              "id": "TrickBot - S0266",
              "display_name": "TrickBot - S0266",
              "target": null
            },
            {
              "id": "Emotet",
              "display_name": "Emotet",
              "target": null
            },
            {
              "id": "Trojan.PornoAsset",
              "display_name": "Trojan.PornoAsset",
              "target": null
            },
            {
              "id": "Ransom.Win64.PORNOASSET.SM1",
              "display_name": "Ransom.Win64.PORNOASSET.SM1",
              "target": null
            },
            {
              "id": "Gen:Variant.Ulise",
              "display_name": "Gen:Variant.Ulise",
              "target": null
            },
            {
              "id": "Trojan.Win64",
              "display_name": "Trojan.Win64",
              "target": null
            },
            {
              "id": "Dropper.Trojan.Agent",
              "display_name": "Dropper.Trojan.Agent",
              "target": null
            },
            {
              "id": "Heur.BZC.YAX.Pantera.10",
              "display_name": "Heur.BZC.YAX.Pantera.10",
              "target": null
            },
            {
              "id": "malicious.high.ml",
              "display_name": "malicious.high.ml",
              "target": null
            },
            {
              "id": "CVE-2015-1650",
              "display_name": "CVE-2015-1650",
              "target": null
            },
            {
              "id": "Worm.Win64.AutoRun",
              "display_name": "Worm.Win64.AutoRun",
              "target": null
            },
            {
              "id": "AIT.Heur.Cottonmouth.8.78F19BD7",
              "display_name": "AIT.Heur.Cottonmouth.8.78F19BD7",
              "target": null
            },
            {
              "id": "Gen:Variant.Mikey",
              "display_name": "Gen:Variant.Mikey",
              "target": null
            },
            {
              "id": "Trojan.Agent",
              "display_name": "Trojan.Agent",
              "target": null
            },
            {
              "id": "Pua.Gen",
              "display_name": "Pua.Gen",
              "target": null
            },
            {
              "id": "Trojan.Downloader.Generic",
              "display_name": "Trojan.Downloader.Generic",
              "target": null
            },
            {
              "id": "Suspected of Trojan.Downloader.gen",
              "display_name": "Suspected of Trojan.Downloader.gen",
              "target": null
            },
            {
              "id": "HEUR:RemoteAdmin.Generic",
              "display_name": "HEUR:RemoteAdmin.Generic",
              "target": null
            },
            {
              "id": "Gen:Heur.Ransom.HiddenTears",
              "display_name": "Gen:Heur.Ransom.HiddenTears",
              "target": null
            },
            {
              "id": "Nemucod.A",
              "display_name": "Nemucod.A",
              "target": null
            },
            {
              "id": "Backdoor.Hupigon",
              "display_name": "Backdoor.Hupigon",
              "target": null
            },
            {
              "id": "Trojan.Starter JS.Iframe",
              "display_name": "Trojan.Starter JS.Iframe",
              "target": null
            },
            {
              "id": "fake ,promethiumm ,strongpity",
              "display_name": "fake ,promethiumm ,strongpity",
              "target": null
            },
            {
              "id": "PUA.Reg1staid",
              "display_name": "PUA.Reg1staid",
              "target": null
            },
            {
              "id": "Malware.Heur_Generic.A",
              "display_name": "Malware.Heur_Generic.A",
              "target": null
            },
            {
              "id": "Bladabindi.Q",
              "display_name": "Bladabindi.Q",
              "target": null
            },
            {
              "id": "W32.eHeur",
              "display_name": "W32.eHeur",
              "target": null
            },
            {
              "id": "malicious.6e0700",
              "display_name": "malicious.6e0700",
              "target": null
            },
            {
              "id": "Trojan.Inject",
              "display_name": "Trojan.Inject",
              "target": null
            },
            {
              "id": "TSGeneric",
              "display_name": "TSGeneric",
              "target": null
            },
            {
              "id": "RedCap.vneda",
              "display_name": "RedCap.vneda",
              "target": null
            },
            {
              "id": "Trojan.Indiloadz",
              "display_name": "Trojan.Indiloadz",
              "target": null
            },
            {
              "id": "Trojan.Ekstak",
              "display_name": "Trojan.Ekstak",
              "target": null
            },
            {
              "id": "staticrr.paleokits.net",
              "display_name": "staticrr.paleokits.net",
              "target": null
            },
            {
              "id": "MSIL.Downloader",
              "display_name": "MSIL.Downloader",
              "target": null
            },
            {
              "id": "Trojan.Autoruns.GenericKDS",
              "display_name": "Trojan.Autoruns.GenericKDS",
              "target": null
            },
            {
              "id": "MSIL.Trojan.BSE",
              "display_name": "MSIL.Trojan.BSE",
              "target": null
            },
            {
              "id": "Adload.AD81",
              "display_name": "Adload.AD81",
              "target": null
            },
            {
              "id": "Packed.Asprotect",
              "display_name": "Packed.Asprotect",
              "target": null
            },
            {
              "id": "Gen:NN.ZemsilF.34062",
              "display_name": "Gen:NN.ZemsilF.34062",
              "target": null
            },
            {
              "id": "Evo",
              "display_name": "Evo",
              "target": null
            },
            {
              "id": "Agent.pwc",
              "display_name": "Agent.pwc",
              "target": null
            },
            {
              "id": "RiskTool.Phpw",
              "display_name": "RiskTool.Phpw",
              "target": null
            },
            {
              "id": "Gen:Variant.Symmi",
              "display_name": "Gen:Variant.Symmi",
              "target": null
            },
            {
              "id": "Trojan.PWS",
              "display_name": "Trojan.PWS",
              "target": null
            },
            {
              "id": "Generic.BitCoinMiner.3",
              "display_name": "Generic.BitCoinMiner.3",
              "target": null
            },
            {
              "id": "Trojan.Tasker",
              "display_name": "Trojan.Tasker",
              "target": null
            },
            {
              "id": "Gen:NN",
              "display_name": "Gen:NN",
              "target": null
            },
            {
              "id": "Downloader.CertutilURLCache",
              "display_name": "Downloader.CertutilURLCache",
              "target": null
            },
            {
              "id": "Elf",
              "display_name": "Elf",
              "target": null
            },
            {
              "id": "Gen:Heur.MSIL.Androm",
              "display_name": "Gen:Heur.MSIL.Androm",
              "target": null
            },
            {
              "id": "Kryptik.NRD",
              "display_name": "Kryptik.NRD",
              "target": null
            },
            {
              "id": "Riskware",
              "display_name": "Riskware",
              "target": null
            },
            {
              "id": "Kuluoz.B.gen",
              "display_name": "Kuluoz.B.gen",
              "target": null
            },
            {
              "id": "Gen:Variant.RevengeRat",
              "display_name": "Gen:Variant.RevengeRat",
              "target": null
            },
            {
              "id": "Gen:Variant.Mikey",
              "display_name": "Gen:Variant.Mikey",
              "target": null
            },
            {
              "id": "VB.Chronos.7",
              "display_name": "VB.Chronos.7",
              "target": null
            },
            {
              "id": "Kryptik.NOE",
              "display_name": "Kryptik.NOE",
              "target": null
            },
            {
              "id": "HEUR:WebToolbar.Generic",
              "display_name": "HEUR:WebToolbar.Generic",
              "target": null
            },
            {
              "id": "Gen:Variant.Barys",
              "display_name": "Gen:Variant.Barys",
              "target": null
            },
            {
              "id": "Backdoor.Xtreme",
              "display_name": "Backdoor.Xtreme",
              "target": null
            },
            {
              "id": "Trojan.MSIL",
              "display_name": "Trojan.MSIL",
              "target": null
            },
            {
              "id": "Gen:Variant.Graftor",
              "display_name": "Gen:Variant.Graftor",
              "target": null
            },
            {
              "id": "Backdoor.Agent",
              "display_name": "Backdoor.Agent",
              "target": null
            },
            {
              "id": "Unsafe",
              "display_name": "Unsafe",
              "target": null
            },
            {
              "id": "Trojan.PHP.Agent",
              "display_name": "Trojan.PHP.Agent",
              "target": null
            },
            {
              "id": "Trojan.Agent",
              "display_name": "Trojan.Agent",
              "target": null
            },
            {
              "id": "HEUR:Exploit.Generic",
              "display_name": "HEUR:Exploit.Generic",
              "target": null
            },
            {
              "id": "Ransom_WCRY.SMALYM",
              "display_name": "Ransom_WCRY.SMALYM",
              "target": null
            },
            {
              "id": "Ransom_WCRY.SMJ",
              "display_name": "Ransom_WCRY.SMJ",
              "target": null
            },
            {
              "id": "Auslogics",
              "display_name": "Auslogics",
              "target": null
            },
            {
              "id": "Gen:Variant.Jaiko",
              "display_name": "Gen:Variant.Jaiko",
              "target": null
            },
            {
              "id": "Exploit.W32.Agent",
              "display_name": "Exploit.W32.Agent",
              "target": null
            },
            {
              "id": "Trojan.Cud.Gen",
              "display_name": "Trojan.Cud.Gen",
              "target": null
            },
            {
              "id": "Trojan.DOC.Downloader",
              "display_name": "Trojan.DOC.Downloader",
              "target": null
            },
            {
              "id": "Backdoor.MSIL.Agent",
              "display_name": "Backdoor.MSIL.Agent",
              "target": null
            },
            {
              "id": "Gen:Trojan.Heur2.LPTbHW@W64.HfsAutoB",
              "display_name": "Gen:Trojan.Heur2.LPTbHW@W64.HfsAutoB",
              "target": null
            },
            {
              "id": "Gen:Variant.Kazy",
              "display_name": "Gen:Variant.Kazy",
              "target": null
            },
            {
              "id": "Gen:Variant.Zusy",
              "display_name": "Gen:Variant.Zusy",
              "target": null
            },
            {
              "id": "Ransom.WannaCrypt",
              "display_name": "Ransom.WannaCrypt",
              "target": null
            },
            {
              "id": "Generic.ServStart.A",
              "display_name": "Generic.ServStart.A",
              "target": null
            },
            {
              "id": "Trojan.Wanna",
              "display_name": "Trojan.Wanna",
              "target": null
            },
            {
              "id": "Generic.MSIL.Bladabindi",
              "display_name": "Generic.MSIL.Bladabindi",
              "target": null
            },
            {
              "id": "TROJ_GEN.R002C0OG518",
              "display_name": "TROJ_GEN.R002C0OG518",
              "target": null
            },
            {
              "id": "Trojan.Chapak",
              "display_name": "Trojan.Chapak",
              "target": null
            },
            {
              "id": "Indiloadz.BB",
              "display_name": "Indiloadz.BB",
              "target": null
            },
            {
              "id": "BehavBehavesLike.PUPXBI",
              "display_name": "BehavBehavesLike.PUPXBI",
              "target": null
            },
            {
              "id": "DeepScan:Generic.SpyAgent.6",
              "display_name": "DeepScan:Generic.SpyAgent.6",
              "target": null
            },
            {
              "id": "Python.KeyLogger",
              "display_name": "Python.KeyLogger",
              "target": null
            },
            {
              "id": "GameHack.CRS",
              "display_name": "GameHack.CRS",
              "target": null
            },
            {
              "id": "Generic.MSIL.PasswordStealer",
              "display_name": "Generic.MSIL.PasswordStealer",
              "target": null
            },
            {
              "id": "PSW.Agent",
              "display_name": "PSW.Agent",
              "target": null
            },
            {
              "id": "malicious.8c45ba",
              "display_name": "malicious.8c45ba",
              "target": null
            },
            {
              "id": "Dropper.Binder",
              "display_name": "Dropper.Binder",
              "target": null
            },
            {
              "id": "Constructor.MSIL",
              "display_name": "Constructor.MSIL",
              "target": null
            },
            {
              "id": "Linux.Agent",
              "display_name": "Linux.Agent",
              "target": null
            },
            {
              "id": "Virus.3DMax.Script",
              "display_name": "Virus.3DMax.Script",
              "target": null
            },
            {
              "id": "ScrInject.B",
              "display_name": "ScrInject.B",
              "target": null
            },
            {
              "id": "Trojan.WisdomEyes.16070401.9500",
              "display_name": "Trojan.WisdomEyes.16070401.9500",
              "target": null
            },
            {
              "id": "Application.SearchProtect",
              "display_name": "Application.SearchProtect",
              "target": null
            },
            {
              "id": "JS:Trojan.Clicker",
              "display_name": "JS:Trojan.Clicker",
              "target": null
            },
            {
              "id": "Faceliker.A",
              "display_name": "Faceliker.A",
              "target": null
            },
            {
              "id": "JS:Trojan.JS.Faceliker",
              "display_name": "JS:Trojan.JS.Faceliker",
              "target": null
            },
            {
              "id": "Constructor.MSIL  Linux.Agent",
              "display_name": "Constructor.MSIL  Linux.Agent",
              "target": null
            },
            {
              "id": "PowerShell.Trojan",
              "display_name": "PowerShell.Trojan",
              "target": null
            },
            {
              "id": "HTML:Script",
              "display_name": "HTML:Script",
              "target": null
            },
            {
              "id": "ScrInject.B",
              "display_name": "ScrInject.B",
              "target": null
            },
            {
              "id": "W32.AIDetectVM",
              "display_name": "W32.AIDetectVM",
              "target": null
            },
            {
              "id": "HackTool.CheatEngine",
              "display_name": "HackTool.CheatEngine",
              "target": null
            },
            {
              "id": "Injector.CLDS",
              "display_name": "Injector.CLDS",
              "target": null
            },
            {
              "id": "VB.Downloader.2",
              "display_name": "VB.Downloader.2",
              "target": null
            },
            {
              "id": "malicious.3e78cc",
              "display_name": "malicious.3e78cc",
              "target": null
            },
            {
              "id": "malicious.d800d6",
              "display_name": "malicious.d800d6",
              "target": null
            },
            {
              "id": "VB.PwShell.2",
              "display_name": "VB.PwShell.2",
              "target": null
            },
            {
              "id": "Backdoor.RBot",
              "display_name": "Backdoor.RBot",
              "target": null
            },
            {
              "id": "malicious.71b1a8",
              "display_name": "malicious.71b1a8",
              "target": null
            },
            {
              "id": "TrojanSpy.KeyLogger",
              "display_name": "TrojanSpy.KeyLogger",
              "target": null
            },
            {
              "id": "Injector.JDO",
              "display_name": "Injector.JDO",
              "target": null
            },
            {
              "id": "Heur.Msword.Gen",
              "display_name": "Heur.Msword.Gen",
              "target": null
            },
            {
              "id": "PSW.Discord",
              "display_name": "PSW.Discord",
              "target": null
            },
            {
              "id": "Packed.VMProtect",
              "display_name": "Packed.VMProtect",
              "target": null
            },
            {
              "id": "HEUR:AdWare.StartSurf",
              "display_name": "HEUR:AdWare.StartSurf",
              "target": null
            },
            {
              "id": "Gen:Heur.NoobyProtect",
              "display_name": "Gen:Heur.NoobyProtect",
              "target": null
            },
            {
              "id": "CIL.HeapOverride",
              "display_name": "CIL.HeapOverride",
              "target": null
            },
            {
              "id": "HEUR:Trojan.Tasker",
              "display_name": "HEUR:Trojan.Tasker",
              "target": null
            },
            {
              "id": "XLM.Trojan.Abracadabra.27",
              "display_name": "XLM.Trojan.Abracadabra.27",
              "target": null
            },
            {
              "id": "HEUR:Backdoor.MSIL.NanoBot",
              "display_name": "HEUR:Backdoor.MSIL.NanoBot",
              "target": null
            },
            {
              "id": "Trojan.PSW.Mimikatz",
              "display_name": "Trojan.PSW.Mimikatz",
              "target": null
            },
            {
              "id": "TrojanSpy.Python",
              "display_name": "TrojanSpy.Python",
              "target": null
            },
            {
              "id": "Trojan.Ole2.Vbs",
              "display_name": "Trojan.Ole2.Vbs",
              "target": null
            },
            {
              "id": "Exploit.MSOffice",
              "display_name": "Exploit.MSOffice",
              "target": null
            },
            {
              "id": "DeepScan:Generic.Ransom.AmnesiaE",
              "display_name": "DeepScan:Generic.Ransom.AmnesiaE",
              "target": null
            },
            {
              "id": "Wacatac.D6",
              "display_name": "Wacatac.D6",
              "target": null
            },
            {
              "id": "Backdoor.Androm",
              "display_name": "Backdoor.Androm",
              "target": null
            },
            {
              "id": "Packed.NetSeal",
              "display_name": "Packed.NetSeal",
              "target": null
            },
            {
              "id": "Trojan.MSIL.Injector",
              "display_name": "Trojan.MSIL.Injector",
              "target": null
            },
            {
              "id": "Trojan.PWS.Agent",
              "display_name": "Trojan.PWS.Agent",
              "target": null
            },
            {
              "id": "TScope.Trojan",
              "display_name": "TScope.Trojan",
              "target": null
            },
            {
              "id": "PSW.Stealer",
              "display_name": "PSW.Stealer",
              "target": null
            },
            {
              "id": "Trojan.PackedNET",
              "display_name": "Trojan.PackedNET",
              "target": null
            },
            {
              "id": "Trojan.Java",
              "display_name": "Trojan.Java",
              "target": null
            },
            {
              "id": "MalwareX",
              "display_name": "MalwareX",
              "target": null
            },
            {
              "id": "Trojan.PSW.Python",
              "display_name": "Trojan.PSW.Python",
              "target": null
            },
            {
              "id": "malicious.11abfc",
              "display_name": "malicious.11abfc",
              "target": null
            },
            {
              "id": "Generic.ASMalwS",
              "display_name": "Generic.ASMalwS",
              "target": null
            },
            {
              "id": "HEUR:Trojan.MSIL.Tasker",
              "display_name": "HEUR:Trojan.MSIL.Tasker",
              "target": null
            },
            {
              "id": "PossibleThreat.PALLAS",
              "display_name": "PossibleThreat.PALLAS",
              "target": null
            },
            {
              "id": "Backdoor.Poison",
              "display_name": "Backdoor.Poison",
              "target": null
            },
            {
              "id": "Generic.MSIL.LimeRAT",
              "display_name": "Generic.MSIL.LimeRAT",
              "target": null
            },
            {
              "id": "PWS-FCZZ",
              "display_name": "PWS-FCZZ",
              "target": null
            },
            {
              "id": "Trojan.Script",
              "display_name": "Trojan.Script",
              "target": null
            },
            {
              "id": "Gen:Heur.MSIL.Inject",
              "display_name": "Gen:Heur.MSIL.Inject",
              "target": null
            },
            {
              "id": "Trojan.PWS.Growtopia",
              "display_name": "Trojan.PWS.Growtopia",
              "target": null
            },
            {
              "id": "Spyware.Bobik",
              "display_name": "Spyware.Bobik",
              "target": null
            },
            {
              "id": "HackTool.BruteForce",
              "display_name": "HackTool.BruteForce",
              "target": null
            },
            {
              "id": "Hack.Patcher",
              "display_name": "Hack.Patcher",
              "target": null
            },
            {
              "id": "PWS.p",
              "display_name": "PWS.p",
              "target": null
            },
            {
              "id": "Suppobox",
              "display_name": "Suppobox",
              "target": null
            },
            {
              "id": "index.php",
              "display_name": "index.php",
              "target": null
            },
            {
              "id": "Packed.VMProtect",
              "display_name": "Packed.VMProtect",
              "target": null
            },
            {
              "id": "SmokeLoader",
              "display_name": "SmokeLoader",
              "target": null
            },
            {
              "id": "Generic.Malware",
              "display_name": "Generic.Malware",
              "target": null
            },
            {
              "id": "SNH:Script [Dropper]",
              "display_name": "SNH:Script [Dropper]",
              "target": null
            },
            {
              "id": "HEUR:Trojan.MSOffice.SAgent",
              "display_name": "HEUR:Trojan.MSOffice.SAgent",
              "target": null
            },
            {
              "id": "Script.INF",
              "display_name": "Script.INF",
              "target": null
            },
            {
              "id": "JS:Trojan.JS.Likejack",
              "display_name": "JS:Trojan.JS.Likejack",
              "target": null
            },
            {
              "id": "SNH:Script [Dropper]",
              "display_name": "SNH:Script [Dropper]",
              "target": null
            },
            {
              "id": "Trojan.JS.Agent",
              "display_name": "Trojan.JS.Agent",
              "target": null
            },
            {
              "id": "APT Notes",
              "display_name": "APT Notes",
              "target": null
            },
            {
              "id": "susp.rtf.objupdate",
              "display_name": "susp.rtf.objupdate",
              "target": null
            },
            {
              "id": "RedCap.zoohz",
              "display_name": "RedCap.zoohz",
              "target": null
            },
            {
              "id": "Trojan.Tasker",
              "display_name": "Trojan.Tasker",
              "target": null
            },
            {
              "id": "virus.office.qexvmc",
              "display_name": "virus.office.qexvmc",
              "target": null
            },
            {
              "id": "Trojan.KillProc",
              "display_name": "Trojan.KillProc",
              "target": null
            },
            {
              "id": "Generic.MSIL.GrwtpStealer.1",
              "display_name": "Generic.MSIL.GrwtpStealer.1",
              "target": null
            },
            {
              "id": "Suspicious.Cloud",
              "display_name": "Suspicious.Cloud",
              "target": null
            },
            {
              "id": "PowerShell.DownLoader",
              "display_name": "PowerShell.DownLoader",
              "target": null
            },
            {
              "id": "Downldr.gen",
              "display_name": "Downldr.gen",
              "target": null
            },
            {
              "id": "AGEN.1030939",
              "display_name": "AGEN.1030939",
              "target": null
            },
            {
              "id": "HackTool.Binder",
              "display_name": "HackTool.Binder",
              "target": null
            },
            {
              "id": "Trojan.Inject",
              "display_name": "Trojan.Inject",
              "target": null
            },
            {
              "id": "Dldr.Agent",
              "display_name": "Dldr.Agent",
              "target": null
            },
            {
              "id": "Dropper.MSIL",
              "display_name": "Dropper.MSIL",
              "target": null
            },
            {
              "id": "Trojan.VBKryjetor",
              "display_name": "Trojan.VBKryjetor",
              "target": null
            },
            {
              "id": "PWSX",
              "display_name": "PWSX",
              "target": null
            },
            {
              "id": "VB:Trojan.VBA.Agent",
              "display_name": "VB:Trojan.VBA.Agent",
              "target": null
            },
            {
              "id": "HEUR:Trojan.MSOffice.Stratos",
              "display_name": "HEUR:Trojan.MSOffice.Stratos",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1071.004",
              "name": "DNS",
              "display_name": "T1071.004 - DNS"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1059.007",
              "name": "JavaScript",
              "display_name": "T1059.007 - JavaScript"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1068",
              "name": "Exploitation for Privilege Escalation",
              "display_name": "T1068 - Exploitation for Privilege Escalation"
            },
            {
              "id": "TA0029",
              "name": "Privilege Escalation",
              "display_name": "TA0029 - Privilege Escalation"
            },
            {
              "id": "T1449",
              "name": "Exploit SS7 to Redirect Phone Calls/SMS",
              "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
            },
            {
              "id": "T1190",
              "name": "Exploit Public-Facing Application",
              "display_name": "T1190 - Exploit Public-Facing Application"
            },
            {
              "id": "T1210",
              "name": "Exploitation of Remote Services",
              "display_name": "T1210 - Exploitation of Remote Services"
            },
            {
              "id": "T1450",
              "name": "Exploit SS7 to Track Device Location",
              "display_name": "T1450 - Exploit SS7 to Track Device Location"
            },
            {
              "id": "T1211",
              "name": "Exploitation for Defense Evasion",
              "display_name": "T1211 - Exploitation for Defense Evasion"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "TA0011",
              "name": "Command and Control",
              "display_name": "TA0011 - Command and Control"
            },
            {
              "id": "T1412",
              "name": "Capture SMS Messages",
              "display_name": "T1412 - Capture SMS Messages"
            },
            {
              "id": "T1454",
              "name": "Malicious SMS Message",
              "display_name": "T1454 - Malicious SMS Message"
            },
            {
              "id": "T1001",
              "name": "Data Obfuscation",
              "display_name": "T1001 - Data Obfuscation"
            },
            {
              "id": "T1114",
              "name": "Email Collection",
              "display_name": "T1114 - Email Collection"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1498",
              "name": "Network Denial of Service",
              "display_name": "T1498 - Network Denial of Service"
            },
            {
              "id": "T1496",
              "name": "Resource Hijacking",
              "display_name": "T1496 - Resource Hijacking"
            },
            {
              "id": "T1176",
              "name": "Browser Extensions",
              "display_name": "T1176 - Browser Extensions"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 338,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 1184,
            "FileHash-SHA1": 949,
            "FileHash-SHA256": 3712,
            "URL": 2925,
            "domain": 627,
            "hostname": 1319,
            "CVE": 26,
            "email": 8,
            "CIDR": 2
          },
          "indicator_count": 10752,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 223,
          "modified_text": "904 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "654d29ff31857aafba0358e1",
          "name": "Lucky Mouse APT27 | Feodo Tracker | Malicious Tor Server | Apple iOS",
          "description": "",
          "modified": "2023-12-09T03:01:57.989000",
          "created": "2023-11-09T18:50:39.675000",
          "tags": [
            "ssl certificate",
            "historical ssl",
            "communicating",
            "contacted",
            "resolutions",
            "whois record",
            "whois whois",
            "whois parent",
            "whois siblings",
            "skynet",
            "threat report",
            "ip summary",
            "url summary",
            "summary",
            "sample",
            "samples",
            "detection list",
            "blacklist",
            "cisco umbrella",
            "site",
            "safe site",
            "million",
            "team",
            "microsoft",
            "back",
            "download",
            "phishing",
            "union",
            "bank",
            "malicious site",
            "blacklist http",
            "exit",
            "traffic",
            "node tcp",
            "tor known",
            "tor relayrouter",
            "et tor",
            "known tor",
            "relayrouter",
            "anonymizer",
            "spammer",
            "malware",
            "dropped",
            "unlocker",
            "http",
            "critical risk",
            "redline stealer",
            "core",
            "hacktool",
            "execution",
            "type win32",
            "exe size",
            "first seen",
            "file name",
            "avast win32",
            "win32",
            "avg win32",
            "fortinet",
            "vitro",
            "mb first",
            "rmndrp",
            "clean mx",
            "undetected dns8",
            "undetected vx",
            "sophos",
            "vault",
            "zdb zeus",
            "cmc threat",
            "snort ip",
            "feodo tracker",
            "cybereason",
            "send bug",
            "pe yandex",
            "no data",
            "tag count",
            "count blacklist",
            "tag tag",
            "algorithm",
            "v3 serial",
            "number",
            "issuer",
            "cus cnr3",
            "olet",
            "subject public",
            "key info",
            "key algorithm",
            "key identifier",
            "first",
            "seen",
            "valid",
            "no na",
            "no no",
            "ip security",
            "cndst root",
            "ca x3",
            "ca id",
            "research group",
            "cnisrg root",
            "no expired",
            "mozilla",
            "android",
            "malicious red team",
            "tsara brashears",
            "cyber stalking",
            "malvertizing",
            "invasion of privacy",
            "threat",
            "adult content",
            "apple",
            "iphone unlocker",
            "android",
            "exploited spyware",
            "malware host",
            "brute force",
            "revenge-rat",
            "banker",
            "evasive",
            "domain",
            "redline",
            "stealer",
            "phishing",
            "ramnit",
            "unreliable subdomains",
            "dridex",
            "gating",
            "msil",
            "rat",
            "loki",
            "network",
            "hacking",
            "sinkhole",
            "azorult",
            "c2",
            "historicalandnew",
            "targeted attack",
            "puffstealer",
            "rultazo",
            "lokibot",
            "loki pws",
            "burkina",
            "banker,dde,dridex,exploit",
            "banker,dridex,evasive",
            "trickbot",
            "ransomware,torrentlocker",
            "exploit_source",
            "blacknet",
            "FileRepMalware",
            "linux agent",
            "blacknet",
            "ios",
            "phishing paypal",
            "tagging",
            "defacement",
            "hit",
            "bounty",
            "phishing site",
            "malware site",
            "malware download",
            "endangerment",
            "Malicious domain - SANS Internet Storm Center",
            "evasive,msil,rat,revenge-rat",
            "prism_setting",
            "prism_object",
            "static engine",
            "social engineering",
            "jansky",
            "worm",
            "network rat",
            "networm",
            "Loki Password Stealer (PWS)",
            "South Carolina Federal Credit Union phishing",
            "darkweb",
            "yandex",
            "redirectors",
            "blacknet threats",
            "phishing,ransomware,sinkhole",
            "wanacrypt0r,wannacry,wcry",
            "tor c++",
            "tor c++ client",
            "python user",
            "js user",
            "hacker",
            "hijacker",
            "heur",
            "maltiverse",
            "alexa top",
            "exploit",
            "riskware",
            "unsafe",
            "outbreak",
            "downer",
            "shell",
            "mediamagnet",
            "sality",
            "swrort",
            "adaptivebee",
            "unruy",
            "iobit",
            "dropper",
            "trojanx",
            "artemis",
            "installcore",
            "webshell",
            "crack",
            "webtoolbar",
            "search live",
            "api blog",
            "docs pricing",
            "november",
            "de indicators",
            "domains",
            "hashes",
            "__convergedlogin_pcustomizationloader_44b450e8d543eb53930d",
            "malicious url",
            "financial",
            "blacknet rat",
            "azorult",
            "stealer",
            "deep scan",
            "blacklist https",
            "referrer",
            "collections kp",
            "incident ip",
            "sneaky server",
            "replacement",
            "unauthorized",
            "emotet",
            "noname057",
            "generic malware",
            "engineering",
            "cyber threat",
            "facebook",
            "paypal",
            "dropbox",
            "united",
            "america",
            "banking",
            "wells fargo",
            "steam",
            "twitter",
            "sliver",
            "daum",
            "swift",
            "runescape",
            "betabot",
            "district",
            "iframe",
            "alexa",
            "downldr",
            "agent",
            "presenoker",
            "bladabindi",
            "live",
            "conduit",
            "pony",
            "covid19",
            "malicious",
            "cobalt strike",
            "suppobox",
            "ramnit",
            "meterpreter",
            "virut",
            "njrat",
            "pykspa",
            "asyncrat",
            "downloader",
            "fakealert",
            "binder",
            "virustotal",
            "formbook",
            "necurs",
            "trojan",
            "msil",
            "hiloti",
            "vawtrak",
            "simda",
            "kraken",
            "solimba",
            "icedid",
            "redirector",
            "suspic",
            "amadey",
            "raccoon",
            "nanocore rat",
            "revenge rat",
            "genkryptik",
            "fuery",
            "wacatac",
            "service",
            "cloudeye",
            "tinba",
            "domaiq",
            "ave maria",
            "zeus",
            "ransomware",
            "zbot",
            "generic",
            "trojanspy",
            "states",
            "inmortal",
            "locky",
            "strike",
            "china cobalt",
            "keybase",
            "cutwail",
            "citadel",
            "radamant",
            "kovter",
            "bradesco",
            "nymaim",
            "amonetize",
            "bondat",
            "ghost rat",
            "vjw0rm",
            "bandoo",
            "matsnu",
            "dnspionage",
            "darkgate",
            "vidar",
            "keylogger",
            "remcos",
            "agenttesla",
            "detplock",
            "win64",
            "smokeloader",
            "agent tesla",
            "kgs0",
            "kls0",
            "urls",
            "type name",
            "dns replication",
            "date",
            "domain",
            "win32 exe",
            "files",
            "detections type",
            "name",
            "drpsuinstaller",
            "vdfsurfs",
            "opera",
            "icwrmind",
            "notepad",
            "installer",
            "miner",
            "unknown",
            "networm",
            "houdini",
            "quasar rat",
            "gamehack",
            "dbatloader",
            "qakbot",
            "ursnif",
            "CVE-2005-1790",
            "CVE-2009-3672",
            "CVE-2010-3962",
            "CVE-2012-3993",
            "CVE-2014-6332",
            "CVE-2017-11882",
            "CVE-2020-0601",
            "CVE-2020-0674",
            "hallrender.com",
            "brian sabey",
            "insurance",
            "botnetwork",
            "botmaster",
            "command_and_control",
            "CVE-2021-27065",
            "CVE-2021-40444",
            "CVE-2023-4966",
            "CVE-2017-0199",
            "CVE-2018-4893",
            "CVE-2010-3333",
            "CVE-2015-1641",
            "CVE-2017-0147",
            "CVE-2017-8570",
            "CVE-2018-0802",
            "CVE-2018-8373",
            "CVE-2017-8759",
            "CVE-2018-8453",
            "CVE-2014-3153",
            "CVE-2015-1650",
            "CVE-2017-0143",
            "CVE-2017-8464",
            "Icefog",
            "Delf.NBX",
            "$WebWatson",
            "Gen:Heur.Ransom.HiddenTears",
            "mobilekey.pw",
            "bitbucket.org",
            "Anomalous.100%",
            "malware distribution site",
            "gootkit",
            "edsaid",
            "rightsaided",
            "betabot",
            "cobaltstrike4.tk",
            "mas.to",
            "BehavesLike.YahLover",
            "srdvd16010404",
            "languageenu",
            "buildno",
            "channelisales",
            "vendorname2581",
            "osregion",
            "device",
            "systemlocale",
            "majorver16",
            "quasar",
            "find",
            "lockbit",
            "chaos",
            "ransomexx",
            "grandoreiro",
            "evilnum",
            "banker"
          ],
          "references": [
            "https://hybrid-analysis.com/sample/6765f47ea77c8274c8e4973ed95aedf59e75998c62f6029e23c58cdf36ed85ba/654afdbdc621e7037801cce7",
            "20.99.186.246 exploit source",
            "fp2e7a.wpc.2be4.phicdn.net",
            "https://www.anyxxxtube.net/search-porn/tsara-brashears/ (phishing, ELF, Prism.exe found)",
            "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian (password cracker)",
            "http://182.22.25.124:7878/182.22.25.124:443     (malicious dropper)",
            "init.ess.apple.com         (malicious code script)",
            "https://www.pornhub.com/video/search?search=tsara+brashears (Malicious PW cracker | stylebk.css stylesheets - not found )",
            "https://urlscan.io/result/a328d9ff-fb49-4078-960d-a757fd41404f/#indicators",
            "VirusTotal Link: https://www.virustotal.com/gui/ip-address/20.99.186.246/detection",
            "Abuse IPDB Link: https://www.abuseipdb.com/check/20.99.186.246",
            "IPv4 45.12.253.72.            command_and_control",
            "Hostname: ddos.dnsnb8.net                        command_and_control",
            "IPv4 95.213.186.51              command_and_control",
            "Hostname: www.supernetforme.com      command_and_control",
            "IPv4 103.224.182.246        command_and_control",
            "IPv4 72.251.233.245           command_and_control",
            "IPv4 63.251.106.25             command_and_control",
            "IPv4 45.15.156.208            command_and_control",
            "IPv4 104.247.81.51             command_and_control",
            "http://ambisexual.phone-sex-blogs.com/http:/ambisexual.phone-sex-blogs.com/images/thumbnails/pic118.jpg             (phishing)",
            "https://downloaddevtools.ir/     (phishing)",
            "happylifehappywife.com",
            "apples.encryptedwork.com        (Interesting in the blacknet)",
            "https://itunes.apple.com/app/apple-store/id284815942/us/app/samsung-galaxy-watch-gear-s/id1117310635.                   (iOS unlocker and hijacker)",
            "https://www.anyxxxtube.net/media/favicon/apple              (password cracker and iOS hijacker)",
            "https://www.apple.com/shop/browse/open/country_selector     (exploit)",
            "www.norad.mil   (federal tracking tool used by attorneys, law firms, and private investigators 'licensed or unlicensed') hi!",
            "http://init-p01st.push.apple.com/bag            (malicious web creator)",
            "opencve.djgummikuh.de        (CVE dispensary)",
            "Maltiverse Research Team",
            "URLscan.io",
            "Deep Research",
            "Hybrid Analysis",
            "URLhaus Abuse.ch",
            "Cyber Threat Coalition",
            "ThreatFox Abuse.ch"
          ],
          "public": 1,
          "adversary": "Lucky Mouse APT27 | NoName057(16) |  Unnamed",
          "targeted_countries": [
            "United States of America",
            "France",
            "Spain"
          ],
          "malware_families": [
            {
              "id": "Feodo",
              "display_name": "Feodo",
              "target": null
            },
            {
              "id": "Dridex",
              "display_name": "Dridex",
              "target": null
            },
            {
              "id": "Redline Stealer",
              "display_name": "Redline Stealer",
              "target": null
            },
            {
              "id": "Ramnit.N",
              "display_name": "Ramnit.N",
              "target": null
            },
            {
              "id": "Loki Bot",
              "display_name": "Loki Bot",
              "target": null
            },
            {
              "id": "Loki Password Stealer (PWS)",
              "display_name": "Loki Password Stealer (PWS)",
              "target": null
            },
            {
              "id": "AZORult",
              "display_name": "AZORult",
              "target": null
            },
            {
              "id": "Zbd Zeus",
              "display_name": "Zbd Zeus",
              "target": null
            },
            {
              "id": "Trojan:MSIL/Burkina",
              "display_name": "Trojan:MSIL/Burkina",
              "target": "/malware/Trojan:MSIL/Burkina"
            },
            {
              "id": "Generic.TrickBot.1",
              "display_name": "Generic.TrickBot.1",
              "target": null
            },
            {
              "id": "Exploit.CVE",
              "display_name": "Exploit.CVE",
              "target": null
            },
            {
              "id": "Injector.IS.gen",
              "display_name": "Injector.IS.gen",
              "target": null
            },
            {
              "id": "Gen:Variant.Razy",
              "display_name": "Gen:Variant.Razy",
              "target": null
            },
            {
              "id": "Trojan.Androm.Gen",
              "display_name": "Trojan.Androm.Gen",
              "target": null
            },
            {
              "id": "HEUR:Trojan.Linux.Agent",
              "display_name": "HEUR:Trojan.Linux.Agent",
              "target": null
            },
            {
              "id": "BScope.Trojan",
              "display_name": "BScope.Trojan",
              "target": null
            },
            {
              "id": "VBA.Downloader",
              "display_name": "VBA.Downloader",
              "target": null
            },
            {
              "id": "Trojan.Notifier",
              "display_name": "Trojan.Notifier",
              "target": null
            },
            {
              "id": "HEUR:Trojan.MSOffice.Alien",
              "display_name": "HEUR:Trojan.MSOffice.Alien",
              "target": null
            },
            {
              "id": "Unsafe.AI_Score_100%",
              "display_name": "Unsafe.AI_Score_100%",
              "target": null
            },
            {
              "id": "Gen:Variant.Johnnie",
              "display_name": "Gen:Variant.Johnnie",
              "target": null
            },
            {
              "id": "DangerousObject.Multi",
              "display_name": "DangerousObject.Multi",
              "target": null
            },
            {
              "id": "Trojan:Python/Downldr",
              "display_name": "Trojan:Python/Downldr",
              "target": "/malware/Trojan:Python/Downldr"
            },
            {
              "id": "Trojan:Linux/Downldr",
              "display_name": "Trojan:Linux/Downldr",
              "target": "/malware/Trojan:Linux/Downldr"
            },
            {
              "id": "Trojan:VBA/Downldr",
              "display_name": "Trojan:VBA/Downldr",
              "target": "/malware/Trojan:VBA/Downldr"
            },
            {
              "id": "TrojanDownloader:Linux/Downldr",
              "display_name": "TrojanDownloader:Linux/Downldr",
              "target": "/malware/TrojanDownloader:Linux/Downldr"
            },
            {
              "id": "Kryptik.FPH.gen",
              "display_name": "Kryptik.FPH.gen",
              "target": null
            },
            {
              "id": "TROJ_FRS.VSNTFK19",
              "display_name": "TROJ_FRS.VSNTFK19",
              "target": null
            },
            {
              "id": "Trojan.Ransom.GenericKD",
              "display_name": "Trojan.Ransom.GenericKD",
              "target": null
            },
            {
              "id": "Phish.JAT",
              "display_name": "Phish.JAT",
              "target": null
            },
            {
              "id": "Phishing.HTML",
              "display_name": "Phishing.HTML",
              "target": null
            },
            {
              "id": "Generic.ASMalwS",
              "display_name": "Generic.ASMalwS",
              "target": null
            },
            {
              "id": "Phish.AB",
              "display_name": "Phish.AB",
              "target": null
            },
            {
              "id": "Generic.Malware",
              "display_name": "Generic.Malware",
              "target": null
            },
            {
              "id": "ml.Generic",
              "display_name": "ml.Generic",
              "target": null
            },
            {
              "id": "Xegumumune.8596c22f",
              "display_name": "Xegumumune.8596c22f",
              "target": null
            },
            {
              "id": "Generic.Malware.SMYB",
              "display_name": "Generic.Malware.SMYB",
              "target": null
            },
            {
              "id": "malicious.moderate.ml",
              "display_name": "malicious.moderate.ml",
              "target": null
            },
            {
              "id": "Agent.NBAE",
              "display_name": "Agent.NBAE",
              "target": null
            },
            {
              "id": "AGEN.1045227",
              "display_name": "AGEN.1045227",
              "target": null
            },
            {
              "id": "Riskware.Agent",
              "display_name": "Riskware.Agent",
              "target": null
            },
            {
              "id": "Gen:Variant.Cerbu",
              "display_name": "Gen:Variant.Cerbu",
              "target": null
            },
            {
              "id": "IL:Trojan.MSILZilla",
              "display_name": "IL:Trojan.MSILZilla",
              "target": null
            },
            {
              "id": "Dropped:Generic.Ransom.DMR",
              "display_name": "Dropped:Generic.Ransom.DMR",
              "target": null
            },
            {
              "id": "Delf.NBX",
              "display_name": "Delf.NBX",
              "target": null
            },
            {
              "id": "malicious.f01f67",
              "display_name": "malicious.f01f67",
              "target": null
            },
            {
              "id": "AGEN.1144657",
              "display_name": "AGEN.1144657",
              "target": null
            },
            {
              "id": "Trojan.Heur",
              "display_name": "Trojan.Heur",
              "target": null
            },
            {
              "id": "Trojan.Malware.300983",
              "display_name": "Trojan.Malware.300983",
              "target": null
            },
            {
              "id": "SdBot.CAOC",
              "display_name": "SdBot.CAOC",
              "target": null
            },
            {
              "id": "Trojan.DelShad",
              "display_name": "Trojan.DelShad",
              "target": null
            },
            {
              "id": "Exploit CVE-2017-11882",
              "display_name": "Exploit CVE-2017-11882",
              "target": null
            },
            {
              "id": "GameHack.NL",
              "display_name": "GameHack.NL",
              "target": null
            },
            {
              "id": "JS:Trojan.HideLink",
              "display_name": "JS:Trojan.HideLink",
              "target": null
            },
            {
              "id": "Script.Agent",
              "display_name": "Script.Agent",
              "target": null
            },
            {
              "id": "Macro.Agent",
              "display_name": "Macro.Agent",
              "target": null
            },
            {
              "id": "Macro.Downloader.AMIP",
              "display_name": "Macro.Downloader.AMIP",
              "target": null
            },
            {
              "id": "Trojan.VBA",
              "display_name": "Trojan.VBA",
              "target": null
            },
            {
              "id": "HEUR.VBA.Trojan",
              "display_name": "HEUR.VBA.Trojan",
              "target": null
            },
            {
              "id": "VB.EmoooDldr.10",
              "display_name": "VB.EmoooDldr.10",
              "target": null
            },
            {
              "id": "VB:Trojan.Valyria",
              "display_name": "VB:Trojan.Valyria",
              "target": null
            },
            {
              "id": "OpenSubtitles.A",
              "display_name": "OpenSubtitles.A",
              "target": null
            },
            {
              "id": "VB.EmoDldr.4",
              "display_name": "VB.EmoDldr.4",
              "target": null
            },
            {
              "id": "Packed-GV",
              "display_name": "Packed-GV",
              "target": null
            },
            {
              "id": "Adware.InstallMonetizer",
              "display_name": "Adware.InstallMonetizer",
              "target": null
            },
            {
              "id": "Skynet",
              "display_name": "Skynet",
              "target": null
            },
            {
              "id": "HW32.Packed",
              "display_name": "HW32.Packed",
              "target": null
            },
            {
              "id": "Zpevdo.B",
              "display_name": "Zpevdo.B",
              "target": null
            },
            {
              "id": "Presenoker",
              "display_name": "Presenoker",
              "target": null
            },
            {
              "id": "SGeneric",
              "display_name": "SGeneric",
              "target": null
            },
            {
              "id": "GameHack.DOM",
              "display_name": "GameHack.DOM",
              "target": null
            },
            {
              "id": "BehavesLike.Ransom",
              "display_name": "BehavesLike.Ransom",
              "target": null
            },
            {
              "id": "CIL.StupidCryptor",
              "display_name": "CIL.StupidCryptor",
              "target": null
            },
            {
              "id": "Gen:Heur.Ransom.MSIL",
              "display_name": "Gen:Heur.Ransom.MSIL",
              "target": null
            },
            {
              "id": "Black.Gen2",
              "display_name": "Black.Gen2",
              "target": null
            },
            {
              "id": "GameHack.CRS",
              "display_name": "GameHack.CRS",
              "target": null
            },
            {
              "id": "Trojan.HTML.PHISH",
              "display_name": "Trojan.HTML.PHISH",
              "target": null
            },
            {
              "id": "Gen:Heur.MSIL.Inject",
              "display_name": "Gen:Heur.MSIL.Inject",
              "target": null
            },
            {
              "id": "Program.Unwanted",
              "display_name": "Program.Unwanted",
              "target": null
            },
            {
              "id": "HEUR/QVM42.3.72EB.Malware",
              "display_name": "HEUR/QVM42.3.72EB.Malware",
              "target": null
            },
            {
              "id": "suspicious.low.ml",
              "display_name": "suspicious.low.ml",
              "target": null
            },
            {
              "id": "JS:Trojan.Cryxos",
              "display_name": "JS:Trojan.Cryxos",
              "target": null
            },
            {
              "id": "Suspicious_GEN.F47V0520",
              "display_name": "Suspicious_GEN.F47V0520",
              "target": null
            },
            {
              "id": "Dropper.Trojan.Generic",
              "display_name": "Dropper.Trojan.Generic",
              "target": null
            },
            {
              "id": "Trojan.TrickBot",
              "display_name": "Trojan.TrickBot",
              "target": null
            },
            {
              "id": "Malware.Tk.Generic",
              "display_name": "Malware.Tk.Generic",
              "target": null
            },
            {
              "id": "TrojanSpy.Java",
              "display_name": "TrojanSpy.Java",
              "target": null
            },
            {
              "id": "Riskware.NetFilter",
              "display_name": "Riskware.NetFilter",
              "target": null
            },
            {
              "id": "RiskWare.Crack",
              "display_name": "RiskWare.Crack",
              "target": null
            },
            {
              "id": "BehavesLike.Exploit",
              "display_name": "BehavesLike.Exploit",
              "target": null
            },
            {
              "id": "Gen:NN.ZemsilF.34128",
              "display_name": "Gen:NN.ZemsilF.34128",
              "target": null
            },
            {
              "id": "Wacapew.C",
              "display_name": "Wacapew.C",
              "target": null
            },
            {
              "id": "Trojan.Malware.121218",
              "display_name": "Trojan.Malware.121218",
              "target": null
            },
            {
              "id": "RiskWare.HackTool.Agent",
              "display_name": "RiskWare.HackTool.Agent",
              "target": null
            },
            {
              "id": "Artemis",
              "display_name": "Artemis",
              "target": null
            },
            {
              "id": "Trojan.Generic",
              "display_name": "Trojan.Generic",
              "target": null
            },
            {
              "id": "W32.Trojan",
              "display_name": "W32.Trojan",
              "target": null
            },
            {
              "id": "BScope.Riskware",
              "display_name": "BScope.Riskware",
              "target": null
            },
            {
              "id": "Gen:Variant.Bulz",
              "display_name": "Gen:Variant.Bulz",
              "target": null
            },
            {
              "id": "Ransom:Win32/CVE-2017-0147",
              "display_name": "Ransom:Win32/CVE-2017-0147",
              "target": "/malware/Ransom:Win32/CVE-2017-0147"
            },
            {
              "id": "Virus.Ramnit",
              "display_name": "Virus.Ramnit",
              "target": null
            },
            {
              "id": "Virus.Virut",
              "display_name": "Virus.Virut",
              "target": null
            },
            {
              "id": "Adware.KuziTui",
              "display_name": "Adware.KuziTui",
              "target": null
            },
            {
              "id": "AGEN.1141126",
              "display_name": "AGEN.1141126",
              "target": null
            },
            {
              "id": "W32.AIDetect",
              "display_name": "W32.AIDetect",
              "target": null
            },
            {
              "id": "Trojan.Python",
              "display_name": "Trojan.Python",
              "target": null
            },
            {
              "id": "W32.AIDetectVM",
              "display_name": "W32.AIDetectVM",
              "target": null
            },
            {
              "id": "Suspicious.Save",
              "display_name": "Suspicious.Save",
              "target": null
            },
            {
              "id": "Adware.Downware",
              "display_name": "Adware.Downware",
              "target": null
            },
            {
              "id": "Ransom.Win64.Wacatac.oa",
              "display_name": "Ransom.Win64.Wacatac.oa",
              "target": null
            },
            {
              "id": "OpenSubtitles.A",
              "display_name": "OpenSubtitles.A",
              "target": null
            },
            {
              "id": "VB.EmoDldr.4",
              "display_name": "VB.EmoDldr.4",
              "target": null
            },
            {
              "id": "Gen:Variant.Midie",
              "display_name": "Gen:Variant.Midie",
              "target": null
            },
            {
              "id": "HEUR/QVM41.2.DA9B.Malware",
              "display_name": "HEUR/QVM41.2.DA9B.Malware",
              "target": null
            },
            {
              "id": "Gen:Variant.Sirefef",
              "display_name": "Gen:Variant.Sirefef",
              "target": null
            },
            {
              "id": "Macro.Trojan.Dropperd",
              "display_name": "Macro.Trojan.Dropperd",
              "target": null
            },
            {
              "id": "BlackNET RAT",
              "display_name": "BlackNET RAT",
              "target": null
            },
            {
              "id": "Gen:Variant.Ursu",
              "display_name": "Gen:Variant.Ursu",
              "target": null
            },
            {
              "id": "Redcap.rlhse",
              "display_name": "Redcap.rlhse",
              "target": null
            },
            {
              "id": "Trojan.Trickster",
              "display_name": "Trojan.Trickster",
              "target": null
            },
            {
              "id": "HTML_REDIR.SMR",
              "display_name": "HTML_REDIR.SMR",
              "target": null
            },
            {
              "id": "TROJ_FRS.VSNTFK19",
              "display_name": "TROJ_FRS.VSNTFK19",
              "target": null
            },
            {
              "id": "Hoax.JS.Phish",
              "display_name": "Hoax.JS.Phish",
              "target": null
            },
            {
              "id": "JS:Iframe",
              "display_name": "JS:Iframe",
              "target": null
            },
            {
              "id": "Application.SQLCrack",
              "display_name": "Application.SQLCrack",
              "target": null
            },
            {
              "id": "susp.lnk",
              "display_name": "susp.lnk",
              "target": null
            },
            {
              "id": "QVM201.0.B70B.Malware",
              "display_name": "QVM201.0.B70B.Malware",
              "target": null
            },
            {
              "id": "Immortal Stealer",
              "display_name": "Immortal Stealer",
              "target": null
            },
            {
              "id": "WebMonitor RAT",
              "display_name": "WebMonitor RAT",
              "target": null
            },
            {
              "id": "Tor - S0183",
              "display_name": "Tor - S0183",
              "target": null
            },
            {
              "id": "WannaCry",
              "display_name": "WannaCry",
              "target": null
            },
            {
              "id": "WannaCryptor",
              "display_name": "WannaCryptor",
              "target": null
            },
            {
              "id": "WebToolbar",
              "display_name": "WebToolbar",
              "target": null
            },
            {
              "id": "BlackNET",
              "display_name": "BlackNET",
              "target": null
            },
            {
              "id": "DeepScan:Generic.Ransom.GandCrab5",
              "display_name": "DeepScan:Generic.Ransom.GandCrab5",
              "target": null
            },
            {
              "id": "TrojanSpy",
              "display_name": "TrojanSpy",
              "target": null
            },
            {
              "id": "States",
              "display_name": "States",
              "target": null
            },
            {
              "id": "Inmortal",
              "display_name": "Inmortal",
              "target": null
            },
            {
              "id": "Domains",
              "display_name": "Domains",
              "target": null
            },
            {
              "id": "Locky",
              "display_name": "Locky",
              "target": null
            },
            {
              "id": "Delf.NBX",
              "display_name": "Delf.NBX",
              "target": null
            },
            {
              "id": "Gen:NN.ZexaF.32515",
              "display_name": "Gen:NN.ZexaF.32515",
              "target": null
            },
            {
              "id": "FileRepMalware",
              "display_name": "FileRepMalware",
              "target": null
            },
            {
              "id": "Gen:Variant.MSILPerseus",
              "display_name": "Gen:Variant.MSILPerseus",
              "target": null
            },
            {
              "id": "Icefog",
              "display_name": "Icefog",
              "target": null
            },
            {
              "id": "$WebWatson",
              "display_name": "$WebWatson",
              "target": null
            },
            {
              "id": "Agent.AIK.gen",
              "display_name": "Agent.AIK.gen",
              "target": null
            },
            {
              "id": "Agent.AIK.genCIL.StupidCryptor",
              "display_name": "Agent.AIK.genCIL.StupidCryptor",
              "target": null
            },
            {
              "id": "Agent.YPEZ",
              "display_name": "Agent.YPEZ",
              "target": null
            },
            {
              "id": "Application.InnovativSol",
              "display_name": "Application.InnovativSol",
              "target": null
            },
            {
              "id": "Agent.ASO",
              "display_name": "Agent.ASO",
              "target": null
            },
            {
              "id": "S-b748adc5",
              "display_name": "S-b748adc5",
              "target": null
            },
            {
              "id": "W32.eHeur",
              "display_name": "W32.eHeur",
              "target": null
            },
            {
              "id": "Kryptik.GUCB",
              "display_name": "Kryptik.GUCB",
              "target": null
            },
            {
              "id": "AgentTesla",
              "display_name": "AgentTesla",
              "target": null
            },
            {
              "id": "Autoit.bimwt",
              "display_name": "Autoit.bimwt",
              "target": null
            },
            {
              "id": "HEUR:Trojan.OLE2.Alien",
              "display_name": "HEUR:Trojan.OLE2.Alien",
              "target": null
            },
            {
              "id": "AGEN.1038489",
              "display_name": "AGEN.1038489",
              "target": null
            },
            {
              "id": "Gen:Variant.Ser.Strictor",
              "display_name": "Gen:Variant.Ser.Strictor",
              "target": null
            },
            {
              "id": "Packed.Themida.Gen",
              "display_name": "Packed.Themida.Gen",
              "target": null
            },
            {
              "id": "AGEN.1043164",
              "display_name": "AGEN.1043164",
              "target": null
            },
            {
              "id": "TrickBot - S0266",
              "display_name": "TrickBot - S0266",
              "target": null
            },
            {
              "id": "Emotet",
              "display_name": "Emotet",
              "target": null
            },
            {
              "id": "Trojan.PornoAsset",
              "display_name": "Trojan.PornoAsset",
              "target": null
            },
            {
              "id": "Ransom.Win64.PORNOASSET.SM1",
              "display_name": "Ransom.Win64.PORNOASSET.SM1",
              "target": null
            },
            {
              "id": "Gen:Variant.Ulise",
              "display_name": "Gen:Variant.Ulise",
              "target": null
            },
            {
              "id": "Trojan.Win64",
              "display_name": "Trojan.Win64",
              "target": null
            },
            {
              "id": "Dropper.Trojan.Agent",
              "display_name": "Dropper.Trojan.Agent",
              "target": null
            },
            {
              "id": "Heur.BZC.YAX.Pantera.10",
              "display_name": "Heur.BZC.YAX.Pantera.10",
              "target": null
            },
            {
              "id": "malicious.high.ml",
              "display_name": "malicious.high.ml",
              "target": null
            },
            {
              "id": "CVE-2015-1650",
              "display_name": "CVE-2015-1650",
              "target": null
            },
            {
              "id": "Worm.Win64.AutoRun",
              "display_name": "Worm.Win64.AutoRun",
              "target": null
            },
            {
              "id": "AIT.Heur.Cottonmouth.8.78F19BD7",
              "display_name": "AIT.Heur.Cottonmouth.8.78F19BD7",
              "target": null
            },
            {
              "id": "Gen:Variant.Mikey",
              "display_name": "Gen:Variant.Mikey",
              "target": null
            },
            {
              "id": "Trojan.Agent",
              "display_name": "Trojan.Agent",
              "target": null
            },
            {
              "id": "Pua.Gen",
              "display_name": "Pua.Gen",
              "target": null
            },
            {
              "id": "Trojan.Downloader.Generic",
              "display_name": "Trojan.Downloader.Generic",
              "target": null
            },
            {
              "id": "Suspected of Trojan.Downloader.gen",
              "display_name": "Suspected of Trojan.Downloader.gen",
              "target": null
            },
            {
              "id": "HEUR:RemoteAdmin.Generic",
              "display_name": "HEUR:RemoteAdmin.Generic",
              "target": null
            },
            {
              "id": "Gen:Heur.Ransom.HiddenTears",
              "display_name": "Gen:Heur.Ransom.HiddenTears",
              "target": null
            },
            {
              "id": "Nemucod.A",
              "display_name": "Nemucod.A",
              "target": null
            },
            {
              "id": "Backdoor.Hupigon",
              "display_name": "Backdoor.Hupigon",
              "target": null
            },
            {
              "id": "Trojan.Starter JS.Iframe",
              "display_name": "Trojan.Starter JS.Iframe",
              "target": null
            },
            {
              "id": "fake ,promethiumm ,strongpity",
              "display_name": "fake ,promethiumm ,strongpity",
              "target": null
            },
            {
              "id": "PUA.Reg1staid",
              "display_name": "PUA.Reg1staid",
              "target": null
            },
            {
              "id": "Malware.Heur_Generic.A",
              "display_name": "Malware.Heur_Generic.A",
              "target": null
            },
            {
              "id": "Bladabindi.Q",
              "display_name": "Bladabindi.Q",
              "target": null
            },
            {
              "id": "W32.eHeur",
              "display_name": "W32.eHeur",
              "target": null
            },
            {
              "id": "malicious.6e0700",
              "display_name": "malicious.6e0700",
              "target": null
            },
            {
              "id": "Trojan.Inject",
              "display_name": "Trojan.Inject",
              "target": null
            },
            {
              "id": "TSGeneric",
              "display_name": "TSGeneric",
              "target": null
            },
            {
              "id": "RedCap.vneda",
              "display_name": "RedCap.vneda",
              "target": null
            },
            {
              "id": "Trojan.Indiloadz",
              "display_name": "Trojan.Indiloadz",
              "target": null
            },
            {
              "id": "Trojan.Ekstak",
              "display_name": "Trojan.Ekstak",
              "target": null
            },
            {
              "id": "staticrr.paleokits.net",
              "display_name": "staticrr.paleokits.net",
              "target": null
            },
            {
              "id": "MSIL.Downloader",
              "display_name": "MSIL.Downloader",
              "target": null
            },
            {
              "id": "Trojan.Autoruns.GenericKDS",
              "display_name": "Trojan.Autoruns.GenericKDS",
              "target": null
            },
            {
              "id": "MSIL.Trojan.BSE",
              "display_name": "MSIL.Trojan.BSE",
              "target": null
            },
            {
              "id": "Adload.AD81",
              "display_name": "Adload.AD81",
              "target": null
            },
            {
              "id": "Packed.Asprotect",
              "display_name": "Packed.Asprotect",
              "target": null
            },
            {
              "id": "Gen:NN.ZemsilF.34062",
              "display_name": "Gen:NN.ZemsilF.34062",
              "target": null
            },
            {
              "id": "Evo",
              "display_name": "Evo",
              "target": null
            },
            {
              "id": "Agent.pwc",
              "display_name": "Agent.pwc",
              "target": null
            },
            {
              "id": "RiskTool.Phpw",
              "display_name": "RiskTool.Phpw",
              "target": null
            },
            {
              "id": "Gen:Variant.Symmi",
              "display_name": "Gen:Variant.Symmi",
              "target": null
            },
            {
              "id": "Trojan.PWS",
              "display_name": "Trojan.PWS",
              "target": null
            },
            {
              "id": "Generic.BitCoinMiner.3",
              "display_name": "Generic.BitCoinMiner.3",
              "target": null
            },
            {
              "id": "Trojan.Tasker",
              "display_name": "Trojan.Tasker",
              "target": null
            },
            {
              "id": "Gen:NN",
              "display_name": "Gen:NN",
              "target": null
            },
            {
              "id": "Downloader.CertutilURLCache",
              "display_name": "Downloader.CertutilURLCache",
              "target": null
            },
            {
              "id": "Elf",
              "display_name": "Elf",
              "target": null
            },
            {
              "id": "Gen:Heur.MSIL.Androm",
              "display_name": "Gen:Heur.MSIL.Androm",
              "target": null
            },
            {
              "id": "Kryptik.NRD",
              "display_name": "Kryptik.NRD",
              "target": null
            },
            {
              "id": "Riskware",
              "display_name": "Riskware",
              "target": null
            },
            {
              "id": "Kuluoz.B.gen",
              "display_name": "Kuluoz.B.gen",
              "target": null
            },
            {
              "id": "Gen:Variant.RevengeRat",
              "display_name": "Gen:Variant.RevengeRat",
              "target": null
            },
            {
              "id": "Gen:Variant.Mikey",
              "display_name": "Gen:Variant.Mikey",
              "target": null
            },
            {
              "id": "VB.Chronos.7",
              "display_name": "VB.Chronos.7",
              "target": null
            },
            {
              "id": "Kryptik.NOE",
              "display_name": "Kryptik.NOE",
              "target": null
            },
            {
              "id": "HEUR:WebToolbar.Generic",
              "display_name": "HEUR:WebToolbar.Generic",
              "target": null
            },
            {
              "id": "Gen:Variant.Barys",
              "display_name": "Gen:Variant.Barys",
              "target": null
            },
            {
              "id": "Backdoor.Xtreme",
              "display_name": "Backdoor.Xtreme",
              "target": null
            },
            {
              "id": "Trojan.MSIL",
              "display_name": "Trojan.MSIL",
              "target": null
            },
            {
              "id": "Gen:Variant.Graftor",
              "display_name": "Gen:Variant.Graftor",
              "target": null
            },
            {
              "id": "Backdoor.Agent",
              "display_name": "Backdoor.Agent",
              "target": null
            },
            {
              "id": "Unsafe",
              "display_name": "Unsafe",
              "target": null
            },
            {
              "id": "Trojan.PHP.Agent",
              "display_name": "Trojan.PHP.Agent",
              "target": null
            },
            {
              "id": "Trojan.Agent",
              "display_name": "Trojan.Agent",
              "target": null
            },
            {
              "id": "HEUR:Exploit.Generic",
              "display_name": "HEUR:Exploit.Generic",
              "target": null
            },
            {
              "id": "Ransom_WCRY.SMALYM",
              "display_name": "Ransom_WCRY.SMALYM",
              "target": null
            },
            {
              "id": "Ransom_WCRY.SMJ",
              "display_name": "Ransom_WCRY.SMJ",
              "target": null
            },
            {
              "id": "Auslogics",
              "display_name": "Auslogics",
              "target": null
            },
            {
              "id": "Gen:Variant.Jaiko",
              "display_name": "Gen:Variant.Jaiko",
              "target": null
            },
            {
              "id": "Exploit.W32.Agent",
              "display_name": "Exploit.W32.Agent",
              "target": null
            },
            {
              "id": "Trojan.Cud.Gen",
              "display_name": "Trojan.Cud.Gen",
              "target": null
            },
            {
              "id": "Trojan.DOC.Downloader",
              "display_name": "Trojan.DOC.Downloader",
              "target": null
            },
            {
              "id": "Backdoor.MSIL.Agent",
              "display_name": "Backdoor.MSIL.Agent",
              "target": null
            },
            {
              "id": "Gen:Trojan.Heur2.LPTbHW@W64.HfsAutoB",
              "display_name": "Gen:Trojan.Heur2.LPTbHW@W64.HfsAutoB",
              "target": null
            },
            {
              "id": "Gen:Variant.Kazy",
              "display_name": "Gen:Variant.Kazy",
              "target": null
            },
            {
              "id": "Gen:Variant.Zusy",
              "display_name": "Gen:Variant.Zusy",
              "target": null
            },
            {
              "id": "Ransom.WannaCrypt",
              "display_name": "Ransom.WannaCrypt",
              "target": null
            },
            {
              "id": "Generic.ServStart.A",
              "display_name": "Generic.ServStart.A",
              "target": null
            },
            {
              "id": "Trojan.Wanna",
              "display_name": "Trojan.Wanna",
              "target": null
            },
            {
              "id": "Generic.MSIL.Bladabindi",
              "display_name": "Generic.MSIL.Bladabindi",
              "target": null
            },
            {
              "id": "TROJ_GEN.R002C0OG518",
              "display_name": "TROJ_GEN.R002C0OG518",
              "target": null
            },
            {
              "id": "Trojan.Chapak",
              "display_name": "Trojan.Chapak",
              "target": null
            },
            {
              "id": "Indiloadz.BB",
              "display_name": "Indiloadz.BB",
              "target": null
            },
            {
              "id": "BehavBehavesLike.PUPXBI",
              "display_name": "BehavBehavesLike.PUPXBI",
              "target": null
            },
            {
              "id": "DeepScan:Generic.SpyAgent.6",
              "display_name": "DeepScan:Generic.SpyAgent.6",
              "target": null
            },
            {
              "id": "Python.KeyLogger",
              "display_name": "Python.KeyLogger",
              "target": null
            },
            {
              "id": "GameHack.CRS",
              "display_name": "GameHack.CRS",
              "target": null
            },
            {
              "id": "Generic.MSIL.PasswordStealer",
              "display_name": "Generic.MSIL.PasswordStealer",
              "target": null
            },
            {
              "id": "PSW.Agent",
              "display_name": "PSW.Agent",
              "target": null
            },
            {
              "id": "malicious.8c45ba",
              "display_name": "malicious.8c45ba",
              "target": null
            },
            {
              "id": "Dropper.Binder",
              "display_name": "Dropper.Binder",
              "target": null
            },
            {
              "id": "Constructor.MSIL",
              "display_name": "Constructor.MSIL",
              "target": null
            },
            {
              "id": "Linux.Agent",
              "display_name": "Linux.Agent",
              "target": null
            },
            {
              "id": "Virus.3DMax.Script",
              "display_name": "Virus.3DMax.Script",
              "target": null
            },
            {
              "id": "ScrInject.B",
              "display_name": "ScrInject.B",
              "target": null
            },
            {
              "id": "Trojan.WisdomEyes.16070401.9500",
              "display_name": "Trojan.WisdomEyes.16070401.9500",
              "target": null
            },
            {
              "id": "Application.SearchProtect",
              "display_name": "Application.SearchProtect",
              "target": null
            },
            {
              "id": "JS:Trojan.Clicker",
              "display_name": "JS:Trojan.Clicker",
              "target": null
            },
            {
              "id": "Faceliker.A",
              "display_name": "Faceliker.A",
              "target": null
            },
            {
              "id": "JS:Trojan.JS.Faceliker",
              "display_name": "JS:Trojan.JS.Faceliker",
              "target": null
            },
            {
              "id": "Constructor.MSIL  Linux.Agent",
              "display_name": "Constructor.MSIL  Linux.Agent",
              "target": null
            },
            {
              "id": "PowerShell.Trojan",
              "display_name": "PowerShell.Trojan",
              "target": null
            },
            {
              "id": "HTML:Script",
              "display_name": "HTML:Script",
              "target": null
            },
            {
              "id": "ScrInject.B",
              "display_name": "ScrInject.B",
              "target": null
            },
            {
              "id": "W32.AIDetectVM",
              "display_name": "W32.AIDetectVM",
              "target": null
            },
            {
              "id": "HackTool.CheatEngine",
              "display_name": "HackTool.CheatEngine",
              "target": null
            },
            {
              "id": "Injector.CLDS",
              "display_name": "Injector.CLDS",
              "target": null
            },
            {
              "id": "VB.Downloader.2",
              "display_name": "VB.Downloader.2",
              "target": null
            },
            {
              "id": "malicious.3e78cc",
              "display_name": "malicious.3e78cc",
              "target": null
            },
            {
              "id": "malicious.d800d6",
              "display_name": "malicious.d800d6",
              "target": null
            },
            {
              "id": "VB.PwShell.2",
              "display_name": "VB.PwShell.2",
              "target": null
            },
            {
              "id": "Backdoor.RBot",
              "display_name": "Backdoor.RBot",
              "target": null
            },
            {
              "id": "malicious.71b1a8",
              "display_name": "malicious.71b1a8",
              "target": null
            },
            {
              "id": "TrojanSpy.KeyLogger",
              "display_name": "TrojanSpy.KeyLogger",
              "target": null
            },
            {
              "id": "Injector.JDO",
              "display_name": "Injector.JDO",
              "target": null
            },
            {
              "id": "Heur.Msword.Gen",
              "display_name": "Heur.Msword.Gen",
              "target": null
            },
            {
              "id": "PSW.Discord",
              "display_name": "PSW.Discord",
              "target": null
            },
            {
              "id": "Packed.VMProtect",
              "display_name": "Packed.VMProtect",
              "target": null
            },
            {
              "id": "HEUR:AdWare.StartSurf",
              "display_name": "HEUR:AdWare.StartSurf",
              "target": null
            },
            {
              "id": "Gen:Heur.NoobyProtect",
              "display_name": "Gen:Heur.NoobyProtect",
              "target": null
            },
            {
              "id": "CIL.HeapOverride",
              "display_name": "CIL.HeapOverride",
              "target": null
            },
            {
              "id": "HEUR:Trojan.Tasker",
              "display_name": "HEUR:Trojan.Tasker",
              "target": null
            },
            {
              "id": "XLM.Trojan.Abracadabra.27",
              "display_name": "XLM.Trojan.Abracadabra.27",
              "target": null
            },
            {
              "id": "HEUR:Backdoor.MSIL.NanoBot",
              "display_name": "HEUR:Backdoor.MSIL.NanoBot",
              "target": null
            },
            {
              "id": "Trojan.PSW.Mimikatz",
              "display_name": "Trojan.PSW.Mimikatz",
              "target": null
            },
            {
              "id": "TrojanSpy.Python",
              "display_name": "TrojanSpy.Python",
              "target": null
            },
            {
              "id": "Trojan.Ole2.Vbs",
              "display_name": "Trojan.Ole2.Vbs",
              "target": null
            },
            {
              "id": "Exploit.MSOffice",
              "display_name": "Exploit.MSOffice",
              "target": null
            },
            {
              "id": "DeepScan:Generic.Ransom.AmnesiaE",
              "display_name": "DeepScan:Generic.Ransom.AmnesiaE",
              "target": null
            },
            {
              "id": "Wacatac.D6",
              "display_name": "Wacatac.D6",
              "target": null
            },
            {
              "id": "Backdoor.Androm",
              "display_name": "Backdoor.Androm",
              "target": null
            },
            {
              "id": "Packed.NetSeal",
              "display_name": "Packed.NetSeal",
              "target": null
            },
            {
              "id": "Trojan.MSIL.Injector",
              "display_name": "Trojan.MSIL.Injector",
              "target": null
            },
            {
              "id": "Trojan.PWS.Agent",
              "display_name": "Trojan.PWS.Agent",
              "target": null
            },
            {
              "id": "TScope.Trojan",
              "display_name": "TScope.Trojan",
              "target": null
            },
            {
              "id": "PSW.Stealer",
              "display_name": "PSW.Stealer",
              "target": null
            },
            {
              "id": "Trojan.PackedNET",
              "display_name": "Trojan.PackedNET",
              "target": null
            },
            {
              "id": "Trojan.Java",
              "display_name": "Trojan.Java",
              "target": null
            },
            {
              "id": "MalwareX",
              "display_name": "MalwareX",
              "target": null
            },
            {
              "id": "Trojan.PSW.Python",
              "display_name": "Trojan.PSW.Python",
              "target": null
            },
            {
              "id": "malicious.11abfc",
              "display_name": "malicious.11abfc",
              "target": null
            },
            {
              "id": "Generic.ASMalwS",
              "display_name": "Generic.ASMalwS",
              "target": null
            },
            {
              "id": "HEUR:Trojan.MSIL.Tasker",
              "display_name": "HEUR:Trojan.MSIL.Tasker",
              "target": null
            },
            {
              "id": "PossibleThreat.PALLAS",
              "display_name": "PossibleThreat.PALLAS",
              "target": null
            },
            {
              "id": "Backdoor.Poison",
              "display_name": "Backdoor.Poison",
              "target": null
            },
            {
              "id": "Generic.MSIL.LimeRAT",
              "display_name": "Generic.MSIL.LimeRAT",
              "target": null
            },
            {
              "id": "PWS-FCZZ",
              "display_name": "PWS-FCZZ",
              "target": null
            },
            {
              "id": "Trojan.Script",
              "display_name": "Trojan.Script",
              "target": null
            },
            {
              "id": "Gen:Heur.MSIL.Inject",
              "display_name": "Gen:Heur.MSIL.Inject",
              "target": null
            },
            {
              "id": "Trojan.PWS.Growtopia",
              "display_name": "Trojan.PWS.Growtopia",
              "target": null
            },
            {
              "id": "Spyware.Bobik",
              "display_name": "Spyware.Bobik",
              "target": null
            },
            {
              "id": "HackTool.BruteForce",
              "display_name": "HackTool.BruteForce",
              "target": null
            },
            {
              "id": "Hack.Patcher",
              "display_name": "Hack.Patcher",
              "target": null
            },
            {
              "id": "PWS.p",
              "display_name": "PWS.p",
              "target": null
            },
            {
              "id": "Suppobox",
              "display_name": "Suppobox",
              "target": null
            },
            {
              "id": "index.php",
              "display_name": "index.php",
              "target": null
            },
            {
              "id": "Packed.VMProtect",
              "display_name": "Packed.VMProtect",
              "target": null
            },
            {
              "id": "SmokeLoader",
              "display_name": "SmokeLoader",
              "target": null
            },
            {
              "id": "Generic.Malware",
              "display_name": "Generic.Malware",
              "target": null
            },
            {
              "id": "SNH:Script [Dropper]",
              "display_name": "SNH:Script [Dropper]",
              "target": null
            },
            {
              "id": "HEUR:Trojan.MSOffice.SAgent",
              "display_name": "HEUR:Trojan.MSOffice.SAgent",
              "target": null
            },
            {
              "id": "Script.INF",
              "display_name": "Script.INF",
              "target": null
            },
            {
              "id": "JS:Trojan.JS.Likejack",
              "display_name": "JS:Trojan.JS.Likejack",
              "target": null
            },
            {
              "id": "SNH:Script [Dropper]",
              "display_name": "SNH:Script [Dropper]",
              "target": null
            },
            {
              "id": "Trojan.JS.Agent",
              "display_name": "Trojan.JS.Agent",
              "target": null
            },
            {
              "id": "APT Notes",
              "display_name": "APT Notes",
              "target": null
            },
            {
              "id": "susp.rtf.objupdate",
              "display_name": "susp.rtf.objupdate",
              "target": null
            },
            {
              "id": "RedCap.zoohz",
              "display_name": "RedCap.zoohz",
              "target": null
            },
            {
              "id": "Trojan.Tasker",
              "display_name": "Trojan.Tasker",
              "target": null
            },
            {
              "id": "virus.office.qexvmc",
              "display_name": "virus.office.qexvmc",
              "target": null
            },
            {
              "id": "Trojan.KillProc",
              "display_name": "Trojan.KillProc",
              "target": null
            },
            {
              "id": "Generic.MSIL.GrwtpStealer.1",
              "display_name": "Generic.MSIL.GrwtpStealer.1",
              "target": null
            },
            {
              "id": "Suspicious.Cloud",
              "display_name": "Suspicious.Cloud",
              "target": null
            },
            {
              "id": "PowerShell.DownLoader",
              "display_name": "PowerShell.DownLoader",
              "target": null
            },
            {
              "id": "Downldr.gen",
              "display_name": "Downldr.gen",
              "target": null
            },
            {
              "id": "AGEN.1030939",
              "display_name": "AGEN.1030939",
              "target": null
            },
            {
              "id": "HackTool.Binder",
              "display_name": "HackTool.Binder",
              "target": null
            },
            {
              "id": "Trojan.Inject",
              "display_name": "Trojan.Inject",
              "target": null
            },
            {
              "id": "Dldr.Agent",
              "display_name": "Dldr.Agent",
              "target": null
            },
            {
              "id": "Dropper.MSIL",
              "display_name": "Dropper.MSIL",
              "target": null
            },
            {
              "id": "Trojan.VBKryjetor",
              "display_name": "Trojan.VBKryjetor",
              "target": null
            },
            {
              "id": "PWSX",
              "display_name": "PWSX",
              "target": null
            },
            {
              "id": "VB:Trojan.VBA.Agent",
              "display_name": "VB:Trojan.VBA.Agent",
              "target": null
            },
            {
              "id": "HEUR:Trojan.MSOffice.Stratos",
              "display_name": "HEUR:Trojan.MSOffice.Stratos",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1071.004",
              "name": "DNS",
              "display_name": "T1071.004 - DNS"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1059.007",
              "name": "JavaScript",
              "display_name": "T1059.007 - JavaScript"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1068",
              "name": "Exploitation for Privilege Escalation",
              "display_name": "T1068 - Exploitation for Privilege Escalation"
            },
            {
              "id": "TA0029",
              "name": "Privilege Escalation",
              "display_name": "TA0029 - Privilege Escalation"
            },
            {
              "id": "T1449",
              "name": "Exploit SS7 to Redirect Phone Calls/SMS",
              "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
            },
            {
              "id": "T1190",
              "name": "Exploit Public-Facing Application",
              "display_name": "T1190 - Exploit Public-Facing Application"
            },
            {
              "id": "T1210",
              "name": "Exploitation of Remote Services",
              "display_name": "T1210 - Exploitation of Remote Services"
            },
            {
              "id": "T1450",
              "name": "Exploit SS7 to Track Device Location",
              "display_name": "T1450 - Exploit SS7 to Track Device Location"
            },
            {
              "id": "T1211",
              "name": "Exploitation for Defense Evasion",
              "display_name": "T1211 - Exploitation for Defense Evasion"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "TA0011",
              "name": "Command and Control",
              "display_name": "TA0011 - Command and Control"
            },
            {
              "id": "T1412",
              "name": "Capture SMS Messages",
              "display_name": "T1412 - Capture SMS Messages"
            },
            {
              "id": "T1454",
              "name": "Malicious SMS Message",
              "display_name": "T1454 - Malicious SMS Message"
            },
            {
              "id": "T1001",
              "name": "Data Obfuscation",
              "display_name": "T1001 - Data Obfuscation"
            },
            {
              "id": "T1114",
              "name": "Email Collection",
              "display_name": "T1114 - Email Collection"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1498",
              "name": "Network Denial of Service",
              "display_name": "T1498 - Network Denial of Service"
            },
            {
              "id": "T1496",
              "name": "Resource Hijacking",
              "display_name": "T1496 - Resource Hijacking"
            },
            {
              "id": "T1176",
              "name": "Browser Extensions",
              "display_name": "T1176 - Browser Extensions"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": "654c597a4a45c8d84f0b15c1",
          "export_count": 341,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 1184,
            "FileHash-SHA1": 949,
            "FileHash-SHA256": 3712,
            "URL": 2925,
            "domain": 627,
            "hostname": 1319,
            "CVE": 26,
            "email": 8,
            "CIDR": 2
          },
          "indicator_count": 10752,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 231,
          "modified_text": "904 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6558126013aef7ce80968842",
          "name": "PuffStealer",
          "description": "",
          "modified": "2023-12-09T03:01:57.989000",
          "created": "2023-11-18T01:24:48.887000",
          "tags": [
            "ssl certificate",
            "historical ssl",
            "communicating",
            "contacted",
            "resolutions",
            "whois record",
            "whois whois",
            "whois parent",
            "whois siblings",
            "skynet",
            "threat report",
            "ip summary",
            "url summary",
            "summary",
            "sample",
            "samples",
            "detection list",
            "blacklist",
            "cisco umbrella",
            "site",
            "safe site",
            "million",
            "team",
            "microsoft",
            "back",
            "download",
            "phishing",
            "union",
            "bank",
            "malicious site",
            "blacklist http",
            "exit",
            "traffic",
            "node tcp",
            "tor known",
            "tor relayrouter",
            "et tor",
            "known tor",
            "relayrouter",
            "anonymizer",
            "spammer",
            "malware",
            "dropped",
            "unlocker",
            "http",
            "critical risk",
            "redline stealer",
            "core",
            "hacktool",
            "execution",
            "type win32",
            "exe size",
            "first seen",
            "file name",
            "avast win32",
            "win32",
            "avg win32",
            "fortinet",
            "vitro",
            "mb first",
            "rmndrp",
            "clean mx",
            "undetected dns8",
            "undetected vx",
            "sophos",
            "vault",
            "zdb zeus",
            "cmc threat",
            "snort ip",
            "feodo tracker",
            "cybereason",
            "send bug",
            "pe yandex",
            "no data",
            "tag count",
            "count blacklist",
            "tag tag",
            "algorithm",
            "v3 serial",
            "number",
            "issuer",
            "cus cnr3",
            "olet",
            "subject public",
            "key info",
            "key algorithm",
            "key identifier",
            "first",
            "seen",
            "valid",
            "no na",
            "no no",
            "ip security",
            "cndst root",
            "ca x3",
            "ca id",
            "research group",
            "cnisrg root",
            "no expired",
            "mozilla",
            "android",
            "malicious red team",
            "tsara brashears",
            "cyber stalking",
            "malvertizing",
            "invasion of privacy",
            "threat",
            "adult content",
            "apple",
            "iphone unlocker",
            "android",
            "exploited spyware",
            "malware host",
            "brute force",
            "revenge-rat",
            "banker",
            "evasive",
            "domain",
            "redline",
            "stealer",
            "phishing",
            "ramnit",
            "unreliable subdomains",
            "dridex",
            "gating",
            "msil",
            "rat",
            "loki",
            "network",
            "hacking",
            "sinkhole",
            "azorult",
            "c2",
            "historicalandnew",
            "targeted attack",
            "puffstealer",
            "rultazo",
            "lokibot",
            "loki pws",
            "burkina",
            "banker,dde,dridex,exploit",
            "banker,dridex,evasive",
            "trickbot",
            "ransomware,torrentlocker",
            "exploit_source",
            "blacknet",
            "FileRepMalware",
            "linux agent",
            "blacknet",
            "ios",
            "phishing paypal",
            "tagging",
            "defacement",
            "hit",
            "bounty",
            "phishing site",
            "malware site",
            "malware download",
            "endangerment",
            "Malicious domain - SANS Internet Storm Center",
            "evasive,msil,rat,revenge-rat",
            "prism_setting",
            "prism_object",
            "static engine",
            "social engineering",
            "jansky",
            "worm",
            "network rat",
            "networm",
            "Loki Password Stealer (PWS)",
            "South Carolina Federal Credit Union phishing",
            "darkweb",
            "yandex",
            "redirectors",
            "blacknet threats",
            "phishing,ransomware,sinkhole",
            "wanacrypt0r,wannacry,wcry",
            "tor c++",
            "tor c++ client",
            "python user",
            "js user",
            "hacker",
            "hijacker",
            "heur",
            "maltiverse",
            "alexa top",
            "exploit",
            "riskware",
            "unsafe",
            "outbreak",
            "downer",
            "shell",
            "mediamagnet",
            "sality",
            "swrort",
            "adaptivebee",
            "unruy",
            "iobit",
            "dropper",
            "trojanx",
            "artemis",
            "installcore",
            "webshell",
            "crack",
            "webtoolbar",
            "search live",
            "api blog",
            "docs pricing",
            "november",
            "de indicators",
            "domains",
            "hashes",
            "__convergedlogin_pcustomizationloader_44b450e8d543eb53930d",
            "malicious url",
            "financial",
            "blacknet rat",
            "azorult",
            "stealer",
            "deep scan",
            "blacklist https",
            "referrer",
            "collections kp",
            "incident ip",
            "sneaky server",
            "replacement",
            "unauthorized",
            "emotet",
            "noname057",
            "generic malware",
            "engineering",
            "cyber threat",
            "facebook",
            "paypal",
            "dropbox",
            "united",
            "america",
            "banking",
            "wells fargo",
            "steam",
            "twitter",
            "sliver",
            "daum",
            "swift",
            "runescape",
            "betabot",
            "district",
            "iframe",
            "alexa",
            "downldr",
            "agent",
            "presenoker",
            "bladabindi",
            "live",
            "conduit",
            "pony",
            "covid19",
            "malicious",
            "cobalt strike",
            "suppobox",
            "ramnit",
            "meterpreter",
            "virut",
            "njrat",
            "pykspa",
            "asyncrat",
            "downloader",
            "fakealert",
            "binder",
            "virustotal",
            "formbook",
            "necurs",
            "trojan",
            "msil",
            "hiloti",
            "vawtrak",
            "simda",
            "kraken",
            "solimba",
            "icedid",
            "redirector",
            "suspic",
            "amadey",
            "raccoon",
            "nanocore rat",
            "revenge rat",
            "genkryptik",
            "fuery",
            "wacatac",
            "service",
            "cloudeye",
            "tinba",
            "domaiq",
            "ave maria",
            "zeus",
            "ransomware",
            "zbot",
            "generic",
            "trojanspy",
            "states",
            "inmortal",
            "locky",
            "strike",
            "china cobalt",
            "keybase",
            "cutwail",
            "citadel",
            "radamant",
            "kovter",
            "bradesco",
            "nymaim",
            "amonetize",
            "bondat",
            "ghost rat",
            "vjw0rm",
            "bandoo",
            "matsnu",
            "dnspionage",
            "darkgate",
            "vidar",
            "keylogger",
            "remcos",
            "agenttesla",
            "detplock",
            "win64",
            "smokeloader",
            "agent tesla",
            "kgs0",
            "kls0",
            "urls",
            "type name",
            "dns replication",
            "date",
            "domain",
            "win32 exe",
            "files",
            "detections type",
            "name",
            "drpsuinstaller",
            "vdfsurfs",
            "opera",
            "icwrmind",
            "notepad",
            "installer",
            "miner",
            "unknown",
            "networm",
            "houdini",
            "quasar rat",
            "gamehack",
            "dbatloader",
            "qakbot",
            "ursnif",
            "CVE-2005-1790",
            "CVE-2009-3672",
            "CVE-2010-3962",
            "CVE-2012-3993",
            "CVE-2014-6332",
            "CVE-2017-11882",
            "CVE-2020-0601",
            "CVE-2020-0674",
            "hallrender.com",
            "brian sabey",
            "insurance",
            "botnetwork",
            "botmaster",
            "command_and_control",
            "CVE-2021-27065",
            "CVE-2021-40444",
            "CVE-2023-4966",
            "CVE-2017-0199",
            "CVE-2018-4893",
            "CVE-2010-3333",
            "CVE-2015-1641",
            "CVE-2017-0147",
            "CVE-2017-8570",
            "CVE-2018-0802",
            "CVE-2018-8373",
            "CVE-2017-8759",
            "CVE-2018-8453",
            "CVE-2014-3153",
            "CVE-2015-1650",
            "CVE-2017-0143",
            "CVE-2017-8464",
            "Icefog",
            "Delf.NBX",
            "$WebWatson",
            "Gen:Heur.Ransom.HiddenTears",
            "mobilekey.pw",
            "bitbucket.org",
            "Anomalous.100%",
            "malware distribution site",
            "gootkit",
            "edsaid",
            "rightsaided",
            "betabot",
            "cobaltstrike4.tk",
            "mas.to",
            "BehavesLike.YahLover",
            "srdvd16010404",
            "languageenu",
            "buildno",
            "channelisales",
            "vendorname2581",
            "osregion",
            "device",
            "systemlocale",
            "majorver16",
            "quasar",
            "find",
            "lockbit",
            "chaos",
            "ransomexx",
            "grandoreiro",
            "evilnum",
            "banker"
          ],
          "references": [
            "https://hybrid-analysis.com/sample/6765f47ea77c8274c8e4973ed95aedf59e75998c62f6029e23c58cdf36ed85ba/654afdbdc621e7037801cce7",
            "20.99.186.246 exploit source",
            "fp2e7a.wpc.2be4.phicdn.net",
            "https://www.anyxxxtube.net/search-porn/tsara-brashears/ (phishing, ELF, Prism.exe found)",
            "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian (password cracker)",
            "http://182.22.25.124:7878/182.22.25.124:443     (malicious dropper)",
            "init.ess.apple.com         (malicious code script)",
            "https://www.pornhub.com/video/search?search=tsara+brashears (Malicious PW cracker | stylebk.css stylesheets - not found )",
            "https://urlscan.io/result/a328d9ff-fb49-4078-960d-a757fd41404f/#indicators",
            "VirusTotal Link: https://www.virustotal.com/gui/ip-address/20.99.186.246/detection",
            "Abuse IPDB Link: https://www.abuseipdb.com/check/20.99.186.246",
            "IPv4 45.12.253.72.            command_and_control",
            "Hostname: ddos.dnsnb8.net                        command_and_control",
            "IPv4 95.213.186.51              command_and_control",
            "Hostname: www.supernetforme.com      command_and_control",
            "IPv4 103.224.182.246        command_and_control",
            "IPv4 72.251.233.245           command_and_control",
            "IPv4 63.251.106.25             command_and_control",
            "IPv4 45.15.156.208            command_and_control",
            "IPv4 104.247.81.51             command_and_control",
            "http://ambisexual.phone-sex-blogs.com/http:/ambisexual.phone-sex-blogs.com/images/thumbnails/pic118.jpg             (phishing)",
            "https://downloaddevtools.ir/     (phishing)",
            "happylifehappywife.com",
            "apples.encryptedwork.com        (Interesting in the blacknet)",
            "https://itunes.apple.com/app/apple-store/id284815942/us/app/samsung-galaxy-watch-gear-s/id1117310635.                   (iOS unlocker and hijacker)",
            "https://www.anyxxxtube.net/media/favicon/apple              (password cracker and iOS hijacker)",
            "https://www.apple.com/shop/browse/open/country_selector     (exploit)",
            "www.norad.mil   (federal tracking tool used by attorneys, law firms, and private investigators 'licensed or unlicensed') hi!",
            "http://init-p01st.push.apple.com/bag            (malicious web creator)",
            "opencve.djgummikuh.de        (CVE dispensary)",
            "Maltiverse Research Team",
            "URLscan.io",
            "Deep Research",
            "Hybrid Analysis",
            "URLhaus Abuse.ch",
            "Cyber Threat Coalition",
            "ThreatFox Abuse.ch"
          ],
          "public": 1,
          "adversary": "Lucky Mouse APT27 | NoName057(16) |  Unnamed",
          "targeted_countries": [
            "United States of America",
            "France",
            "Spain"
          ],
          "malware_families": [
            {
              "id": "Feodo",
              "display_name": "Feodo",
              "target": null
            },
            {
              "id": "Dridex",
              "display_name": "Dridex",
              "target": null
            },
            {
              "id": "Redline Stealer",
              "display_name": "Redline Stealer",
              "target": null
            },
            {
              "id": "Ramnit.N",
              "display_name": "Ramnit.N",
              "target": null
            },
            {
              "id": "Loki Bot",
              "display_name": "Loki Bot",
              "target": null
            },
            {
              "id": "Loki Password Stealer (PWS)",
              "display_name": "Loki Password Stealer (PWS)",
              "target": null
            },
            {
              "id": "AZORult",
              "display_name": "AZORult",
              "target": null
            },
            {
              "id": "Zbd Zeus",
              "display_name": "Zbd Zeus",
              "target": null
            },
            {
              "id": "Trojan:MSIL/Burkina",
              "display_name": "Trojan:MSIL/Burkina",
              "target": "/malware/Trojan:MSIL/Burkina"
            },
            {
              "id": "Generic.TrickBot.1",
              "display_name": "Generic.TrickBot.1",
              "target": null
            },
            {
              "id": "Exploit.CVE",
              "display_name": "Exploit.CVE",
              "target": null
            },
            {
              "id": "Injector.IS.gen",
              "display_name": "Injector.IS.gen",
              "target": null
            },
            {
              "id": "Gen:Variant.Razy",
              "display_name": "Gen:Variant.Razy",
              "target": null
            },
            {
              "id": "Trojan.Androm.Gen",
              "display_name": "Trojan.Androm.Gen",
              "target": null
            },
            {
              "id": "HEUR:Trojan.Linux.Agent",
              "display_name": "HEUR:Trojan.Linux.Agent",
              "target": null
            },
            {
              "id": "BScope.Trojan",
              "display_name": "BScope.Trojan",
              "target": null
            },
            {
              "id": "VBA.Downloader",
              "display_name": "VBA.Downloader",
              "target": null
            },
            {
              "id": "Trojan.Notifier",
              "display_name": "Trojan.Notifier",
              "target": null
            },
            {
              "id": "HEUR:Trojan.MSOffice.Alien",
              "display_name": "HEUR:Trojan.MSOffice.Alien",
              "target": null
            },
            {
              "id": "Unsafe.AI_Score_100%",
              "display_name": "Unsafe.AI_Score_100%",
              "target": null
            },
            {
              "id": "Gen:Variant.Johnnie",
              "display_name": "Gen:Variant.Johnnie",
              "target": null
            },
            {
              "id": "DangerousObject.Multi",
              "display_name": "DangerousObject.Multi",
              "target": null
            },
            {
              "id": "Trojan:Python/Downldr",
              "display_name": "Trojan:Python/Downldr",
              "target": "/malware/Trojan:Python/Downldr"
            },
            {
              "id": "Trojan:Linux/Downldr",
              "display_name": "Trojan:Linux/Downldr",
              "target": "/malware/Trojan:Linux/Downldr"
            },
            {
              "id": "Trojan:VBA/Downldr",
              "display_name": "Trojan:VBA/Downldr",
              "target": "/malware/Trojan:VBA/Downldr"
            },
            {
              "id": "TrojanDownloader:Linux/Downldr",
              "display_name": "TrojanDownloader:Linux/Downldr",
              "target": "/malware/TrojanDownloader:Linux/Downldr"
            },
            {
              "id": "Kryptik.FPH.gen",
              "display_name": "Kryptik.FPH.gen",
              "target": null
            },
            {
              "id": "TROJ_FRS.VSNTFK19",
              "display_name": "TROJ_FRS.VSNTFK19",
              "target": null
            },
            {
              "id": "Trojan.Ransom.GenericKD",
              "display_name": "Trojan.Ransom.GenericKD",
              "target": null
            },
            {
              "id": "Phish.JAT",
              "display_name": "Phish.JAT",
              "target": null
            },
            {
              "id": "Phishing.HTML",
              "display_name": "Phishing.HTML",
              "target": null
            },
            {
              "id": "Generic.ASMalwS",
              "display_name": "Generic.ASMalwS",
              "target": null
            },
            {
              "id": "Phish.AB",
              "display_name": "Phish.AB",
              "target": null
            },
            {
              "id": "Generic.Malware",
              "display_name": "Generic.Malware",
              "target": null
            },
            {
              "id": "ml.Generic",
              "display_name": "ml.Generic",
              "target": null
            },
            {
              "id": "Xegumumune.8596c22f",
              "display_name": "Xegumumune.8596c22f",
              "target": null
            },
            {
              "id": "Generic.Malware.SMYB",
              "display_name": "Generic.Malware.SMYB",
              "target": null
            },
            {
              "id": "malicious.moderate.ml",
              "display_name": "malicious.moderate.ml",
              "target": null
            },
            {
              "id": "Agent.NBAE",
              "display_name": "Agent.NBAE",
              "target": null
            },
            {
              "id": "AGEN.1045227",
              "display_name": "AGEN.1045227",
              "target": null
            },
            {
              "id": "Riskware.Agent",
              "display_name": "Riskware.Agent",
              "target": null
            },
            {
              "id": "Gen:Variant.Cerbu",
              "display_name": "Gen:Variant.Cerbu",
              "target": null
            },
            {
              "id": "IL:Trojan.MSILZilla",
              "display_name": "IL:Trojan.MSILZilla",
              "target": null
            },
            {
              "id": "Dropped:Generic.Ransom.DMR",
              "display_name": "Dropped:Generic.Ransom.DMR",
              "target": null
            },
            {
              "id": "Delf.NBX",
              "display_name": "Delf.NBX",
              "target": null
            },
            {
              "id": "malicious.f01f67",
              "display_name": "malicious.f01f67",
              "target": null
            },
            {
              "id": "AGEN.1144657",
              "display_name": "AGEN.1144657",
              "target": null
            },
            {
              "id": "Trojan.Heur",
              "display_name": "Trojan.Heur",
              "target": null
            },
            {
              "id": "Trojan.Malware.300983",
              "display_name": "Trojan.Malware.300983",
              "target": null
            },
            {
              "id": "SdBot.CAOC",
              "display_name": "SdBot.CAOC",
              "target": null
            },
            {
              "id": "Trojan.DelShad",
              "display_name": "Trojan.DelShad",
              "target": null
            },
            {
              "id": "Exploit CVE-2017-11882",
              "display_name": "Exploit CVE-2017-11882",
              "target": null
            },
            {
              "id": "GameHack.NL",
              "display_name": "GameHack.NL",
              "target": null
            },
            {
              "id": "JS:Trojan.HideLink",
              "display_name": "JS:Trojan.HideLink",
              "target": null
            },
            {
              "id": "Script.Agent",
              "display_name": "Script.Agent",
              "target": null
            },
            {
              "id": "Macro.Agent",
              "display_name": "Macro.Agent",
              "target": null
            },
            {
              "id": "Macro.Downloader.AMIP",
              "display_name": "Macro.Downloader.AMIP",
              "target": null
            },
            {
              "id": "Trojan.VBA",
              "display_name": "Trojan.VBA",
              "target": null
            },
            {
              "id": "HEUR.VBA.Trojan",
              "display_name": "HEUR.VBA.Trojan",
              "target": null
            },
            {
              "id": "VB.EmoooDldr.10",
              "display_name": "VB.EmoooDldr.10",
              "target": null
            },
            {
              "id": "VB:Trojan.Valyria",
              "display_name": "VB:Trojan.Valyria",
              "target": null
            },
            {
              "id": "OpenSubtitles.A",
              "display_name": "OpenSubtitles.A",
              "target": null
            },
            {
              "id": "VB.EmoDldr.4",
              "display_name": "VB.EmoDldr.4",
              "target": null
            },
            {
              "id": "Packed-GV",
              "display_name": "Packed-GV",
              "target": null
            },
            {
              "id": "Adware.InstallMonetizer",
              "display_name": "Adware.InstallMonetizer",
              "target": null
            },
            {
              "id": "Skynet",
              "display_name": "Skynet",
              "target": null
            },
            {
              "id": "HW32.Packed",
              "display_name": "HW32.Packed",
              "target": null
            },
            {
              "id": "Zpevdo.B",
              "display_name": "Zpevdo.B",
              "target": null
            },
            {
              "id": "Presenoker",
              "display_name": "Presenoker",
              "target": null
            },
            {
              "id": "SGeneric",
              "display_name": "SGeneric",
              "target": null
            },
            {
              "id": "GameHack.DOM",
              "display_name": "GameHack.DOM",
              "target": null
            },
            {
              "id": "BehavesLike.Ransom",
              "display_name": "BehavesLike.Ransom",
              "target": null
            },
            {
              "id": "CIL.StupidCryptor",
              "display_name": "CIL.StupidCryptor",
              "target": null
            },
            {
              "id": "Gen:Heur.Ransom.MSIL",
              "display_name": "Gen:Heur.Ransom.MSIL",
              "target": null
            },
            {
              "id": "Black.Gen2",
              "display_name": "Black.Gen2",
              "target": null
            },
            {
              "id": "GameHack.CRS",
              "display_name": "GameHack.CRS",
              "target": null
            },
            {
              "id": "Trojan.HTML.PHISH",
              "display_name": "Trojan.HTML.PHISH",
              "target": null
            },
            {
              "id": "Gen:Heur.MSIL.Inject",
              "display_name": "Gen:Heur.MSIL.Inject",
              "target": null
            },
            {
              "id": "Program.Unwanted",
              "display_name": "Program.Unwanted",
              "target": null
            },
            {
              "id": "HEUR/QVM42.3.72EB.Malware",
              "display_name": "HEUR/QVM42.3.72EB.Malware",
              "target": null
            },
            {
              "id": "suspicious.low.ml",
              "display_name": "suspicious.low.ml",
              "target": null
            },
            {
              "id": "JS:Trojan.Cryxos",
              "display_name": "JS:Trojan.Cryxos",
              "target": null
            },
            {
              "id": "Suspicious_GEN.F47V0520",
              "display_name": "Suspicious_GEN.F47V0520",
              "target": null
            },
            {
              "id": "Dropper.Trojan.Generic",
              "display_name": "Dropper.Trojan.Generic",
              "target": null
            },
            {
              "id": "Trojan.TrickBot",
              "display_name": "Trojan.TrickBot",
              "target": null
            },
            {
              "id": "Malware.Tk.Generic",
              "display_name": "Malware.Tk.Generic",
              "target": null
            },
            {
              "id": "TrojanSpy.Java",
              "display_name": "TrojanSpy.Java",
              "target": null
            },
            {
              "id": "Riskware.NetFilter",
              "display_name": "Riskware.NetFilter",
              "target": null
            },
            {
              "id": "RiskWare.Crack",
              "display_name": "RiskWare.Crack",
              "target": null
            },
            {
              "id": "BehavesLike.Exploit",
              "display_name": "BehavesLike.Exploit",
              "target": null
            },
            {
              "id": "Gen:NN.ZemsilF.34128",
              "display_name": "Gen:NN.ZemsilF.34128",
              "target": null
            },
            {
              "id": "Wacapew.C",
              "display_name": "Wacapew.C",
              "target": null
            },
            {
              "id": "Trojan.Malware.121218",
              "display_name": "Trojan.Malware.121218",
              "target": null
            },
            {
              "id": "RiskWare.HackTool.Agent",
              "display_name": "RiskWare.HackTool.Agent",
              "target": null
            },
            {
              "id": "Artemis",
              "display_name": "Artemis",
              "target": null
            },
            {
              "id": "Trojan.Generic",
              "display_name": "Trojan.Generic",
              "target": null
            },
            {
              "id": "W32.Trojan",
              "display_name": "W32.Trojan",
              "target": null
            },
            {
              "id": "BScope.Riskware",
              "display_name": "BScope.Riskware",
              "target": null
            },
            {
              "id": "Gen:Variant.Bulz",
              "display_name": "Gen:Variant.Bulz",
              "target": null
            },
            {
              "id": "Ransom:Win32/CVE-2017-0147",
              "display_name": "Ransom:Win32/CVE-2017-0147",
              "target": "/malware/Ransom:Win32/CVE-2017-0147"
            },
            {
              "id": "Virus.Ramnit",
              "display_name": "Virus.Ramnit",
              "target": null
            },
            {
              "id": "Virus.Virut",
              "display_name": "Virus.Virut",
              "target": null
            },
            {
              "id": "Adware.KuziTui",
              "display_name": "Adware.KuziTui",
              "target": null
            },
            {
              "id": "AGEN.1141126",
              "display_name": "AGEN.1141126",
              "target": null
            },
            {
              "id": "W32.AIDetect",
              "display_name": "W32.AIDetect",
              "target": null
            },
            {
              "id": "Trojan.Python",
              "display_name": "Trojan.Python",
              "target": null
            },
            {
              "id": "W32.AIDetectVM",
              "display_name": "W32.AIDetectVM",
              "target": null
            },
            {
              "id": "Suspicious.Save",
              "display_name": "Suspicious.Save",
              "target": null
            },
            {
              "id": "Adware.Downware",
              "display_name": "Adware.Downware",
              "target": null
            },
            {
              "id": "Ransom.Win64.Wacatac.oa",
              "display_name": "Ransom.Win64.Wacatac.oa",
              "target": null
            },
            {
              "id": "OpenSubtitles.A",
              "display_name": "OpenSubtitles.A",
              "target": null
            },
            {
              "id": "VB.EmoDldr.4",
              "display_name": "VB.EmoDldr.4",
              "target": null
            },
            {
              "id": "Gen:Variant.Midie",
              "display_name": "Gen:Variant.Midie",
              "target": null
            },
            {
              "id": "HEUR/QVM41.2.DA9B.Malware",
              "display_name": "HEUR/QVM41.2.DA9B.Malware",
              "target": null
            },
            {
              "id": "Gen:Variant.Sirefef",
              "display_name": "Gen:Variant.Sirefef",
              "target": null
            },
            {
              "id": "Macro.Trojan.Dropperd",
              "display_name": "Macro.Trojan.Dropperd",
              "target": null
            },
            {
              "id": "BlackNET RAT",
              "display_name": "BlackNET RAT",
              "target": null
            },
            {
              "id": "Gen:Variant.Ursu",
              "display_name": "Gen:Variant.Ursu",
              "target": null
            },
            {
              "id": "Redcap.rlhse",
              "display_name": "Redcap.rlhse",
              "target": null
            },
            {
              "id": "Trojan.Trickster",
              "display_name": "Trojan.Trickster",
              "target": null
            },
            {
              "id": "HTML_REDIR.SMR",
              "display_name": "HTML_REDIR.SMR",
              "target": null
            },
            {
              "id": "TROJ_FRS.VSNTFK19",
              "display_name": "TROJ_FRS.VSNTFK19",
              "target": null
            },
            {
              "id": "Hoax.JS.Phish",
              "display_name": "Hoax.JS.Phish",
              "target": null
            },
            {
              "id": "JS:Iframe",
              "display_name": "JS:Iframe",
              "target": null
            },
            {
              "id": "Application.SQLCrack",
              "display_name": "Application.SQLCrack",
              "target": null
            },
            {
              "id": "susp.lnk",
              "display_name": "susp.lnk",
              "target": null
            },
            {
              "id": "QVM201.0.B70B.Malware",
              "display_name": "QVM201.0.B70B.Malware",
              "target": null
            },
            {
              "id": "Immortal Stealer",
              "display_name": "Immortal Stealer",
              "target": null
            },
            {
              "id": "WebMonitor RAT",
              "display_name": "WebMonitor RAT",
              "target": null
            },
            {
              "id": "Tor - S0183",
              "display_name": "Tor - S0183",
              "target": null
            },
            {
              "id": "WannaCry",
              "display_name": "WannaCry",
              "target": null
            },
            {
              "id": "WannaCryptor",
              "display_name": "WannaCryptor",
              "target": null
            },
            {
              "id": "WebToolbar",
              "display_name": "WebToolbar",
              "target": null
            },
            {
              "id": "BlackNET",
              "display_name": "BlackNET",
              "target": null
            },
            {
              "id": "DeepScan:Generic.Ransom.GandCrab5",
              "display_name": "DeepScan:Generic.Ransom.GandCrab5",
              "target": null
            },
            {
              "id": "TrojanSpy",
              "display_name": "TrojanSpy",
              "target": null
            },
            {
              "id": "States",
              "display_name": "States",
              "target": null
            },
            {
              "id": "Inmortal",
              "display_name": "Inmortal",
              "target": null
            },
            {
              "id": "Domains",
              "display_name": "Domains",
              "target": null
            },
            {
              "id": "Locky",
              "display_name": "Locky",
              "target": null
            },
            {
              "id": "Delf.NBX",
              "display_name": "Delf.NBX",
              "target": null
            },
            {
              "id": "Gen:NN.ZexaF.32515",
              "display_name": "Gen:NN.ZexaF.32515",
              "target": null
            },
            {
              "id": "FileRepMalware",
              "display_name": "FileRepMalware",
              "target": null
            },
            {
              "id": "Gen:Variant.MSILPerseus",
              "display_name": "Gen:Variant.MSILPerseus",
              "target": null
            },
            {
              "id": "Icefog",
              "display_name": "Icefog",
              "target": null
            },
            {
              "id": "$WebWatson",
              "display_name": "$WebWatson",
              "target": null
            },
            {
              "id": "Agent.AIK.gen",
              "display_name": "Agent.AIK.gen",
              "target": null
            },
            {
              "id": "Agent.AIK.genCIL.StupidCryptor",
              "display_name": "Agent.AIK.genCIL.StupidCryptor",
              "target": null
            },
            {
              "id": "Agent.YPEZ",
              "display_name": "Agent.YPEZ",
              "target": null
            },
            {
              "id": "Application.InnovativSol",
              "display_name": "Application.InnovativSol",
              "target": null
            },
            {
              "id": "Agent.ASO",
              "display_name": "Agent.ASO",
              "target": null
            },
            {
              "id": "S-b748adc5",
              "display_name": "S-b748adc5",
              "target": null
            },
            {
              "id": "W32.eHeur",
              "display_name": "W32.eHeur",
              "target": null
            },
            {
              "id": "Kryptik.GUCB",
              "display_name": "Kryptik.GUCB",
              "target": null
            },
            {
              "id": "AgentTesla",
              "display_name": "AgentTesla",
              "target": null
            },
            {
              "id": "Autoit.bimwt",
              "display_name": "Autoit.bimwt",
              "target": null
            },
            {
              "id": "HEUR:Trojan.OLE2.Alien",
              "display_name": "HEUR:Trojan.OLE2.Alien",
              "target": null
            },
            {
              "id": "AGEN.1038489",
              "display_name": "AGEN.1038489",
              "target": null
            },
            {
              "id": "Gen:Variant.Ser.Strictor",
              "display_name": "Gen:Variant.Ser.Strictor",
              "target": null
            },
            {
              "id": "Packed.Themida.Gen",
              "display_name": "Packed.Themida.Gen",
              "target": null
            },
            {
              "id": "AGEN.1043164",
              "display_name": "AGEN.1043164",
              "target": null
            },
            {
              "id": "TrickBot - S0266",
              "display_name": "TrickBot - S0266",
              "target": null
            },
            {
              "id": "Emotet",
              "display_name": "Emotet",
              "target": null
            },
            {
              "id": "Trojan.PornoAsset",
              "display_name": "Trojan.PornoAsset",
              "target": null
            },
            {
              "id": "Ransom.Win64.PORNOASSET.SM1",
              "display_name": "Ransom.Win64.PORNOASSET.SM1",
              "target": null
            },
            {
              "id": "Gen:Variant.Ulise",
              "display_name": "Gen:Variant.Ulise",
              "target": null
            },
            {
              "id": "Trojan.Win64",
              "display_name": "Trojan.Win64",
              "target": null
            },
            {
              "id": "Dropper.Trojan.Agent",
              "display_name": "Dropper.Trojan.Agent",
              "target": null
            },
            {
              "id": "Heur.BZC.YAX.Pantera.10",
              "display_name": "Heur.BZC.YAX.Pantera.10",
              "target": null
            },
            {
              "id": "malicious.high.ml",
              "display_name": "malicious.high.ml",
              "target": null
            },
            {
              "id": "CVE-2015-1650",
              "display_name": "CVE-2015-1650",
              "target": null
            },
            {
              "id": "Worm.Win64.AutoRun",
              "display_name": "Worm.Win64.AutoRun",
              "target": null
            },
            {
              "id": "AIT.Heur.Cottonmouth.8.78F19BD7",
              "display_name": "AIT.Heur.Cottonmouth.8.78F19BD7",
              "target": null
            },
            {
              "id": "Gen:Variant.Mikey",
              "display_name": "Gen:Variant.Mikey",
              "target": null
            },
            {
              "id": "Trojan.Agent",
              "display_name": "Trojan.Agent",
              "target": null
            },
            {
              "id": "Pua.Gen",
              "display_name": "Pua.Gen",
              "target": null
            },
            {
              "id": "Trojan.Downloader.Generic",
              "display_name": "Trojan.Downloader.Generic",
              "target": null
            },
            {
              "id": "Suspected of Trojan.Downloader.gen",
              "display_name": "Suspected of Trojan.Downloader.gen",
              "target": null
            },
            {
              "id": "HEUR:RemoteAdmin.Generic",
              "display_name": "HEUR:RemoteAdmin.Generic",
              "target": null
            },
            {
              "id": "Gen:Heur.Ransom.HiddenTears",
              "display_name": "Gen:Heur.Ransom.HiddenTears",
              "target": null
            },
            {
              "id": "Nemucod.A",
              "display_name": "Nemucod.A",
              "target": null
            },
            {
              "id": "Backdoor.Hupigon",
              "display_name": "Backdoor.Hupigon",
              "target": null
            },
            {
              "id": "Trojan.Starter JS.Iframe",
              "display_name": "Trojan.Starter JS.Iframe",
              "target": null
            },
            {
              "id": "fake ,promethiumm ,strongpity",
              "display_name": "fake ,promethiumm ,strongpity",
              "target": null
            },
            {
              "id": "PUA.Reg1staid",
              "display_name": "PUA.Reg1staid",
              "target": null
            },
            {
              "id": "Malware.Heur_Generic.A",
              "display_name": "Malware.Heur_Generic.A",
              "target": null
            },
            {
              "id": "Bladabindi.Q",
              "display_name": "Bladabindi.Q",
              "target": null
            },
            {
              "id": "W32.eHeur",
              "display_name": "W32.eHeur",
              "target": null
            },
            {
              "id": "malicious.6e0700",
              "display_name": "malicious.6e0700",
              "target": null
            },
            {
              "id": "Trojan.Inject",
              "display_name": "Trojan.Inject",
              "target": null
            },
            {
              "id": "TSGeneric",
              "display_name": "TSGeneric",
              "target": null
            },
            {
              "id": "RedCap.vneda",
              "display_name": "RedCap.vneda",
              "target": null
            },
            {
              "id": "Trojan.Indiloadz",
              "display_name": "Trojan.Indiloadz",
              "target": null
            },
            {
              "id": "Trojan.Ekstak",
              "display_name": "Trojan.Ekstak",
              "target": null
            },
            {
              "id": "staticrr.paleokits.net",
              "display_name": "staticrr.paleokits.net",
              "target": null
            },
            {
              "id": "MSIL.Downloader",
              "display_name": "MSIL.Downloader",
              "target": null
            },
            {
              "id": "Trojan.Autoruns.GenericKDS",
              "display_name": "Trojan.Autoruns.GenericKDS",
              "target": null
            },
            {
              "id": "MSIL.Trojan.BSE",
              "display_name": "MSIL.Trojan.BSE",
              "target": null
            },
            {
              "id": "Adload.AD81",
              "display_name": "Adload.AD81",
              "target": null
            },
            {
              "id": "Packed.Asprotect",
              "display_name": "Packed.Asprotect",
              "target": null
            },
            {
              "id": "Gen:NN.ZemsilF.34062",
              "display_name": "Gen:NN.ZemsilF.34062",
              "target": null
            },
            {
              "id": "Evo",
              "display_name": "Evo",
              "target": null
            },
            {
              "id": "Agent.pwc",
              "display_name": "Agent.pwc",
              "target": null
            },
            {
              "id": "RiskTool.Phpw",
              "display_name": "RiskTool.Phpw",
              "target": null
            },
            {
              "id": "Gen:Variant.Symmi",
              "display_name": "Gen:Variant.Symmi",
              "target": null
            },
            {
              "id": "Trojan.PWS",
              "display_name": "Trojan.PWS",
              "target": null
            },
            {
              "id": "Generic.BitCoinMiner.3",
              "display_name": "Generic.BitCoinMiner.3",
              "target": null
            },
            {
              "id": "Trojan.Tasker",
              "display_name": "Trojan.Tasker",
              "target": null
            },
            {
              "id": "Gen:NN",
              "display_name": "Gen:NN",
              "target": null
            },
            {
              "id": "Downloader.CertutilURLCache",
              "display_name": "Downloader.CertutilURLCache",
              "target": null
            },
            {
              "id": "Elf",
              "display_name": "Elf",
              "target": null
            },
            {
              "id": "Gen:Heur.MSIL.Androm",
              "display_name": "Gen:Heur.MSIL.Androm",
              "target": null
            },
            {
              "id": "Kryptik.NRD",
              "display_name": "Kryptik.NRD",
              "target": null
            },
            {
              "id": "Riskware",
              "display_name": "Riskware",
              "target": null
            },
            {
              "id": "Kuluoz.B.gen",
              "display_name": "Kuluoz.B.gen",
              "target": null
            },
            {
              "id": "Gen:Variant.RevengeRat",
              "display_name": "Gen:Variant.RevengeRat",
              "target": null
            },
            {
              "id": "Gen:Variant.Mikey",
              "display_name": "Gen:Variant.Mikey",
              "target": null
            },
            {
              "id": "VB.Chronos.7",
              "display_name": "VB.Chronos.7",
              "target": null
            },
            {
              "id": "Kryptik.NOE",
              "display_name": "Kryptik.NOE",
              "target": null
            },
            {
              "id": "HEUR:WebToolbar.Generic",
              "display_name": "HEUR:WebToolbar.Generic",
              "target": null
            },
            {
              "id": "Gen:Variant.Barys",
              "display_name": "Gen:Variant.Barys",
              "target": null
            },
            {
              "id": "Backdoor.Xtreme",
              "display_name": "Backdoor.Xtreme",
              "target": null
            },
            {
              "id": "Trojan.MSIL",
              "display_name": "Trojan.MSIL",
              "target": null
            },
            {
              "id": "Gen:Variant.Graftor",
              "display_name": "Gen:Variant.Graftor",
              "target": null
            },
            {
              "id": "Backdoor.Agent",
              "display_name": "Backdoor.Agent",
              "target": null
            },
            {
              "id": "Unsafe",
              "display_name": "Unsafe",
              "target": null
            },
            {
              "id": "Trojan.PHP.Agent",
              "display_name": "Trojan.PHP.Agent",
              "target": null
            },
            {
              "id": "Trojan.Agent",
              "display_name": "Trojan.Agent",
              "target": null
            },
            {
              "id": "HEUR:Exploit.Generic",
              "display_name": "HEUR:Exploit.Generic",
              "target": null
            },
            {
              "id": "Ransom_WCRY.SMALYM",
              "display_name": "Ransom_WCRY.SMALYM",
              "target": null
            },
            {
              "id": "Ransom_WCRY.SMJ",
              "display_name": "Ransom_WCRY.SMJ",
              "target": null
            },
            {
              "id": "Auslogics",
              "display_name": "Auslogics",
              "target": null
            },
            {
              "id": "Gen:Variant.Jaiko",
              "display_name": "Gen:Variant.Jaiko",
              "target": null
            },
            {
              "id": "Exploit.W32.Agent",
              "display_name": "Exploit.W32.Agent",
              "target": null
            },
            {
              "id": "Trojan.Cud.Gen",
              "display_name": "Trojan.Cud.Gen",
              "target": null
            },
            {
              "id": "Trojan.DOC.Downloader",
              "display_name": "Trojan.DOC.Downloader",
              "target": null
            },
            {
              "id": "Backdoor.MSIL.Agent",
              "display_name": "Backdoor.MSIL.Agent",
              "target": null
            },
            {
              "id": "Gen:Trojan.Heur2.LPTbHW@W64.HfsAutoB",
              "display_name": "Gen:Trojan.Heur2.LPTbHW@W64.HfsAutoB",
              "target": null
            },
            {
              "id": "Gen:Variant.Kazy",
              "display_name": "Gen:Variant.Kazy",
              "target": null
            },
            {
              "id": "Gen:Variant.Zusy",
              "display_name": "Gen:Variant.Zusy",
              "target": null
            },
            {
              "id": "Ransom.WannaCrypt",
              "display_name": "Ransom.WannaCrypt",
              "target": null
            },
            {
              "id": "Generic.ServStart.A",
              "display_name": "Generic.ServStart.A",
              "target": null
            },
            {
              "id": "Trojan.Wanna",
              "display_name": "Trojan.Wanna",
              "target": null
            },
            {
              "id": "Generic.MSIL.Bladabindi",
              "display_name": "Generic.MSIL.Bladabindi",
              "target": null
            },
            {
              "id": "TROJ_GEN.R002C0OG518",
              "display_name": "TROJ_GEN.R002C0OG518",
              "target": null
            },
            {
              "id": "Trojan.Chapak",
              "display_name": "Trojan.Chapak",
              "target": null
            },
            {
              "id": "Indiloadz.BB",
              "display_name": "Indiloadz.BB",
              "target": null
            },
            {
              "id": "BehavBehavesLike.PUPXBI",
              "display_name": "BehavBehavesLike.PUPXBI",
              "target": null
            },
            {
              "id": "DeepScan:Generic.SpyAgent.6",
              "display_name": "DeepScan:Generic.SpyAgent.6",
              "target": null
            },
            {
              "id": "Python.KeyLogger",
              "display_name": "Python.KeyLogger",
              "target": null
            },
            {
              "id": "GameHack.CRS",
              "display_name": "GameHack.CRS",
              "target": null
            },
            {
              "id": "Generic.MSIL.PasswordStealer",
              "display_name": "Generic.MSIL.PasswordStealer",
              "target": null
            },
            {
              "id": "PSW.Agent",
              "display_name": "PSW.Agent",
              "target": null
            },
            {
              "id": "malicious.8c45ba",
              "display_name": "malicious.8c45ba",
              "target": null
            },
            {
              "id": "Dropper.Binder",
              "display_name": "Dropper.Binder",
              "target": null
            },
            {
              "id": "Constructor.MSIL",
              "display_name": "Constructor.MSIL",
              "target": null
            },
            {
              "id": "Linux.Agent",
              "display_name": "Linux.Agent",
              "target": null
            },
            {
              "id": "Virus.3DMax.Script",
              "display_name": "Virus.3DMax.Script",
              "target": null
            },
            {
              "id": "ScrInject.B",
              "display_name": "ScrInject.B",
              "target": null
            },
            {
              "id": "Trojan.WisdomEyes.16070401.9500",
              "display_name": "Trojan.WisdomEyes.16070401.9500",
              "target": null
            },
            {
              "id": "Application.SearchProtect",
              "display_name": "Application.SearchProtect",
              "target": null
            },
            {
              "id": "JS:Trojan.Clicker",
              "display_name": "JS:Trojan.Clicker",
              "target": null
            },
            {
              "id": "Faceliker.A",
              "display_name": "Faceliker.A",
              "target": null
            },
            {
              "id": "JS:Trojan.JS.Faceliker",
              "display_name": "JS:Trojan.JS.Faceliker",
              "target": null
            },
            {
              "id": "Constructor.MSIL  Linux.Agent",
              "display_name": "Constructor.MSIL  Linux.Agent",
              "target": null
            },
            {
              "id": "PowerShell.Trojan",
              "display_name": "PowerShell.Trojan",
              "target": null
            },
            {
              "id": "HTML:Script",
              "display_name": "HTML:Script",
              "target": null
            },
            {
              "id": "ScrInject.B",
              "display_name": "ScrInject.B",
              "target": null
            },
            {
              "id": "W32.AIDetectVM",
              "display_name": "W32.AIDetectVM",
              "target": null
            },
            {
              "id": "HackTool.CheatEngine",
              "display_name": "HackTool.CheatEngine",
              "target": null
            },
            {
              "id": "Injector.CLDS",
              "display_name": "Injector.CLDS",
              "target": null
            },
            {
              "id": "VB.Downloader.2",
              "display_name": "VB.Downloader.2",
              "target": null
            },
            {
              "id": "malicious.3e78cc",
              "display_name": "malicious.3e78cc",
              "target": null
            },
            {
              "id": "malicious.d800d6",
              "display_name": "malicious.d800d6",
              "target": null
            },
            {
              "id": "VB.PwShell.2",
              "display_name": "VB.PwShell.2",
              "target": null
            },
            {
              "id": "Backdoor.RBot",
              "display_name": "Backdoor.RBot",
              "target": null
            },
            {
              "id": "malicious.71b1a8",
              "display_name": "malicious.71b1a8",
              "target": null
            },
            {
              "id": "TrojanSpy.KeyLogger",
              "display_name": "TrojanSpy.KeyLogger",
              "target": null
            },
            {
              "id": "Injector.JDO",
              "display_name": "Injector.JDO",
              "target": null
            },
            {
              "id": "Heur.Msword.Gen",
              "display_name": "Heur.Msword.Gen",
              "target": null
            },
            {
              "id": "PSW.Discord",
              "display_name": "PSW.Discord",
              "target": null
            },
            {
              "id": "Packed.VMProtect",
              "display_name": "Packed.VMProtect",
              "target": null
            },
            {
              "id": "HEUR:AdWare.StartSurf",
              "display_name": "HEUR:AdWare.StartSurf",
              "target": null
            },
            {
              "id": "Gen:Heur.NoobyProtect",
              "display_name": "Gen:Heur.NoobyProtect",
              "target": null
            },
            {
              "id": "CIL.HeapOverride",
              "display_name": "CIL.HeapOverride",
              "target": null
            },
            {
              "id": "HEUR:Trojan.Tasker",
              "display_name": "HEUR:Trojan.Tasker",
              "target": null
            },
            {
              "id": "XLM.Trojan.Abracadabra.27",
              "display_name": "XLM.Trojan.Abracadabra.27",
              "target": null
            },
            {
              "id": "HEUR:Backdoor.MSIL.NanoBot",
              "display_name": "HEUR:Backdoor.MSIL.NanoBot",
              "target": null
            },
            {
              "id": "Trojan.PSW.Mimikatz",
              "display_name": "Trojan.PSW.Mimikatz",
              "target": null
            },
            {
              "id": "TrojanSpy.Python",
              "display_name": "TrojanSpy.Python",
              "target": null
            },
            {
              "id": "Trojan.Ole2.Vbs",
              "display_name": "Trojan.Ole2.Vbs",
              "target": null
            },
            {
              "id": "Exploit.MSOffice",
              "display_name": "Exploit.MSOffice",
              "target": null
            },
            {
              "id": "DeepScan:Generic.Ransom.AmnesiaE",
              "display_name": "DeepScan:Generic.Ransom.AmnesiaE",
              "target": null
            },
            {
              "id": "Wacatac.D6",
              "display_name": "Wacatac.D6",
              "target": null
            },
            {
              "id": "Backdoor.Androm",
              "display_name": "Backdoor.Androm",
              "target": null
            },
            {
              "id": "Packed.NetSeal",
              "display_name": "Packed.NetSeal",
              "target": null
            },
            {
              "id": "Trojan.MSIL.Injector",
              "display_name": "Trojan.MSIL.Injector",
              "target": null
            },
            {
              "id": "Trojan.PWS.Agent",
              "display_name": "Trojan.PWS.Agent",
              "target": null
            },
            {
              "id": "TScope.Trojan",
              "display_name": "TScope.Trojan",
              "target": null
            },
            {
              "id": "PSW.Stealer",
              "display_name": "PSW.Stealer",
              "target": null
            },
            {
              "id": "Trojan.PackedNET",
              "display_name": "Trojan.PackedNET",
              "target": null
            },
            {
              "id": "Trojan.Java",
              "display_name": "Trojan.Java",
              "target": null
            },
            {
              "id": "MalwareX",
              "display_name": "MalwareX",
              "target": null
            },
            {
              "id": "Trojan.PSW.Python",
              "display_name": "Trojan.PSW.Python",
              "target": null
            },
            {
              "id": "malicious.11abfc",
              "display_name": "malicious.11abfc",
              "target": null
            },
            {
              "id": "Generic.ASMalwS",
              "display_name": "Generic.ASMalwS",
              "target": null
            },
            {
              "id": "HEUR:Trojan.MSIL.Tasker",
              "display_name": "HEUR:Trojan.MSIL.Tasker",
              "target": null
            },
            {
              "id": "PossibleThreat.PALLAS",
              "display_name": "PossibleThreat.PALLAS",
              "target": null
            },
            {
              "id": "Backdoor.Poison",
              "display_name": "Backdoor.Poison",
              "target": null
            },
            {
              "id": "Generic.MSIL.LimeRAT",
              "display_name": "Generic.MSIL.LimeRAT",
              "target": null
            },
            {
              "id": "PWS-FCZZ",
              "display_name": "PWS-FCZZ",
              "target": null
            },
            {
              "id": "Trojan.Script",
              "display_name": "Trojan.Script",
              "target": null
            },
            {
              "id": "Gen:Heur.MSIL.Inject",
              "display_name": "Gen:Heur.MSIL.Inject",
              "target": null
            },
            {
              "id": "Trojan.PWS.Growtopia",
              "display_name": "Trojan.PWS.Growtopia",
              "target": null
            },
            {
              "id": "Spyware.Bobik",
              "display_name": "Spyware.Bobik",
              "target": null
            },
            {
              "id": "HackTool.BruteForce",
              "display_name": "HackTool.BruteForce",
              "target": null
            },
            {
              "id": "Hack.Patcher",
              "display_name": "Hack.Patcher",
              "target": null
            },
            {
              "id": "PWS.p",
              "display_name": "PWS.p",
              "target": null
            },
            {
              "id": "Suppobox",
              "display_name": "Suppobox",
              "target": null
            },
            {
              "id": "index.php",
              "display_name": "index.php",
              "target": null
            },
            {
              "id": "Packed.VMProtect",
              "display_name": "Packed.VMProtect",
              "target": null
            },
            {
              "id": "SmokeLoader",
              "display_name": "SmokeLoader",
              "target": null
            },
            {
              "id": "Generic.Malware",
              "display_name": "Generic.Malware",
              "target": null
            },
            {
              "id": "SNH:Script [Dropper]",
              "display_name": "SNH:Script [Dropper]",
              "target": null
            },
            {
              "id": "HEUR:Trojan.MSOffice.SAgent",
              "display_name": "HEUR:Trojan.MSOffice.SAgent",
              "target": null
            },
            {
              "id": "Script.INF",
              "display_name": "Script.INF",
              "target": null
            },
            {
              "id": "JS:Trojan.JS.Likejack",
              "display_name": "JS:Trojan.JS.Likejack",
              "target": null
            },
            {
              "id": "SNH:Script [Dropper]",
              "display_name": "SNH:Script [Dropper]",
              "target": null
            },
            {
              "id": "Trojan.JS.Agent",
              "display_name": "Trojan.JS.Agent",
              "target": null
            },
            {
              "id": "APT Notes",
              "display_name": "APT Notes",
              "target": null
            },
            {
              "id": "susp.rtf.objupdate",
              "display_name": "susp.rtf.objupdate",
              "target": null
            },
            {
              "id": "RedCap.zoohz",
              "display_name": "RedCap.zoohz",
              "target": null
            },
            {
              "id": "Trojan.Tasker",
              "display_name": "Trojan.Tasker",
              "target": null
            },
            {
              "id": "virus.office.qexvmc",
              "display_name": "virus.office.qexvmc",
              "target": null
            },
            {
              "id": "Trojan.KillProc",
              "display_name": "Trojan.KillProc",
              "target": null
            },
            {
              "id": "Generic.MSIL.GrwtpStealer.1",
              "display_name": "Generic.MSIL.GrwtpStealer.1",
              "target": null
            },
            {
              "id": "Suspicious.Cloud",
              "display_name": "Suspicious.Cloud",
              "target": null
            },
            {
              "id": "PowerShell.DownLoader",
              "display_name": "PowerShell.DownLoader",
              "target": null
            },
            {
              "id": "Downldr.gen",
              "display_name": "Downldr.gen",
              "target": null
            },
            {
              "id": "AGEN.1030939",
              "display_name": "AGEN.1030939",
              "target": null
            },
            {
              "id": "HackTool.Binder",
              "display_name": "HackTool.Binder",
              "target": null
            },
            {
              "id": "Trojan.Inject",
              "display_name": "Trojan.Inject",
              "target": null
            },
            {
              "id": "Dldr.Agent",
              "display_name": "Dldr.Agent",
              "target": null
            },
            {
              "id": "Dropper.MSIL",
              "display_name": "Dropper.MSIL",
              "target": null
            },
            {
              "id": "Trojan.VBKryjetor",
              "display_name": "Trojan.VBKryjetor",
              "target": null
            },
            {
              "id": "PWSX",
              "display_name": "PWSX",
              "target": null
            },
            {
              "id": "VB:Trojan.VBA.Agent",
              "display_name": "VB:Trojan.VBA.Agent",
              "target": null
            },
            {
              "id": "HEUR:Trojan.MSOffice.Stratos",
              "display_name": "HEUR:Trojan.MSOffice.Stratos",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1071.004",
              "name": "DNS",
              "display_name": "T1071.004 - DNS"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1059.007",
              "name": "JavaScript",
              "display_name": "T1059.007 - JavaScript"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1068",
              "name": "Exploitation for Privilege Escalation",
              "display_name": "T1068 - Exploitation for Privilege Escalation"
            },
            {
              "id": "TA0029",
              "name": "Privilege Escalation",
              "display_name": "TA0029 - Privilege Escalation"
            },
            {
              "id": "T1449",
              "name": "Exploit SS7 to Redirect Phone Calls/SMS",
              "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
            },
            {
              "id": "T1190",
              "name": "Exploit Public-Facing Application",
              "display_name": "T1190 - Exploit Public-Facing Application"
            },
            {
              "id": "T1210",
              "name": "Exploitation of Remote Services",
              "display_name": "T1210 - Exploitation of Remote Services"
            },
            {
              "id": "T1450",
              "name": "Exploit SS7 to Track Device Location",
              "display_name": "T1450 - Exploit SS7 to Track Device Location"
            },
            {
              "id": "T1211",
              "name": "Exploitation for Defense Evasion",
              "display_name": "T1211 - Exploitation for Defense Evasion"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "TA0011",
              "name": "Command and Control",
              "display_name": "TA0011 - Command and Control"
            },
            {
              "id": "T1412",
              "name": "Capture SMS Messages",
              "display_name": "T1412 - Capture SMS Messages"
            },
            {
              "id": "T1454",
              "name": "Malicious SMS Message",
              "display_name": "T1454 - Malicious SMS Message"
            },
            {
              "id": "T1001",
              "name": "Data Obfuscation",
              "display_name": "T1001 - Data Obfuscation"
            },
            {
              "id": "T1114",
              "name": "Email Collection",
              "display_name": "T1114 - Email Collection"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1498",
              "name": "Network Denial of Service",
              "display_name": "T1498 - Network Denial of Service"
            },
            {
              "id": "T1496",
              "name": "Resource Hijacking",
              "display_name": "T1496 - Resource Hijacking"
            },
            {
              "id": "T1176",
              "name": "Browser Extensions",
              "display_name": "T1176 - Browser Extensions"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": "654c5970817e6bf8b0e5b5ff",
          "export_count": 334,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 1184,
            "FileHash-SHA1": 949,
            "FileHash-SHA256": 3712,
            "URL": 2925,
            "domain": 627,
            "hostname": 1319,
            "CVE": 26,
            "email": 8,
            "CIDR": 2
          },
          "indicator_count": 10752,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 228,
          "modified_text": "904 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "https://hybrid-analysis.com/sample/6765f47ea77c8274c8e4973ed95aedf59e75998c62f6029e23c58cdf36ed85ba/654afdbdc621e7037801cce7",
        "https://www.apple.com/shop/browse/open/country_selector     (exploit)",
        "IPv4 45.15.156.208            command_and_control",
        "Hostname: www.supernetforme.com      command_and_control",
        "IPv4 45.12.253.72.            command_and_control",
        "https://www.pornhub.com/video/search?search=tsara+brashears (Malicious PW cracker | stylebk.css stylesheets - not found )",
        "http://init-p01st.push.apple.com/bag            (malicious web creator)",
        "www.norad.mil   (federal tracking tool used by attorneys, law firms, and private investigators 'licensed or unlicensed') hi!",
        "https://www.anyxxxtube.net/search-porn/tsara-brashears/ (phishing, ELF, Prism.exe found)",
        "http://182.22.25.124:7878/182.22.25.124:443     (malicious dropper)",
        "Abuse IPDB Link: https://www.abuseipdb.com/check/20.99.186.246",
        "https://downloaddevtools.ir/     (phishing)",
        "opencve.djgummikuh.de        (CVE dispensary)",
        "Maltiverse Research Team",
        "VirusTotal Link: https://www.virustotal.com/gui/ip-address/20.99.186.246/detection",
        "Hostname: ddos.dnsnb8.net                        command_and_control",
        "IPv4 95.213.186.51              command_and_control",
        "URLhaus Abuse.ch",
        "https://itunes.apple.com/app/apple-store/id284815942/us/app/samsung-galaxy-watch-gear-s/id1117310635.                   (iOS unlocker and hijacker)",
        "fp2e7a.wpc.2be4.phicdn.net",
        "apples.encryptedwork.com        (Interesting in the blacknet)",
        "ThreatFox Abuse.ch",
        "Hybrid Analysis",
        "init.ess.apple.com         (malicious code script)",
        "happylifehappywife.com",
        "http://ambisexual.phone-sex-blogs.com/http:/ambisexual.phone-sex-blogs.com/images/thumbnails/pic118.jpg             (phishing)",
        "https://urlscan.io/result/a328d9ff-fb49-4078-960d-a757fd41404f/#indicators",
        "20.99.186.246 exploit source",
        "https://www.anyxxxtube.net/media/favicon/apple              (password cracker and iOS hijacker)",
        "IPv4 63.251.106.25             command_and_control",
        "Deep Research",
        "IPv4 72.251.233.245           command_and_control",
        "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian (password cracker)",
        "Cyber Threat Coalition",
        "IPv4 103.224.182.246        command_and_control",
        "URLscan.io",
        "IPv4 104.247.81.51             command_and_control"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 0
        },
        "other": {
          "adversary": [
            "Lucky Mouse APT27 | NoName057(16) |  Unnamed"
          ],
          "malware_families": [
            "Vb.pwshell.2",
            "Bscope.trojan",
            "Generic.malware.smyb",
            "Behavbehaveslike.pupxbi",
            "Dropper.binder",
            "Suppobox",
            "Adload.ad81",
            "Blacknet",
            "Trojan.tasker",
            "Heur:trojan.tasker",
            "Psw.stealer",
            "Dridex",
            "Trojan.trickbot",
            "Trojan.downloader.generic",
            "Apt notes",
            "Trojan.ransom.generickd",
            "Dropped:generic.ransom.dmr",
            "Malicious.high.ml",
            "Agent.aik.gen",
            "Trojan.autoruns.generickds",
            "Unsafe.ai_score_100%",
            "Evo",
            "Gen:variant.graftor",
            "Suspicious.cloud",
            "Black.gen2",
            "Trojan.wanna",
            "Trojan.inject",
            "Index.php",
            "Agen.1043164",
            "Gen:variant.jaiko",
            "Gen:variant.johnnie",
            "Presenoker",
            "Vb.emooodldr.10",
            "Trojan.ekstak",
            "Psw.discord",
            "Malicious.moderate.ml",
            "Suspicious.low.ml",
            "Tor - s0183",
            "Html_redir.smr",
            "Trojan.malware.121218",
            "Riskware",
            "Kryptik.gucb",
            "Kryptik.noe",
            "Troj_gen.r002c0og518",
            "Elf",
            "Worm.win64.autorun",
            "Staticrr.paleokits.net",
            "Gen:variant.zusy",
            "Injector.jdo",
            "Ransom.wannacrypt",
            "Powershell.downloader",
            "Emotet",
            "Malicious.11abfc",
            "Faceliker.a",
            "Scrinject.b",
            "Downloader.certutilurlcache",
            "Riskware.hacktool.agent",
            "Agen.1038489",
            "Program.unwanted",
            "Heur:trojan.msil.tasker",
            "Trojan.php.agent",
            "Constructor.msil  linux.agent",
            "Ml.generic",
            "Trojan.indiloadz",
            "Heur:exploit.generic",
            "Artemis",
            "Gamehack.nl",
            "Script.inf",
            "Backdoor.xtreme",
            "Constructor.msil",
            "Riskware.agent",
            "Redcap.rlhse",
            "Gen:variant.ulise",
            "Trojan.pws.growtopia",
            "Gen:heur.msil.androm",
            "Troj_frs.vsntfk19",
            "Backdoor.agent",
            "Gen:nn.zexaf.32515",
            "Heur:trojan.linux.agent",
            "Malicious.d800d6",
            "Generic.malware",
            "Virus.virut",
            "Phishing.html",
            "Filerepmalware",
            "Dropper.msil",
            "Redcap.vneda",
            "Wannacryptor",
            "Ransom.win64.wacatac.oa",
            "Ransom_wcry.smj",
            "Agent.pwc",
            "Sdbot.caoc",
            "Trojan.killproc",
            "Exploit.msoffice",
            "Trojan.msil.injector",
            "Riskware.netfilter",
            "Gen:variant.symmi",
            "Trojan.generic",
            "Heur.msword.gen",
            "Powershell.trojan",
            "Generic.trickbot.1",
            "Risktool.phpw",
            "Delf.nbx",
            "Wannacry",
            "Downldr.gen",
            "Generic.msil.passwordstealer",
            "Gen:variant.cerbu",
            "Agent.ypez",
            "Python.keylogger",
            "Tsgeneric",
            "Vb:trojan.valyria",
            "Unsafe",
            "Gen:variant.ursu",
            "Phish.ab",
            "Trojan.pws.agent",
            "Adware.kuzitui",
            "Possiblethreat.pallas",
            "Injector.is.gen",
            "Webmonitor rat",
            "Gen:variant.barys",
            "States",
            "Trojan.starter js.iframe",
            "Malicious.f01f67",
            "Bscope.riskware",
            "Trojan.delshad",
            "Gen:variant.midie",
            "Agen.1141126",
            "Suspected of trojan.downloader.gen",
            "Deepscan:generic.ransom.gandcrab5",
            "Susp.rtf.objupdate",
            "Gen:heur.msil.inject",
            "Trojandownloader:linux/downldr",
            "Trojan.wisdomeyes.16070401.9500",
            "Heur/qvm42.3.72eb.malware",
            "Dangerousobject.multi",
            "Trojan.chapak",
            "Zbd zeus",
            "Azorult",
            "Hacktool.cheatengine",
            "Wacatac.d6",
            "Virus.3dmax.script",
            "Msil.trojan.bse",
            "Gen:heur.ransom.msil",
            "Trojan.python",
            "Trojanspy",
            "Trojanspy.python",
            "Trojan.androm.gen",
            "Trickbot - s0266",
            "Trojanspy.keylogger",
            "Gen:nn.zemsilf.34062",
            "Vb.emodldr.4",
            "Trojan.pornoasset",
            "Js:trojan.js.likejack",
            "Ait.heur.cottonmouth.8.78f19bd7",
            "Immortal stealer",
            "Behaveslike.exploit",
            "Generic.msil.grwtpstealer.1",
            "Msil.downloader",
            "Macro.trojan.dropperd",
            "Hacktool.bruteforce",
            "Agenttesla",
            "Fake ,promethiumm ,strongpity",
            "Locky",
            "Backdoor.hupigon",
            "Js:trojan.clicker",
            "Suspicious.save",
            "Nemucod.a",
            "Malware.tk.generic",
            "Generic.msil.bladabindi",
            "Js:trojan.hidelink",
            "Gen:variant.revengerat",
            "Malicious.71b1a8",
            "Webtoolbar",
            "Packed.asprotect",
            "Gen:variant.kazy",
            "Gen:variant.mikey",
            "Bladabindi.q",
            "Trojan.java",
            "Injector.clds",
            "Gen:heur.noobyprotect",
            "Linux.agent",
            "Zpevdo.b",
            "Trojan.ole2.vbs",
            "Malwarex",
            "Exploit.w32.agent",
            "Gen:heur.ransom.hiddentears",
            "Generic.msil.limerat",
            "Virus.office.qexvmc",
            "Autoit.bimwt",
            "Qvm201.0.b70b.malware",
            "Kryptik.fph.gen",
            "Heur.vba.trojan",
            "W32.eheur",
            "Gen:variant.razy",
            "Ramnit.n",
            "Trojan:vba/downldr",
            "Heur:remoteadmin.generic",
            "Agent.nbae",
            "Malicious.8c45ba",
            "Il:trojan.msilzilla",
            "Gamehack.crs",
            "Heur:webtoolbar.generic",
            "Domains",
            "Pws.p",
            "Agent.aik.gencil.stupidcryptor",
            "Deepscan:generic.spyagent.6",
            "$webwatson",
            "Vb.downloader.2",
            "Macro.downloader.amip",
            "Gen:variant.bulz",
            "Heur:trojan.ole2.alien",
            "Trojan.script",
            "Psw.agent",
            "Exploit.cve",
            "Auslogics",
            "Dropper.trojan.generic",
            "Blacknet rat",
            "Application.innovativsol",
            "Susp.lnk",
            "Trojan.packednet",
            "Script.agent",
            "Gen:trojan.heur2.lptbhw@w64.hfsautob",
            "Trojan.agent",
            "Backdoor.rbot",
            "Js:trojan.js.faceliker",
            "Trojan.trickster",
            "Hack.patcher",
            "Generic.asmalws",
            "Heur:backdoor.msil.nanobot",
            "Heur:trojan.msoffice.alien",
            "Icefog",
            "Kryptik.nrd",
            "Js:trojan.cryxos",
            "Trojan.cud.gen",
            "Vb:trojan.vba.agent",
            "W32.trojan",
            "Trojan.win64",
            "Trojan:python/downldr",
            "Trojan.vbkryjetor",
            "Ransom.win64.pornoasset.sm1",
            "Gen:nn",
            "Indiloadz.bb",
            "Dropper.trojan.agent",
            "Backdoor.msil.agent",
            "Loki bot",
            "Agen.1030939",
            "Skynet",
            "Trojan.heur",
            "Gen:variant.msilperseus",
            "Macro.agent",
            "Packed.themida.gen",
            "Pua.gen",
            "Riskware.crack",
            "Hacktool.binder",
            "S-b748adc5",
            "Exploit cve-2017-11882",
            "Virus.ramnit",
            "Hw32.packed",
            "Generic.bitcoinminer.3",
            "Sgeneric",
            "Suspicious_gen.f47v0520",
            "Feodo",
            "Backdoor.poison",
            "Packed-gv",
            "Opensubtitles.a",
            "Cil.stupidcryptor",
            "Heur.bzc.yax.pantera.10",
            "Deepscan:generic.ransom.amnesiae",
            "Xegumumune.8596c22f",
            "Gen:variant.sirefef",
            "Trojan.pws",
            "Agen.1144657",
            "Js:iframe",
            "Application.searchprotect",
            "Vb.chronos.7",
            "Ransom:win32/cve-2017-0147",
            "Adware.downware",
            "Hoax.js.phish",
            "Malware.heur_generic.a",
            "Tscope.trojan",
            "Adware.installmonetizer",
            "Gamehack.dom",
            "Smokeloader",
            "Application.sqlcrack",
            "Malicious.6e0700",
            "Trojan.malware.300983",
            "Heur:adware.startsurf",
            "Trojan.js.agent",
            "Cil.heapoverride",
            "Trojan.psw.mimikatz",
            "Xlm.trojan.abracadabra.27",
            "Trojan.doc.downloader",
            "Trojan.html.phish",
            "Loki password stealer (pws)",
            "Gen:nn.zemsilf.34128",
            "Redline stealer",
            "Heur/qvm41.2.da9b.malware",
            "Wacapew.c",
            "Trojan.psw.python",
            "Trojanspy.java",
            "Dldr.agent",
            "W32.aidetectvm",
            "Behaveslike.ransom",
            "Snh:script [dropper]",
            "Malicious.3e78cc",
            "Cve-2015-1650",
            "Generic.servstart.a",
            "Agen.1045227",
            "Phish.jat",
            "Pws-fczz",
            "Packed.netseal",
            "Trojan:linux/downldr",
            "Trojan:msil/burkina",
            "Vba.downloader",
            "Pwsx",
            "Kuluoz.b.gen",
            "Pua.reg1staid",
            "Heur:trojan.msoffice.sagent",
            "Trojan.vba",
            "Inmortal",
            "W32.aidetect",
            "Backdoor.androm",
            "Trojan.notifier",
            "Agent.aso",
            "Html:script",
            "Trojan.msil",
            "Gen:variant.ser.strictor",
            "Packed.vmprotect",
            "Ransom_wcry.smalym",
            "Heur:trojan.msoffice.stratos",
            "Redcap.zoohz",
            "Spyware.bobik"
          ],
          "industries": [],
          "unique_indicators": 11430
        }
      }
    },
    "false_positive": [],
    "alexa": "http://www.alexa.com/siteinfo/inwx.de",
    "whois": "http://whois.domaintools.com/inwx.de",
    "domain": "inwx.de",
    "hostname": "management.inwx.de"
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 7,
  "pulses": [
    {
      "id": "69fc2ceaf9989ac75c80ac68",
      "name": "Credit [ty] OctoSeek - please follow them [Lucky Mouse APT27 | Feodo Tracker | Malicious Tor Server] - this post is so true",
      "description": "",
      "modified": "2026-05-07T06:24:09.569000",
      "created": "2026-05-07T06:10:50.373000",
      "tags": [
        "ssl certificate",
        "historical ssl",
        "communicating",
        "contacted",
        "resolutions",
        "whois record",
        "whois whois",
        "whois parent",
        "whois siblings",
        "skynet",
        "threat report",
        "ip summary",
        "url summary",
        "summary",
        "sample",
        "samples",
        "detection list",
        "blacklist",
        "cisco umbrella",
        "site",
        "safe site",
        "million",
        "team",
        "microsoft",
        "back",
        "download",
        "phishing",
        "union",
        "bank",
        "malicious site",
        "blacklist http",
        "exit",
        "traffic",
        "node tcp",
        "tor known",
        "tor relayrouter",
        "et tor",
        "known tor",
        "relayrouter",
        "anonymizer",
        "spammer",
        "malware",
        "dropped",
        "unlocker",
        "http",
        "critical risk",
        "redline stealer",
        "core",
        "hacktool",
        "execution",
        "type win32",
        "exe size",
        "first seen",
        "file name",
        "avast win32",
        "win32",
        "avg win32",
        "fortinet",
        "vitro",
        "mb first",
        "rmndrp",
        "clean mx",
        "undetected dns8",
        "undetected vx",
        "sophos",
        "vault",
        "zdb zeus",
        "cmc threat",
        "snort ip",
        "feodo tracker",
        "cybereason",
        "send bug",
        "pe yandex",
        "no data",
        "tag count",
        "count blacklist",
        "tag tag",
        "algorithm",
        "v3 serial",
        "number",
        "issuer",
        "cus cnr3",
        "olet",
        "subject public",
        "key info",
        "key algorithm",
        "key identifier",
        "first",
        "seen",
        "valid",
        "no na",
        "no no",
        "ip security",
        "cndst root",
        "ca x3",
        "ca id",
        "research group",
        "cnisrg root",
        "no expired",
        "mozilla",
        "android",
        "malicious red team",
        "tsara brashears",
        "cyber stalking",
        "malvertizing",
        "invasion of privacy",
        "threat",
        "adult content",
        "apple",
        "iphone unlocker",
        "android",
        "exploited spyware",
        "malware host",
        "brute force",
        "revenge-rat",
        "banker",
        "evasive",
        "domain",
        "redline",
        "stealer",
        "phishing",
        "ramnit",
        "unreliable subdomains",
        "dridex",
        "gating",
        "msil",
        "rat",
        "loki",
        "network",
        "hacking",
        "sinkhole",
        "azorult",
        "c2",
        "historicalandnew",
        "targeted attack",
        "puffstealer",
        "rultazo",
        "lokibot",
        "loki pws",
        "burkina",
        "banker,dde,dridex,exploit",
        "banker,dridex,evasive",
        "trickbot",
        "ransomware,torrentlocker",
        "exploit_source",
        "blacknet",
        "FileRepMalware",
        "linux agent",
        "blacknet",
        "ios",
        "phishing paypal",
        "tagging",
        "defacement",
        "hit",
        "bounty",
        "phishing site",
        "malware site",
        "malware download",
        "endangerment",
        "Malicious domain - SANS Internet Storm Center",
        "evasive,msil,rat,revenge-rat",
        "prism_setting",
        "prism_object",
        "static engine",
        "social engineering",
        "jansky",
        "worm",
        "network rat",
        "networm",
        "Loki Password Stealer (PWS)",
        "South Carolina Federal Credit Union phishing",
        "darkweb",
        "yandex",
        "redirectors",
        "blacknet threats",
        "phishing,ransomware,sinkhole",
        "wanacrypt0r,wannacry,wcry",
        "tor c++",
        "tor c++ client",
        "python user",
        "js user",
        "hacker",
        "hijacker",
        "heur",
        "maltiverse",
        "alexa top",
        "exploit",
        "riskware",
        "unsafe",
        "outbreak",
        "downer",
        "shell",
        "mediamagnet",
        "sality",
        "swrort",
        "adaptivebee",
        "unruy",
        "iobit",
        "dropper",
        "trojanx",
        "artemis",
        "installcore",
        "webshell",
        "crack",
        "webtoolbar",
        "search live",
        "api blog",
        "docs pricing",
        "november",
        "de indicators",
        "domains",
        "hashes",
        "__convergedlogin_pcustomizationloader_44b450e8d543eb53930d",
        "malicious url",
        "financial",
        "blacknet rat",
        "azorult",
        "stealer",
        "deep scan",
        "blacklist https",
        "referrer",
        "collections kp",
        "incident ip",
        "sneaky server",
        "replacement",
        "unauthorized",
        "emotet",
        "noname057",
        "generic malware",
        "engineering",
        "cyber threat",
        "facebook",
        "paypal",
        "dropbox",
        "united",
        "america",
        "banking",
        "wells fargo",
        "steam",
        "twitter",
        "sliver",
        "daum",
        "swift",
        "runescape",
        "betabot",
        "district",
        "iframe",
        "alexa",
        "downldr",
        "agent",
        "presenoker",
        "bladabindi",
        "live",
        "conduit",
        "pony",
        "covid19",
        "malicious",
        "cobalt strike",
        "suppobox",
        "ramnit",
        "meterpreter",
        "virut",
        "njrat",
        "pykspa",
        "asyncrat",
        "downloader",
        "fakealert",
        "binder",
        "virustotal",
        "formbook",
        "necurs",
        "trojan",
        "msil",
        "hiloti",
        "vawtrak",
        "simda",
        "kraken",
        "solimba",
        "icedid",
        "redirector",
        "suspic",
        "amadey",
        "raccoon",
        "nanocore rat",
        "revenge rat",
        "genkryptik",
        "fuery",
        "wacatac",
        "service",
        "cloudeye",
        "tinba",
        "domaiq",
        "ave maria",
        "zeus",
        "ransomware",
        "zbot",
        "generic",
        "trojanspy",
        "states",
        "inmortal",
        "locky",
        "strike",
        "china cobalt",
        "keybase",
        "cutwail",
        "citadel",
        "radamant",
        "kovter",
        "bradesco",
        "nymaim",
        "amonetize",
        "bondat",
        "ghost rat",
        "vjw0rm",
        "bandoo",
        "matsnu",
        "dnspionage",
        "darkgate",
        "vidar",
        "keylogger",
        "remcos",
        "agenttesla",
        "detplock",
        "win64",
        "smokeloader",
        "agent tesla",
        "kgs0",
        "kls0",
        "urls",
        "type name",
        "dns replication",
        "date",
        "domain",
        "win32 exe",
        "files",
        "detections type",
        "name",
        "drpsuinstaller",
        "vdfsurfs",
        "opera",
        "icwrmind",
        "notepad",
        "installer",
        "miner",
        "unknown",
        "networm",
        "houdini",
        "quasar rat",
        "gamehack",
        "dbatloader",
        "qakbot",
        "ursnif",
        "CVE-2005-1790",
        "CVE-2009-3672",
        "CVE-2010-3962",
        "CVE-2012-3993",
        "CVE-2014-6332",
        "CVE-2017-11882",
        "CVE-2020-0601",
        "CVE-2020-0674",
        "hallrender.com",
        "brian sabey",
        "insurance",
        "botnetwork",
        "botmaster",
        "command_and_control",
        "CVE-2021-27065",
        "CVE-2021-40444",
        "CVE-2023-4966",
        "CVE-2017-0199",
        "CVE-2018-4893",
        "CVE-2010-3333",
        "CVE-2015-1641",
        "CVE-2017-0147",
        "CVE-2017-8570",
        "CVE-2018-0802",
        "CVE-2018-8373",
        "CVE-2017-8759",
        "CVE-2018-8453",
        "CVE-2014-3153",
        "CVE-2015-1650",
        "CVE-2017-0143",
        "CVE-2017-8464",
        "Icefog",
        "Delf.NBX",
        "$WebWatson",
        "Gen:Heur.Ransom.HiddenTears",
        "mobilekey.pw",
        "bitbucket.org",
        "Anomalous.100%",
        "malware distribution site",
        "gootkit",
        "edsaid",
        "rightsaided",
        "betabot",
        "cobaltstrike4.tk",
        "mas.to",
        "BehavesLike.YahLover",
        "srdvd16010404",
        "languageenu",
        "buildno",
        "channelisales",
        "vendorname2581",
        "osregion",
        "device",
        "systemlocale",
        "majorver16",
        "quasar",
        "find",
        "lockbit",
        "chaos",
        "ransomexx",
        "grandoreiro",
        "evilnum",
        "banker"
      ],
      "references": [
        "https://hybrid-analysis.com/sample/6765f47ea77c8274c8e4973ed95aedf59e75998c62f6029e23c58cdf36ed85ba/654afdbdc621e7037801cce7",
        "20.99.186.246 exploit source",
        "fp2e7a.wpc.2be4.phicdn.net",
        "https://www.anyxxxtube.net/search-porn/tsara-brashears/ (phishing, ELF, Prism.exe found)",
        "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian (password cracker)",
        "http://182.22.25.124:7878/182.22.25.124:443     (malicious dropper)",
        "init.ess.apple.com         (malicious code script)",
        "https://www.pornhub.com/video/search?search=tsara+brashears (Malicious PW cracker | stylebk.css stylesheets - not found )",
        "https://urlscan.io/result/a328d9ff-fb49-4078-960d-a757fd41404f/#indicators",
        "VirusTotal Link: https://www.virustotal.com/gui/ip-address/20.99.186.246/detection",
        "Abuse IPDB Link: https://www.abuseipdb.com/check/20.99.186.246",
        "IPv4 45.12.253.72.            command_and_control",
        "Hostname: ddos.dnsnb8.net                        command_and_control",
        "IPv4 95.213.186.51              command_and_control",
        "Hostname: www.supernetforme.com      command_and_control",
        "IPv4 103.224.182.246        command_and_control",
        "IPv4 72.251.233.245           command_and_control",
        "IPv4 63.251.106.25             command_and_control",
        "IPv4 45.15.156.208            command_and_control",
        "IPv4 104.247.81.51             command_and_control",
        "http://ambisexual.phone-sex-blogs.com/http:/ambisexual.phone-sex-blogs.com/images/thumbnails/pic118.jpg             (phishing)",
        "https://downloaddevtools.ir/     (phishing)",
        "happylifehappywife.com",
        "apples.encryptedwork.com        (Interesting in the blacknet)",
        "https://itunes.apple.com/app/apple-store/id284815942/us/app/samsung-galaxy-watch-gear-s/id1117310635.                   (iOS unlocker and hijacker)",
        "https://www.anyxxxtube.net/media/favicon/apple              (password cracker and iOS hijacker)",
        "https://www.apple.com/shop/browse/open/country_selector     (exploit)",
        "www.norad.mil   (federal tracking tool used by attorneys, law firms, and private investigators 'licensed or unlicensed') hi!",
        "http://init-p01st.push.apple.com/bag            (malicious web creator)",
        "opencve.djgummikuh.de        (CVE dispensary)",
        "Maltiverse Research Team",
        "URLscan.io",
        "Deep Research",
        "Hybrid Analysis",
        "URLhaus Abuse.ch",
        "Cyber Threat Coalition",
        "ThreatFox Abuse.ch"
      ],
      "public": 1,
      "adversary": "Lucky Mouse APT27 | NoName057(16) |  Unnamed",
      "targeted_countries": [
        "United States of America",
        "France",
        "Spain"
      ],
      "malware_families": [
        {
          "id": "Feodo",
          "display_name": "Feodo",
          "target": null
        },
        {
          "id": "Dridex",
          "display_name": "Dridex",
          "target": null
        },
        {
          "id": "Redline Stealer",
          "display_name": "Redline Stealer",
          "target": null
        },
        {
          "id": "Ramnit.N",
          "display_name": "Ramnit.N",
          "target": null
        },
        {
          "id": "Loki Bot",
          "display_name": "Loki Bot",
          "target": null
        },
        {
          "id": "Loki Password Stealer (PWS)",
          "display_name": "Loki Password Stealer (PWS)",
          "target": null
        },
        {
          "id": "AZORult",
          "display_name": "AZORult",
          "target": null
        },
        {
          "id": "Zbd Zeus",
          "display_name": "Zbd Zeus",
          "target": null
        },
        {
          "id": "Trojan:MSIL/Burkina",
          "display_name": "Trojan:MSIL/Burkina",
          "target": "/malware/Trojan:MSIL/Burkina"
        },
        {
          "id": "Generic.TrickBot.1",
          "display_name": "Generic.TrickBot.1",
          "target": null
        },
        {
          "id": "Exploit.CVE",
          "display_name": "Exploit.CVE",
          "target": null
        },
        {
          "id": "Injector.IS.gen",
          "display_name": "Injector.IS.gen",
          "target": null
        },
        {
          "id": "Gen:Variant.Razy",
          "display_name": "Gen:Variant.Razy",
          "target": null
        },
        {
          "id": "Trojan.Androm.Gen",
          "display_name": "Trojan.Androm.Gen",
          "target": null
        },
        {
          "id": "HEUR:Trojan.Linux.Agent",
          "display_name": "HEUR:Trojan.Linux.Agent",
          "target": null
        },
        {
          "id": "BScope.Trojan",
          "display_name": "BScope.Trojan",
          "target": null
        },
        {
          "id": "VBA.Downloader",
          "display_name": "VBA.Downloader",
          "target": null
        },
        {
          "id": "Trojan.Notifier",
          "display_name": "Trojan.Notifier",
          "target": null
        },
        {
          "id": "HEUR:Trojan.MSOffice.Alien",
          "display_name": "HEUR:Trojan.MSOffice.Alien",
          "target": null
        },
        {
          "id": "Unsafe.AI_Score_100%",
          "display_name": "Unsafe.AI_Score_100%",
          "target": null
        },
        {
          "id": "Gen:Variant.Johnnie",
          "display_name": "Gen:Variant.Johnnie",
          "target": null
        },
        {
          "id": "DangerousObject.Multi",
          "display_name": "DangerousObject.Multi",
          "target": null
        },
        {
          "id": "Trojan:Python/Downldr",
          "display_name": "Trojan:Python/Downldr",
          "target": "/malware/Trojan:Python/Downldr"
        },
        {
          "id": "Trojan:Linux/Downldr",
          "display_name": "Trojan:Linux/Downldr",
          "target": "/malware/Trojan:Linux/Downldr"
        },
        {
          "id": "Trojan:VBA/Downldr",
          "display_name": "Trojan:VBA/Downldr",
          "target": "/malware/Trojan:VBA/Downldr"
        },
        {
          "id": "TrojanDownloader:Linux/Downldr",
          "display_name": "TrojanDownloader:Linux/Downldr",
          "target": "/malware/TrojanDownloader:Linux/Downldr"
        },
        {
          "id": "Kryptik.FPH.gen",
          "display_name": "Kryptik.FPH.gen",
          "target": null
        },
        {
          "id": "TROJ_FRS.VSNTFK19",
          "display_name": "TROJ_FRS.VSNTFK19",
          "target": null
        },
        {
          "id": "Trojan.Ransom.GenericKD",
          "display_name": "Trojan.Ransom.GenericKD",
          "target": null
        },
        {
          "id": "Phish.JAT",
          "display_name": "Phish.JAT",
          "target": null
        },
        {
          "id": "Phishing.HTML",
          "display_name": "Phishing.HTML",
          "target": null
        },
        {
          "id": "Generic.ASMalwS",
          "display_name": "Generic.ASMalwS",
          "target": null
        },
        {
          "id": "Phish.AB",
          "display_name": "Phish.AB",
          "target": null
        },
        {
          "id": "Generic.Malware",
          "display_name": "Generic.Malware",
          "target": null
        },
        {
          "id": "ml.Generic",
          "display_name": "ml.Generic",
          "target": null
        },
        {
          "id": "Xegumumune.8596c22f",
          "display_name": "Xegumumune.8596c22f",
          "target": null
        },
        {
          "id": "Generic.Malware.SMYB",
          "display_name": "Generic.Malware.SMYB",
          "target": null
        },
        {
          "id": "malicious.moderate.ml",
          "display_name": "malicious.moderate.ml",
          "target": null
        },
        {
          "id": "Agent.NBAE",
          "display_name": "Agent.NBAE",
          "target": null
        },
        {
          "id": "AGEN.1045227",
          "display_name": "AGEN.1045227",
          "target": null
        },
        {
          "id": "Riskware.Agent",
          "display_name": "Riskware.Agent",
          "target": null
        },
        {
          "id": "Gen:Variant.Cerbu",
          "display_name": "Gen:Variant.Cerbu",
          "target": null
        },
        {
          "id": "IL:Trojan.MSILZilla",
          "display_name": "IL:Trojan.MSILZilla",
          "target": null
        },
        {
          "id": "Dropped:Generic.Ransom.DMR",
          "display_name": "Dropped:Generic.Ransom.DMR",
          "target": null
        },
        {
          "id": "Delf.NBX",
          "display_name": "Delf.NBX",
          "target": null
        },
        {
          "id": "malicious.f01f67",
          "display_name": "malicious.f01f67",
          "target": null
        },
        {
          "id": "AGEN.1144657",
          "display_name": "AGEN.1144657",
          "target": null
        },
        {
          "id": "Trojan.Heur",
          "display_name": "Trojan.Heur",
          "target": null
        },
        {
          "id": "Trojan.Malware.300983",
          "display_name": "Trojan.Malware.300983",
          "target": null
        },
        {
          "id": "SdBot.CAOC",
          "display_name": "SdBot.CAOC",
          "target": null
        },
        {
          "id": "Trojan.DelShad",
          "display_name": "Trojan.DelShad",
          "target": null
        },
        {
          "id": "Exploit CVE-2017-11882",
          "display_name": "Exploit CVE-2017-11882",
          "target": null
        },
        {
          "id": "GameHack.NL",
          "display_name": "GameHack.NL",
          "target": null
        },
        {
          "id": "JS:Trojan.HideLink",
          "display_name": "JS:Trojan.HideLink",
          "target": null
        },
        {
          "id": "Script.Agent",
          "display_name": "Script.Agent",
          "target": null
        },
        {
          "id": "Macro.Agent",
          "display_name": "Macro.Agent",
          "target": null
        },
        {
          "id": "Macro.Downloader.AMIP",
          "display_name": "Macro.Downloader.AMIP",
          "target": null
        },
        {
          "id": "Trojan.VBA",
          "display_name": "Trojan.VBA",
          "target": null
        },
        {
          "id": "HEUR.VBA.Trojan",
          "display_name": "HEUR.VBA.Trojan",
          "target": null
        },
        {
          "id": "VB.EmoooDldr.10",
          "display_name": "VB.EmoooDldr.10",
          "target": null
        },
        {
          "id": "VB:Trojan.Valyria",
          "display_name": "VB:Trojan.Valyria",
          "target": null
        },
        {
          "id": "OpenSubtitles.A",
          "display_name": "OpenSubtitles.A",
          "target": null
        },
        {
          "id": "VB.EmoDldr.4",
          "display_name": "VB.EmoDldr.4",
          "target": null
        },
        {
          "id": "Packed-GV",
          "display_name": "Packed-GV",
          "target": null
        },
        {
          "id": "Adware.InstallMonetizer",
          "display_name": "Adware.InstallMonetizer",
          "target": null
        },
        {
          "id": "Skynet",
          "display_name": "Skynet",
          "target": null
        },
        {
          "id": "HW32.Packed",
          "display_name": "HW32.Packed",
          "target": null
        },
        {
          "id": "Zpevdo.B",
          "display_name": "Zpevdo.B",
          "target": null
        },
        {
          "id": "Presenoker",
          "display_name": "Presenoker",
          "target": null
        },
        {
          "id": "SGeneric",
          "display_name": "SGeneric",
          "target": null
        },
        {
          "id": "GameHack.DOM",
          "display_name": "GameHack.DOM",
          "target": null
        },
        {
          "id": "BehavesLike.Ransom",
          "display_name": "BehavesLike.Ransom",
          "target": null
        },
        {
          "id": "CIL.StupidCryptor",
          "display_name": "CIL.StupidCryptor",
          "target": null
        },
        {
          "id": "Gen:Heur.Ransom.MSIL",
          "display_name": "Gen:Heur.Ransom.MSIL",
          "target": null
        },
        {
          "id": "Black.Gen2",
          "display_name": "Black.Gen2",
          "target": null
        },
        {
          "id": "GameHack.CRS",
          "display_name": "GameHack.CRS",
          "target": null
        },
        {
          "id": "Trojan.HTML.PHISH",
          "display_name": "Trojan.HTML.PHISH",
          "target": null
        },
        {
          "id": "Gen:Heur.MSIL.Inject",
          "display_name": "Gen:Heur.MSIL.Inject",
          "target": null
        },
        {
          "id": "Program.Unwanted",
          "display_name": "Program.Unwanted",
          "target": null
        },
        {
          "id": "HEUR/QVM42.3.72EB.Malware",
          "display_name": "HEUR/QVM42.3.72EB.Malware",
          "target": null
        },
        {
          "id": "suspicious.low.ml",
          "display_name": "suspicious.low.ml",
          "target": null
        },
        {
          "id": "JS:Trojan.Cryxos",
          "display_name": "JS:Trojan.Cryxos",
          "target": null
        },
        {
          "id": "Suspicious_GEN.F47V0520",
          "display_name": "Suspicious_GEN.F47V0520",
          "target": null
        },
        {
          "id": "Dropper.Trojan.Generic",
          "display_name": "Dropper.Trojan.Generic",
          "target": null
        },
        {
          "id": "Trojan.TrickBot",
          "display_name": "Trojan.TrickBot",
          "target": null
        },
        {
          "id": "Malware.Tk.Generic",
          "display_name": "Malware.Tk.Generic",
          "target": null
        },
        {
          "id": "TrojanSpy.Java",
          "display_name": "TrojanSpy.Java",
          "target": null
        },
        {
          "id": "Riskware.NetFilter",
          "display_name": "Riskware.NetFilter",
          "target": null
        },
        {
          "id": "RiskWare.Crack",
          "display_name": "RiskWare.Crack",
          "target": null
        },
        {
          "id": "BehavesLike.Exploit",
          "display_name": "BehavesLike.Exploit",
          "target": null
        },
        {
          "id": "Gen:NN.ZemsilF.34128",
          "display_name": "Gen:NN.ZemsilF.34128",
          "target": null
        },
        {
          "id": "Wacapew.C",
          "display_name": "Wacapew.C",
          "target": null
        },
        {
          "id": "Trojan.Malware.121218",
          "display_name": "Trojan.Malware.121218",
          "target": null
        },
        {
          "id": "RiskWare.HackTool.Agent",
          "display_name": "RiskWare.HackTool.Agent",
          "target": null
        },
        {
          "id": "Artemis",
          "display_name": "Artemis",
          "target": null
        },
        {
          "id": "Trojan.Generic",
          "display_name": "Trojan.Generic",
          "target": null
        },
        {
          "id": "W32.Trojan",
          "display_name": "W32.Trojan",
          "target": null
        },
        {
          "id": "BScope.Riskware",
          "display_name": "BScope.Riskware",
          "target": null
        },
        {
          "id": "Gen:Variant.Bulz",
          "display_name": "Gen:Variant.Bulz",
          "target": null
        },
        {
          "id": "Ransom:Win32/CVE-2017-0147",
          "display_name": "Ransom:Win32/CVE-2017-0147",
          "target": "/malware/Ransom:Win32/CVE-2017-0147"
        },
        {
          "id": "Virus.Ramnit",
          "display_name": "Virus.Ramnit",
          "target": null
        },
        {
          "id": "Virus.Virut",
          "display_name": "Virus.Virut",
          "target": null
        },
        {
          "id": "Adware.KuziTui",
          "display_name": "Adware.KuziTui",
          "target": null
        },
        {
          "id": "AGEN.1141126",
          "display_name": "AGEN.1141126",
          "target": null
        },
        {
          "id": "W32.AIDetect",
          "display_name": "W32.AIDetect",
          "target": null
        },
        {
          "id": "Trojan.Python",
          "display_name": "Trojan.Python",
          "target": null
        },
        {
          "id": "W32.AIDetectVM",
          "display_name": "W32.AIDetectVM",
          "target": null
        },
        {
          "id": "Suspicious.Save",
          "display_name": "Suspicious.Save",
          "target": null
        },
        {
          "id": "Adware.Downware",
          "display_name": "Adware.Downware",
          "target": null
        },
        {
          "id": "Ransom.Win64.Wacatac.oa",
          "display_name": "Ransom.Win64.Wacatac.oa",
          "target": null
        },
        {
          "id": "OpenSubtitles.A",
          "display_name": "OpenSubtitles.A",
          "target": null
        },
        {
          "id": "VB.EmoDldr.4",
          "display_name": "VB.EmoDldr.4",
          "target": null
        },
        {
          "id": "Gen:Variant.Midie",
          "display_name": "Gen:Variant.Midie",
          "target": null
        },
        {
          "id": "HEUR/QVM41.2.DA9B.Malware",
          "display_name": "HEUR/QVM41.2.DA9B.Malware",
          "target": null
        },
        {
          "id": "Gen:Variant.Sirefef",
          "display_name": "Gen:Variant.Sirefef",
          "target": null
        },
        {
          "id": "Macro.Trojan.Dropperd",
          "display_name": "Macro.Trojan.Dropperd",
          "target": null
        },
        {
          "id": "BlackNET RAT",
          "display_name": "BlackNET RAT",
          "target": null
        },
        {
          "id": "Gen:Variant.Ursu",
          "display_name": "Gen:Variant.Ursu",
          "target": null
        },
        {
          "id": "Redcap.rlhse",
          "display_name": "Redcap.rlhse",
          "target": null
        },
        {
          "id": "Trojan.Trickster",
          "display_name": "Trojan.Trickster",
          "target": null
        },
        {
          "id": "HTML_REDIR.SMR",
          "display_name": "HTML_REDIR.SMR",
          "target": null
        },
        {
          "id": "TROJ_FRS.VSNTFK19",
          "display_name": "TROJ_FRS.VSNTFK19",
          "target": null
        },
        {
          "id": "Hoax.JS.Phish",
          "display_name": "Hoax.JS.Phish",
          "target": null
        },
        {
          "id": "JS:Iframe",
          "display_name": "JS:Iframe",
          "target": null
        },
        {
          "id": "Application.SQLCrack",
          "display_name": "Application.SQLCrack",
          "target": null
        },
        {
          "id": "susp.lnk",
          "display_name": "susp.lnk",
          "target": null
        },
        {
          "id": "QVM201.0.B70B.Malware",
          "display_name": "QVM201.0.B70B.Malware",
          "target": null
        },
        {
          "id": "Immortal Stealer",
          "display_name": "Immortal Stealer",
          "target": null
        },
        {
          "id": "WebMonitor RAT",
          "display_name": "WebMonitor RAT",
          "target": null
        },
        {
          "id": "Tor - S0183",
          "display_name": "Tor - S0183",
          "target": null
        },
        {
          "id": "WannaCry",
          "display_name": "WannaCry",
          "target": null
        },
        {
          "id": "WannaCryptor",
          "display_name": "WannaCryptor",
          "target": null
        },
        {
          "id": "WebToolbar",
          "display_name": "WebToolbar",
          "target": null
        },
        {
          "id": "BlackNET",
          "display_name": "BlackNET",
          "target": null
        },
        {
          "id": "DeepScan:Generic.Ransom.GandCrab5",
          "display_name": "DeepScan:Generic.Ransom.GandCrab5",
          "target": null
        },
        {
          "id": "TrojanSpy",
          "display_name": "TrojanSpy",
          "target": null
        },
        {
          "id": "States",
          "display_name": "States",
          "target": null
        },
        {
          "id": "Inmortal",
          "display_name": "Inmortal",
          "target": null
        },
        {
          "id": "Domains",
          "display_name": "Domains",
          "target": null
        },
        {
          "id": "Locky",
          "display_name": "Locky",
          "target": null
        },
        {
          "id": "Delf.NBX",
          "display_name": "Delf.NBX",
          "target": null
        },
        {
          "id": "Gen:NN.ZexaF.32515",
          "display_name": "Gen:NN.ZexaF.32515",
          "target": null
        },
        {
          "id": "FileRepMalware",
          "display_name": "FileRepMalware",
          "target": null
        },
        {
          "id": "Gen:Variant.MSILPerseus",
          "display_name": "Gen:Variant.MSILPerseus",
          "target": null
        },
        {
          "id": "Icefog",
          "display_name": "Icefog",
          "target": null
        },
        {
          "id": "$WebWatson",
          "display_name": "$WebWatson",
          "target": null
        },
        {
          "id": "Agent.AIK.gen",
          "display_name": "Agent.AIK.gen",
          "target": null
        },
        {
          "id": "Agent.AIK.genCIL.StupidCryptor",
          "display_name": "Agent.AIK.genCIL.StupidCryptor",
          "target": null
        },
        {
          "id": "Agent.YPEZ",
          "display_name": "Agent.YPEZ",
          "target": null
        },
        {
          "id": "Application.InnovativSol",
          "display_name": "Application.InnovativSol",
          "target": null
        },
        {
          "id": "Agent.ASO",
          "display_name": "Agent.ASO",
          "target": null
        },
        {
          "id": "S-b748adc5",
          "display_name": "S-b748adc5",
          "target": null
        },
        {
          "id": "W32.eHeur",
          "display_name": "W32.eHeur",
          "target": null
        },
        {
          "id": "Kryptik.GUCB",
          "display_name": "Kryptik.GUCB",
          "target": null
        },
        {
          "id": "AgentTesla",
          "display_name": "AgentTesla",
          "target": null
        },
        {
          "id": "Autoit.bimwt",
          "display_name": "Autoit.bimwt",
          "target": null
        },
        {
          "id": "HEUR:Trojan.OLE2.Alien",
          "display_name": "HEUR:Trojan.OLE2.Alien",
          "target": null
        },
        {
          "id": "AGEN.1038489",
          "display_name": "AGEN.1038489",
          "target": null
        },
        {
          "id": "Gen:Variant.Ser.Strictor",
          "display_name": "Gen:Variant.Ser.Strictor",
          "target": null
        },
        {
          "id": "Packed.Themida.Gen",
          "display_name": "Packed.Themida.Gen",
          "target": null
        },
        {
          "id": "AGEN.1043164",
          "display_name": "AGEN.1043164",
          "target": null
        },
        {
          "id": "TrickBot - S0266",
          "display_name": "TrickBot - S0266",
          "target": null
        },
        {
          "id": "Emotet",
          "display_name": "Emotet",
          "target": null
        },
        {
          "id": "Trojan.PornoAsset",
          "display_name": "Trojan.PornoAsset",
          "target": null
        },
        {
          "id": "Ransom.Win64.PORNOASSET.SM1",
          "display_name": "Ransom.Win64.PORNOASSET.SM1",
          "target": null
        },
        {
          "id": "Gen:Variant.Ulise",
          "display_name": "Gen:Variant.Ulise",
          "target": null
        },
        {
          "id": "Trojan.Win64",
          "display_name": "Trojan.Win64",
          "target": null
        },
        {
          "id": "Dropper.Trojan.Agent",
          "display_name": "Dropper.Trojan.Agent",
          "target": null
        },
        {
          "id": "Heur.BZC.YAX.Pantera.10",
          "display_name": "Heur.BZC.YAX.Pantera.10",
          "target": null
        },
        {
          "id": "malicious.high.ml",
          "display_name": "malicious.high.ml",
          "target": null
        },
        {
          "id": "CVE-2015-1650",
          "display_name": "CVE-2015-1650",
          "target": null
        },
        {
          "id": "Worm.Win64.AutoRun",
          "display_name": "Worm.Win64.AutoRun",
          "target": null
        },
        {
          "id": "AIT.Heur.Cottonmouth.8.78F19BD7",
          "display_name": "AIT.Heur.Cottonmouth.8.78F19BD7",
          "target": null
        },
        {
          "id": "Gen:Variant.Mikey",
          "display_name": "Gen:Variant.Mikey",
          "target": null
        },
        {
          "id": "Trojan.Agent",
          "display_name": "Trojan.Agent",
          "target": null
        },
        {
          "id": "Pua.Gen",
          "display_name": "Pua.Gen",
          "target": null
        },
        {
          "id": "Trojan.Downloader.Generic",
          "display_name": "Trojan.Downloader.Generic",
          "target": null
        },
        {
          "id": "Suspected of Trojan.Downloader.gen",
          "display_name": "Suspected of Trojan.Downloader.gen",
          "target": null
        },
        {
          "id": "HEUR:RemoteAdmin.Generic",
          "display_name": "HEUR:RemoteAdmin.Generic",
          "target": null
        },
        {
          "id": "Gen:Heur.Ransom.HiddenTears",
          "display_name": "Gen:Heur.Ransom.HiddenTears",
          "target": null
        },
        {
          "id": "Nemucod.A",
          "display_name": "Nemucod.A",
          "target": null
        },
        {
          "id": "Backdoor.Hupigon",
          "display_name": "Backdoor.Hupigon",
          "target": null
        },
        {
          "id": "Trojan.Starter JS.Iframe",
          "display_name": "Trojan.Starter JS.Iframe",
          "target": null
        },
        {
          "id": "fake ,promethiumm ,strongpity",
          "display_name": "fake ,promethiumm ,strongpity",
          "target": null
        },
        {
          "id": "PUA.Reg1staid",
          "display_name": "PUA.Reg1staid",
          "target": null
        },
        {
          "id": "Malware.Heur_Generic.A",
          "display_name": "Malware.Heur_Generic.A",
          "target": null
        },
        {
          "id": "Bladabindi.Q",
          "display_name": "Bladabindi.Q",
          "target": null
        },
        {
          "id": "W32.eHeur",
          "display_name": "W32.eHeur",
          "target": null
        },
        {
          "id": "malicious.6e0700",
          "display_name": "malicious.6e0700",
          "target": null
        },
        {
          "id": "Trojan.Inject",
          "display_name": "Trojan.Inject",
          "target": null
        },
        {
          "id": "TSGeneric",
          "display_name": "TSGeneric",
          "target": null
        },
        {
          "id": "RedCap.vneda",
          "display_name": "RedCap.vneda",
          "target": null
        },
        {
          "id": "Trojan.Indiloadz",
          "display_name": "Trojan.Indiloadz",
          "target": null
        },
        {
          "id": "Trojan.Ekstak",
          "display_name": "Trojan.Ekstak",
          "target": null
        },
        {
          "id": "staticrr.paleokits.net",
          "display_name": "staticrr.paleokits.net",
          "target": null
        },
        {
          "id": "MSIL.Downloader",
          "display_name": "MSIL.Downloader",
          "target": null
        },
        {
          "id": "Trojan.Autoruns.GenericKDS",
          "display_name": "Trojan.Autoruns.GenericKDS",
          "target": null
        },
        {
          "id": "MSIL.Trojan.BSE",
          "display_name": "MSIL.Trojan.BSE",
          "target": null
        },
        {
          "id": "Adload.AD81",
          "display_name": "Adload.AD81",
          "target": null
        },
        {
          "id": "Packed.Asprotect",
          "display_name": "Packed.Asprotect",
          "target": null
        },
        {
          "id": "Gen:NN.ZemsilF.34062",
          "display_name": "Gen:NN.ZemsilF.34062",
          "target": null
        },
        {
          "id": "Evo",
          "display_name": "Evo",
          "target": null
        },
        {
          "id": "Agent.pwc",
          "display_name": "Agent.pwc",
          "target": null
        },
        {
          "id": "RiskTool.Phpw",
          "display_name": "RiskTool.Phpw",
          "target": null
        },
        {
          "id": "Gen:Variant.Symmi",
          "display_name": "Gen:Variant.Symmi",
          "target": null
        },
        {
          "id": "Trojan.PWS",
          "display_name": "Trojan.PWS",
          "target": null
        },
        {
          "id": "Generic.BitCoinMiner.3",
          "display_name": "Generic.BitCoinMiner.3",
          "target": null
        },
        {
          "id": "Trojan.Tasker",
          "display_name": "Trojan.Tasker",
          "target": null
        },
        {
          "id": "Gen:NN",
          "display_name": "Gen:NN",
          "target": null
        },
        {
          "id": "Downloader.CertutilURLCache",
          "display_name": "Downloader.CertutilURLCache",
          "target": null
        },
        {
          "id": "Elf",
          "display_name": "Elf",
          "target": null
        },
        {
          "id": "Gen:Heur.MSIL.Androm",
          "display_name": "Gen:Heur.MSIL.Androm",
          "target": null
        },
        {
          "id": "Kryptik.NRD",
          "display_name": "Kryptik.NRD",
          "target": null
        },
        {
          "id": "Riskware",
          "display_name": "Riskware",
          "target": null
        },
        {
          "id": "Kuluoz.B.gen",
          "display_name": "Kuluoz.B.gen",
          "target": null
        },
        {
          "id": "Gen:Variant.RevengeRat",
          "display_name": "Gen:Variant.RevengeRat",
          "target": null
        },
        {
          "id": "Gen:Variant.Mikey",
          "display_name": "Gen:Variant.Mikey",
          "target": null
        },
        {
          "id": "VB.Chronos.7",
          "display_name": "VB.Chronos.7",
          "target": null
        },
        {
          "id": "Kryptik.NOE",
          "display_name": "Kryptik.NOE",
          "target": null
        },
        {
          "id": "HEUR:WebToolbar.Generic",
          "display_name": "HEUR:WebToolbar.Generic",
          "target": null
        },
        {
          "id": "Gen:Variant.Barys",
          "display_name": "Gen:Variant.Barys",
          "target": null
        },
        {
          "id": "Backdoor.Xtreme",
          "display_name": "Backdoor.Xtreme",
          "target": null
        },
        {
          "id": "Trojan.MSIL",
          "display_name": "Trojan.MSIL",
          "target": null
        },
        {
          "id": "Gen:Variant.Graftor",
          "display_name": "Gen:Variant.Graftor",
          "target": null
        },
        {
          "id": "Backdoor.Agent",
          "display_name": "Backdoor.Agent",
          "target": null
        },
        {
          "id": "Unsafe",
          "display_name": "Unsafe",
          "target": null
        },
        {
          "id": "Trojan.PHP.Agent",
          "display_name": "Trojan.PHP.Agent",
          "target": null
        },
        {
          "id": "Trojan.Agent",
          "display_name": "Trojan.Agent",
          "target": null
        },
        {
          "id": "HEUR:Exploit.Generic",
          "display_name": "HEUR:Exploit.Generic",
          "target": null
        },
        {
          "id": "Ransom_WCRY.SMALYM",
          "display_name": "Ransom_WCRY.SMALYM",
          "target": null
        },
        {
          "id": "Ransom_WCRY.SMJ",
          "display_name": "Ransom_WCRY.SMJ",
          "target": null
        },
        {
          "id": "Auslogics",
          "display_name": "Auslogics",
          "target": null
        },
        {
          "id": "Gen:Variant.Jaiko",
          "display_name": "Gen:Variant.Jaiko",
          "target": null
        },
        {
          "id": "Exploit.W32.Agent",
          "display_name": "Exploit.W32.Agent",
          "target": null
        },
        {
          "id": "Trojan.Cud.Gen",
          "display_name": "Trojan.Cud.Gen",
          "target": null
        },
        {
          "id": "Trojan.DOC.Downloader",
          "display_name": "Trojan.DOC.Downloader",
          "target": null
        },
        {
          "id": "Backdoor.MSIL.Agent",
          "display_name": "Backdoor.MSIL.Agent",
          "target": null
        },
        {
          "id": "Gen:Trojan.Heur2.LPTbHW@W64.HfsAutoB",
          "display_name": "Gen:Trojan.Heur2.LPTbHW@W64.HfsAutoB",
          "target": null
        },
        {
          "id": "Gen:Variant.Kazy",
          "display_name": "Gen:Variant.Kazy",
          "target": null
        },
        {
          "id": "Gen:Variant.Zusy",
          "display_name": "Gen:Variant.Zusy",
          "target": null
        },
        {
          "id": "Ransom.WannaCrypt",
          "display_name": "Ransom.WannaCrypt",
          "target": null
        },
        {
          "id": "Generic.ServStart.A",
          "display_name": "Generic.ServStart.A",
          "target": null
        },
        {
          "id": "Trojan.Wanna",
          "display_name": "Trojan.Wanna",
          "target": null
        },
        {
          "id": "Generic.MSIL.Bladabindi",
          "display_name": "Generic.MSIL.Bladabindi",
          "target": null
        },
        {
          "id": "TROJ_GEN.R002C0OG518",
          "display_name": "TROJ_GEN.R002C0OG518",
          "target": null
        },
        {
          "id": "Trojan.Chapak",
          "display_name": "Trojan.Chapak",
          "target": null
        },
        {
          "id": "Indiloadz.BB",
          "display_name": "Indiloadz.BB",
          "target": null
        },
        {
          "id": "BehavBehavesLike.PUPXBI",
          "display_name": "BehavBehavesLike.PUPXBI",
          "target": null
        },
        {
          "id": "DeepScan:Generic.SpyAgent.6",
          "display_name": "DeepScan:Generic.SpyAgent.6",
          "target": null
        },
        {
          "id": "Python.KeyLogger",
          "display_name": "Python.KeyLogger",
          "target": null
        },
        {
          "id": "GameHack.CRS",
          "display_name": "GameHack.CRS",
          "target": null
        },
        {
          "id": "Generic.MSIL.PasswordStealer",
          "display_name": "Generic.MSIL.PasswordStealer",
          "target": null
        },
        {
          "id": "PSW.Agent",
          "display_name": "PSW.Agent",
          "target": null
        },
        {
          "id": "malicious.8c45ba",
          "display_name": "malicious.8c45ba",
          "target": null
        },
        {
          "id": "Dropper.Binder",
          "display_name": "Dropper.Binder",
          "target": null
        },
        {
          "id": "Constructor.MSIL",
          "display_name": "Constructor.MSIL",
          "target": null
        },
        {
          "id": "Linux.Agent",
          "display_name": "Linux.Agent",
          "target": null
        },
        {
          "id": "Virus.3DMax.Script",
          "display_name": "Virus.3DMax.Script",
          "target": null
        },
        {
          "id": "ScrInject.B",
          "display_name": "ScrInject.B",
          "target": null
        },
        {
          "id": "Trojan.WisdomEyes.16070401.9500",
          "display_name": "Trojan.WisdomEyes.16070401.9500",
          "target": null
        },
        {
          "id": "Application.SearchProtect",
          "display_name": "Application.SearchProtect",
          "target": null
        },
        {
          "id": "JS:Trojan.Clicker",
          "display_name": "JS:Trojan.Clicker",
          "target": null
        },
        {
          "id": "Faceliker.A",
          "display_name": "Faceliker.A",
          "target": null
        },
        {
          "id": "JS:Trojan.JS.Faceliker",
          "display_name": "JS:Trojan.JS.Faceliker",
          "target": null
        },
        {
          "id": "Constructor.MSIL  Linux.Agent",
          "display_name": "Constructor.MSIL  Linux.Agent",
          "target": null
        },
        {
          "id": "PowerShell.Trojan",
          "display_name": "PowerShell.Trojan",
          "target": null
        },
        {
          "id": "HTML:Script",
          "display_name": "HTML:Script",
          "target": null
        },
        {
          "id": "ScrInject.B",
          "display_name": "ScrInject.B",
          "target": null
        },
        {
          "id": "W32.AIDetectVM",
          "display_name": "W32.AIDetectVM",
          "target": null
        },
        {
          "id": "HackTool.CheatEngine",
          "display_name": "HackTool.CheatEngine",
          "target": null
        },
        {
          "id": "Injector.CLDS",
          "display_name": "Injector.CLDS",
          "target": null
        },
        {
          "id": "VB.Downloader.2",
          "display_name": "VB.Downloader.2",
          "target": null
        },
        {
          "id": "malicious.3e78cc",
          "display_name": "malicious.3e78cc",
          "target": null
        },
        {
          "id": "malicious.d800d6",
          "display_name": "malicious.d800d6",
          "target": null
        },
        {
          "id": "VB.PwShell.2",
          "display_name": "VB.PwShell.2",
          "target": null
        },
        {
          "id": "Backdoor.RBot",
          "display_name": "Backdoor.RBot",
          "target": null
        },
        {
          "id": "malicious.71b1a8",
          "display_name": "malicious.71b1a8",
          "target": null
        },
        {
          "id": "TrojanSpy.KeyLogger",
          "display_name": "TrojanSpy.KeyLogger",
          "target": null
        },
        {
          "id": "Injector.JDO",
          "display_name": "Injector.JDO",
          "target": null
        },
        {
          "id": "Heur.Msword.Gen",
          "display_name": "Heur.Msword.Gen",
          "target": null
        },
        {
          "id": "PSW.Discord",
          "display_name": "PSW.Discord",
          "target": null
        },
        {
          "id": "Packed.VMProtect",
          "display_name": "Packed.VMProtect",
          "target": null
        },
        {
          "id": "HEUR:AdWare.StartSurf",
          "display_name": "HEUR:AdWare.StartSurf",
          "target": null
        },
        {
          "id": "Gen:Heur.NoobyProtect",
          "display_name": "Gen:Heur.NoobyProtect",
          "target": null
        },
        {
          "id": "CIL.HeapOverride",
          "display_name": "CIL.HeapOverride",
          "target": null
        },
        {
          "id": "HEUR:Trojan.Tasker",
          "display_name": "HEUR:Trojan.Tasker",
          "target": null
        },
        {
          "id": "XLM.Trojan.Abracadabra.27",
          "display_name": "XLM.Trojan.Abracadabra.27",
          "target": null
        },
        {
          "id": "HEUR:Backdoor.MSIL.NanoBot",
          "display_name": "HEUR:Backdoor.MSIL.NanoBot",
          "target": null
        },
        {
          "id": "Trojan.PSW.Mimikatz",
          "display_name": "Trojan.PSW.Mimikatz",
          "target": null
        },
        {
          "id": "TrojanSpy.Python",
          "display_name": "TrojanSpy.Python",
          "target": null
        },
        {
          "id": "Trojan.Ole2.Vbs",
          "display_name": "Trojan.Ole2.Vbs",
          "target": null
        },
        {
          "id": "Exploit.MSOffice",
          "display_name": "Exploit.MSOffice",
          "target": null
        },
        {
          "id": "DeepScan:Generic.Ransom.AmnesiaE",
          "display_name": "DeepScan:Generic.Ransom.AmnesiaE",
          "target": null
        },
        {
          "id": "Wacatac.D6",
          "display_name": "Wacatac.D6",
          "target": null
        },
        {
          "id": "Backdoor.Androm",
          "display_name": "Backdoor.Androm",
          "target": null
        },
        {
          "id": "Packed.NetSeal",
          "display_name": "Packed.NetSeal",
          "target": null
        },
        {
          "id": "Trojan.MSIL.Injector",
          "display_name": "Trojan.MSIL.Injector",
          "target": null
        },
        {
          "id": "Trojan.PWS.Agent",
          "display_name": "Trojan.PWS.Agent",
          "target": null
        },
        {
          "id": "TScope.Trojan",
          "display_name": "TScope.Trojan",
          "target": null
        },
        {
          "id": "PSW.Stealer",
          "display_name": "PSW.Stealer",
          "target": null
        },
        {
          "id": "Trojan.PackedNET",
          "display_name": "Trojan.PackedNET",
          "target": null
        },
        {
          "id": "Trojan.Java",
          "display_name": "Trojan.Java",
          "target": null
        },
        {
          "id": "MalwareX",
          "display_name": "MalwareX",
          "target": null
        },
        {
          "id": "Trojan.PSW.Python",
          "display_name": "Trojan.PSW.Python",
          "target": null
        },
        {
          "id": "malicious.11abfc",
          "display_name": "malicious.11abfc",
          "target": null
        },
        {
          "id": "Generic.ASMalwS",
          "display_name": "Generic.ASMalwS",
          "target": null
        },
        {
          "id": "HEUR:Trojan.MSIL.Tasker",
          "display_name": "HEUR:Trojan.MSIL.Tasker",
          "target": null
        },
        {
          "id": "PossibleThreat.PALLAS",
          "display_name": "PossibleThreat.PALLAS",
          "target": null
        },
        {
          "id": "Backdoor.Poison",
          "display_name": "Backdoor.Poison",
          "target": null
        },
        {
          "id": "Generic.MSIL.LimeRAT",
          "display_name": "Generic.MSIL.LimeRAT",
          "target": null
        },
        {
          "id": "PWS-FCZZ",
          "display_name": "PWS-FCZZ",
          "target": null
        },
        {
          "id": "Trojan.Script",
          "display_name": "Trojan.Script",
          "target": null
        },
        {
          "id": "Gen:Heur.MSIL.Inject",
          "display_name": "Gen:Heur.MSIL.Inject",
          "target": null
        },
        {
          "id": "Trojan.PWS.Growtopia",
          "display_name": "Trojan.PWS.Growtopia",
          "target": null
        },
        {
          "id": "Spyware.Bobik",
          "display_name": "Spyware.Bobik",
          "target": null
        },
        {
          "id": "HackTool.BruteForce",
          "display_name": "HackTool.BruteForce",
          "target": null
        },
        {
          "id": "Hack.Patcher",
          "display_name": "Hack.Patcher",
          "target": null
        },
        {
          "id": "PWS.p",
          "display_name": "PWS.p",
          "target": null
        },
        {
          "id": "Suppobox",
          "display_name": "Suppobox",
          "target": null
        },
        {
          "id": "index.php",
          "display_name": "index.php",
          "target": null
        },
        {
          "id": "Packed.VMProtect",
          "display_name": "Packed.VMProtect",
          "target": null
        },
        {
          "id": "SmokeLoader",
          "display_name": "SmokeLoader",
          "target": null
        },
        {
          "id": "Generic.Malware",
          "display_name": "Generic.Malware",
          "target": null
        },
        {
          "id": "SNH:Script [Dropper]",
          "display_name": "SNH:Script [Dropper]",
          "target": null
        },
        {
          "id": "HEUR:Trojan.MSOffice.SAgent",
          "display_name": "HEUR:Trojan.MSOffice.SAgent",
          "target": null
        },
        {
          "id": "Script.INF",
          "display_name": "Script.INF",
          "target": null
        },
        {
          "id": "JS:Trojan.JS.Likejack",
          "display_name": "JS:Trojan.JS.Likejack",
          "target": null
        },
        {
          "id": "SNH:Script [Dropper]",
          "display_name": "SNH:Script [Dropper]",
          "target": null
        },
        {
          "id": "Trojan.JS.Agent",
          "display_name": "Trojan.JS.Agent",
          "target": null
        },
        {
          "id": "APT Notes",
          "display_name": "APT Notes",
          "target": null
        },
        {
          "id": "susp.rtf.objupdate",
          "display_name": "susp.rtf.objupdate",
          "target": null
        },
        {
          "id": "RedCap.zoohz",
          "display_name": "RedCap.zoohz",
          "target": null
        },
        {
          "id": "Trojan.Tasker",
          "display_name": "Trojan.Tasker",
          "target": null
        },
        {
          "id": "virus.office.qexvmc",
          "display_name": "virus.office.qexvmc",
          "target": null
        },
        {
          "id": "Trojan.KillProc",
          "display_name": "Trojan.KillProc",
          "target": null
        },
        {
          "id": "Generic.MSIL.GrwtpStealer.1",
          "display_name": "Generic.MSIL.GrwtpStealer.1",
          "target": null
        },
        {
          "id": "Suspicious.Cloud",
          "display_name": "Suspicious.Cloud",
          "target": null
        },
        {
          "id": "PowerShell.DownLoader",
          "display_name": "PowerShell.DownLoader",
          "target": null
        },
        {
          "id": "Downldr.gen",
          "display_name": "Downldr.gen",
          "target": null
        },
        {
          "id": "AGEN.1030939",
          "display_name": "AGEN.1030939",
          "target": null
        },
        {
          "id": "HackTool.Binder",
          "display_name": "HackTool.Binder",
          "target": null
        },
        {
          "id": "Trojan.Inject",
          "display_name": "Trojan.Inject",
          "target": null
        },
        {
          "id": "Dldr.Agent",
          "display_name": "Dldr.Agent",
          "target": null
        },
        {
          "id": "Dropper.MSIL",
          "display_name": "Dropper.MSIL",
          "target": null
        },
        {
          "id": "Trojan.VBKryjetor",
          "display_name": "Trojan.VBKryjetor",
          "target": null
        },
        {
          "id": "PWSX",
          "display_name": "PWSX",
          "target": null
        },
        {
          "id": "VB:Trojan.VBA.Agent",
          "display_name": "VB:Trojan.VBA.Agent",
          "target": null
        },
        {
          "id": "HEUR:Trojan.MSOffice.Stratos",
          "display_name": "HEUR:Trojan.MSOffice.Stratos",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1071.001",
          "name": "Web Protocols",
          "display_name": "T1071.001 - Web Protocols"
        },
        {
          "id": "T1071.004",
          "name": "DNS",
          "display_name": "T1071.004 - DNS"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1059.007",
          "name": "JavaScript",
          "display_name": "T1059.007 - JavaScript"
        },
        {
          "id": "T1497",
          "name": "Virtualization/Sandbox Evasion",
          "display_name": "T1497 - Virtualization/Sandbox Evasion"
        },
        {
          "id": "T1068",
          "name": "Exploitation for Privilege Escalation",
          "display_name": "T1068 - Exploitation for Privilege Escalation"
        },
        {
          "id": "TA0029",
          "name": "Privilege Escalation",
          "display_name": "TA0029 - Privilege Escalation"
        },
        {
          "id": "T1449",
          "name": "Exploit SS7 to Redirect Phone Calls/SMS",
          "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
        },
        {
          "id": "T1190",
          "name": "Exploit Public-Facing Application",
          "display_name": "T1190 - Exploit Public-Facing Application"
        },
        {
          "id": "T1210",
          "name": "Exploitation of Remote Services",
          "display_name": "T1210 - Exploitation of Remote Services"
        },
        {
          "id": "T1450",
          "name": "Exploit SS7 to Track Device Location",
          "display_name": "T1450 - Exploit SS7 to Track Device Location"
        },
        {
          "id": "T1211",
          "name": "Exploitation for Defense Evasion",
          "display_name": "T1211 - Exploitation for Defense Evasion"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "TA0011",
          "name": "Command and Control",
          "display_name": "TA0011 - Command and Control"
        },
        {
          "id": "T1412",
          "name": "Capture SMS Messages",
          "display_name": "T1412 - Capture SMS Messages"
        },
        {
          "id": "T1454",
          "name": "Malicious SMS Message",
          "display_name": "T1454 - Malicious SMS Message"
        },
        {
          "id": "T1001",
          "name": "Data Obfuscation",
          "display_name": "T1001 - Data Obfuscation"
        },
        {
          "id": "T1114",
          "name": "Email Collection",
          "display_name": "T1114 - Email Collection"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1498",
          "name": "Network Denial of Service",
          "display_name": "T1498 - Network Denial of Service"
        },
        {
          "id": "T1496",
          "name": "Resource Hijacking",
          "display_name": "T1496 - Resource Hijacking"
        },
        {
          "id": "T1176",
          "name": "Browser Extensions",
          "display_name": "T1176 - Browser Extensions"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": "654c597a4a45c8d84f0b15c1",
      "export_count": 3,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 1184,
        "FileHash-SHA1": 949,
        "FileHash-SHA256": 3712,
        "URL": 2927,
        "domain": 627,
        "hostname": 1320,
        "CVE": 26,
        "email": 8,
        "CIDR": 2
      },
      "indicator_count": 10755,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 68,
      "modified_text": "24 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "69fc2ce920f63f0ab26c6871",
      "name": "Credit [ty] OctoSeek - please follow them [Lucky Mouse APT27 | Feodo Tracker | Malicious Tor Server] - this post is so true",
      "description": "",
      "modified": "2026-05-07T06:22:38.844000",
      "created": "2026-05-07T06:10:49.008000",
      "tags": [
        "ssl certificate",
        "historical ssl",
        "communicating",
        "contacted",
        "resolutions",
        "whois record",
        "whois whois",
        "whois parent",
        "whois siblings",
        "skynet",
        "threat report",
        "ip summary",
        "url summary",
        "summary",
        "sample",
        "samples",
        "detection list",
        "blacklist",
        "cisco umbrella",
        "site",
        "safe site",
        "million",
        "team",
        "microsoft",
        "back",
        "download",
        "phishing",
        "union",
        "bank",
        "malicious site",
        "blacklist http",
        "exit",
        "traffic",
        "node tcp",
        "tor known",
        "tor relayrouter",
        "et tor",
        "known tor",
        "relayrouter",
        "anonymizer",
        "spammer",
        "malware",
        "dropped",
        "unlocker",
        "http",
        "critical risk",
        "redline stealer",
        "core",
        "hacktool",
        "execution",
        "type win32",
        "exe size",
        "first seen",
        "file name",
        "avast win32",
        "win32",
        "avg win32",
        "fortinet",
        "vitro",
        "mb first",
        "rmndrp",
        "clean mx",
        "undetected dns8",
        "undetected vx",
        "sophos",
        "vault",
        "zdb zeus",
        "cmc threat",
        "snort ip",
        "feodo tracker",
        "cybereason",
        "send bug",
        "pe yandex",
        "no data",
        "tag count",
        "count blacklist",
        "tag tag",
        "algorithm",
        "v3 serial",
        "number",
        "issuer",
        "cus cnr3",
        "olet",
        "subject public",
        "key info",
        "key algorithm",
        "key identifier",
        "first",
        "seen",
        "valid",
        "no na",
        "no no",
        "ip security",
        "cndst root",
        "ca x3",
        "ca id",
        "research group",
        "cnisrg root",
        "no expired",
        "mozilla",
        "android",
        "malicious red team",
        "tsara brashears",
        "cyber stalking",
        "malvertizing",
        "invasion of privacy",
        "threat",
        "adult content",
        "apple",
        "iphone unlocker",
        "android",
        "exploited spyware",
        "malware host",
        "brute force",
        "revenge-rat",
        "banker",
        "evasive",
        "domain",
        "redline",
        "stealer",
        "phishing",
        "ramnit",
        "unreliable subdomains",
        "dridex",
        "gating",
        "msil",
        "rat",
        "loki",
        "network",
        "hacking",
        "sinkhole",
        "azorult",
        "c2",
        "historicalandnew",
        "targeted attack",
        "puffstealer",
        "rultazo",
        "lokibot",
        "loki pws",
        "burkina",
        "banker,dde,dridex,exploit",
        "banker,dridex,evasive",
        "trickbot",
        "ransomware,torrentlocker",
        "exploit_source",
        "blacknet",
        "FileRepMalware",
        "linux agent",
        "blacknet",
        "ios",
        "phishing paypal",
        "tagging",
        "defacement",
        "hit",
        "bounty",
        "phishing site",
        "malware site",
        "malware download",
        "endangerment",
        "Malicious domain - SANS Internet Storm Center",
        "evasive,msil,rat,revenge-rat",
        "prism_setting",
        "prism_object",
        "static engine",
        "social engineering",
        "jansky",
        "worm",
        "network rat",
        "networm",
        "Loki Password Stealer (PWS)",
        "South Carolina Federal Credit Union phishing",
        "darkweb",
        "yandex",
        "redirectors",
        "blacknet threats",
        "phishing,ransomware,sinkhole",
        "wanacrypt0r,wannacry,wcry",
        "tor c++",
        "tor c++ client",
        "python user",
        "js user",
        "hacker",
        "hijacker",
        "heur",
        "maltiverse",
        "alexa top",
        "exploit",
        "riskware",
        "unsafe",
        "outbreak",
        "downer",
        "shell",
        "mediamagnet",
        "sality",
        "swrort",
        "adaptivebee",
        "unruy",
        "iobit",
        "dropper",
        "trojanx",
        "artemis",
        "installcore",
        "webshell",
        "crack",
        "webtoolbar",
        "search live",
        "api blog",
        "docs pricing",
        "november",
        "de indicators",
        "domains",
        "hashes",
        "__convergedlogin_pcustomizationloader_44b450e8d543eb53930d",
        "malicious url",
        "financial",
        "blacknet rat",
        "azorult",
        "stealer",
        "deep scan",
        "blacklist https",
        "referrer",
        "collections kp",
        "incident ip",
        "sneaky server",
        "replacement",
        "unauthorized",
        "emotet",
        "noname057",
        "generic malware",
        "engineering",
        "cyber threat",
        "facebook",
        "paypal",
        "dropbox",
        "united",
        "america",
        "banking",
        "wells fargo",
        "steam",
        "twitter",
        "sliver",
        "daum",
        "swift",
        "runescape",
        "betabot",
        "district",
        "iframe",
        "alexa",
        "downldr",
        "agent",
        "presenoker",
        "bladabindi",
        "live",
        "conduit",
        "pony",
        "covid19",
        "malicious",
        "cobalt strike",
        "suppobox",
        "ramnit",
        "meterpreter",
        "virut",
        "njrat",
        "pykspa",
        "asyncrat",
        "downloader",
        "fakealert",
        "binder",
        "virustotal",
        "formbook",
        "necurs",
        "trojan",
        "msil",
        "hiloti",
        "vawtrak",
        "simda",
        "kraken",
        "solimba",
        "icedid",
        "redirector",
        "suspic",
        "amadey",
        "raccoon",
        "nanocore rat",
        "revenge rat",
        "genkryptik",
        "fuery",
        "wacatac",
        "service",
        "cloudeye",
        "tinba",
        "domaiq",
        "ave maria",
        "zeus",
        "ransomware",
        "zbot",
        "generic",
        "trojanspy",
        "states",
        "inmortal",
        "locky",
        "strike",
        "china cobalt",
        "keybase",
        "cutwail",
        "citadel",
        "radamant",
        "kovter",
        "bradesco",
        "nymaim",
        "amonetize",
        "bondat",
        "ghost rat",
        "vjw0rm",
        "bandoo",
        "matsnu",
        "dnspionage",
        "darkgate",
        "vidar",
        "keylogger",
        "remcos",
        "agenttesla",
        "detplock",
        "win64",
        "smokeloader",
        "agent tesla",
        "kgs0",
        "kls0",
        "urls",
        "type name",
        "dns replication",
        "date",
        "domain",
        "win32 exe",
        "files",
        "detections type",
        "name",
        "drpsuinstaller",
        "vdfsurfs",
        "opera",
        "icwrmind",
        "notepad",
        "installer",
        "miner",
        "unknown",
        "networm",
        "houdini",
        "quasar rat",
        "gamehack",
        "dbatloader",
        "qakbot",
        "ursnif",
        "CVE-2005-1790",
        "CVE-2009-3672",
        "CVE-2010-3962",
        "CVE-2012-3993",
        "CVE-2014-6332",
        "CVE-2017-11882",
        "CVE-2020-0601",
        "CVE-2020-0674",
        "hallrender.com",
        "brian sabey",
        "insurance",
        "botnetwork",
        "botmaster",
        "command_and_control",
        "CVE-2021-27065",
        "CVE-2021-40444",
        "CVE-2023-4966",
        "CVE-2017-0199",
        "CVE-2018-4893",
        "CVE-2010-3333",
        "CVE-2015-1641",
        "CVE-2017-0147",
        "CVE-2017-8570",
        "CVE-2018-0802",
        "CVE-2018-8373",
        "CVE-2017-8759",
        "CVE-2018-8453",
        "CVE-2014-3153",
        "CVE-2015-1650",
        "CVE-2017-0143",
        "CVE-2017-8464",
        "Icefog",
        "Delf.NBX",
        "$WebWatson",
        "Gen:Heur.Ransom.HiddenTears",
        "mobilekey.pw",
        "bitbucket.org",
        "Anomalous.100%",
        "malware distribution site",
        "gootkit",
        "edsaid",
        "rightsaided",
        "betabot",
        "cobaltstrike4.tk",
        "mas.to",
        "BehavesLike.YahLover",
        "srdvd16010404",
        "languageenu",
        "buildno",
        "channelisales",
        "vendorname2581",
        "osregion",
        "device",
        "systemlocale",
        "majorver16",
        "quasar",
        "find",
        "lockbit",
        "chaos",
        "ransomexx",
        "grandoreiro",
        "evilnum",
        "banker"
      ],
      "references": [
        "https://hybrid-analysis.com/sample/6765f47ea77c8274c8e4973ed95aedf59e75998c62f6029e23c58cdf36ed85ba/654afdbdc621e7037801cce7",
        "20.99.186.246 exploit source",
        "fp2e7a.wpc.2be4.phicdn.net",
        "https://www.anyxxxtube.net/search-porn/tsara-brashears/ (phishing, ELF, Prism.exe found)",
        "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian (password cracker)",
        "http://182.22.25.124:7878/182.22.25.124:443     (malicious dropper)",
        "init.ess.apple.com         (malicious code script)",
        "https://www.pornhub.com/video/search?search=tsara+brashears (Malicious PW cracker | stylebk.css stylesheets - not found )",
        "https://urlscan.io/result/a328d9ff-fb49-4078-960d-a757fd41404f/#indicators",
        "VirusTotal Link: https://www.virustotal.com/gui/ip-address/20.99.186.246/detection",
        "Abuse IPDB Link: https://www.abuseipdb.com/check/20.99.186.246",
        "IPv4 45.12.253.72.            command_and_control",
        "Hostname: ddos.dnsnb8.net                        command_and_control",
        "IPv4 95.213.186.51              command_and_control",
        "Hostname: www.supernetforme.com      command_and_control",
        "IPv4 103.224.182.246        command_and_control",
        "IPv4 72.251.233.245           command_and_control",
        "IPv4 63.251.106.25             command_and_control",
        "IPv4 45.15.156.208            command_and_control",
        "IPv4 104.247.81.51             command_and_control",
        "http://ambisexual.phone-sex-blogs.com/http:/ambisexual.phone-sex-blogs.com/images/thumbnails/pic118.jpg             (phishing)",
        "https://downloaddevtools.ir/     (phishing)",
        "happylifehappywife.com",
        "apples.encryptedwork.com        (Interesting in the blacknet)",
        "https://itunes.apple.com/app/apple-store/id284815942/us/app/samsung-galaxy-watch-gear-s/id1117310635.                   (iOS unlocker and hijacker)",
        "https://www.anyxxxtube.net/media/favicon/apple              (password cracker and iOS hijacker)",
        "https://www.apple.com/shop/browse/open/country_selector     (exploit)",
        "www.norad.mil   (federal tracking tool used by attorneys, law firms, and private investigators 'licensed or unlicensed') hi!",
        "http://init-p01st.push.apple.com/bag            (malicious web creator)",
        "opencve.djgummikuh.de        (CVE dispensary)",
        "Maltiverse Research Team",
        "URLscan.io",
        "Deep Research",
        "Hybrid Analysis",
        "URLhaus Abuse.ch",
        "Cyber Threat Coalition",
        "ThreatFox Abuse.ch"
      ],
      "public": 1,
      "adversary": "Lucky Mouse APT27 | NoName057(16) |  Unnamed",
      "targeted_countries": [
        "United States of America",
        "France",
        "Spain"
      ],
      "malware_families": [
        {
          "id": "Feodo",
          "display_name": "Feodo",
          "target": null
        },
        {
          "id": "Dridex",
          "display_name": "Dridex",
          "target": null
        },
        {
          "id": "Redline Stealer",
          "display_name": "Redline Stealer",
          "target": null
        },
        {
          "id": "Ramnit.N",
          "display_name": "Ramnit.N",
          "target": null
        },
        {
          "id": "Loki Bot",
          "display_name": "Loki Bot",
          "target": null
        },
        {
          "id": "Loki Password Stealer (PWS)",
          "display_name": "Loki Password Stealer (PWS)",
          "target": null
        },
        {
          "id": "AZORult",
          "display_name": "AZORult",
          "target": null
        },
        {
          "id": "Zbd Zeus",
          "display_name": "Zbd Zeus",
          "target": null
        },
        {
          "id": "Trojan:MSIL/Burkina",
          "display_name": "Trojan:MSIL/Burkina",
          "target": "/malware/Trojan:MSIL/Burkina"
        },
        {
          "id": "Generic.TrickBot.1",
          "display_name": "Generic.TrickBot.1",
          "target": null
        },
        {
          "id": "Exploit.CVE",
          "display_name": "Exploit.CVE",
          "target": null
        },
        {
          "id": "Injector.IS.gen",
          "display_name": "Injector.IS.gen",
          "target": null
        },
        {
          "id": "Gen:Variant.Razy",
          "display_name": "Gen:Variant.Razy",
          "target": null
        },
        {
          "id": "Trojan.Androm.Gen",
          "display_name": "Trojan.Androm.Gen",
          "target": null
        },
        {
          "id": "HEUR:Trojan.Linux.Agent",
          "display_name": "HEUR:Trojan.Linux.Agent",
          "target": null
        },
        {
          "id": "BScope.Trojan",
          "display_name": "BScope.Trojan",
          "target": null
        },
        {
          "id": "VBA.Downloader",
          "display_name": "VBA.Downloader",
          "target": null
        },
        {
          "id": "Trojan.Notifier",
          "display_name": "Trojan.Notifier",
          "target": null
        },
        {
          "id": "HEUR:Trojan.MSOffice.Alien",
          "display_name": "HEUR:Trojan.MSOffice.Alien",
          "target": null
        },
        {
          "id": "Unsafe.AI_Score_100%",
          "display_name": "Unsafe.AI_Score_100%",
          "target": null
        },
        {
          "id": "Gen:Variant.Johnnie",
          "display_name": "Gen:Variant.Johnnie",
          "target": null
        },
        {
          "id": "DangerousObject.Multi",
          "display_name": "DangerousObject.Multi",
          "target": null
        },
        {
          "id": "Trojan:Python/Downldr",
          "display_name": "Trojan:Python/Downldr",
          "target": "/malware/Trojan:Python/Downldr"
        },
        {
          "id": "Trojan:Linux/Downldr",
          "display_name": "Trojan:Linux/Downldr",
          "target": "/malware/Trojan:Linux/Downldr"
        },
        {
          "id": "Trojan:VBA/Downldr",
          "display_name": "Trojan:VBA/Downldr",
          "target": "/malware/Trojan:VBA/Downldr"
        },
        {
          "id": "TrojanDownloader:Linux/Downldr",
          "display_name": "TrojanDownloader:Linux/Downldr",
          "target": "/malware/TrojanDownloader:Linux/Downldr"
        },
        {
          "id": "Kryptik.FPH.gen",
          "display_name": "Kryptik.FPH.gen",
          "target": null
        },
        {
          "id": "TROJ_FRS.VSNTFK19",
          "display_name": "TROJ_FRS.VSNTFK19",
          "target": null
        },
        {
          "id": "Trojan.Ransom.GenericKD",
          "display_name": "Trojan.Ransom.GenericKD",
          "target": null
        },
        {
          "id": "Phish.JAT",
          "display_name": "Phish.JAT",
          "target": null
        },
        {
          "id": "Phishing.HTML",
          "display_name": "Phishing.HTML",
          "target": null
        },
        {
          "id": "Generic.ASMalwS",
          "display_name": "Generic.ASMalwS",
          "target": null
        },
        {
          "id": "Phish.AB",
          "display_name": "Phish.AB",
          "target": null
        },
        {
          "id": "Generic.Malware",
          "display_name": "Generic.Malware",
          "target": null
        },
        {
          "id": "ml.Generic",
          "display_name": "ml.Generic",
          "target": null
        },
        {
          "id": "Xegumumune.8596c22f",
          "display_name": "Xegumumune.8596c22f",
          "target": null
        },
        {
          "id": "Generic.Malware.SMYB",
          "display_name": "Generic.Malware.SMYB",
          "target": null
        },
        {
          "id": "malicious.moderate.ml",
          "display_name": "malicious.moderate.ml",
          "target": null
        },
        {
          "id": "Agent.NBAE",
          "display_name": "Agent.NBAE",
          "target": null
        },
        {
          "id": "AGEN.1045227",
          "display_name": "AGEN.1045227",
          "target": null
        },
        {
          "id": "Riskware.Agent",
          "display_name": "Riskware.Agent",
          "target": null
        },
        {
          "id": "Gen:Variant.Cerbu",
          "display_name": "Gen:Variant.Cerbu",
          "target": null
        },
        {
          "id": "IL:Trojan.MSILZilla",
          "display_name": "IL:Trojan.MSILZilla",
          "target": null
        },
        {
          "id": "Dropped:Generic.Ransom.DMR",
          "display_name": "Dropped:Generic.Ransom.DMR",
          "target": null
        },
        {
          "id": "Delf.NBX",
          "display_name": "Delf.NBX",
          "target": null
        },
        {
          "id": "malicious.f01f67",
          "display_name": "malicious.f01f67",
          "target": null
        },
        {
          "id": "AGEN.1144657",
          "display_name": "AGEN.1144657",
          "target": null
        },
        {
          "id": "Trojan.Heur",
          "display_name": "Trojan.Heur",
          "target": null
        },
        {
          "id": "Trojan.Malware.300983",
          "display_name": "Trojan.Malware.300983",
          "target": null
        },
        {
          "id": "SdBot.CAOC",
          "display_name": "SdBot.CAOC",
          "target": null
        },
        {
          "id": "Trojan.DelShad",
          "display_name": "Trojan.DelShad",
          "target": null
        },
        {
          "id": "Exploit CVE-2017-11882",
          "display_name": "Exploit CVE-2017-11882",
          "target": null
        },
        {
          "id": "GameHack.NL",
          "display_name": "GameHack.NL",
          "target": null
        },
        {
          "id": "JS:Trojan.HideLink",
          "display_name": "JS:Trojan.HideLink",
          "target": null
        },
        {
          "id": "Script.Agent",
          "display_name": "Script.Agent",
          "target": null
        },
        {
          "id": "Macro.Agent",
          "display_name": "Macro.Agent",
          "target": null
        },
        {
          "id": "Macro.Downloader.AMIP",
          "display_name": "Macro.Downloader.AMIP",
          "target": null
        },
        {
          "id": "Trojan.VBA",
          "display_name": "Trojan.VBA",
          "target": null
        },
        {
          "id": "HEUR.VBA.Trojan",
          "display_name": "HEUR.VBA.Trojan",
          "target": null
        },
        {
          "id": "VB.EmoooDldr.10",
          "display_name": "VB.EmoooDldr.10",
          "target": null
        },
        {
          "id": "VB:Trojan.Valyria",
          "display_name": "VB:Trojan.Valyria",
          "target": null
        },
        {
          "id": "OpenSubtitles.A",
          "display_name": "OpenSubtitles.A",
          "target": null
        },
        {
          "id": "VB.EmoDldr.4",
          "display_name": "VB.EmoDldr.4",
          "target": null
        },
        {
          "id": "Packed-GV",
          "display_name": "Packed-GV",
          "target": null
        },
        {
          "id": "Adware.InstallMonetizer",
          "display_name": "Adware.InstallMonetizer",
          "target": null
        },
        {
          "id": "Skynet",
          "display_name": "Skynet",
          "target": null
        },
        {
          "id": "HW32.Packed",
          "display_name": "HW32.Packed",
          "target": null
        },
        {
          "id": "Zpevdo.B",
          "display_name": "Zpevdo.B",
          "target": null
        },
        {
          "id": "Presenoker",
          "display_name": "Presenoker",
          "target": null
        },
        {
          "id": "SGeneric",
          "display_name": "SGeneric",
          "target": null
        },
        {
          "id": "GameHack.DOM",
          "display_name": "GameHack.DOM",
          "target": null
        },
        {
          "id": "BehavesLike.Ransom",
          "display_name": "BehavesLike.Ransom",
          "target": null
        },
        {
          "id": "CIL.StupidCryptor",
          "display_name": "CIL.StupidCryptor",
          "target": null
        },
        {
          "id": "Gen:Heur.Ransom.MSIL",
          "display_name": "Gen:Heur.Ransom.MSIL",
          "target": null
        },
        {
          "id": "Black.Gen2",
          "display_name": "Black.Gen2",
          "target": null
        },
        {
          "id": "GameHack.CRS",
          "display_name": "GameHack.CRS",
          "target": null
        },
        {
          "id": "Trojan.HTML.PHISH",
          "display_name": "Trojan.HTML.PHISH",
          "target": null
        },
        {
          "id": "Gen:Heur.MSIL.Inject",
          "display_name": "Gen:Heur.MSIL.Inject",
          "target": null
        },
        {
          "id": "Program.Unwanted",
          "display_name": "Program.Unwanted",
          "target": null
        },
        {
          "id": "HEUR/QVM42.3.72EB.Malware",
          "display_name": "HEUR/QVM42.3.72EB.Malware",
          "target": null
        },
        {
          "id": "suspicious.low.ml",
          "display_name": "suspicious.low.ml",
          "target": null
        },
        {
          "id": "JS:Trojan.Cryxos",
          "display_name": "JS:Trojan.Cryxos",
          "target": null
        },
        {
          "id": "Suspicious_GEN.F47V0520",
          "display_name": "Suspicious_GEN.F47V0520",
          "target": null
        },
        {
          "id": "Dropper.Trojan.Generic",
          "display_name": "Dropper.Trojan.Generic",
          "target": null
        },
        {
          "id": "Trojan.TrickBot",
          "display_name": "Trojan.TrickBot",
          "target": null
        },
        {
          "id": "Malware.Tk.Generic",
          "display_name": "Malware.Tk.Generic",
          "target": null
        },
        {
          "id": "TrojanSpy.Java",
          "display_name": "TrojanSpy.Java",
          "target": null
        },
        {
          "id": "Riskware.NetFilter",
          "display_name": "Riskware.NetFilter",
          "target": null
        },
        {
          "id": "RiskWare.Crack",
          "display_name": "RiskWare.Crack",
          "target": null
        },
        {
          "id": "BehavesLike.Exploit",
          "display_name": "BehavesLike.Exploit",
          "target": null
        },
        {
          "id": "Gen:NN.ZemsilF.34128",
          "display_name": "Gen:NN.ZemsilF.34128",
          "target": null
        },
        {
          "id": "Wacapew.C",
          "display_name": "Wacapew.C",
          "target": null
        },
        {
          "id": "Trojan.Malware.121218",
          "display_name": "Trojan.Malware.121218",
          "target": null
        },
        {
          "id": "RiskWare.HackTool.Agent",
          "display_name": "RiskWare.HackTool.Agent",
          "target": null
        },
        {
          "id": "Artemis",
          "display_name": "Artemis",
          "target": null
        },
        {
          "id": "Trojan.Generic",
          "display_name": "Trojan.Generic",
          "target": null
        },
        {
          "id": "W32.Trojan",
          "display_name": "W32.Trojan",
          "target": null
        },
        {
          "id": "BScope.Riskware",
          "display_name": "BScope.Riskware",
          "target": null
        },
        {
          "id": "Gen:Variant.Bulz",
          "display_name": "Gen:Variant.Bulz",
          "target": null
        },
        {
          "id": "Ransom:Win32/CVE-2017-0147",
          "display_name": "Ransom:Win32/CVE-2017-0147",
          "target": "/malware/Ransom:Win32/CVE-2017-0147"
        },
        {
          "id": "Virus.Ramnit",
          "display_name": "Virus.Ramnit",
          "target": null
        },
        {
          "id": "Virus.Virut",
          "display_name": "Virus.Virut",
          "target": null
        },
        {
          "id": "Adware.KuziTui",
          "display_name": "Adware.KuziTui",
          "target": null
        },
        {
          "id": "AGEN.1141126",
          "display_name": "AGEN.1141126",
          "target": null
        },
        {
          "id": "W32.AIDetect",
          "display_name": "W32.AIDetect",
          "target": null
        },
        {
          "id": "Trojan.Python",
          "display_name": "Trojan.Python",
          "target": null
        },
        {
          "id": "W32.AIDetectVM",
          "display_name": "W32.AIDetectVM",
          "target": null
        },
        {
          "id": "Suspicious.Save",
          "display_name": "Suspicious.Save",
          "target": null
        },
        {
          "id": "Adware.Downware",
          "display_name": "Adware.Downware",
          "target": null
        },
        {
          "id": "Ransom.Win64.Wacatac.oa",
          "display_name": "Ransom.Win64.Wacatac.oa",
          "target": null
        },
        {
          "id": "OpenSubtitles.A",
          "display_name": "OpenSubtitles.A",
          "target": null
        },
        {
          "id": "VB.EmoDldr.4",
          "display_name": "VB.EmoDldr.4",
          "target": null
        },
        {
          "id": "Gen:Variant.Midie",
          "display_name": "Gen:Variant.Midie",
          "target": null
        },
        {
          "id": "HEUR/QVM41.2.DA9B.Malware",
          "display_name": "HEUR/QVM41.2.DA9B.Malware",
          "target": null
        },
        {
          "id": "Gen:Variant.Sirefef",
          "display_name": "Gen:Variant.Sirefef",
          "target": null
        },
        {
          "id": "Macro.Trojan.Dropperd",
          "display_name": "Macro.Trojan.Dropperd",
          "target": null
        },
        {
          "id": "BlackNET RAT",
          "display_name": "BlackNET RAT",
          "target": null
        },
        {
          "id": "Gen:Variant.Ursu",
          "display_name": "Gen:Variant.Ursu",
          "target": null
        },
        {
          "id": "Redcap.rlhse",
          "display_name": "Redcap.rlhse",
          "target": null
        },
        {
          "id": "Trojan.Trickster",
          "display_name": "Trojan.Trickster",
          "target": null
        },
        {
          "id": "HTML_REDIR.SMR",
          "display_name": "HTML_REDIR.SMR",
          "target": null
        },
        {
          "id": "TROJ_FRS.VSNTFK19",
          "display_name": "TROJ_FRS.VSNTFK19",
          "target": null
        },
        {
          "id": "Hoax.JS.Phish",
          "display_name": "Hoax.JS.Phish",
          "target": null
        },
        {
          "id": "JS:Iframe",
          "display_name": "JS:Iframe",
          "target": null
        },
        {
          "id": "Application.SQLCrack",
          "display_name": "Application.SQLCrack",
          "target": null
        },
        {
          "id": "susp.lnk",
          "display_name": "susp.lnk",
          "target": null
        },
        {
          "id": "QVM201.0.B70B.Malware",
          "display_name": "QVM201.0.B70B.Malware",
          "target": null
        },
        {
          "id": "Immortal Stealer",
          "display_name": "Immortal Stealer",
          "target": null
        },
        {
          "id": "WebMonitor RAT",
          "display_name": "WebMonitor RAT",
          "target": null
        },
        {
          "id": "Tor - S0183",
          "display_name": "Tor - S0183",
          "target": null
        },
        {
          "id": "WannaCry",
          "display_name": "WannaCry",
          "target": null
        },
        {
          "id": "WannaCryptor",
          "display_name": "WannaCryptor",
          "target": null
        },
        {
          "id": "WebToolbar",
          "display_name": "WebToolbar",
          "target": null
        },
        {
          "id": "BlackNET",
          "display_name": "BlackNET",
          "target": null
        },
        {
          "id": "DeepScan:Generic.Ransom.GandCrab5",
          "display_name": "DeepScan:Generic.Ransom.GandCrab5",
          "target": null
        },
        {
          "id": "TrojanSpy",
          "display_name": "TrojanSpy",
          "target": null
        },
        {
          "id": "States",
          "display_name": "States",
          "target": null
        },
        {
          "id": "Inmortal",
          "display_name": "Inmortal",
          "target": null
        },
        {
          "id": "Domains",
          "display_name": "Domains",
          "target": null
        },
        {
          "id": "Locky",
          "display_name": "Locky",
          "target": null
        },
        {
          "id": "Delf.NBX",
          "display_name": "Delf.NBX",
          "target": null
        },
        {
          "id": "Gen:NN.ZexaF.32515",
          "display_name": "Gen:NN.ZexaF.32515",
          "target": null
        },
        {
          "id": "FileRepMalware",
          "display_name": "FileRepMalware",
          "target": null
        },
        {
          "id": "Gen:Variant.MSILPerseus",
          "display_name": "Gen:Variant.MSILPerseus",
          "target": null
        },
        {
          "id": "Icefog",
          "display_name": "Icefog",
          "target": null
        },
        {
          "id": "$WebWatson",
          "display_name": "$WebWatson",
          "target": null
        },
        {
          "id": "Agent.AIK.gen",
          "display_name": "Agent.AIK.gen",
          "target": null
        },
        {
          "id": "Agent.AIK.genCIL.StupidCryptor",
          "display_name": "Agent.AIK.genCIL.StupidCryptor",
          "target": null
        },
        {
          "id": "Agent.YPEZ",
          "display_name": "Agent.YPEZ",
          "target": null
        },
        {
          "id": "Application.InnovativSol",
          "display_name": "Application.InnovativSol",
          "target": null
        },
        {
          "id": "Agent.ASO",
          "display_name": "Agent.ASO",
          "target": null
        },
        {
          "id": "S-b748adc5",
          "display_name": "S-b748adc5",
          "target": null
        },
        {
          "id": "W32.eHeur",
          "display_name": "W32.eHeur",
          "target": null
        },
        {
          "id": "Kryptik.GUCB",
          "display_name": "Kryptik.GUCB",
          "target": null
        },
        {
          "id": "AgentTesla",
          "display_name": "AgentTesla",
          "target": null
        },
        {
          "id": "Autoit.bimwt",
          "display_name": "Autoit.bimwt",
          "target": null
        },
        {
          "id": "HEUR:Trojan.OLE2.Alien",
          "display_name": "HEUR:Trojan.OLE2.Alien",
          "target": null
        },
        {
          "id": "AGEN.1038489",
          "display_name": "AGEN.1038489",
          "target": null
        },
        {
          "id": "Gen:Variant.Ser.Strictor",
          "display_name": "Gen:Variant.Ser.Strictor",
          "target": null
        },
        {
          "id": "Packed.Themida.Gen",
          "display_name": "Packed.Themida.Gen",
          "target": null
        },
        {
          "id": "AGEN.1043164",
          "display_name": "AGEN.1043164",
          "target": null
        },
        {
          "id": "TrickBot - S0266",
          "display_name": "TrickBot - S0266",
          "target": null
        },
        {
          "id": "Emotet",
          "display_name": "Emotet",
          "target": null
        },
        {
          "id": "Trojan.PornoAsset",
          "display_name": "Trojan.PornoAsset",
          "target": null
        },
        {
          "id": "Ransom.Win64.PORNOASSET.SM1",
          "display_name": "Ransom.Win64.PORNOASSET.SM1",
          "target": null
        },
        {
          "id": "Gen:Variant.Ulise",
          "display_name": "Gen:Variant.Ulise",
          "target": null
        },
        {
          "id": "Trojan.Win64",
          "display_name": "Trojan.Win64",
          "target": null
        },
        {
          "id": "Dropper.Trojan.Agent",
          "display_name": "Dropper.Trojan.Agent",
          "target": null
        },
        {
          "id": "Heur.BZC.YAX.Pantera.10",
          "display_name": "Heur.BZC.YAX.Pantera.10",
          "target": null
        },
        {
          "id": "malicious.high.ml",
          "display_name": "malicious.high.ml",
          "target": null
        },
        {
          "id": "CVE-2015-1650",
          "display_name": "CVE-2015-1650",
          "target": null
        },
        {
          "id": "Worm.Win64.AutoRun",
          "display_name": "Worm.Win64.AutoRun",
          "target": null
        },
        {
          "id": "AIT.Heur.Cottonmouth.8.78F19BD7",
          "display_name": "AIT.Heur.Cottonmouth.8.78F19BD7",
          "target": null
        },
        {
          "id": "Gen:Variant.Mikey",
          "display_name": "Gen:Variant.Mikey",
          "target": null
        },
        {
          "id": "Trojan.Agent",
          "display_name": "Trojan.Agent",
          "target": null
        },
        {
          "id": "Pua.Gen",
          "display_name": "Pua.Gen",
          "target": null
        },
        {
          "id": "Trojan.Downloader.Generic",
          "display_name": "Trojan.Downloader.Generic",
          "target": null
        },
        {
          "id": "Suspected of Trojan.Downloader.gen",
          "display_name": "Suspected of Trojan.Downloader.gen",
          "target": null
        },
        {
          "id": "HEUR:RemoteAdmin.Generic",
          "display_name": "HEUR:RemoteAdmin.Generic",
          "target": null
        },
        {
          "id": "Gen:Heur.Ransom.HiddenTears",
          "display_name": "Gen:Heur.Ransom.HiddenTears",
          "target": null
        },
        {
          "id": "Nemucod.A",
          "display_name": "Nemucod.A",
          "target": null
        },
        {
          "id": "Backdoor.Hupigon",
          "display_name": "Backdoor.Hupigon",
          "target": null
        },
        {
          "id": "Trojan.Starter JS.Iframe",
          "display_name": "Trojan.Starter JS.Iframe",
          "target": null
        },
        {
          "id": "fake ,promethiumm ,strongpity",
          "display_name": "fake ,promethiumm ,strongpity",
          "target": null
        },
        {
          "id": "PUA.Reg1staid",
          "display_name": "PUA.Reg1staid",
          "target": null
        },
        {
          "id": "Malware.Heur_Generic.A",
          "display_name": "Malware.Heur_Generic.A",
          "target": null
        },
        {
          "id": "Bladabindi.Q",
          "display_name": "Bladabindi.Q",
          "target": null
        },
        {
          "id": "W32.eHeur",
          "display_name": "W32.eHeur",
          "target": null
        },
        {
          "id": "malicious.6e0700",
          "display_name": "malicious.6e0700",
          "target": null
        },
        {
          "id": "Trojan.Inject",
          "display_name": "Trojan.Inject",
          "target": null
        },
        {
          "id": "TSGeneric",
          "display_name": "TSGeneric",
          "target": null
        },
        {
          "id": "RedCap.vneda",
          "display_name": "RedCap.vneda",
          "target": null
        },
        {
          "id": "Trojan.Indiloadz",
          "display_name": "Trojan.Indiloadz",
          "target": null
        },
        {
          "id": "Trojan.Ekstak",
          "display_name": "Trojan.Ekstak",
          "target": null
        },
        {
          "id": "staticrr.paleokits.net",
          "display_name": "staticrr.paleokits.net",
          "target": null
        },
        {
          "id": "MSIL.Downloader",
          "display_name": "MSIL.Downloader",
          "target": null
        },
        {
          "id": "Trojan.Autoruns.GenericKDS",
          "display_name": "Trojan.Autoruns.GenericKDS",
          "target": null
        },
        {
          "id": "MSIL.Trojan.BSE",
          "display_name": "MSIL.Trojan.BSE",
          "target": null
        },
        {
          "id": "Adload.AD81",
          "display_name": "Adload.AD81",
          "target": null
        },
        {
          "id": "Packed.Asprotect",
          "display_name": "Packed.Asprotect",
          "target": null
        },
        {
          "id": "Gen:NN.ZemsilF.34062",
          "display_name": "Gen:NN.ZemsilF.34062",
          "target": null
        },
        {
          "id": "Evo",
          "display_name": "Evo",
          "target": null
        },
        {
          "id": "Agent.pwc",
          "display_name": "Agent.pwc",
          "target": null
        },
        {
          "id": "RiskTool.Phpw",
          "display_name": "RiskTool.Phpw",
          "target": null
        },
        {
          "id": "Gen:Variant.Symmi",
          "display_name": "Gen:Variant.Symmi",
          "target": null
        },
        {
          "id": "Trojan.PWS",
          "display_name": "Trojan.PWS",
          "target": null
        },
        {
          "id": "Generic.BitCoinMiner.3",
          "display_name": "Generic.BitCoinMiner.3",
          "target": null
        },
        {
          "id": "Trojan.Tasker",
          "display_name": "Trojan.Tasker",
          "target": null
        },
        {
          "id": "Gen:NN",
          "display_name": "Gen:NN",
          "target": null
        },
        {
          "id": "Downloader.CertutilURLCache",
          "display_name": "Downloader.CertutilURLCache",
          "target": null
        },
        {
          "id": "Elf",
          "display_name": "Elf",
          "target": null
        },
        {
          "id": "Gen:Heur.MSIL.Androm",
          "display_name": "Gen:Heur.MSIL.Androm",
          "target": null
        },
        {
          "id": "Kryptik.NRD",
          "display_name": "Kryptik.NRD",
          "target": null
        },
        {
          "id": "Riskware",
          "display_name": "Riskware",
          "target": null
        },
        {
          "id": "Kuluoz.B.gen",
          "display_name": "Kuluoz.B.gen",
          "target": null
        },
        {
          "id": "Gen:Variant.RevengeRat",
          "display_name": "Gen:Variant.RevengeRat",
          "target": null
        },
        {
          "id": "Gen:Variant.Mikey",
          "display_name": "Gen:Variant.Mikey",
          "target": null
        },
        {
          "id": "VB.Chronos.7",
          "display_name": "VB.Chronos.7",
          "target": null
        },
        {
          "id": "Kryptik.NOE",
          "display_name": "Kryptik.NOE",
          "target": null
        },
        {
          "id": "HEUR:WebToolbar.Generic",
          "display_name": "HEUR:WebToolbar.Generic",
          "target": null
        },
        {
          "id": "Gen:Variant.Barys",
          "display_name": "Gen:Variant.Barys",
          "target": null
        },
        {
          "id": "Backdoor.Xtreme",
          "display_name": "Backdoor.Xtreme",
          "target": null
        },
        {
          "id": "Trojan.MSIL",
          "display_name": "Trojan.MSIL",
          "target": null
        },
        {
          "id": "Gen:Variant.Graftor",
          "display_name": "Gen:Variant.Graftor",
          "target": null
        },
        {
          "id": "Backdoor.Agent",
          "display_name": "Backdoor.Agent",
          "target": null
        },
        {
          "id": "Unsafe",
          "display_name": "Unsafe",
          "target": null
        },
        {
          "id": "Trojan.PHP.Agent",
          "display_name": "Trojan.PHP.Agent",
          "target": null
        },
        {
          "id": "Trojan.Agent",
          "display_name": "Trojan.Agent",
          "target": null
        },
        {
          "id": "HEUR:Exploit.Generic",
          "display_name": "HEUR:Exploit.Generic",
          "target": null
        },
        {
          "id": "Ransom_WCRY.SMALYM",
          "display_name": "Ransom_WCRY.SMALYM",
          "target": null
        },
        {
          "id": "Ransom_WCRY.SMJ",
          "display_name": "Ransom_WCRY.SMJ",
          "target": null
        },
        {
          "id": "Auslogics",
          "display_name": "Auslogics",
          "target": null
        },
        {
          "id": "Gen:Variant.Jaiko",
          "display_name": "Gen:Variant.Jaiko",
          "target": null
        },
        {
          "id": "Exploit.W32.Agent",
          "display_name": "Exploit.W32.Agent",
          "target": null
        },
        {
          "id": "Trojan.Cud.Gen",
          "display_name": "Trojan.Cud.Gen",
          "target": null
        },
        {
          "id": "Trojan.DOC.Downloader",
          "display_name": "Trojan.DOC.Downloader",
          "target": null
        },
        {
          "id": "Backdoor.MSIL.Agent",
          "display_name": "Backdoor.MSIL.Agent",
          "target": null
        },
        {
          "id": "Gen:Trojan.Heur2.LPTbHW@W64.HfsAutoB",
          "display_name": "Gen:Trojan.Heur2.LPTbHW@W64.HfsAutoB",
          "target": null
        },
        {
          "id": "Gen:Variant.Kazy",
          "display_name": "Gen:Variant.Kazy",
          "target": null
        },
        {
          "id": "Gen:Variant.Zusy",
          "display_name": "Gen:Variant.Zusy",
          "target": null
        },
        {
          "id": "Ransom.WannaCrypt",
          "display_name": "Ransom.WannaCrypt",
          "target": null
        },
        {
          "id": "Generic.ServStart.A",
          "display_name": "Generic.ServStart.A",
          "target": null
        },
        {
          "id": "Trojan.Wanna",
          "display_name": "Trojan.Wanna",
          "target": null
        },
        {
          "id": "Generic.MSIL.Bladabindi",
          "display_name": "Generic.MSIL.Bladabindi",
          "target": null
        },
        {
          "id": "TROJ_GEN.R002C0OG518",
          "display_name": "TROJ_GEN.R002C0OG518",
          "target": null
        },
        {
          "id": "Trojan.Chapak",
          "display_name": "Trojan.Chapak",
          "target": null
        },
        {
          "id": "Indiloadz.BB",
          "display_name": "Indiloadz.BB",
          "target": null
        },
        {
          "id": "BehavBehavesLike.PUPXBI",
          "display_name": "BehavBehavesLike.PUPXBI",
          "target": null
        },
        {
          "id": "DeepScan:Generic.SpyAgent.6",
          "display_name": "DeepScan:Generic.SpyAgent.6",
          "target": null
        },
        {
          "id": "Python.KeyLogger",
          "display_name": "Python.KeyLogger",
          "target": null
        },
        {
          "id": "GameHack.CRS",
          "display_name": "GameHack.CRS",
          "target": null
        },
        {
          "id": "Generic.MSIL.PasswordStealer",
          "display_name": "Generic.MSIL.PasswordStealer",
          "target": null
        },
        {
          "id": "PSW.Agent",
          "display_name": "PSW.Agent",
          "target": null
        },
        {
          "id": "malicious.8c45ba",
          "display_name": "malicious.8c45ba",
          "target": null
        },
        {
          "id": "Dropper.Binder",
          "display_name": "Dropper.Binder",
          "target": null
        },
        {
          "id": "Constructor.MSIL",
          "display_name": "Constructor.MSIL",
          "target": null
        },
        {
          "id": "Linux.Agent",
          "display_name": "Linux.Agent",
          "target": null
        },
        {
          "id": "Virus.3DMax.Script",
          "display_name": "Virus.3DMax.Script",
          "target": null
        },
        {
          "id": "ScrInject.B",
          "display_name": "ScrInject.B",
          "target": null
        },
        {
          "id": "Trojan.WisdomEyes.16070401.9500",
          "display_name": "Trojan.WisdomEyes.16070401.9500",
          "target": null
        },
        {
          "id": "Application.SearchProtect",
          "display_name": "Application.SearchProtect",
          "target": null
        },
        {
          "id": "JS:Trojan.Clicker",
          "display_name": "JS:Trojan.Clicker",
          "target": null
        },
        {
          "id": "Faceliker.A",
          "display_name": "Faceliker.A",
          "target": null
        },
        {
          "id": "JS:Trojan.JS.Faceliker",
          "display_name": "JS:Trojan.JS.Faceliker",
          "target": null
        },
        {
          "id": "Constructor.MSIL  Linux.Agent",
          "display_name": "Constructor.MSIL  Linux.Agent",
          "target": null
        },
        {
          "id": "PowerShell.Trojan",
          "display_name": "PowerShell.Trojan",
          "target": null
        },
        {
          "id": "HTML:Script",
          "display_name": "HTML:Script",
          "target": null
        },
        {
          "id": "ScrInject.B",
          "display_name": "ScrInject.B",
          "target": null
        },
        {
          "id": "W32.AIDetectVM",
          "display_name": "W32.AIDetectVM",
          "target": null
        },
        {
          "id": "HackTool.CheatEngine",
          "display_name": "HackTool.CheatEngine",
          "target": null
        },
        {
          "id": "Injector.CLDS",
          "display_name": "Injector.CLDS",
          "target": null
        },
        {
          "id": "VB.Downloader.2",
          "display_name": "VB.Downloader.2",
          "target": null
        },
        {
          "id": "malicious.3e78cc",
          "display_name": "malicious.3e78cc",
          "target": null
        },
        {
          "id": "malicious.d800d6",
          "display_name": "malicious.d800d6",
          "target": null
        },
        {
          "id": "VB.PwShell.2",
          "display_name": "VB.PwShell.2",
          "target": null
        },
        {
          "id": "Backdoor.RBot",
          "display_name": "Backdoor.RBot",
          "target": null
        },
        {
          "id": "malicious.71b1a8",
          "display_name": "malicious.71b1a8",
          "target": null
        },
        {
          "id": "TrojanSpy.KeyLogger",
          "display_name": "TrojanSpy.KeyLogger",
          "target": null
        },
        {
          "id": "Injector.JDO",
          "display_name": "Injector.JDO",
          "target": null
        },
        {
          "id": "Heur.Msword.Gen",
          "display_name": "Heur.Msword.Gen",
          "target": null
        },
        {
          "id": "PSW.Discord",
          "display_name": "PSW.Discord",
          "target": null
        },
        {
          "id": "Packed.VMProtect",
          "display_name": "Packed.VMProtect",
          "target": null
        },
        {
          "id": "HEUR:AdWare.StartSurf",
          "display_name": "HEUR:AdWare.StartSurf",
          "target": null
        },
        {
          "id": "Gen:Heur.NoobyProtect",
          "display_name": "Gen:Heur.NoobyProtect",
          "target": null
        },
        {
          "id": "CIL.HeapOverride",
          "display_name": "CIL.HeapOverride",
          "target": null
        },
        {
          "id": "HEUR:Trojan.Tasker",
          "display_name": "HEUR:Trojan.Tasker",
          "target": null
        },
        {
          "id": "XLM.Trojan.Abracadabra.27",
          "display_name": "XLM.Trojan.Abracadabra.27",
          "target": null
        },
        {
          "id": "HEUR:Backdoor.MSIL.NanoBot",
          "display_name": "HEUR:Backdoor.MSIL.NanoBot",
          "target": null
        },
        {
          "id": "Trojan.PSW.Mimikatz",
          "display_name": "Trojan.PSW.Mimikatz",
          "target": null
        },
        {
          "id": "TrojanSpy.Python",
          "display_name": "TrojanSpy.Python",
          "target": null
        },
        {
          "id": "Trojan.Ole2.Vbs",
          "display_name": "Trojan.Ole2.Vbs",
          "target": null
        },
        {
          "id": "Exploit.MSOffice",
          "display_name": "Exploit.MSOffice",
          "target": null
        },
        {
          "id": "DeepScan:Generic.Ransom.AmnesiaE",
          "display_name": "DeepScan:Generic.Ransom.AmnesiaE",
          "target": null
        },
        {
          "id": "Wacatac.D6",
          "display_name": "Wacatac.D6",
          "target": null
        },
        {
          "id": "Backdoor.Androm",
          "display_name": "Backdoor.Androm",
          "target": null
        },
        {
          "id": "Packed.NetSeal",
          "display_name": "Packed.NetSeal",
          "target": null
        },
        {
          "id": "Trojan.MSIL.Injector",
          "display_name": "Trojan.MSIL.Injector",
          "target": null
        },
        {
          "id": "Trojan.PWS.Agent",
          "display_name": "Trojan.PWS.Agent",
          "target": null
        },
        {
          "id": "TScope.Trojan",
          "display_name": "TScope.Trojan",
          "target": null
        },
        {
          "id": "PSW.Stealer",
          "display_name": "PSW.Stealer",
          "target": null
        },
        {
          "id": "Trojan.PackedNET",
          "display_name": "Trojan.PackedNET",
          "target": null
        },
        {
          "id": "Trojan.Java",
          "display_name": "Trojan.Java",
          "target": null
        },
        {
          "id": "MalwareX",
          "display_name": "MalwareX",
          "target": null
        },
        {
          "id": "Trojan.PSW.Python",
          "display_name": "Trojan.PSW.Python",
          "target": null
        },
        {
          "id": "malicious.11abfc",
          "display_name": "malicious.11abfc",
          "target": null
        },
        {
          "id": "Generic.ASMalwS",
          "display_name": "Generic.ASMalwS",
          "target": null
        },
        {
          "id": "HEUR:Trojan.MSIL.Tasker",
          "display_name": "HEUR:Trojan.MSIL.Tasker",
          "target": null
        },
        {
          "id": "PossibleThreat.PALLAS",
          "display_name": "PossibleThreat.PALLAS",
          "target": null
        },
        {
          "id": "Backdoor.Poison",
          "display_name": "Backdoor.Poison",
          "target": null
        },
        {
          "id": "Generic.MSIL.LimeRAT",
          "display_name": "Generic.MSIL.LimeRAT",
          "target": null
        },
        {
          "id": "PWS-FCZZ",
          "display_name": "PWS-FCZZ",
          "target": null
        },
        {
          "id": "Trojan.Script",
          "display_name": "Trojan.Script",
          "target": null
        },
        {
          "id": "Gen:Heur.MSIL.Inject",
          "display_name": "Gen:Heur.MSIL.Inject",
          "target": null
        },
        {
          "id": "Trojan.PWS.Growtopia",
          "display_name": "Trojan.PWS.Growtopia",
          "target": null
        },
        {
          "id": "Spyware.Bobik",
          "display_name": "Spyware.Bobik",
          "target": null
        },
        {
          "id": "HackTool.BruteForce",
          "display_name": "HackTool.BruteForce",
          "target": null
        },
        {
          "id": "Hack.Patcher",
          "display_name": "Hack.Patcher",
          "target": null
        },
        {
          "id": "PWS.p",
          "display_name": "PWS.p",
          "target": null
        },
        {
          "id": "Suppobox",
          "display_name": "Suppobox",
          "target": null
        },
        {
          "id": "index.php",
          "display_name": "index.php",
          "target": null
        },
        {
          "id": "Packed.VMProtect",
          "display_name": "Packed.VMProtect",
          "target": null
        },
        {
          "id": "SmokeLoader",
          "display_name": "SmokeLoader",
          "target": null
        },
        {
          "id": "Generic.Malware",
          "display_name": "Generic.Malware",
          "target": null
        },
        {
          "id": "SNH:Script [Dropper]",
          "display_name": "SNH:Script [Dropper]",
          "target": null
        },
        {
          "id": "HEUR:Trojan.MSOffice.SAgent",
          "display_name": "HEUR:Trojan.MSOffice.SAgent",
          "target": null
        },
        {
          "id": "Script.INF",
          "display_name": "Script.INF",
          "target": null
        },
        {
          "id": "JS:Trojan.JS.Likejack",
          "display_name": "JS:Trojan.JS.Likejack",
          "target": null
        },
        {
          "id": "SNH:Script [Dropper]",
          "display_name": "SNH:Script [Dropper]",
          "target": null
        },
        {
          "id": "Trojan.JS.Agent",
          "display_name": "Trojan.JS.Agent",
          "target": null
        },
        {
          "id": "APT Notes",
          "display_name": "APT Notes",
          "target": null
        },
        {
          "id": "susp.rtf.objupdate",
          "display_name": "susp.rtf.objupdate",
          "target": null
        },
        {
          "id": "RedCap.zoohz",
          "display_name": "RedCap.zoohz",
          "target": null
        },
        {
          "id": "Trojan.Tasker",
          "display_name": "Trojan.Tasker",
          "target": null
        },
        {
          "id": "virus.office.qexvmc",
          "display_name": "virus.office.qexvmc",
          "target": null
        },
        {
          "id": "Trojan.KillProc",
          "display_name": "Trojan.KillProc",
          "target": null
        },
        {
          "id": "Generic.MSIL.GrwtpStealer.1",
          "display_name": "Generic.MSIL.GrwtpStealer.1",
          "target": null
        },
        {
          "id": "Suspicious.Cloud",
          "display_name": "Suspicious.Cloud",
          "target": null
        },
        {
          "id": "PowerShell.DownLoader",
          "display_name": "PowerShell.DownLoader",
          "target": null
        },
        {
          "id": "Downldr.gen",
          "display_name": "Downldr.gen",
          "target": null
        },
        {
          "id": "AGEN.1030939",
          "display_name": "AGEN.1030939",
          "target": null
        },
        {
          "id": "HackTool.Binder",
          "display_name": "HackTool.Binder",
          "target": null
        },
        {
          "id": "Trojan.Inject",
          "display_name": "Trojan.Inject",
          "target": null
        },
        {
          "id": "Dldr.Agent",
          "display_name": "Dldr.Agent",
          "target": null
        },
        {
          "id": "Dropper.MSIL",
          "display_name": "Dropper.MSIL",
          "target": null
        },
        {
          "id": "Trojan.VBKryjetor",
          "display_name": "Trojan.VBKryjetor",
          "target": null
        },
        {
          "id": "PWSX",
          "display_name": "PWSX",
          "target": null
        },
        {
          "id": "VB:Trojan.VBA.Agent",
          "display_name": "VB:Trojan.VBA.Agent",
          "target": null
        },
        {
          "id": "HEUR:Trojan.MSOffice.Stratos",
          "display_name": "HEUR:Trojan.MSOffice.Stratos",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1071.001",
          "name": "Web Protocols",
          "display_name": "T1071.001 - Web Protocols"
        },
        {
          "id": "T1071.004",
          "name": "DNS",
          "display_name": "T1071.004 - DNS"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1059.007",
          "name": "JavaScript",
          "display_name": "T1059.007 - JavaScript"
        },
        {
          "id": "T1497",
          "name": "Virtualization/Sandbox Evasion",
          "display_name": "T1497 - Virtualization/Sandbox Evasion"
        },
        {
          "id": "T1068",
          "name": "Exploitation for Privilege Escalation",
          "display_name": "T1068 - Exploitation for Privilege Escalation"
        },
        {
          "id": "TA0029",
          "name": "Privilege Escalation",
          "display_name": "TA0029 - Privilege Escalation"
        },
        {
          "id": "T1449",
          "name": "Exploit SS7 to Redirect Phone Calls/SMS",
          "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
        },
        {
          "id": "T1190",
          "name": "Exploit Public-Facing Application",
          "display_name": "T1190 - Exploit Public-Facing Application"
        },
        {
          "id": "T1210",
          "name": "Exploitation of Remote Services",
          "display_name": "T1210 - Exploitation of Remote Services"
        },
        {
          "id": "T1450",
          "name": "Exploit SS7 to Track Device Location",
          "display_name": "T1450 - Exploit SS7 to Track Device Location"
        },
        {
          "id": "T1211",
          "name": "Exploitation for Defense Evasion",
          "display_name": "T1211 - Exploitation for Defense Evasion"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "TA0011",
          "name": "Command and Control",
          "display_name": "TA0011 - Command and Control"
        },
        {
          "id": "T1412",
          "name": "Capture SMS Messages",
          "display_name": "T1412 - Capture SMS Messages"
        },
        {
          "id": "T1454",
          "name": "Malicious SMS Message",
          "display_name": "T1454 - Malicious SMS Message"
        },
        {
          "id": "T1001",
          "name": "Data Obfuscation",
          "display_name": "T1001 - Data Obfuscation"
        },
        {
          "id": "T1114",
          "name": "Email Collection",
          "display_name": "T1114 - Email Collection"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1498",
          "name": "Network Denial of Service",
          "display_name": "T1498 - Network Denial of Service"
        },
        {
          "id": "T1496",
          "name": "Resource Hijacking",
          "display_name": "T1496 - Resource Hijacking"
        },
        {
          "id": "T1176",
          "name": "Browser Extensions",
          "display_name": "T1176 - Browser Extensions"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": "654c597a4a45c8d84f0b15c1",
      "export_count": 1,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 1184,
        "FileHash-SHA1": 949,
        "FileHash-SHA256": 3712,
        "URL": 2927,
        "domain": 627,
        "hostname": 1320,
        "CVE": 26,
        "email": 8,
        "CIDR": 2
      },
      "indicator_count": 10755,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 67,
      "modified_text": "24 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "654c5970817e6bf8b0e5b5ff",
      "name": "Lucky Mouse APT27 | Feodo Tracker | Malicious Tor Server | Apple iOS",
      "description": "Darkside 2020 Ecosystem .BEware\nMalicious Tor server. Link found in pulse created prior. \nMalvertizing target: Tsara Brashears\nRevenge Porn.\nThere may me others. Malicious Apple activities, locating, CVE exploits, unlocking, hijacker, service transfer, spyware, malicious full auth, tracking, endless. Seems to originate from a law firm that goes to far to defend clients and silence alleged victims. \nSome State allow  the same  privileges  and tools the federal government to insurance, workers compensation, investigators and insurance company law firms for investigations. \nFear tactics they seem willing to back up. I was approached and asked about my cyber knowledge by strangers. I am followed now for using a tool properly.\nALL terms auto populated from various tools from various tools used including, State, Brian Sabey, cyber stalking. Perhaps he's made contact with target. Danger!",
      "modified": "2023-12-09T03:01:57.989000",
      "created": "2023-11-09T04:00:48.087000",
      "tags": [
        "ssl certificate",
        "historical ssl",
        "communicating",
        "contacted",
        "resolutions",
        "whois record",
        "whois whois",
        "whois parent",
        "whois siblings",
        "skynet",
        "threat report",
        "ip summary",
        "url summary",
        "summary",
        "sample",
        "samples",
        "detection list",
        "blacklist",
        "cisco umbrella",
        "site",
        "safe site",
        "million",
        "team",
        "microsoft",
        "back",
        "download",
        "phishing",
        "union",
        "bank",
        "malicious site",
        "blacklist http",
        "exit",
        "traffic",
        "node tcp",
        "tor known",
        "tor relayrouter",
        "et tor",
        "known tor",
        "relayrouter",
        "anonymizer",
        "spammer",
        "malware",
        "dropped",
        "unlocker",
        "http",
        "critical risk",
        "redline stealer",
        "core",
        "hacktool",
        "execution",
        "type win32",
        "exe size",
        "first seen",
        "file name",
        "avast win32",
        "win32",
        "avg win32",
        "fortinet",
        "vitro",
        "mb first",
        "rmndrp",
        "clean mx",
        "undetected dns8",
        "undetected vx",
        "sophos",
        "vault",
        "zdb zeus",
        "cmc threat",
        "snort ip",
        "feodo tracker",
        "cybereason",
        "send bug",
        "pe yandex",
        "no data",
        "tag count",
        "count blacklist",
        "tag tag",
        "algorithm",
        "v3 serial",
        "number",
        "issuer",
        "cus cnr3",
        "olet",
        "subject public",
        "key info",
        "key algorithm",
        "key identifier",
        "first",
        "seen",
        "valid",
        "no na",
        "no no",
        "ip security",
        "cndst root",
        "ca x3",
        "ca id",
        "research group",
        "cnisrg root",
        "no expired",
        "mozilla",
        "android",
        "malicious red team",
        "tsara brashears",
        "cyber stalking",
        "malvertizing",
        "invasion of privacy",
        "threat",
        "adult content",
        "apple",
        "iphone unlocker",
        "android",
        "exploited spyware",
        "malware host",
        "brute force",
        "revenge-rat",
        "banker",
        "evasive",
        "domain",
        "redline",
        "stealer",
        "phishing",
        "ramnit",
        "unreliable subdomains",
        "dridex",
        "gating",
        "msil",
        "rat",
        "loki",
        "network",
        "hacking",
        "sinkhole",
        "azorult",
        "c2",
        "historicalandnew",
        "targeted attack",
        "puffstealer",
        "rultazo",
        "lokibot",
        "loki pws",
        "burkina",
        "banker,dde,dridex,exploit",
        "banker,dridex,evasive",
        "trickbot",
        "ransomware,torrentlocker",
        "exploit_source",
        "blacknet",
        "FileRepMalware",
        "linux agent",
        "blacknet",
        "ios",
        "phishing paypal",
        "tagging",
        "defacement",
        "hit",
        "bounty",
        "phishing site",
        "malware site",
        "malware download",
        "endangerment",
        "Malicious domain - SANS Internet Storm Center",
        "evasive,msil,rat,revenge-rat",
        "prism_setting",
        "prism_object",
        "static engine",
        "social engineering",
        "jansky",
        "worm",
        "network rat",
        "networm",
        "Loki Password Stealer (PWS)",
        "South Carolina Federal Credit Union phishing",
        "darkweb",
        "yandex",
        "redirectors",
        "blacknet threats",
        "phishing,ransomware,sinkhole",
        "wanacrypt0r,wannacry,wcry",
        "tor c++",
        "tor c++ client",
        "python user",
        "js user",
        "hacker",
        "hijacker",
        "heur",
        "maltiverse",
        "alexa top",
        "exploit",
        "riskware",
        "unsafe",
        "outbreak",
        "downer",
        "shell",
        "mediamagnet",
        "sality",
        "swrort",
        "adaptivebee",
        "unruy",
        "iobit",
        "dropper",
        "trojanx",
        "artemis",
        "installcore",
        "webshell",
        "crack",
        "webtoolbar",
        "search live",
        "api blog",
        "docs pricing",
        "november",
        "de indicators",
        "domains",
        "hashes",
        "__convergedlogin_pcustomizationloader_44b450e8d543eb53930d",
        "malicious url",
        "financial",
        "blacknet rat",
        "azorult",
        "stealer",
        "deep scan",
        "blacklist https",
        "referrer",
        "collections kp",
        "incident ip",
        "sneaky server",
        "replacement",
        "unauthorized",
        "emotet",
        "noname057",
        "generic malware",
        "engineering",
        "cyber threat",
        "facebook",
        "paypal",
        "dropbox",
        "united",
        "america",
        "banking",
        "wells fargo",
        "steam",
        "twitter",
        "sliver",
        "daum",
        "swift",
        "runescape",
        "betabot",
        "district",
        "iframe",
        "alexa",
        "downldr",
        "agent",
        "presenoker",
        "bladabindi",
        "live",
        "conduit",
        "pony",
        "covid19",
        "malicious",
        "cobalt strike",
        "suppobox",
        "ramnit",
        "meterpreter",
        "virut",
        "njrat",
        "pykspa",
        "asyncrat",
        "downloader",
        "fakealert",
        "binder",
        "virustotal",
        "formbook",
        "necurs",
        "trojan",
        "msil",
        "hiloti",
        "vawtrak",
        "simda",
        "kraken",
        "solimba",
        "icedid",
        "redirector",
        "suspic",
        "amadey",
        "raccoon",
        "nanocore rat",
        "revenge rat",
        "genkryptik",
        "fuery",
        "wacatac",
        "service",
        "cloudeye",
        "tinba",
        "domaiq",
        "ave maria",
        "zeus",
        "ransomware",
        "zbot",
        "generic",
        "trojanspy",
        "states",
        "inmortal",
        "locky",
        "strike",
        "china cobalt",
        "keybase",
        "cutwail",
        "citadel",
        "radamant",
        "kovter",
        "bradesco",
        "nymaim",
        "amonetize",
        "bondat",
        "ghost rat",
        "vjw0rm",
        "bandoo",
        "matsnu",
        "dnspionage",
        "darkgate",
        "vidar",
        "keylogger",
        "remcos",
        "agenttesla",
        "detplock",
        "win64",
        "smokeloader",
        "agent tesla",
        "kgs0",
        "kls0",
        "urls",
        "type name",
        "dns replication",
        "date",
        "domain",
        "win32 exe",
        "files",
        "detections type",
        "name",
        "drpsuinstaller",
        "vdfsurfs",
        "opera",
        "icwrmind",
        "notepad",
        "installer",
        "miner",
        "unknown",
        "networm",
        "houdini",
        "quasar rat",
        "gamehack",
        "dbatloader",
        "qakbot",
        "ursnif",
        "CVE-2005-1790",
        "CVE-2009-3672",
        "CVE-2010-3962",
        "CVE-2012-3993",
        "CVE-2014-6332",
        "CVE-2017-11882",
        "CVE-2020-0601",
        "CVE-2020-0674",
        "hallrender.com",
        "brian sabey",
        "insurance",
        "botnetwork",
        "botmaster",
        "command_and_control",
        "CVE-2021-27065",
        "CVE-2021-40444",
        "CVE-2023-4966",
        "CVE-2017-0199",
        "CVE-2018-4893",
        "CVE-2010-3333",
        "CVE-2015-1641",
        "CVE-2017-0147",
        "CVE-2017-8570",
        "CVE-2018-0802",
        "CVE-2018-8373",
        "CVE-2017-8759",
        "CVE-2018-8453",
        "CVE-2014-3153",
        "CVE-2015-1650",
        "CVE-2017-0143",
        "CVE-2017-8464",
        "Icefog",
        "Delf.NBX",
        "$WebWatson",
        "Gen:Heur.Ransom.HiddenTears",
        "mobilekey.pw",
        "bitbucket.org",
        "Anomalous.100%",
        "malware distribution site",
        "gootkit",
        "edsaid",
        "rightsaided",
        "betabot",
        "cobaltstrike4.tk",
        "mas.to",
        "BehavesLike.YahLover",
        "srdvd16010404",
        "languageenu",
        "buildno",
        "channelisales",
        "vendorname2581",
        "osregion",
        "device",
        "systemlocale",
        "majorver16",
        "quasar",
        "find",
        "lockbit",
        "chaos",
        "ransomexx",
        "grandoreiro",
        "evilnum",
        "banker"
      ],
      "references": [
        "https://hybrid-analysis.com/sample/6765f47ea77c8274c8e4973ed95aedf59e75998c62f6029e23c58cdf36ed85ba/654afdbdc621e7037801cce7",
        "20.99.186.246 exploit source",
        "fp2e7a.wpc.2be4.phicdn.net",
        "https://www.anyxxxtube.net/search-porn/tsara-brashears/ (phishing, ELF, Prism.exe found)",
        "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian (password cracker)",
        "http://182.22.25.124:7878/182.22.25.124:443     (malicious dropper)",
        "init.ess.apple.com         (malicious code script)",
        "https://www.pornhub.com/video/search?search=tsara+brashears (Malicious PW cracker | stylebk.css stylesheets - not found )",
        "https://urlscan.io/result/a328d9ff-fb49-4078-960d-a757fd41404f/#indicators",
        "VirusTotal Link: https://www.virustotal.com/gui/ip-address/20.99.186.246/detection",
        "Abuse IPDB Link: https://www.abuseipdb.com/check/20.99.186.246",
        "IPv4 45.12.253.72.            command_and_control",
        "Hostname: ddos.dnsnb8.net                        command_and_control",
        "IPv4 95.213.186.51              command_and_control",
        "Hostname: www.supernetforme.com      command_and_control",
        "IPv4 103.224.182.246        command_and_control",
        "IPv4 72.251.233.245           command_and_control",
        "IPv4 63.251.106.25             command_and_control",
        "IPv4 45.15.156.208            command_and_control",
        "IPv4 104.247.81.51             command_and_control",
        "http://ambisexual.phone-sex-blogs.com/http:/ambisexual.phone-sex-blogs.com/images/thumbnails/pic118.jpg             (phishing)",
        "https://downloaddevtools.ir/     (phishing)",
        "happylifehappywife.com",
        "apples.encryptedwork.com        (Interesting in the blacknet)",
        "https://itunes.apple.com/app/apple-store/id284815942/us/app/samsung-galaxy-watch-gear-s/id1117310635.                   (iOS unlocker and hijacker)",
        "https://www.anyxxxtube.net/media/favicon/apple              (password cracker and iOS hijacker)",
        "https://www.apple.com/shop/browse/open/country_selector     (exploit)",
        "www.norad.mil   (federal tracking tool used by attorneys, law firms, and private investigators 'licensed or unlicensed') hi!",
        "http://init-p01st.push.apple.com/bag            (malicious web creator)",
        "opencve.djgummikuh.de        (CVE dispensary)",
        "Maltiverse Research Team",
        "URLscan.io",
        "Deep Research",
        "Hybrid Analysis",
        "URLhaus Abuse.ch",
        "Cyber Threat Coalition",
        "ThreatFox Abuse.ch"
      ],
      "public": 1,
      "adversary": "Lucky Mouse APT27 | NoName057(16) |  Unnamed",
      "targeted_countries": [
        "United States of America",
        "France",
        "Spain"
      ],
      "malware_families": [
        {
          "id": "Feodo",
          "display_name": "Feodo",
          "target": null
        },
        {
          "id": "Dridex",
          "display_name": "Dridex",
          "target": null
        },
        {
          "id": "Redline Stealer",
          "display_name": "Redline Stealer",
          "target": null
        },
        {
          "id": "Ramnit.N",
          "display_name": "Ramnit.N",
          "target": null
        },
        {
          "id": "Loki Bot",
          "display_name": "Loki Bot",
          "target": null
        },
        {
          "id": "Loki Password Stealer (PWS)",
          "display_name": "Loki Password Stealer (PWS)",
          "target": null
        },
        {
          "id": "AZORult",
          "display_name": "AZORult",
          "target": null
        },
        {
          "id": "Zbd Zeus",
          "display_name": "Zbd Zeus",
          "target": null
        },
        {
          "id": "Trojan:MSIL/Burkina",
          "display_name": "Trojan:MSIL/Burkina",
          "target": "/malware/Trojan:MSIL/Burkina"
        },
        {
          "id": "Generic.TrickBot.1",
          "display_name": "Generic.TrickBot.1",
          "target": null
        },
        {
          "id": "Exploit.CVE",
          "display_name": "Exploit.CVE",
          "target": null
        },
        {
          "id": "Injector.IS.gen",
          "display_name": "Injector.IS.gen",
          "target": null
        },
        {
          "id": "Gen:Variant.Razy",
          "display_name": "Gen:Variant.Razy",
          "target": null
        },
        {
          "id": "Trojan.Androm.Gen",
          "display_name": "Trojan.Androm.Gen",
          "target": null
        },
        {
          "id": "HEUR:Trojan.Linux.Agent",
          "display_name": "HEUR:Trojan.Linux.Agent",
          "target": null
        },
        {
          "id": "BScope.Trojan",
          "display_name": "BScope.Trojan",
          "target": null
        },
        {
          "id": "VBA.Downloader",
          "display_name": "VBA.Downloader",
          "target": null
        },
        {
          "id": "Trojan.Notifier",
          "display_name": "Trojan.Notifier",
          "target": null
        },
        {
          "id": "HEUR:Trojan.MSOffice.Alien",
          "display_name": "HEUR:Trojan.MSOffice.Alien",
          "target": null
        },
        {
          "id": "Unsafe.AI_Score_100%",
          "display_name": "Unsafe.AI_Score_100%",
          "target": null
        },
        {
          "id": "Gen:Variant.Johnnie",
          "display_name": "Gen:Variant.Johnnie",
          "target": null
        },
        {
          "id": "DangerousObject.Multi",
          "display_name": "DangerousObject.Multi",
          "target": null
        },
        {
          "id": "Trojan:Python/Downldr",
          "display_name": "Trojan:Python/Downldr",
          "target": "/malware/Trojan:Python/Downldr"
        },
        {
          "id": "Trojan:Linux/Downldr",
          "display_name": "Trojan:Linux/Downldr",
          "target": "/malware/Trojan:Linux/Downldr"
        },
        {
          "id": "Trojan:VBA/Downldr",
          "display_name": "Trojan:VBA/Downldr",
          "target": "/malware/Trojan:VBA/Downldr"
        },
        {
          "id": "TrojanDownloader:Linux/Downldr",
          "display_name": "TrojanDownloader:Linux/Downldr",
          "target": "/malware/TrojanDownloader:Linux/Downldr"
        },
        {
          "id": "Kryptik.FPH.gen",
          "display_name": "Kryptik.FPH.gen",
          "target": null
        },
        {
          "id": "TROJ_FRS.VSNTFK19",
          "display_name": "TROJ_FRS.VSNTFK19",
          "target": null
        },
        {
          "id": "Trojan.Ransom.GenericKD",
          "display_name": "Trojan.Ransom.GenericKD",
          "target": null
        },
        {
          "id": "Phish.JAT",
          "display_name": "Phish.JAT",
          "target": null
        },
        {
          "id": "Phishing.HTML",
          "display_name": "Phishing.HTML",
          "target": null
        },
        {
          "id": "Generic.ASMalwS",
          "display_name": "Generic.ASMalwS",
          "target": null
        },
        {
          "id": "Phish.AB",
          "display_name": "Phish.AB",
          "target": null
        },
        {
          "id": "Generic.Malware",
          "display_name": "Generic.Malware",
          "target": null
        },
        {
          "id": "ml.Generic",
          "display_name": "ml.Generic",
          "target": null
        },
        {
          "id": "Xegumumune.8596c22f",
          "display_name": "Xegumumune.8596c22f",
          "target": null
        },
        {
          "id": "Generic.Malware.SMYB",
          "display_name": "Generic.Malware.SMYB",
          "target": null
        },
        {
          "id": "malicious.moderate.ml",
          "display_name": "malicious.moderate.ml",
          "target": null
        },
        {
          "id": "Agent.NBAE",
          "display_name": "Agent.NBAE",
          "target": null
        },
        {
          "id": "AGEN.1045227",
          "display_name": "AGEN.1045227",
          "target": null
        },
        {
          "id": "Riskware.Agent",
          "display_name": "Riskware.Agent",
          "target": null
        },
        {
          "id": "Gen:Variant.Cerbu",
          "display_name": "Gen:Variant.Cerbu",
          "target": null
        },
        {
          "id": "IL:Trojan.MSILZilla",
          "display_name": "IL:Trojan.MSILZilla",
          "target": null
        },
        {
          "id": "Dropped:Generic.Ransom.DMR",
          "display_name": "Dropped:Generic.Ransom.DMR",
          "target": null
        },
        {
          "id": "Delf.NBX",
          "display_name": "Delf.NBX",
          "target": null
        },
        {
          "id": "malicious.f01f67",
          "display_name": "malicious.f01f67",
          "target": null
        },
        {
          "id": "AGEN.1144657",
          "display_name": "AGEN.1144657",
          "target": null
        },
        {
          "id": "Trojan.Heur",
          "display_name": "Trojan.Heur",
          "target": null
        },
        {
          "id": "Trojan.Malware.300983",
          "display_name": "Trojan.Malware.300983",
          "target": null
        },
        {
          "id": "SdBot.CAOC",
          "display_name": "SdBot.CAOC",
          "target": null
        },
        {
          "id": "Trojan.DelShad",
          "display_name": "Trojan.DelShad",
          "target": null
        },
        {
          "id": "Exploit CVE-2017-11882",
          "display_name": "Exploit CVE-2017-11882",
          "target": null
        },
        {
          "id": "GameHack.NL",
          "display_name": "GameHack.NL",
          "target": null
        },
        {
          "id": "JS:Trojan.HideLink",
          "display_name": "JS:Trojan.HideLink",
          "target": null
        },
        {
          "id": "Script.Agent",
          "display_name": "Script.Agent",
          "target": null
        },
        {
          "id": "Macro.Agent",
          "display_name": "Macro.Agent",
          "target": null
        },
        {
          "id": "Macro.Downloader.AMIP",
          "display_name": "Macro.Downloader.AMIP",
          "target": null
        },
        {
          "id": "Trojan.VBA",
          "display_name": "Trojan.VBA",
          "target": null
        },
        {
          "id": "HEUR.VBA.Trojan",
          "display_name": "HEUR.VBA.Trojan",
          "target": null
        },
        {
          "id": "VB.EmoooDldr.10",
          "display_name": "VB.EmoooDldr.10",
          "target": null
        },
        {
          "id": "VB:Trojan.Valyria",
          "display_name": "VB:Trojan.Valyria",
          "target": null
        },
        {
          "id": "OpenSubtitles.A",
          "display_name": "OpenSubtitles.A",
          "target": null
        },
        {
          "id": "VB.EmoDldr.4",
          "display_name": "VB.EmoDldr.4",
          "target": null
        },
        {
          "id": "Packed-GV",
          "display_name": "Packed-GV",
          "target": null
        },
        {
          "id": "Adware.InstallMonetizer",
          "display_name": "Adware.InstallMonetizer",
          "target": null
        },
        {
          "id": "Skynet",
          "display_name": "Skynet",
          "target": null
        },
        {
          "id": "HW32.Packed",
          "display_name": "HW32.Packed",
          "target": null
        },
        {
          "id": "Zpevdo.B",
          "display_name": "Zpevdo.B",
          "target": null
        },
        {
          "id": "Presenoker",
          "display_name": "Presenoker",
          "target": null
        },
        {
          "id": "SGeneric",
          "display_name": "SGeneric",
          "target": null
        },
        {
          "id": "GameHack.DOM",
          "display_name": "GameHack.DOM",
          "target": null
        },
        {
          "id": "BehavesLike.Ransom",
          "display_name": "BehavesLike.Ransom",
          "target": null
        },
        {
          "id": "CIL.StupidCryptor",
          "display_name": "CIL.StupidCryptor",
          "target": null
        },
        {
          "id": "Gen:Heur.Ransom.MSIL",
          "display_name": "Gen:Heur.Ransom.MSIL",
          "target": null
        },
        {
          "id": "Black.Gen2",
          "display_name": "Black.Gen2",
          "target": null
        },
        {
          "id": "GameHack.CRS",
          "display_name": "GameHack.CRS",
          "target": null
        },
        {
          "id": "Trojan.HTML.PHISH",
          "display_name": "Trojan.HTML.PHISH",
          "target": null
        },
        {
          "id": "Gen:Heur.MSIL.Inject",
          "display_name": "Gen:Heur.MSIL.Inject",
          "target": null
        },
        {
          "id": "Program.Unwanted",
          "display_name": "Program.Unwanted",
          "target": null
        },
        {
          "id": "HEUR/QVM42.3.72EB.Malware",
          "display_name": "HEUR/QVM42.3.72EB.Malware",
          "target": null
        },
        {
          "id": "suspicious.low.ml",
          "display_name": "suspicious.low.ml",
          "target": null
        },
        {
          "id": "JS:Trojan.Cryxos",
          "display_name": "JS:Trojan.Cryxos",
          "target": null
        },
        {
          "id": "Suspicious_GEN.F47V0520",
          "display_name": "Suspicious_GEN.F47V0520",
          "target": null
        },
        {
          "id": "Dropper.Trojan.Generic",
          "display_name": "Dropper.Trojan.Generic",
          "target": null
        },
        {
          "id": "Trojan.TrickBot",
          "display_name": "Trojan.TrickBot",
          "target": null
        },
        {
          "id": "Malware.Tk.Generic",
          "display_name": "Malware.Tk.Generic",
          "target": null
        },
        {
          "id": "TrojanSpy.Java",
          "display_name": "TrojanSpy.Java",
          "target": null
        },
        {
          "id": "Riskware.NetFilter",
          "display_name": "Riskware.NetFilter",
          "target": null
        },
        {
          "id": "RiskWare.Crack",
          "display_name": "RiskWare.Crack",
          "target": null
        },
        {
          "id": "BehavesLike.Exploit",
          "display_name": "BehavesLike.Exploit",
          "target": null
        },
        {
          "id": "Gen:NN.ZemsilF.34128",
          "display_name": "Gen:NN.ZemsilF.34128",
          "target": null
        },
        {
          "id": "Wacapew.C",
          "display_name": "Wacapew.C",
          "target": null
        },
        {
          "id": "Trojan.Malware.121218",
          "display_name": "Trojan.Malware.121218",
          "target": null
        },
        {
          "id": "RiskWare.HackTool.Agent",
          "display_name": "RiskWare.HackTool.Agent",
          "target": null
        },
        {
          "id": "Artemis",
          "display_name": "Artemis",
          "target": null
        },
        {
          "id": "Trojan.Generic",
          "display_name": "Trojan.Generic",
          "target": null
        },
        {
          "id": "W32.Trojan",
          "display_name": "W32.Trojan",
          "target": null
        },
        {
          "id": "BScope.Riskware",
          "display_name": "BScope.Riskware",
          "target": null
        },
        {
          "id": "Gen:Variant.Bulz",
          "display_name": "Gen:Variant.Bulz",
          "target": null
        },
        {
          "id": "Ransom:Win32/CVE-2017-0147",
          "display_name": "Ransom:Win32/CVE-2017-0147",
          "target": "/malware/Ransom:Win32/CVE-2017-0147"
        },
        {
          "id": "Virus.Ramnit",
          "display_name": "Virus.Ramnit",
          "target": null
        },
        {
          "id": "Virus.Virut",
          "display_name": "Virus.Virut",
          "target": null
        },
        {
          "id": "Adware.KuziTui",
          "display_name": "Adware.KuziTui",
          "target": null
        },
        {
          "id": "AGEN.1141126",
          "display_name": "AGEN.1141126",
          "target": null
        },
        {
          "id": "W32.AIDetect",
          "display_name": "W32.AIDetect",
          "target": null
        },
        {
          "id": "Trojan.Python",
          "display_name": "Trojan.Python",
          "target": null
        },
        {
          "id": "W32.AIDetectVM",
          "display_name": "W32.AIDetectVM",
          "target": null
        },
        {
          "id": "Suspicious.Save",
          "display_name": "Suspicious.Save",
          "target": null
        },
        {
          "id": "Adware.Downware",
          "display_name": "Adware.Downware",
          "target": null
        },
        {
          "id": "Ransom.Win64.Wacatac.oa",
          "display_name": "Ransom.Win64.Wacatac.oa",
          "target": null
        },
        {
          "id": "OpenSubtitles.A",
          "display_name": "OpenSubtitles.A",
          "target": null
        },
        {
          "id": "VB.EmoDldr.4",
          "display_name": "VB.EmoDldr.4",
          "target": null
        },
        {
          "id": "Gen:Variant.Midie",
          "display_name": "Gen:Variant.Midie",
          "target": null
        },
        {
          "id": "HEUR/QVM41.2.DA9B.Malware",
          "display_name": "HEUR/QVM41.2.DA9B.Malware",
          "target": null
        },
        {
          "id": "Gen:Variant.Sirefef",
          "display_name": "Gen:Variant.Sirefef",
          "target": null
        },
        {
          "id": "Macro.Trojan.Dropperd",
          "display_name": "Macro.Trojan.Dropperd",
          "target": null
        },
        {
          "id": "BlackNET RAT",
          "display_name": "BlackNET RAT",
          "target": null
        },
        {
          "id": "Gen:Variant.Ursu",
          "display_name": "Gen:Variant.Ursu",
          "target": null
        },
        {
          "id": "Redcap.rlhse",
          "display_name": "Redcap.rlhse",
          "target": null
        },
        {
          "id": "Trojan.Trickster",
          "display_name": "Trojan.Trickster",
          "target": null
        },
        {
          "id": "HTML_REDIR.SMR",
          "display_name": "HTML_REDIR.SMR",
          "target": null
        },
        {
          "id": "TROJ_FRS.VSNTFK19",
          "display_name": "TROJ_FRS.VSNTFK19",
          "target": null
        },
        {
          "id": "Hoax.JS.Phish",
          "display_name": "Hoax.JS.Phish",
          "target": null
        },
        {
          "id": "JS:Iframe",
          "display_name": "JS:Iframe",
          "target": null
        },
        {
          "id": "Application.SQLCrack",
          "display_name": "Application.SQLCrack",
          "target": null
        },
        {
          "id": "susp.lnk",
          "display_name": "susp.lnk",
          "target": null
        },
        {
          "id": "QVM201.0.B70B.Malware",
          "display_name": "QVM201.0.B70B.Malware",
          "target": null
        },
        {
          "id": "Immortal Stealer",
          "display_name": "Immortal Stealer",
          "target": null
        },
        {
          "id": "WebMonitor RAT",
          "display_name": "WebMonitor RAT",
          "target": null
        },
        {
          "id": "Tor - S0183",
          "display_name": "Tor - S0183",
          "target": null
        },
        {
          "id": "WannaCry",
          "display_name": "WannaCry",
          "target": null
        },
        {
          "id": "WannaCryptor",
          "display_name": "WannaCryptor",
          "target": null
        },
        {
          "id": "WebToolbar",
          "display_name": "WebToolbar",
          "target": null
        },
        {
          "id": "BlackNET",
          "display_name": "BlackNET",
          "target": null
        },
        {
          "id": "DeepScan:Generic.Ransom.GandCrab5",
          "display_name": "DeepScan:Generic.Ransom.GandCrab5",
          "target": null
        },
        {
          "id": "TrojanSpy",
          "display_name": "TrojanSpy",
          "target": null
        },
        {
          "id": "States",
          "display_name": "States",
          "target": null
        },
        {
          "id": "Inmortal",
          "display_name": "Inmortal",
          "target": null
        },
        {
          "id": "Domains",
          "display_name": "Domains",
          "target": null
        },
        {
          "id": "Locky",
          "display_name": "Locky",
          "target": null
        },
        {
          "id": "Delf.NBX",
          "display_name": "Delf.NBX",
          "target": null
        },
        {
          "id": "Gen:NN.ZexaF.32515",
          "display_name": "Gen:NN.ZexaF.32515",
          "target": null
        },
        {
          "id": "FileRepMalware",
          "display_name": "FileRepMalware",
          "target": null
        },
        {
          "id": "Gen:Variant.MSILPerseus",
          "display_name": "Gen:Variant.MSILPerseus",
          "target": null
        },
        {
          "id": "Icefog",
          "display_name": "Icefog",
          "target": null
        },
        {
          "id": "$WebWatson",
          "display_name": "$WebWatson",
          "target": null
        },
        {
          "id": "Agent.AIK.gen",
          "display_name": "Agent.AIK.gen",
          "target": null
        },
        {
          "id": "Agent.AIK.genCIL.StupidCryptor",
          "display_name": "Agent.AIK.genCIL.StupidCryptor",
          "target": null
        },
        {
          "id": "Agent.YPEZ",
          "display_name": "Agent.YPEZ",
          "target": null
        },
        {
          "id": "Application.InnovativSol",
          "display_name": "Application.InnovativSol",
          "target": null
        },
        {
          "id": "Agent.ASO",
          "display_name": "Agent.ASO",
          "target": null
        },
        {
          "id": "S-b748adc5",
          "display_name": "S-b748adc5",
          "target": null
        },
        {
          "id": "W32.eHeur",
          "display_name": "W32.eHeur",
          "target": null
        },
        {
          "id": "Kryptik.GUCB",
          "display_name": "Kryptik.GUCB",
          "target": null
        },
        {
          "id": "AgentTesla",
          "display_name": "AgentTesla",
          "target": null
        },
        {
          "id": "Autoit.bimwt",
          "display_name": "Autoit.bimwt",
          "target": null
        },
        {
          "id": "HEUR:Trojan.OLE2.Alien",
          "display_name": "HEUR:Trojan.OLE2.Alien",
          "target": null
        },
        {
          "id": "AGEN.1038489",
          "display_name": "AGEN.1038489",
          "target": null
        },
        {
          "id": "Gen:Variant.Ser.Strictor",
          "display_name": "Gen:Variant.Ser.Strictor",
          "target": null
        },
        {
          "id": "Packed.Themida.Gen",
          "display_name": "Packed.Themida.Gen",
          "target": null
        },
        {
          "id": "AGEN.1043164",
          "display_name": "AGEN.1043164",
          "target": null
        },
        {
          "id": "TrickBot - S0266",
          "display_name": "TrickBot - S0266",
          "target": null
        },
        {
          "id": "Emotet",
          "display_name": "Emotet",
          "target": null
        },
        {
          "id": "Trojan.PornoAsset",
          "display_name": "Trojan.PornoAsset",
          "target": null
        },
        {
          "id": "Ransom.Win64.PORNOASSET.SM1",
          "display_name": "Ransom.Win64.PORNOASSET.SM1",
          "target": null
        },
        {
          "id": "Gen:Variant.Ulise",
          "display_name": "Gen:Variant.Ulise",
          "target": null
        },
        {
          "id": "Trojan.Win64",
          "display_name": "Trojan.Win64",
          "target": null
        },
        {
          "id": "Dropper.Trojan.Agent",
          "display_name": "Dropper.Trojan.Agent",
          "target": null
        },
        {
          "id": "Heur.BZC.YAX.Pantera.10",
          "display_name": "Heur.BZC.YAX.Pantera.10",
          "target": null
        },
        {
          "id": "malicious.high.ml",
          "display_name": "malicious.high.ml",
          "target": null
        },
        {
          "id": "CVE-2015-1650",
          "display_name": "CVE-2015-1650",
          "target": null
        },
        {
          "id": "Worm.Win64.AutoRun",
          "display_name": "Worm.Win64.AutoRun",
          "target": null
        },
        {
          "id": "AIT.Heur.Cottonmouth.8.78F19BD7",
          "display_name": "AIT.Heur.Cottonmouth.8.78F19BD7",
          "target": null
        },
        {
          "id": "Gen:Variant.Mikey",
          "display_name": "Gen:Variant.Mikey",
          "target": null
        },
        {
          "id": "Trojan.Agent",
          "display_name": "Trojan.Agent",
          "target": null
        },
        {
          "id": "Pua.Gen",
          "display_name": "Pua.Gen",
          "target": null
        },
        {
          "id": "Trojan.Downloader.Generic",
          "display_name": "Trojan.Downloader.Generic",
          "target": null
        },
        {
          "id": "Suspected of Trojan.Downloader.gen",
          "display_name": "Suspected of Trojan.Downloader.gen",
          "target": null
        },
        {
          "id": "HEUR:RemoteAdmin.Generic",
          "display_name": "HEUR:RemoteAdmin.Generic",
          "target": null
        },
        {
          "id": "Gen:Heur.Ransom.HiddenTears",
          "display_name": "Gen:Heur.Ransom.HiddenTears",
          "target": null
        },
        {
          "id": "Nemucod.A",
          "display_name": "Nemucod.A",
          "target": null
        },
        {
          "id": "Backdoor.Hupigon",
          "display_name": "Backdoor.Hupigon",
          "target": null
        },
        {
          "id": "Trojan.Starter JS.Iframe",
          "display_name": "Trojan.Starter JS.Iframe",
          "target": null
        },
        {
          "id": "fake ,promethiumm ,strongpity",
          "display_name": "fake ,promethiumm ,strongpity",
          "target": null
        },
        {
          "id": "PUA.Reg1staid",
          "display_name": "PUA.Reg1staid",
          "target": null
        },
        {
          "id": "Malware.Heur_Generic.A",
          "display_name": "Malware.Heur_Generic.A",
          "target": null
        },
        {
          "id": "Bladabindi.Q",
          "display_name": "Bladabindi.Q",
          "target": null
        },
        {
          "id": "W32.eHeur",
          "display_name": "W32.eHeur",
          "target": null
        },
        {
          "id": "malicious.6e0700",
          "display_name": "malicious.6e0700",
          "target": null
        },
        {
          "id": "Trojan.Inject",
          "display_name": "Trojan.Inject",
          "target": null
        },
        {
          "id": "TSGeneric",
          "display_name": "TSGeneric",
          "target": null
        },
        {
          "id": "RedCap.vneda",
          "display_name": "RedCap.vneda",
          "target": null
        },
        {
          "id": "Trojan.Indiloadz",
          "display_name": "Trojan.Indiloadz",
          "target": null
        },
        {
          "id": "Trojan.Ekstak",
          "display_name": "Trojan.Ekstak",
          "target": null
        },
        {
          "id": "staticrr.paleokits.net",
          "display_name": "staticrr.paleokits.net",
          "target": null
        },
        {
          "id": "MSIL.Downloader",
          "display_name": "MSIL.Downloader",
          "target": null
        },
        {
          "id": "Trojan.Autoruns.GenericKDS",
          "display_name": "Trojan.Autoruns.GenericKDS",
          "target": null
        },
        {
          "id": "MSIL.Trojan.BSE",
          "display_name": "MSIL.Trojan.BSE",
          "target": null
        },
        {
          "id": "Adload.AD81",
          "display_name": "Adload.AD81",
          "target": null
        },
        {
          "id": "Packed.Asprotect",
          "display_name": "Packed.Asprotect",
          "target": null
        },
        {
          "id": "Gen:NN.ZemsilF.34062",
          "display_name": "Gen:NN.ZemsilF.34062",
          "target": null
        },
        {
          "id": "Evo",
          "display_name": "Evo",
          "target": null
        },
        {
          "id": "Agent.pwc",
          "display_name": "Agent.pwc",
          "target": null
        },
        {
          "id": "RiskTool.Phpw",
          "display_name": "RiskTool.Phpw",
          "target": null
        },
        {
          "id": "Gen:Variant.Symmi",
          "display_name": "Gen:Variant.Symmi",
          "target": null
        },
        {
          "id": "Trojan.PWS",
          "display_name": "Trojan.PWS",
          "target": null
        },
        {
          "id": "Generic.BitCoinMiner.3",
          "display_name": "Generic.BitCoinMiner.3",
          "target": null
        },
        {
          "id": "Trojan.Tasker",
          "display_name": "Trojan.Tasker",
          "target": null
        },
        {
          "id": "Gen:NN",
          "display_name": "Gen:NN",
          "target": null
        },
        {
          "id": "Downloader.CertutilURLCache",
          "display_name": "Downloader.CertutilURLCache",
          "target": null
        },
        {
          "id": "Elf",
          "display_name": "Elf",
          "target": null
        },
        {
          "id": "Gen:Heur.MSIL.Androm",
          "display_name": "Gen:Heur.MSIL.Androm",
          "target": null
        },
        {
          "id": "Kryptik.NRD",
          "display_name": "Kryptik.NRD",
          "target": null
        },
        {
          "id": "Riskware",
          "display_name": "Riskware",
          "target": null
        },
        {
          "id": "Kuluoz.B.gen",
          "display_name": "Kuluoz.B.gen",
          "target": null
        },
        {
          "id": "Gen:Variant.RevengeRat",
          "display_name": "Gen:Variant.RevengeRat",
          "target": null
        },
        {
          "id": "Gen:Variant.Mikey",
          "display_name": "Gen:Variant.Mikey",
          "target": null
        },
        {
          "id": "VB.Chronos.7",
          "display_name": "VB.Chronos.7",
          "target": null
        },
        {
          "id": "Kryptik.NOE",
          "display_name": "Kryptik.NOE",
          "target": null
        },
        {
          "id": "HEUR:WebToolbar.Generic",
          "display_name": "HEUR:WebToolbar.Generic",
          "target": null
        },
        {
          "id": "Gen:Variant.Barys",
          "display_name": "Gen:Variant.Barys",
          "target": null
        },
        {
          "id": "Backdoor.Xtreme",
          "display_name": "Backdoor.Xtreme",
          "target": null
        },
        {
          "id": "Trojan.MSIL",
          "display_name": "Trojan.MSIL",
          "target": null
        },
        {
          "id": "Gen:Variant.Graftor",
          "display_name": "Gen:Variant.Graftor",
          "target": null
        },
        {
          "id": "Backdoor.Agent",
          "display_name": "Backdoor.Agent",
          "target": null
        },
        {
          "id": "Unsafe",
          "display_name": "Unsafe",
          "target": null
        },
        {
          "id": "Trojan.PHP.Agent",
          "display_name": "Trojan.PHP.Agent",
          "target": null
        },
        {
          "id": "Trojan.Agent",
          "display_name": "Trojan.Agent",
          "target": null
        },
        {
          "id": "HEUR:Exploit.Generic",
          "display_name": "HEUR:Exploit.Generic",
          "target": null
        },
        {
          "id": "Ransom_WCRY.SMALYM",
          "display_name": "Ransom_WCRY.SMALYM",
          "target": null
        },
        {
          "id": "Ransom_WCRY.SMJ",
          "display_name": "Ransom_WCRY.SMJ",
          "target": null
        },
        {
          "id": "Auslogics",
          "display_name": "Auslogics",
          "target": null
        },
        {
          "id": "Gen:Variant.Jaiko",
          "display_name": "Gen:Variant.Jaiko",
          "target": null
        },
        {
          "id": "Exploit.W32.Agent",
          "display_name": "Exploit.W32.Agent",
          "target": null
        },
        {
          "id": "Trojan.Cud.Gen",
          "display_name": "Trojan.Cud.Gen",
          "target": null
        },
        {
          "id": "Trojan.DOC.Downloader",
          "display_name": "Trojan.DOC.Downloader",
          "target": null
        },
        {
          "id": "Backdoor.MSIL.Agent",
          "display_name": "Backdoor.MSIL.Agent",
          "target": null
        },
        {
          "id": "Gen:Trojan.Heur2.LPTbHW@W64.HfsAutoB",
          "display_name": "Gen:Trojan.Heur2.LPTbHW@W64.HfsAutoB",
          "target": null
        },
        {
          "id": "Gen:Variant.Kazy",
          "display_name": "Gen:Variant.Kazy",
          "target": null
        },
        {
          "id": "Gen:Variant.Zusy",
          "display_name": "Gen:Variant.Zusy",
          "target": null
        },
        {
          "id": "Ransom.WannaCrypt",
          "display_name": "Ransom.WannaCrypt",
          "target": null
        },
        {
          "id": "Generic.ServStart.A",
          "display_name": "Generic.ServStart.A",
          "target": null
        },
        {
          "id": "Trojan.Wanna",
          "display_name": "Trojan.Wanna",
          "target": null
        },
        {
          "id": "Generic.MSIL.Bladabindi",
          "display_name": "Generic.MSIL.Bladabindi",
          "target": null
        },
        {
          "id": "TROJ_GEN.R002C0OG518",
          "display_name": "TROJ_GEN.R002C0OG518",
          "target": null
        },
        {
          "id": "Trojan.Chapak",
          "display_name": "Trojan.Chapak",
          "target": null
        },
        {
          "id": "Indiloadz.BB",
          "display_name": "Indiloadz.BB",
          "target": null
        },
        {
          "id": "BehavBehavesLike.PUPXBI",
          "display_name": "BehavBehavesLike.PUPXBI",
          "target": null
        },
        {
          "id": "DeepScan:Generic.SpyAgent.6",
          "display_name": "DeepScan:Generic.SpyAgent.6",
          "target": null
        },
        {
          "id": "Python.KeyLogger",
          "display_name": "Python.KeyLogger",
          "target": null
        },
        {
          "id": "GameHack.CRS",
          "display_name": "GameHack.CRS",
          "target": null
        },
        {
          "id": "Generic.MSIL.PasswordStealer",
          "display_name": "Generic.MSIL.PasswordStealer",
          "target": null
        },
        {
          "id": "PSW.Agent",
          "display_name": "PSW.Agent",
          "target": null
        },
        {
          "id": "malicious.8c45ba",
          "display_name": "malicious.8c45ba",
          "target": null
        },
        {
          "id": "Dropper.Binder",
          "display_name": "Dropper.Binder",
          "target": null
        },
        {
          "id": "Constructor.MSIL",
          "display_name": "Constructor.MSIL",
          "target": null
        },
        {
          "id": "Linux.Agent",
          "display_name": "Linux.Agent",
          "target": null
        },
        {
          "id": "Virus.3DMax.Script",
          "display_name": "Virus.3DMax.Script",
          "target": null
        },
        {
          "id": "ScrInject.B",
          "display_name": "ScrInject.B",
          "target": null
        },
        {
          "id": "Trojan.WisdomEyes.16070401.9500",
          "display_name": "Trojan.WisdomEyes.16070401.9500",
          "target": null
        },
        {
          "id": "Application.SearchProtect",
          "display_name": "Application.SearchProtect",
          "target": null
        },
        {
          "id": "JS:Trojan.Clicker",
          "display_name": "JS:Trojan.Clicker",
          "target": null
        },
        {
          "id": "Faceliker.A",
          "display_name": "Faceliker.A",
          "target": null
        },
        {
          "id": "JS:Trojan.JS.Faceliker",
          "display_name": "JS:Trojan.JS.Faceliker",
          "target": null
        },
        {
          "id": "Constructor.MSIL  Linux.Agent",
          "display_name": "Constructor.MSIL  Linux.Agent",
          "target": null
        },
        {
          "id": "PowerShell.Trojan",
          "display_name": "PowerShell.Trojan",
          "target": null
        },
        {
          "id": "HTML:Script",
          "display_name": "HTML:Script",
          "target": null
        },
        {
          "id": "ScrInject.B",
          "display_name": "ScrInject.B",
          "target": null
        },
        {
          "id": "W32.AIDetectVM",
          "display_name": "W32.AIDetectVM",
          "target": null
        },
        {
          "id": "HackTool.CheatEngine",
          "display_name": "HackTool.CheatEngine",
          "target": null
        },
        {
          "id": "Injector.CLDS",
          "display_name": "Injector.CLDS",
          "target": null
        },
        {
          "id": "VB.Downloader.2",
          "display_name": "VB.Downloader.2",
          "target": null
        },
        {
          "id": "malicious.3e78cc",
          "display_name": "malicious.3e78cc",
          "target": null
        },
        {
          "id": "malicious.d800d6",
          "display_name": "malicious.d800d6",
          "target": null
        },
        {
          "id": "VB.PwShell.2",
          "display_name": "VB.PwShell.2",
          "target": null
        },
        {
          "id": "Backdoor.RBot",
          "display_name": "Backdoor.RBot",
          "target": null
        },
        {
          "id": "malicious.71b1a8",
          "display_name": "malicious.71b1a8",
          "target": null
        },
        {
          "id": "TrojanSpy.KeyLogger",
          "display_name": "TrojanSpy.KeyLogger",
          "target": null
        },
        {
          "id": "Injector.JDO",
          "display_name": "Injector.JDO",
          "target": null
        },
        {
          "id": "Heur.Msword.Gen",
          "display_name": "Heur.Msword.Gen",
          "target": null
        },
        {
          "id": "PSW.Discord",
          "display_name": "PSW.Discord",
          "target": null
        },
        {
          "id": "Packed.VMProtect",
          "display_name": "Packed.VMProtect",
          "target": null
        },
        {
          "id": "HEUR:AdWare.StartSurf",
          "display_name": "HEUR:AdWare.StartSurf",
          "target": null
        },
        {
          "id": "Gen:Heur.NoobyProtect",
          "display_name": "Gen:Heur.NoobyProtect",
          "target": null
        },
        {
          "id": "CIL.HeapOverride",
          "display_name": "CIL.HeapOverride",
          "target": null
        },
        {
          "id": "HEUR:Trojan.Tasker",
          "display_name": "HEUR:Trojan.Tasker",
          "target": null
        },
        {
          "id": "XLM.Trojan.Abracadabra.27",
          "display_name": "XLM.Trojan.Abracadabra.27",
          "target": null
        },
        {
          "id": "HEUR:Backdoor.MSIL.NanoBot",
          "display_name": "HEUR:Backdoor.MSIL.NanoBot",
          "target": null
        },
        {
          "id": "Trojan.PSW.Mimikatz",
          "display_name": "Trojan.PSW.Mimikatz",
          "target": null
        },
        {
          "id": "TrojanSpy.Python",
          "display_name": "TrojanSpy.Python",
          "target": null
        },
        {
          "id": "Trojan.Ole2.Vbs",
          "display_name": "Trojan.Ole2.Vbs",
          "target": null
        },
        {
          "id": "Exploit.MSOffice",
          "display_name": "Exploit.MSOffice",
          "target": null
        },
        {
          "id": "DeepScan:Generic.Ransom.AmnesiaE",
          "display_name": "DeepScan:Generic.Ransom.AmnesiaE",
          "target": null
        },
        {
          "id": "Wacatac.D6",
          "display_name": "Wacatac.D6",
          "target": null
        },
        {
          "id": "Backdoor.Androm",
          "display_name": "Backdoor.Androm",
          "target": null
        },
        {
          "id": "Packed.NetSeal",
          "display_name": "Packed.NetSeal",
          "target": null
        },
        {
          "id": "Trojan.MSIL.Injector",
          "display_name": "Trojan.MSIL.Injector",
          "target": null
        },
        {
          "id": "Trojan.PWS.Agent",
          "display_name": "Trojan.PWS.Agent",
          "target": null
        },
        {
          "id": "TScope.Trojan",
          "display_name": "TScope.Trojan",
          "target": null
        },
        {
          "id": "PSW.Stealer",
          "display_name": "PSW.Stealer",
          "target": null
        },
        {
          "id": "Trojan.PackedNET",
          "display_name": "Trojan.PackedNET",
          "target": null
        },
        {
          "id": "Trojan.Java",
          "display_name": "Trojan.Java",
          "target": null
        },
        {
          "id": "MalwareX",
          "display_name": "MalwareX",
          "target": null
        },
        {
          "id": "Trojan.PSW.Python",
          "display_name": "Trojan.PSW.Python",
          "target": null
        },
        {
          "id": "malicious.11abfc",
          "display_name": "malicious.11abfc",
          "target": null
        },
        {
          "id": "Generic.ASMalwS",
          "display_name": "Generic.ASMalwS",
          "target": null
        },
        {
          "id": "HEUR:Trojan.MSIL.Tasker",
          "display_name": "HEUR:Trojan.MSIL.Tasker",
          "target": null
        },
        {
          "id": "PossibleThreat.PALLAS",
          "display_name": "PossibleThreat.PALLAS",
          "target": null
        },
        {
          "id": "Backdoor.Poison",
          "display_name": "Backdoor.Poison",
          "target": null
        },
        {
          "id": "Generic.MSIL.LimeRAT",
          "display_name": "Generic.MSIL.LimeRAT",
          "target": null
        },
        {
          "id": "PWS-FCZZ",
          "display_name": "PWS-FCZZ",
          "target": null
        },
        {
          "id": "Trojan.Script",
          "display_name": "Trojan.Script",
          "target": null
        },
        {
          "id": "Gen:Heur.MSIL.Inject",
          "display_name": "Gen:Heur.MSIL.Inject",
          "target": null
        },
        {
          "id": "Trojan.PWS.Growtopia",
          "display_name": "Trojan.PWS.Growtopia",
          "target": null
        },
        {
          "id": "Spyware.Bobik",
          "display_name": "Spyware.Bobik",
          "target": null
        },
        {
          "id": "HackTool.BruteForce",
          "display_name": "HackTool.BruteForce",
          "target": null
        },
        {
          "id": "Hack.Patcher",
          "display_name": "Hack.Patcher",
          "target": null
        },
        {
          "id": "PWS.p",
          "display_name": "PWS.p",
          "target": null
        },
        {
          "id": "Suppobox",
          "display_name": "Suppobox",
          "target": null
        },
        {
          "id": "index.php",
          "display_name": "index.php",
          "target": null
        },
        {
          "id": "Packed.VMProtect",
          "display_name": "Packed.VMProtect",
          "target": null
        },
        {
          "id": "SmokeLoader",
          "display_name": "SmokeLoader",
          "target": null
        },
        {
          "id": "Generic.Malware",
          "display_name": "Generic.Malware",
          "target": null
        },
        {
          "id": "SNH:Script [Dropper]",
          "display_name": "SNH:Script [Dropper]",
          "target": null
        },
        {
          "id": "HEUR:Trojan.MSOffice.SAgent",
          "display_name": "HEUR:Trojan.MSOffice.SAgent",
          "target": null
        },
        {
          "id": "Script.INF",
          "display_name": "Script.INF",
          "target": null
        },
        {
          "id": "JS:Trojan.JS.Likejack",
          "display_name": "JS:Trojan.JS.Likejack",
          "target": null
        },
        {
          "id": "SNH:Script [Dropper]",
          "display_name": "SNH:Script [Dropper]",
          "target": null
        },
        {
          "id": "Trojan.JS.Agent",
          "display_name": "Trojan.JS.Agent",
          "target": null
        },
        {
          "id": "APT Notes",
          "display_name": "APT Notes",
          "target": null
        },
        {
          "id": "susp.rtf.objupdate",
          "display_name": "susp.rtf.objupdate",
          "target": null
        },
        {
          "id": "RedCap.zoohz",
          "display_name": "RedCap.zoohz",
          "target": null
        },
        {
          "id": "Trojan.Tasker",
          "display_name": "Trojan.Tasker",
          "target": null
        },
        {
          "id": "virus.office.qexvmc",
          "display_name": "virus.office.qexvmc",
          "target": null
        },
        {
          "id": "Trojan.KillProc",
          "display_name": "Trojan.KillProc",
          "target": null
        },
        {
          "id": "Generic.MSIL.GrwtpStealer.1",
          "display_name": "Generic.MSIL.GrwtpStealer.1",
          "target": null
        },
        {
          "id": "Suspicious.Cloud",
          "display_name": "Suspicious.Cloud",
          "target": null
        },
        {
          "id": "PowerShell.DownLoader",
          "display_name": "PowerShell.DownLoader",
          "target": null
        },
        {
          "id": "Downldr.gen",
          "display_name": "Downldr.gen",
          "target": null
        },
        {
          "id": "AGEN.1030939",
          "display_name": "AGEN.1030939",
          "target": null
        },
        {
          "id": "HackTool.Binder",
          "display_name": "HackTool.Binder",
          "target": null
        },
        {
          "id": "Trojan.Inject",
          "display_name": "Trojan.Inject",
          "target": null
        },
        {
          "id": "Dldr.Agent",
          "display_name": "Dldr.Agent",
          "target": null
        },
        {
          "id": "Dropper.MSIL",
          "display_name": "Dropper.MSIL",
          "target": null
        },
        {
          "id": "Trojan.VBKryjetor",
          "display_name": "Trojan.VBKryjetor",
          "target": null
        },
        {
          "id": "PWSX",
          "display_name": "PWSX",
          "target": null
        },
        {
          "id": "VB:Trojan.VBA.Agent",
          "display_name": "VB:Trojan.VBA.Agent",
          "target": null
        },
        {
          "id": "HEUR:Trojan.MSOffice.Stratos",
          "display_name": "HEUR:Trojan.MSOffice.Stratos",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1071.001",
          "name": "Web Protocols",
          "display_name": "T1071.001 - Web Protocols"
        },
        {
          "id": "T1071.004",
          "name": "DNS",
          "display_name": "T1071.004 - DNS"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1059.007",
          "name": "JavaScript",
          "display_name": "T1059.007 - JavaScript"
        },
        {
          "id": "T1497",
          "name": "Virtualization/Sandbox Evasion",
          "display_name": "T1497 - Virtualization/Sandbox Evasion"
        },
        {
          "id": "T1068",
          "name": "Exploitation for Privilege Escalation",
          "display_name": "T1068 - Exploitation for Privilege Escalation"
        },
        {
          "id": "TA0029",
          "name": "Privilege Escalation",
          "display_name": "TA0029 - Privilege Escalation"
        },
        {
          "id": "T1449",
          "name": "Exploit SS7 to Redirect Phone Calls/SMS",
          "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
        },
        {
          "id": "T1190",
          "name": "Exploit Public-Facing Application",
          "display_name": "T1190 - Exploit Public-Facing Application"
        },
        {
          "id": "T1210",
          "name": "Exploitation of Remote Services",
          "display_name": "T1210 - Exploitation of Remote Services"
        },
        {
          "id": "T1450",
          "name": "Exploit SS7 to Track Device Location",
          "display_name": "T1450 - Exploit SS7 to Track Device Location"
        },
        {
          "id": "T1211",
          "name": "Exploitation for Defense Evasion",
          "display_name": "T1211 - Exploitation for Defense Evasion"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "TA0011",
          "name": "Command and Control",
          "display_name": "TA0011 - Command and Control"
        },
        {
          "id": "T1412",
          "name": "Capture SMS Messages",
          "display_name": "T1412 - Capture SMS Messages"
        },
        {
          "id": "T1454",
          "name": "Malicious SMS Message",
          "display_name": "T1454 - Malicious SMS Message"
        },
        {
          "id": "T1001",
          "name": "Data Obfuscation",
          "display_name": "T1001 - Data Obfuscation"
        },
        {
          "id": "T1114",
          "name": "Email Collection",
          "display_name": "T1114 - Email Collection"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1498",
          "name": "Network Denial of Service",
          "display_name": "T1498 - Network Denial of Service"
        },
        {
          "id": "T1496",
          "name": "Resource Hijacking",
          "display_name": "T1496 - Resource Hijacking"
        },
        {
          "id": "T1176",
          "name": "Browser Extensions",
          "display_name": "T1176 - Browser Extensions"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 339,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 1184,
        "FileHash-SHA1": 949,
        "FileHash-SHA256": 3712,
        "URL": 2925,
        "domain": 627,
        "hostname": 1319,
        "CVE": 26,
        "email": 8,
        "CIDR": 2
      },
      "indicator_count": 10752,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 222,
      "modified_text": "904 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "654c597a4a45c8d84f0b15c1",
      "name": "Lucky Mouse APT27 | Feodo Tracker | Malicious Tor Server | Apple iOS",
      "description": "Darkside 2020 Ecosystem .BEware\nMalicious Tor server. Link found in pulse created prior. \nMalvertizing target: Tsara Brashears\nRevenge Porn.\nThere may me others. Malicious Apple activities, locating, CVE exploits, unlocking, hijacker, service transfer, spyware, malicious full auth, tracking, endless. Seems to originate from a law firm that goes to far to defend clients and silence alleged victims. \nSome State allow  the same  privileges  and tools the federal government to insurance, workers compensation, investigators and insurance company law firms for investigations. \nFear tactics they seem willing to back up. I was approached and asked about my cyber knowledge by strangers. I am followed now for using a tool properly.\nALL terms auto populated from various tools from various tools used including, State, Brian Sabey, cyber stalking. Perhaps he's made contact with target. Danger!",
      "modified": "2023-12-09T03:01:57.989000",
      "created": "2023-11-09T04:00:58.166000",
      "tags": [
        "ssl certificate",
        "historical ssl",
        "communicating",
        "contacted",
        "resolutions",
        "whois record",
        "whois whois",
        "whois parent",
        "whois siblings",
        "skynet",
        "threat report",
        "ip summary",
        "url summary",
        "summary",
        "sample",
        "samples",
        "detection list",
        "blacklist",
        "cisco umbrella",
        "site",
        "safe site",
        "million",
        "team",
        "microsoft",
        "back",
        "download",
        "phishing",
        "union",
        "bank",
        "malicious site",
        "blacklist http",
        "exit",
        "traffic",
        "node tcp",
        "tor known",
        "tor relayrouter",
        "et tor",
        "known tor",
        "relayrouter",
        "anonymizer",
        "spammer",
        "malware",
        "dropped",
        "unlocker",
        "http",
        "critical risk",
        "redline stealer",
        "core",
        "hacktool",
        "execution",
        "type win32",
        "exe size",
        "first seen",
        "file name",
        "avast win32",
        "win32",
        "avg win32",
        "fortinet",
        "vitro",
        "mb first",
        "rmndrp",
        "clean mx",
        "undetected dns8",
        "undetected vx",
        "sophos",
        "vault",
        "zdb zeus",
        "cmc threat",
        "snort ip",
        "feodo tracker",
        "cybereason",
        "send bug",
        "pe yandex",
        "no data",
        "tag count",
        "count blacklist",
        "tag tag",
        "algorithm",
        "v3 serial",
        "number",
        "issuer",
        "cus cnr3",
        "olet",
        "subject public",
        "key info",
        "key algorithm",
        "key identifier",
        "first",
        "seen",
        "valid",
        "no na",
        "no no",
        "ip security",
        "cndst root",
        "ca x3",
        "ca id",
        "research group",
        "cnisrg root",
        "no expired",
        "mozilla",
        "android",
        "malicious red team",
        "tsara brashears",
        "cyber stalking",
        "malvertizing",
        "invasion of privacy",
        "threat",
        "adult content",
        "apple",
        "iphone unlocker",
        "android",
        "exploited spyware",
        "malware host",
        "brute force",
        "revenge-rat",
        "banker",
        "evasive",
        "domain",
        "redline",
        "stealer",
        "phishing",
        "ramnit",
        "unreliable subdomains",
        "dridex",
        "gating",
        "msil",
        "rat",
        "loki",
        "network",
        "hacking",
        "sinkhole",
        "azorult",
        "c2",
        "historicalandnew",
        "targeted attack",
        "puffstealer",
        "rultazo",
        "lokibot",
        "loki pws",
        "burkina",
        "banker,dde,dridex,exploit",
        "banker,dridex,evasive",
        "trickbot",
        "ransomware,torrentlocker",
        "exploit_source",
        "blacknet",
        "FileRepMalware",
        "linux agent",
        "blacknet",
        "ios",
        "phishing paypal",
        "tagging",
        "defacement",
        "hit",
        "bounty",
        "phishing site",
        "malware site",
        "malware download",
        "endangerment",
        "Malicious domain - SANS Internet Storm Center",
        "evasive,msil,rat,revenge-rat",
        "prism_setting",
        "prism_object",
        "static engine",
        "social engineering",
        "jansky",
        "worm",
        "network rat",
        "networm",
        "Loki Password Stealer (PWS)",
        "South Carolina Federal Credit Union phishing",
        "darkweb",
        "yandex",
        "redirectors",
        "blacknet threats",
        "phishing,ransomware,sinkhole",
        "wanacrypt0r,wannacry,wcry",
        "tor c++",
        "tor c++ client",
        "python user",
        "js user",
        "hacker",
        "hijacker",
        "heur",
        "maltiverse",
        "alexa top",
        "exploit",
        "riskware",
        "unsafe",
        "outbreak",
        "downer",
        "shell",
        "mediamagnet",
        "sality",
        "swrort",
        "adaptivebee",
        "unruy",
        "iobit",
        "dropper",
        "trojanx",
        "artemis",
        "installcore",
        "webshell",
        "crack",
        "webtoolbar",
        "search live",
        "api blog",
        "docs pricing",
        "november",
        "de indicators",
        "domains",
        "hashes",
        "__convergedlogin_pcustomizationloader_44b450e8d543eb53930d",
        "malicious url",
        "financial",
        "blacknet rat",
        "azorult",
        "stealer",
        "deep scan",
        "blacklist https",
        "referrer",
        "collections kp",
        "incident ip",
        "sneaky server",
        "replacement",
        "unauthorized",
        "emotet",
        "noname057",
        "generic malware",
        "engineering",
        "cyber threat",
        "facebook",
        "paypal",
        "dropbox",
        "united",
        "america",
        "banking",
        "wells fargo",
        "steam",
        "twitter",
        "sliver",
        "daum",
        "swift",
        "runescape",
        "betabot",
        "district",
        "iframe",
        "alexa",
        "downldr",
        "agent",
        "presenoker",
        "bladabindi",
        "live",
        "conduit",
        "pony",
        "covid19",
        "malicious",
        "cobalt strike",
        "suppobox",
        "ramnit",
        "meterpreter",
        "virut",
        "njrat",
        "pykspa",
        "asyncrat",
        "downloader",
        "fakealert",
        "binder",
        "virustotal",
        "formbook",
        "necurs",
        "trojan",
        "msil",
        "hiloti",
        "vawtrak",
        "simda",
        "kraken",
        "solimba",
        "icedid",
        "redirector",
        "suspic",
        "amadey",
        "raccoon",
        "nanocore rat",
        "revenge rat",
        "genkryptik",
        "fuery",
        "wacatac",
        "service",
        "cloudeye",
        "tinba",
        "domaiq",
        "ave maria",
        "zeus",
        "ransomware",
        "zbot",
        "generic",
        "trojanspy",
        "states",
        "inmortal",
        "locky",
        "strike",
        "china cobalt",
        "keybase",
        "cutwail",
        "citadel",
        "radamant",
        "kovter",
        "bradesco",
        "nymaim",
        "amonetize",
        "bondat",
        "ghost rat",
        "vjw0rm",
        "bandoo",
        "matsnu",
        "dnspionage",
        "darkgate",
        "vidar",
        "keylogger",
        "remcos",
        "agenttesla",
        "detplock",
        "win64",
        "smokeloader",
        "agent tesla",
        "kgs0",
        "kls0",
        "urls",
        "type name",
        "dns replication",
        "date",
        "domain",
        "win32 exe",
        "files",
        "detections type",
        "name",
        "drpsuinstaller",
        "vdfsurfs",
        "opera",
        "icwrmind",
        "notepad",
        "installer",
        "miner",
        "unknown",
        "networm",
        "houdini",
        "quasar rat",
        "gamehack",
        "dbatloader",
        "qakbot",
        "ursnif",
        "CVE-2005-1790",
        "CVE-2009-3672",
        "CVE-2010-3962",
        "CVE-2012-3993",
        "CVE-2014-6332",
        "CVE-2017-11882",
        "CVE-2020-0601",
        "CVE-2020-0674",
        "hallrender.com",
        "brian sabey",
        "insurance",
        "botnetwork",
        "botmaster",
        "command_and_control",
        "CVE-2021-27065",
        "CVE-2021-40444",
        "CVE-2023-4966",
        "CVE-2017-0199",
        "CVE-2018-4893",
        "CVE-2010-3333",
        "CVE-2015-1641",
        "CVE-2017-0147",
        "CVE-2017-8570",
        "CVE-2018-0802",
        "CVE-2018-8373",
        "CVE-2017-8759",
        "CVE-2018-8453",
        "CVE-2014-3153",
        "CVE-2015-1650",
        "CVE-2017-0143",
        "CVE-2017-8464",
        "Icefog",
        "Delf.NBX",
        "$WebWatson",
        "Gen:Heur.Ransom.HiddenTears",
        "mobilekey.pw",
        "bitbucket.org",
        "Anomalous.100%",
        "malware distribution site",
        "gootkit",
        "edsaid",
        "rightsaided",
        "betabot",
        "cobaltstrike4.tk",
        "mas.to",
        "BehavesLike.YahLover",
        "srdvd16010404",
        "languageenu",
        "buildno",
        "channelisales",
        "vendorname2581",
        "osregion",
        "device",
        "systemlocale",
        "majorver16",
        "quasar",
        "find",
        "lockbit",
        "chaos",
        "ransomexx",
        "grandoreiro",
        "evilnum",
        "banker"
      ],
      "references": [
        "https://hybrid-analysis.com/sample/6765f47ea77c8274c8e4973ed95aedf59e75998c62f6029e23c58cdf36ed85ba/654afdbdc621e7037801cce7",
        "20.99.186.246 exploit source",
        "fp2e7a.wpc.2be4.phicdn.net",
        "https://www.anyxxxtube.net/search-porn/tsara-brashears/ (phishing, ELF, Prism.exe found)",
        "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian (password cracker)",
        "http://182.22.25.124:7878/182.22.25.124:443     (malicious dropper)",
        "init.ess.apple.com         (malicious code script)",
        "https://www.pornhub.com/video/search?search=tsara+brashears (Malicious PW cracker | stylebk.css stylesheets - not found )",
        "https://urlscan.io/result/a328d9ff-fb49-4078-960d-a757fd41404f/#indicators",
        "VirusTotal Link: https://www.virustotal.com/gui/ip-address/20.99.186.246/detection",
        "Abuse IPDB Link: https://www.abuseipdb.com/check/20.99.186.246",
        "IPv4 45.12.253.72.            command_and_control",
        "Hostname: ddos.dnsnb8.net                        command_and_control",
        "IPv4 95.213.186.51              command_and_control",
        "Hostname: www.supernetforme.com      command_and_control",
        "IPv4 103.224.182.246        command_and_control",
        "IPv4 72.251.233.245           command_and_control",
        "IPv4 63.251.106.25             command_and_control",
        "IPv4 45.15.156.208            command_and_control",
        "IPv4 104.247.81.51             command_and_control",
        "http://ambisexual.phone-sex-blogs.com/http:/ambisexual.phone-sex-blogs.com/images/thumbnails/pic118.jpg             (phishing)",
        "https://downloaddevtools.ir/     (phishing)",
        "happylifehappywife.com",
        "apples.encryptedwork.com        (Interesting in the blacknet)",
        "https://itunes.apple.com/app/apple-store/id284815942/us/app/samsung-galaxy-watch-gear-s/id1117310635.                   (iOS unlocker and hijacker)",
        "https://www.anyxxxtube.net/media/favicon/apple              (password cracker and iOS hijacker)",
        "https://www.apple.com/shop/browse/open/country_selector     (exploit)",
        "www.norad.mil   (federal tracking tool used by attorneys, law firms, and private investigators 'licensed or unlicensed') hi!",
        "http://init-p01st.push.apple.com/bag            (malicious web creator)",
        "opencve.djgummikuh.de        (CVE dispensary)",
        "Maltiverse Research Team",
        "URLscan.io",
        "Deep Research",
        "Hybrid Analysis",
        "URLhaus Abuse.ch",
        "Cyber Threat Coalition",
        "ThreatFox Abuse.ch"
      ],
      "public": 1,
      "adversary": "Lucky Mouse APT27 | NoName057(16) |  Unnamed",
      "targeted_countries": [
        "United States of America",
        "France",
        "Spain"
      ],
      "malware_families": [
        {
          "id": "Feodo",
          "display_name": "Feodo",
          "target": null
        },
        {
          "id": "Dridex",
          "display_name": "Dridex",
          "target": null
        },
        {
          "id": "Redline Stealer",
          "display_name": "Redline Stealer",
          "target": null
        },
        {
          "id": "Ramnit.N",
          "display_name": "Ramnit.N",
          "target": null
        },
        {
          "id": "Loki Bot",
          "display_name": "Loki Bot",
          "target": null
        },
        {
          "id": "Loki Password Stealer (PWS)",
          "display_name": "Loki Password Stealer (PWS)",
          "target": null
        },
        {
          "id": "AZORult",
          "display_name": "AZORult",
          "target": null
        },
        {
          "id": "Zbd Zeus",
          "display_name": "Zbd Zeus",
          "target": null
        },
        {
          "id": "Trojan:MSIL/Burkina",
          "display_name": "Trojan:MSIL/Burkina",
          "target": "/malware/Trojan:MSIL/Burkina"
        },
        {
          "id": "Generic.TrickBot.1",
          "display_name": "Generic.TrickBot.1",
          "target": null
        },
        {
          "id": "Exploit.CVE",
          "display_name": "Exploit.CVE",
          "target": null
        },
        {
          "id": "Injector.IS.gen",
          "display_name": "Injector.IS.gen",
          "target": null
        },
        {
          "id": "Gen:Variant.Razy",
          "display_name": "Gen:Variant.Razy",
          "target": null
        },
        {
          "id": "Trojan.Androm.Gen",
          "display_name": "Trojan.Androm.Gen",
          "target": null
        },
        {
          "id": "HEUR:Trojan.Linux.Agent",
          "display_name": "HEUR:Trojan.Linux.Agent",
          "target": null
        },
        {
          "id": "BScope.Trojan",
          "display_name": "BScope.Trojan",
          "target": null
        },
        {
          "id": "VBA.Downloader",
          "display_name": "VBA.Downloader",
          "target": null
        },
        {
          "id": "Trojan.Notifier",
          "display_name": "Trojan.Notifier",
          "target": null
        },
        {
          "id": "HEUR:Trojan.MSOffice.Alien",
          "display_name": "HEUR:Trojan.MSOffice.Alien",
          "target": null
        },
        {
          "id": "Unsafe.AI_Score_100%",
          "display_name": "Unsafe.AI_Score_100%",
          "target": null
        },
        {
          "id": "Gen:Variant.Johnnie",
          "display_name": "Gen:Variant.Johnnie",
          "target": null
        },
        {
          "id": "DangerousObject.Multi",
          "display_name": "DangerousObject.Multi",
          "target": null
        },
        {
          "id": "Trojan:Python/Downldr",
          "display_name": "Trojan:Python/Downldr",
          "target": "/malware/Trojan:Python/Downldr"
        },
        {
          "id": "Trojan:Linux/Downldr",
          "display_name": "Trojan:Linux/Downldr",
          "target": "/malware/Trojan:Linux/Downldr"
        },
        {
          "id": "Trojan:VBA/Downldr",
          "display_name": "Trojan:VBA/Downldr",
          "target": "/malware/Trojan:VBA/Downldr"
        },
        {
          "id": "TrojanDownloader:Linux/Downldr",
          "display_name": "TrojanDownloader:Linux/Downldr",
          "target": "/malware/TrojanDownloader:Linux/Downldr"
        },
        {
          "id": "Kryptik.FPH.gen",
          "display_name": "Kryptik.FPH.gen",
          "target": null
        },
        {
          "id": "TROJ_FRS.VSNTFK19",
          "display_name": "TROJ_FRS.VSNTFK19",
          "target": null
        },
        {
          "id": "Trojan.Ransom.GenericKD",
          "display_name": "Trojan.Ransom.GenericKD",
          "target": null
        },
        {
          "id": "Phish.JAT",
          "display_name": "Phish.JAT",
          "target": null
        },
        {
          "id": "Phishing.HTML",
          "display_name": "Phishing.HTML",
          "target": null
        },
        {
          "id": "Generic.ASMalwS",
          "display_name": "Generic.ASMalwS",
          "target": null
        },
        {
          "id": "Phish.AB",
          "display_name": "Phish.AB",
          "target": null
        },
        {
          "id": "Generic.Malware",
          "display_name": "Generic.Malware",
          "target": null
        },
        {
          "id": "ml.Generic",
          "display_name": "ml.Generic",
          "target": null
        },
        {
          "id": "Xegumumune.8596c22f",
          "display_name": "Xegumumune.8596c22f",
          "target": null
        },
        {
          "id": "Generic.Malware.SMYB",
          "display_name": "Generic.Malware.SMYB",
          "target": null
        },
        {
          "id": "malicious.moderate.ml",
          "display_name": "malicious.moderate.ml",
          "target": null
        },
        {
          "id": "Agent.NBAE",
          "display_name": "Agent.NBAE",
          "target": null
        },
        {
          "id": "AGEN.1045227",
          "display_name": "AGEN.1045227",
          "target": null
        },
        {
          "id": "Riskware.Agent",
          "display_name": "Riskware.Agent",
          "target": null
        },
        {
          "id": "Gen:Variant.Cerbu",
          "display_name": "Gen:Variant.Cerbu",
          "target": null
        },
        {
          "id": "IL:Trojan.MSILZilla",
          "display_name": "IL:Trojan.MSILZilla",
          "target": null
        },
        {
          "id": "Dropped:Generic.Ransom.DMR",
          "display_name": "Dropped:Generic.Ransom.DMR",
          "target": null
        },
        {
          "id": "Delf.NBX",
          "display_name": "Delf.NBX",
          "target": null
        },
        {
          "id": "malicious.f01f67",
          "display_name": "malicious.f01f67",
          "target": null
        },
        {
          "id": "AGEN.1144657",
          "display_name": "AGEN.1144657",
          "target": null
        },
        {
          "id": "Trojan.Heur",
          "display_name": "Trojan.Heur",
          "target": null
        },
        {
          "id": "Trojan.Malware.300983",
          "display_name": "Trojan.Malware.300983",
          "target": null
        },
        {
          "id": "SdBot.CAOC",
          "display_name": "SdBot.CAOC",
          "target": null
        },
        {
          "id": "Trojan.DelShad",
          "display_name": "Trojan.DelShad",
          "target": null
        },
        {
          "id": "Exploit CVE-2017-11882",
          "display_name": "Exploit CVE-2017-11882",
          "target": null
        },
        {
          "id": "GameHack.NL",
          "display_name": "GameHack.NL",
          "target": null
        },
        {
          "id": "JS:Trojan.HideLink",
          "display_name": "JS:Trojan.HideLink",
          "target": null
        },
        {
          "id": "Script.Agent",
          "display_name": "Script.Agent",
          "target": null
        },
        {
          "id": "Macro.Agent",
          "display_name": "Macro.Agent",
          "target": null
        },
        {
          "id": "Macro.Downloader.AMIP",
          "display_name": "Macro.Downloader.AMIP",
          "target": null
        },
        {
          "id": "Trojan.VBA",
          "display_name": "Trojan.VBA",
          "target": null
        },
        {
          "id": "HEUR.VBA.Trojan",
          "display_name": "HEUR.VBA.Trojan",
          "target": null
        },
        {
          "id": "VB.EmoooDldr.10",
          "display_name": "VB.EmoooDldr.10",
          "target": null
        },
        {
          "id": "VB:Trojan.Valyria",
          "display_name": "VB:Trojan.Valyria",
          "target": null
        },
        {
          "id": "OpenSubtitles.A",
          "display_name": "OpenSubtitles.A",
          "target": null
        },
        {
          "id": "VB.EmoDldr.4",
          "display_name": "VB.EmoDldr.4",
          "target": null
        },
        {
          "id": "Packed-GV",
          "display_name": "Packed-GV",
          "target": null
        },
        {
          "id": "Adware.InstallMonetizer",
          "display_name": "Adware.InstallMonetizer",
          "target": null
        },
        {
          "id": "Skynet",
          "display_name": "Skynet",
          "target": null
        },
        {
          "id": "HW32.Packed",
          "display_name": "HW32.Packed",
          "target": null
        },
        {
          "id": "Zpevdo.B",
          "display_name": "Zpevdo.B",
          "target": null
        },
        {
          "id": "Presenoker",
          "display_name": "Presenoker",
          "target": null
        },
        {
          "id": "SGeneric",
          "display_name": "SGeneric",
          "target": null
        },
        {
          "id": "GameHack.DOM",
          "display_name": "GameHack.DOM",
          "target": null
        },
        {
          "id": "BehavesLike.Ransom",
          "display_name": "BehavesLike.Ransom",
          "target": null
        },
        {
          "id": "CIL.StupidCryptor",
          "display_name": "CIL.StupidCryptor",
          "target": null
        },
        {
          "id": "Gen:Heur.Ransom.MSIL",
          "display_name": "Gen:Heur.Ransom.MSIL",
          "target": null
        },
        {
          "id": "Black.Gen2",
          "display_name": "Black.Gen2",
          "target": null
        },
        {
          "id": "GameHack.CRS",
          "display_name": "GameHack.CRS",
          "target": null
        },
        {
          "id": "Trojan.HTML.PHISH",
          "display_name": "Trojan.HTML.PHISH",
          "target": null
        },
        {
          "id": "Gen:Heur.MSIL.Inject",
          "display_name": "Gen:Heur.MSIL.Inject",
          "target": null
        },
        {
          "id": "Program.Unwanted",
          "display_name": "Program.Unwanted",
          "target": null
        },
        {
          "id": "HEUR/QVM42.3.72EB.Malware",
          "display_name": "HEUR/QVM42.3.72EB.Malware",
          "target": null
        },
        {
          "id": "suspicious.low.ml",
          "display_name": "suspicious.low.ml",
          "target": null
        },
        {
          "id": "JS:Trojan.Cryxos",
          "display_name": "JS:Trojan.Cryxos",
          "target": null
        },
        {
          "id": "Suspicious_GEN.F47V0520",
          "display_name": "Suspicious_GEN.F47V0520",
          "target": null
        },
        {
          "id": "Dropper.Trojan.Generic",
          "display_name": "Dropper.Trojan.Generic",
          "target": null
        },
        {
          "id": "Trojan.TrickBot",
          "display_name": "Trojan.TrickBot",
          "target": null
        },
        {
          "id": "Malware.Tk.Generic",
          "display_name": "Malware.Tk.Generic",
          "target": null
        },
        {
          "id": "TrojanSpy.Java",
          "display_name": "TrojanSpy.Java",
          "target": null
        },
        {
          "id": "Riskware.NetFilter",
          "display_name": "Riskware.NetFilter",
          "target": null
        },
        {
          "id": "RiskWare.Crack",
          "display_name": "RiskWare.Crack",
          "target": null
        },
        {
          "id": "BehavesLike.Exploit",
          "display_name": "BehavesLike.Exploit",
          "target": null
        },
        {
          "id": "Gen:NN.ZemsilF.34128",
          "display_name": "Gen:NN.ZemsilF.34128",
          "target": null
        },
        {
          "id": "Wacapew.C",
          "display_name": "Wacapew.C",
          "target": null
        },
        {
          "id": "Trojan.Malware.121218",
          "display_name": "Trojan.Malware.121218",
          "target": null
        },
        {
          "id": "RiskWare.HackTool.Agent",
          "display_name": "RiskWare.HackTool.Agent",
          "target": null
        },
        {
          "id": "Artemis",
          "display_name": "Artemis",
          "target": null
        },
        {
          "id": "Trojan.Generic",
          "display_name": "Trojan.Generic",
          "target": null
        },
        {
          "id": "W32.Trojan",
          "display_name": "W32.Trojan",
          "target": null
        },
        {
          "id": "BScope.Riskware",
          "display_name": "BScope.Riskware",
          "target": null
        },
        {
          "id": "Gen:Variant.Bulz",
          "display_name": "Gen:Variant.Bulz",
          "target": null
        },
        {
          "id": "Ransom:Win32/CVE-2017-0147",
          "display_name": "Ransom:Win32/CVE-2017-0147",
          "target": "/malware/Ransom:Win32/CVE-2017-0147"
        },
        {
          "id": "Virus.Ramnit",
          "display_name": "Virus.Ramnit",
          "target": null
        },
        {
          "id": "Virus.Virut",
          "display_name": "Virus.Virut",
          "target": null
        },
        {
          "id": "Adware.KuziTui",
          "display_name": "Adware.KuziTui",
          "target": null
        },
        {
          "id": "AGEN.1141126",
          "display_name": "AGEN.1141126",
          "target": null
        },
        {
          "id": "W32.AIDetect",
          "display_name": "W32.AIDetect",
          "target": null
        },
        {
          "id": "Trojan.Python",
          "display_name": "Trojan.Python",
          "target": null
        },
        {
          "id": "W32.AIDetectVM",
          "display_name": "W32.AIDetectVM",
          "target": null
        },
        {
          "id": "Suspicious.Save",
          "display_name": "Suspicious.Save",
          "target": null
        },
        {
          "id": "Adware.Downware",
          "display_name": "Adware.Downware",
          "target": null
        },
        {
          "id": "Ransom.Win64.Wacatac.oa",
          "display_name": "Ransom.Win64.Wacatac.oa",
          "target": null
        },
        {
          "id": "OpenSubtitles.A",
          "display_name": "OpenSubtitles.A",
          "target": null
        },
        {
          "id": "VB.EmoDldr.4",
          "display_name": "VB.EmoDldr.4",
          "target": null
        },
        {
          "id": "Gen:Variant.Midie",
          "display_name": "Gen:Variant.Midie",
          "target": null
        },
        {
          "id": "HEUR/QVM41.2.DA9B.Malware",
          "display_name": "HEUR/QVM41.2.DA9B.Malware",
          "target": null
        },
        {
          "id": "Gen:Variant.Sirefef",
          "display_name": "Gen:Variant.Sirefef",
          "target": null
        },
        {
          "id": "Macro.Trojan.Dropperd",
          "display_name": "Macro.Trojan.Dropperd",
          "target": null
        },
        {
          "id": "BlackNET RAT",
          "display_name": "BlackNET RAT",
          "target": null
        },
        {
          "id": "Gen:Variant.Ursu",
          "display_name": "Gen:Variant.Ursu",
          "target": null
        },
        {
          "id": "Redcap.rlhse",
          "display_name": "Redcap.rlhse",
          "target": null
        },
        {
          "id": "Trojan.Trickster",
          "display_name": "Trojan.Trickster",
          "target": null
        },
        {
          "id": "HTML_REDIR.SMR",
          "display_name": "HTML_REDIR.SMR",
          "target": null
        },
        {
          "id": "TROJ_FRS.VSNTFK19",
          "display_name": "TROJ_FRS.VSNTFK19",
          "target": null
        },
        {
          "id": "Hoax.JS.Phish",
          "display_name": "Hoax.JS.Phish",
          "target": null
        },
        {
          "id": "JS:Iframe",
          "display_name": "JS:Iframe",
          "target": null
        },
        {
          "id": "Application.SQLCrack",
          "display_name": "Application.SQLCrack",
          "target": null
        },
        {
          "id": "susp.lnk",
          "display_name": "susp.lnk",
          "target": null
        },
        {
          "id": "QVM201.0.B70B.Malware",
          "display_name": "QVM201.0.B70B.Malware",
          "target": null
        },
        {
          "id": "Immortal Stealer",
          "display_name": "Immortal Stealer",
          "target": null
        },
        {
          "id": "WebMonitor RAT",
          "display_name": "WebMonitor RAT",
          "target": null
        },
        {
          "id": "Tor - S0183",
          "display_name": "Tor - S0183",
          "target": null
        },
        {
          "id": "WannaCry",
          "display_name": "WannaCry",
          "target": null
        },
        {
          "id": "WannaCryptor",
          "display_name": "WannaCryptor",
          "target": null
        },
        {
          "id": "WebToolbar",
          "display_name": "WebToolbar",
          "target": null
        },
        {
          "id": "BlackNET",
          "display_name": "BlackNET",
          "target": null
        },
        {
          "id": "DeepScan:Generic.Ransom.GandCrab5",
          "display_name": "DeepScan:Generic.Ransom.GandCrab5",
          "target": null
        },
        {
          "id": "TrojanSpy",
          "display_name": "TrojanSpy",
          "target": null
        },
        {
          "id": "States",
          "display_name": "States",
          "target": null
        },
        {
          "id": "Inmortal",
          "display_name": "Inmortal",
          "target": null
        },
        {
          "id": "Domains",
          "display_name": "Domains",
          "target": null
        },
        {
          "id": "Locky",
          "display_name": "Locky",
          "target": null
        },
        {
          "id": "Delf.NBX",
          "display_name": "Delf.NBX",
          "target": null
        },
        {
          "id": "Gen:NN.ZexaF.32515",
          "display_name": "Gen:NN.ZexaF.32515",
          "target": null
        },
        {
          "id": "FileRepMalware",
          "display_name": "FileRepMalware",
          "target": null
        },
        {
          "id": "Gen:Variant.MSILPerseus",
          "display_name": "Gen:Variant.MSILPerseus",
          "target": null
        },
        {
          "id": "Icefog",
          "display_name": "Icefog",
          "target": null
        },
        {
          "id": "$WebWatson",
          "display_name": "$WebWatson",
          "target": null
        },
        {
          "id": "Agent.AIK.gen",
          "display_name": "Agent.AIK.gen",
          "target": null
        },
        {
          "id": "Agent.AIK.genCIL.StupidCryptor",
          "display_name": "Agent.AIK.genCIL.StupidCryptor",
          "target": null
        },
        {
          "id": "Agent.YPEZ",
          "display_name": "Agent.YPEZ",
          "target": null
        },
        {
          "id": "Application.InnovativSol",
          "display_name": "Application.InnovativSol",
          "target": null
        },
        {
          "id": "Agent.ASO",
          "display_name": "Agent.ASO",
          "target": null
        },
        {
          "id": "S-b748adc5",
          "display_name": "S-b748adc5",
          "target": null
        },
        {
          "id": "W32.eHeur",
          "display_name": "W32.eHeur",
          "target": null
        },
        {
          "id": "Kryptik.GUCB",
          "display_name": "Kryptik.GUCB",
          "target": null
        },
        {
          "id": "AgentTesla",
          "display_name": "AgentTesla",
          "target": null
        },
        {
          "id": "Autoit.bimwt",
          "display_name": "Autoit.bimwt",
          "target": null
        },
        {
          "id": "HEUR:Trojan.OLE2.Alien",
          "display_name": "HEUR:Trojan.OLE2.Alien",
          "target": null
        },
        {
          "id": "AGEN.1038489",
          "display_name": "AGEN.1038489",
          "target": null
        },
        {
          "id": "Gen:Variant.Ser.Strictor",
          "display_name": "Gen:Variant.Ser.Strictor",
          "target": null
        },
        {
          "id": "Packed.Themida.Gen",
          "display_name": "Packed.Themida.Gen",
          "target": null
        },
        {
          "id": "AGEN.1043164",
          "display_name": "AGEN.1043164",
          "target": null
        },
        {
          "id": "TrickBot - S0266",
          "display_name": "TrickBot - S0266",
          "target": null
        },
        {
          "id": "Emotet",
          "display_name": "Emotet",
          "target": null
        },
        {
          "id": "Trojan.PornoAsset",
          "display_name": "Trojan.PornoAsset",
          "target": null
        },
        {
          "id": "Ransom.Win64.PORNOASSET.SM1",
          "display_name": "Ransom.Win64.PORNOASSET.SM1",
          "target": null
        },
        {
          "id": "Gen:Variant.Ulise",
          "display_name": "Gen:Variant.Ulise",
          "target": null
        },
        {
          "id": "Trojan.Win64",
          "display_name": "Trojan.Win64",
          "target": null
        },
        {
          "id": "Dropper.Trojan.Agent",
          "display_name": "Dropper.Trojan.Agent",
          "target": null
        },
        {
          "id": "Heur.BZC.YAX.Pantera.10",
          "display_name": "Heur.BZC.YAX.Pantera.10",
          "target": null
        },
        {
          "id": "malicious.high.ml",
          "display_name": "malicious.high.ml",
          "target": null
        },
        {
          "id": "CVE-2015-1650",
          "display_name": "CVE-2015-1650",
          "target": null
        },
        {
          "id": "Worm.Win64.AutoRun",
          "display_name": "Worm.Win64.AutoRun",
          "target": null
        },
        {
          "id": "AIT.Heur.Cottonmouth.8.78F19BD7",
          "display_name": "AIT.Heur.Cottonmouth.8.78F19BD7",
          "target": null
        },
        {
          "id": "Gen:Variant.Mikey",
          "display_name": "Gen:Variant.Mikey",
          "target": null
        },
        {
          "id": "Trojan.Agent",
          "display_name": "Trojan.Agent",
          "target": null
        },
        {
          "id": "Pua.Gen",
          "display_name": "Pua.Gen",
          "target": null
        },
        {
          "id": "Trojan.Downloader.Generic",
          "display_name": "Trojan.Downloader.Generic",
          "target": null
        },
        {
          "id": "Suspected of Trojan.Downloader.gen",
          "display_name": "Suspected of Trojan.Downloader.gen",
          "target": null
        },
        {
          "id": "HEUR:RemoteAdmin.Generic",
          "display_name": "HEUR:RemoteAdmin.Generic",
          "target": null
        },
        {
          "id": "Gen:Heur.Ransom.HiddenTears",
          "display_name": "Gen:Heur.Ransom.HiddenTears",
          "target": null
        },
        {
          "id": "Nemucod.A",
          "display_name": "Nemucod.A",
          "target": null
        },
        {
          "id": "Backdoor.Hupigon",
          "display_name": "Backdoor.Hupigon",
          "target": null
        },
        {
          "id": "Trojan.Starter JS.Iframe",
          "display_name": "Trojan.Starter JS.Iframe",
          "target": null
        },
        {
          "id": "fake ,promethiumm ,strongpity",
          "display_name": "fake ,promethiumm ,strongpity",
          "target": null
        },
        {
          "id": "PUA.Reg1staid",
          "display_name": "PUA.Reg1staid",
          "target": null
        },
        {
          "id": "Malware.Heur_Generic.A",
          "display_name": "Malware.Heur_Generic.A",
          "target": null
        },
        {
          "id": "Bladabindi.Q",
          "display_name": "Bladabindi.Q",
          "target": null
        },
        {
          "id": "W32.eHeur",
          "display_name": "W32.eHeur",
          "target": null
        },
        {
          "id": "malicious.6e0700",
          "display_name": "malicious.6e0700",
          "target": null
        },
        {
          "id": "Trojan.Inject",
          "display_name": "Trojan.Inject",
          "target": null
        },
        {
          "id": "TSGeneric",
          "display_name": "TSGeneric",
          "target": null
        },
        {
          "id": "RedCap.vneda",
          "display_name": "RedCap.vneda",
          "target": null
        },
        {
          "id": "Trojan.Indiloadz",
          "display_name": "Trojan.Indiloadz",
          "target": null
        },
        {
          "id": "Trojan.Ekstak",
          "display_name": "Trojan.Ekstak",
          "target": null
        },
        {
          "id": "staticrr.paleokits.net",
          "display_name": "staticrr.paleokits.net",
          "target": null
        },
        {
          "id": "MSIL.Downloader",
          "display_name": "MSIL.Downloader",
          "target": null
        },
        {
          "id": "Trojan.Autoruns.GenericKDS",
          "display_name": "Trojan.Autoruns.GenericKDS",
          "target": null
        },
        {
          "id": "MSIL.Trojan.BSE",
          "display_name": "MSIL.Trojan.BSE",
          "target": null
        },
        {
          "id": "Adload.AD81",
          "display_name": "Adload.AD81",
          "target": null
        },
        {
          "id": "Packed.Asprotect",
          "display_name": "Packed.Asprotect",
          "target": null
        },
        {
          "id": "Gen:NN.ZemsilF.34062",
          "display_name": "Gen:NN.ZemsilF.34062",
          "target": null
        },
        {
          "id": "Evo",
          "display_name": "Evo",
          "target": null
        },
        {
          "id": "Agent.pwc",
          "display_name": "Agent.pwc",
          "target": null
        },
        {
          "id": "RiskTool.Phpw",
          "display_name": "RiskTool.Phpw",
          "target": null
        },
        {
          "id": "Gen:Variant.Symmi",
          "display_name": "Gen:Variant.Symmi",
          "target": null
        },
        {
          "id": "Trojan.PWS",
          "display_name": "Trojan.PWS",
          "target": null
        },
        {
          "id": "Generic.BitCoinMiner.3",
          "display_name": "Generic.BitCoinMiner.3",
          "target": null
        },
        {
          "id": "Trojan.Tasker",
          "display_name": "Trojan.Tasker",
          "target": null
        },
        {
          "id": "Gen:NN",
          "display_name": "Gen:NN",
          "target": null
        },
        {
          "id": "Downloader.CertutilURLCache",
          "display_name": "Downloader.CertutilURLCache",
          "target": null
        },
        {
          "id": "Elf",
          "display_name": "Elf",
          "target": null
        },
        {
          "id": "Gen:Heur.MSIL.Androm",
          "display_name": "Gen:Heur.MSIL.Androm",
          "target": null
        },
        {
          "id": "Kryptik.NRD",
          "display_name": "Kryptik.NRD",
          "target": null
        },
        {
          "id": "Riskware",
          "display_name": "Riskware",
          "target": null
        },
        {
          "id": "Kuluoz.B.gen",
          "display_name": "Kuluoz.B.gen",
          "target": null
        },
        {
          "id": "Gen:Variant.RevengeRat",
          "display_name": "Gen:Variant.RevengeRat",
          "target": null
        },
        {
          "id": "Gen:Variant.Mikey",
          "display_name": "Gen:Variant.Mikey",
          "target": null
        },
        {
          "id": "VB.Chronos.7",
          "display_name": "VB.Chronos.7",
          "target": null
        },
        {
          "id": "Kryptik.NOE",
          "display_name": "Kryptik.NOE",
          "target": null
        },
        {
          "id": "HEUR:WebToolbar.Generic",
          "display_name": "HEUR:WebToolbar.Generic",
          "target": null
        },
        {
          "id": "Gen:Variant.Barys",
          "display_name": "Gen:Variant.Barys",
          "target": null
        },
        {
          "id": "Backdoor.Xtreme",
          "display_name": "Backdoor.Xtreme",
          "target": null
        },
        {
          "id": "Trojan.MSIL",
          "display_name": "Trojan.MSIL",
          "target": null
        },
        {
          "id": "Gen:Variant.Graftor",
          "display_name": "Gen:Variant.Graftor",
          "target": null
        },
        {
          "id": "Backdoor.Agent",
          "display_name": "Backdoor.Agent",
          "target": null
        },
        {
          "id": "Unsafe",
          "display_name": "Unsafe",
          "target": null
        },
        {
          "id": "Trojan.PHP.Agent",
          "display_name": "Trojan.PHP.Agent",
          "target": null
        },
        {
          "id": "Trojan.Agent",
          "display_name": "Trojan.Agent",
          "target": null
        },
        {
          "id": "HEUR:Exploit.Generic",
          "display_name": "HEUR:Exploit.Generic",
          "target": null
        },
        {
          "id": "Ransom_WCRY.SMALYM",
          "display_name": "Ransom_WCRY.SMALYM",
          "target": null
        },
        {
          "id": "Ransom_WCRY.SMJ",
          "display_name": "Ransom_WCRY.SMJ",
          "target": null
        },
        {
          "id": "Auslogics",
          "display_name": "Auslogics",
          "target": null
        },
        {
          "id": "Gen:Variant.Jaiko",
          "display_name": "Gen:Variant.Jaiko",
          "target": null
        },
        {
          "id": "Exploit.W32.Agent",
          "display_name": "Exploit.W32.Agent",
          "target": null
        },
        {
          "id": "Trojan.Cud.Gen",
          "display_name": "Trojan.Cud.Gen",
          "target": null
        },
        {
          "id": "Trojan.DOC.Downloader",
          "display_name": "Trojan.DOC.Downloader",
          "target": null
        },
        {
          "id": "Backdoor.MSIL.Agent",
          "display_name": "Backdoor.MSIL.Agent",
          "target": null
        },
        {
          "id": "Gen:Trojan.Heur2.LPTbHW@W64.HfsAutoB",
          "display_name": "Gen:Trojan.Heur2.LPTbHW@W64.HfsAutoB",
          "target": null
        },
        {
          "id": "Gen:Variant.Kazy",
          "display_name": "Gen:Variant.Kazy",
          "target": null
        },
        {
          "id": "Gen:Variant.Zusy",
          "display_name": "Gen:Variant.Zusy",
          "target": null
        },
        {
          "id": "Ransom.WannaCrypt",
          "display_name": "Ransom.WannaCrypt",
          "target": null
        },
        {
          "id": "Generic.ServStart.A",
          "display_name": "Generic.ServStart.A",
          "target": null
        },
        {
          "id": "Trojan.Wanna",
          "display_name": "Trojan.Wanna",
          "target": null
        },
        {
          "id": "Generic.MSIL.Bladabindi",
          "display_name": "Generic.MSIL.Bladabindi",
          "target": null
        },
        {
          "id": "TROJ_GEN.R002C0OG518",
          "display_name": "TROJ_GEN.R002C0OG518",
          "target": null
        },
        {
          "id": "Trojan.Chapak",
          "display_name": "Trojan.Chapak",
          "target": null
        },
        {
          "id": "Indiloadz.BB",
          "display_name": "Indiloadz.BB",
          "target": null
        },
        {
          "id": "BehavBehavesLike.PUPXBI",
          "display_name": "BehavBehavesLike.PUPXBI",
          "target": null
        },
        {
          "id": "DeepScan:Generic.SpyAgent.6",
          "display_name": "DeepScan:Generic.SpyAgent.6",
          "target": null
        },
        {
          "id": "Python.KeyLogger",
          "display_name": "Python.KeyLogger",
          "target": null
        },
        {
          "id": "GameHack.CRS",
          "display_name": "GameHack.CRS",
          "target": null
        },
        {
          "id": "Generic.MSIL.PasswordStealer",
          "display_name": "Generic.MSIL.PasswordStealer",
          "target": null
        },
        {
          "id": "PSW.Agent",
          "display_name": "PSW.Agent",
          "target": null
        },
        {
          "id": "malicious.8c45ba",
          "display_name": "malicious.8c45ba",
          "target": null
        },
        {
          "id": "Dropper.Binder",
          "display_name": "Dropper.Binder",
          "target": null
        },
        {
          "id": "Constructor.MSIL",
          "display_name": "Constructor.MSIL",
          "target": null
        },
        {
          "id": "Linux.Agent",
          "display_name": "Linux.Agent",
          "target": null
        },
        {
          "id": "Virus.3DMax.Script",
          "display_name": "Virus.3DMax.Script",
          "target": null
        },
        {
          "id": "ScrInject.B",
          "display_name": "ScrInject.B",
          "target": null
        },
        {
          "id": "Trojan.WisdomEyes.16070401.9500",
          "display_name": "Trojan.WisdomEyes.16070401.9500",
          "target": null
        },
        {
          "id": "Application.SearchProtect",
          "display_name": "Application.SearchProtect",
          "target": null
        },
        {
          "id": "JS:Trojan.Clicker",
          "display_name": "JS:Trojan.Clicker",
          "target": null
        },
        {
          "id": "Faceliker.A",
          "display_name": "Faceliker.A",
          "target": null
        },
        {
          "id": "JS:Trojan.JS.Faceliker",
          "display_name": "JS:Trojan.JS.Faceliker",
          "target": null
        },
        {
          "id": "Constructor.MSIL  Linux.Agent",
          "display_name": "Constructor.MSIL  Linux.Agent",
          "target": null
        },
        {
          "id": "PowerShell.Trojan",
          "display_name": "PowerShell.Trojan",
          "target": null
        },
        {
          "id": "HTML:Script",
          "display_name": "HTML:Script",
          "target": null
        },
        {
          "id": "ScrInject.B",
          "display_name": "ScrInject.B",
          "target": null
        },
        {
          "id": "W32.AIDetectVM",
          "display_name": "W32.AIDetectVM",
          "target": null
        },
        {
          "id": "HackTool.CheatEngine",
          "display_name": "HackTool.CheatEngine",
          "target": null
        },
        {
          "id": "Injector.CLDS",
          "display_name": "Injector.CLDS",
          "target": null
        },
        {
          "id": "VB.Downloader.2",
          "display_name": "VB.Downloader.2",
          "target": null
        },
        {
          "id": "malicious.3e78cc",
          "display_name": "malicious.3e78cc",
          "target": null
        },
        {
          "id": "malicious.d800d6",
          "display_name": "malicious.d800d6",
          "target": null
        },
        {
          "id": "VB.PwShell.2",
          "display_name": "VB.PwShell.2",
          "target": null
        },
        {
          "id": "Backdoor.RBot",
          "display_name": "Backdoor.RBot",
          "target": null
        },
        {
          "id": "malicious.71b1a8",
          "display_name": "malicious.71b1a8",
          "target": null
        },
        {
          "id": "TrojanSpy.KeyLogger",
          "display_name": "TrojanSpy.KeyLogger",
          "target": null
        },
        {
          "id": "Injector.JDO",
          "display_name": "Injector.JDO",
          "target": null
        },
        {
          "id": "Heur.Msword.Gen",
          "display_name": "Heur.Msword.Gen",
          "target": null
        },
        {
          "id": "PSW.Discord",
          "display_name": "PSW.Discord",
          "target": null
        },
        {
          "id": "Packed.VMProtect",
          "display_name": "Packed.VMProtect",
          "target": null
        },
        {
          "id": "HEUR:AdWare.StartSurf",
          "display_name": "HEUR:AdWare.StartSurf",
          "target": null
        },
        {
          "id": "Gen:Heur.NoobyProtect",
          "display_name": "Gen:Heur.NoobyProtect",
          "target": null
        },
        {
          "id": "CIL.HeapOverride",
          "display_name": "CIL.HeapOverride",
          "target": null
        },
        {
          "id": "HEUR:Trojan.Tasker",
          "display_name": "HEUR:Trojan.Tasker",
          "target": null
        },
        {
          "id": "XLM.Trojan.Abracadabra.27",
          "display_name": "XLM.Trojan.Abracadabra.27",
          "target": null
        },
        {
          "id": "HEUR:Backdoor.MSIL.NanoBot",
          "display_name": "HEUR:Backdoor.MSIL.NanoBot",
          "target": null
        },
        {
          "id": "Trojan.PSW.Mimikatz",
          "display_name": "Trojan.PSW.Mimikatz",
          "target": null
        },
        {
          "id": "TrojanSpy.Python",
          "display_name": "TrojanSpy.Python",
          "target": null
        },
        {
          "id": "Trojan.Ole2.Vbs",
          "display_name": "Trojan.Ole2.Vbs",
          "target": null
        },
        {
          "id": "Exploit.MSOffice",
          "display_name": "Exploit.MSOffice",
          "target": null
        },
        {
          "id": "DeepScan:Generic.Ransom.AmnesiaE",
          "display_name": "DeepScan:Generic.Ransom.AmnesiaE",
          "target": null
        },
        {
          "id": "Wacatac.D6",
          "display_name": "Wacatac.D6",
          "target": null
        },
        {
          "id": "Backdoor.Androm",
          "display_name": "Backdoor.Androm",
          "target": null
        },
        {
          "id": "Packed.NetSeal",
          "display_name": "Packed.NetSeal",
          "target": null
        },
        {
          "id": "Trojan.MSIL.Injector",
          "display_name": "Trojan.MSIL.Injector",
          "target": null
        },
        {
          "id": "Trojan.PWS.Agent",
          "display_name": "Trojan.PWS.Agent",
          "target": null
        },
        {
          "id": "TScope.Trojan",
          "display_name": "TScope.Trojan",
          "target": null
        },
        {
          "id": "PSW.Stealer",
          "display_name": "PSW.Stealer",
          "target": null
        },
        {
          "id": "Trojan.PackedNET",
          "display_name": "Trojan.PackedNET",
          "target": null
        },
        {
          "id": "Trojan.Java",
          "display_name": "Trojan.Java",
          "target": null
        },
        {
          "id": "MalwareX",
          "display_name": "MalwareX",
          "target": null
        },
        {
          "id": "Trojan.PSW.Python",
          "display_name": "Trojan.PSW.Python",
          "target": null
        },
        {
          "id": "malicious.11abfc",
          "display_name": "malicious.11abfc",
          "target": null
        },
        {
          "id": "Generic.ASMalwS",
          "display_name": "Generic.ASMalwS",
          "target": null
        },
        {
          "id": "HEUR:Trojan.MSIL.Tasker",
          "display_name": "HEUR:Trojan.MSIL.Tasker",
          "target": null
        },
        {
          "id": "PossibleThreat.PALLAS",
          "display_name": "PossibleThreat.PALLAS",
          "target": null
        },
        {
          "id": "Backdoor.Poison",
          "display_name": "Backdoor.Poison",
          "target": null
        },
        {
          "id": "Generic.MSIL.LimeRAT",
          "display_name": "Generic.MSIL.LimeRAT",
          "target": null
        },
        {
          "id": "PWS-FCZZ",
          "display_name": "PWS-FCZZ",
          "target": null
        },
        {
          "id": "Trojan.Script",
          "display_name": "Trojan.Script",
          "target": null
        },
        {
          "id": "Gen:Heur.MSIL.Inject",
          "display_name": "Gen:Heur.MSIL.Inject",
          "target": null
        },
        {
          "id": "Trojan.PWS.Growtopia",
          "display_name": "Trojan.PWS.Growtopia",
          "target": null
        },
        {
          "id": "Spyware.Bobik",
          "display_name": "Spyware.Bobik",
          "target": null
        },
        {
          "id": "HackTool.BruteForce",
          "display_name": "HackTool.BruteForce",
          "target": null
        },
        {
          "id": "Hack.Patcher",
          "display_name": "Hack.Patcher",
          "target": null
        },
        {
          "id": "PWS.p",
          "display_name": "PWS.p",
          "target": null
        },
        {
          "id": "Suppobox",
          "display_name": "Suppobox",
          "target": null
        },
        {
          "id": "index.php",
          "display_name": "index.php",
          "target": null
        },
        {
          "id": "Packed.VMProtect",
          "display_name": "Packed.VMProtect",
          "target": null
        },
        {
          "id": "SmokeLoader",
          "display_name": "SmokeLoader",
          "target": null
        },
        {
          "id": "Generic.Malware",
          "display_name": "Generic.Malware",
          "target": null
        },
        {
          "id": "SNH:Script [Dropper]",
          "display_name": "SNH:Script [Dropper]",
          "target": null
        },
        {
          "id": "HEUR:Trojan.MSOffice.SAgent",
          "display_name": "HEUR:Trojan.MSOffice.SAgent",
          "target": null
        },
        {
          "id": "Script.INF",
          "display_name": "Script.INF",
          "target": null
        },
        {
          "id": "JS:Trojan.JS.Likejack",
          "display_name": "JS:Trojan.JS.Likejack",
          "target": null
        },
        {
          "id": "SNH:Script [Dropper]",
          "display_name": "SNH:Script [Dropper]",
          "target": null
        },
        {
          "id": "Trojan.JS.Agent",
          "display_name": "Trojan.JS.Agent",
          "target": null
        },
        {
          "id": "APT Notes",
          "display_name": "APT Notes",
          "target": null
        },
        {
          "id": "susp.rtf.objupdate",
          "display_name": "susp.rtf.objupdate",
          "target": null
        },
        {
          "id": "RedCap.zoohz",
          "display_name": "RedCap.zoohz",
          "target": null
        },
        {
          "id": "Trojan.Tasker",
          "display_name": "Trojan.Tasker",
          "target": null
        },
        {
          "id": "virus.office.qexvmc",
          "display_name": "virus.office.qexvmc",
          "target": null
        },
        {
          "id": "Trojan.KillProc",
          "display_name": "Trojan.KillProc",
          "target": null
        },
        {
          "id": "Generic.MSIL.GrwtpStealer.1",
          "display_name": "Generic.MSIL.GrwtpStealer.1",
          "target": null
        },
        {
          "id": "Suspicious.Cloud",
          "display_name": "Suspicious.Cloud",
          "target": null
        },
        {
          "id": "PowerShell.DownLoader",
          "display_name": "PowerShell.DownLoader",
          "target": null
        },
        {
          "id": "Downldr.gen",
          "display_name": "Downldr.gen",
          "target": null
        },
        {
          "id": "AGEN.1030939",
          "display_name": "AGEN.1030939",
          "target": null
        },
        {
          "id": "HackTool.Binder",
          "display_name": "HackTool.Binder",
          "target": null
        },
        {
          "id": "Trojan.Inject",
          "display_name": "Trojan.Inject",
          "target": null
        },
        {
          "id": "Dldr.Agent",
          "display_name": "Dldr.Agent",
          "target": null
        },
        {
          "id": "Dropper.MSIL",
          "display_name": "Dropper.MSIL",
          "target": null
        },
        {
          "id": "Trojan.VBKryjetor",
          "display_name": "Trojan.VBKryjetor",
          "target": null
        },
        {
          "id": "PWSX",
          "display_name": "PWSX",
          "target": null
        },
        {
          "id": "VB:Trojan.VBA.Agent",
          "display_name": "VB:Trojan.VBA.Agent",
          "target": null
        },
        {
          "id": "HEUR:Trojan.MSOffice.Stratos",
          "display_name": "HEUR:Trojan.MSOffice.Stratos",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1071.001",
          "name": "Web Protocols",
          "display_name": "T1071.001 - Web Protocols"
        },
        {
          "id": "T1071.004",
          "name": "DNS",
          "display_name": "T1071.004 - DNS"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1059.007",
          "name": "JavaScript",
          "display_name": "T1059.007 - JavaScript"
        },
        {
          "id": "T1497",
          "name": "Virtualization/Sandbox Evasion",
          "display_name": "T1497 - Virtualization/Sandbox Evasion"
        },
        {
          "id": "T1068",
          "name": "Exploitation for Privilege Escalation",
          "display_name": "T1068 - Exploitation for Privilege Escalation"
        },
        {
          "id": "TA0029",
          "name": "Privilege Escalation",
          "display_name": "TA0029 - Privilege Escalation"
        },
        {
          "id": "T1449",
          "name": "Exploit SS7 to Redirect Phone Calls/SMS",
          "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
        },
        {
          "id": "T1190",
          "name": "Exploit Public-Facing Application",
          "display_name": "T1190 - Exploit Public-Facing Application"
        },
        {
          "id": "T1210",
          "name": "Exploitation of Remote Services",
          "display_name": "T1210 - Exploitation of Remote Services"
        },
        {
          "id": "T1450",
          "name": "Exploit SS7 to Track Device Location",
          "display_name": "T1450 - Exploit SS7 to Track Device Location"
        },
        {
          "id": "T1211",
          "name": "Exploitation for Defense Evasion",
          "display_name": "T1211 - Exploitation for Defense Evasion"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "TA0011",
          "name": "Command and Control",
          "display_name": "TA0011 - Command and Control"
        },
        {
          "id": "T1412",
          "name": "Capture SMS Messages",
          "display_name": "T1412 - Capture SMS Messages"
        },
        {
          "id": "T1454",
          "name": "Malicious SMS Message",
          "display_name": "T1454 - Malicious SMS Message"
        },
        {
          "id": "T1001",
          "name": "Data Obfuscation",
          "display_name": "T1001 - Data Obfuscation"
        },
        {
          "id": "T1114",
          "name": "Email Collection",
          "display_name": "T1114 - Email Collection"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1498",
          "name": "Network Denial of Service",
          "display_name": "T1498 - Network Denial of Service"
        },
        {
          "id": "T1496",
          "name": "Resource Hijacking",
          "display_name": "T1496 - Resource Hijacking"
        },
        {
          "id": "T1176",
          "name": "Browser Extensions",
          "display_name": "T1176 - Browser Extensions"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 338,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 1184,
        "FileHash-SHA1": 949,
        "FileHash-SHA256": 3712,
        "URL": 2925,
        "domain": 627,
        "hostname": 1319,
        "CVE": 26,
        "email": 8,
        "CIDR": 2
      },
      "indicator_count": 10752,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 223,
      "modified_text": "904 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "654c606d74f82e547c77ad89",
      "name": "Ransom.Win64.PORNOASSET.SM1 | DeepScan:Generic.Ransom.GandCrab5",
      "description": "Ransom.Win64.PORNOASSET.SM1 DeepScan:Generic.Ransom.GandCrab5\nBlackNET RAT $WebWatson\nAuto generated results from a variety of tools.",
      "modified": "2023-12-09T03:01:57.989000",
      "created": "2023-11-09T04:30:37.089000",
      "tags": [
        "ssl certificate",
        "historical ssl",
        "communicating",
        "contacted",
        "resolutions",
        "whois record",
        "whois whois",
        "whois parent",
        "whois siblings",
        "skynet",
        "threat report",
        "ip summary",
        "url summary",
        "summary",
        "sample",
        "samples",
        "detection list",
        "blacklist",
        "cisco umbrella",
        "site",
        "safe site",
        "million",
        "team",
        "microsoft",
        "back",
        "download",
        "phishing",
        "union",
        "bank",
        "malicious site",
        "blacklist http",
        "exit",
        "traffic",
        "node tcp",
        "tor known",
        "tor relayrouter",
        "et tor",
        "known tor",
        "relayrouter",
        "anonymizer",
        "spammer",
        "malware",
        "dropped",
        "unlocker",
        "http",
        "critical risk",
        "redline stealer",
        "core",
        "hacktool",
        "execution",
        "type win32",
        "exe size",
        "first seen",
        "file name",
        "avast win32",
        "win32",
        "avg win32",
        "fortinet",
        "vitro",
        "mb first",
        "rmndrp",
        "clean mx",
        "undetected dns8",
        "undetected vx",
        "sophos",
        "vault",
        "zdb zeus",
        "cmc threat",
        "snort ip",
        "feodo tracker",
        "cybereason",
        "send bug",
        "pe yandex",
        "no data",
        "tag count",
        "count blacklist",
        "tag tag",
        "algorithm",
        "v3 serial",
        "number",
        "issuer",
        "cus cnr3",
        "olet",
        "subject public",
        "key info",
        "key algorithm",
        "key identifier",
        "first",
        "seen",
        "valid",
        "no na",
        "no no",
        "ip security",
        "cndst root",
        "ca x3",
        "ca id",
        "research group",
        "cnisrg root",
        "no expired",
        "mozilla",
        "android",
        "malicious red team",
        "tsara brashears",
        "cyber stalking",
        "malvertizing",
        "invasion of privacy",
        "threat",
        "adult content",
        "apple",
        "iphone unlocker",
        "android",
        "exploited spyware",
        "malware host",
        "brute force",
        "revenge-rat",
        "banker",
        "evasive",
        "domain",
        "redline",
        "stealer",
        "phishing",
        "ramnit",
        "unreliable subdomains",
        "dridex",
        "gating",
        "msil",
        "rat",
        "loki",
        "network",
        "hacking",
        "sinkhole",
        "azorult",
        "c2",
        "historicalandnew",
        "targeted attack",
        "puffstealer",
        "rultazo",
        "lokibot",
        "loki pws",
        "burkina",
        "banker,dde,dridex,exploit",
        "banker,dridex,evasive",
        "trickbot",
        "ransomware,torrentlocker",
        "exploit_source",
        "blacknet",
        "FileRepMalware",
        "linux agent",
        "blacknet",
        "ios",
        "phishing paypal",
        "tagging",
        "defacement",
        "hit",
        "bounty",
        "phishing site",
        "malware site",
        "malware download",
        "endangerment",
        "Malicious domain - SANS Internet Storm Center",
        "evasive,msil,rat,revenge-rat",
        "prism_setting",
        "prism_object",
        "static engine",
        "social engineering",
        "jansky",
        "worm",
        "network rat",
        "networm",
        "Loki Password Stealer (PWS)",
        "South Carolina Federal Credit Union phishing",
        "darkweb",
        "yandex",
        "redirectors",
        "blacknet threats",
        "phishing,ransomware,sinkhole",
        "wanacrypt0r,wannacry,wcry",
        "tor c++",
        "tor c++ client",
        "python user",
        "js user",
        "hacker",
        "hijacker",
        "heur",
        "maltiverse",
        "alexa top",
        "exploit",
        "riskware",
        "unsafe",
        "outbreak",
        "downer",
        "shell",
        "mediamagnet",
        "sality",
        "swrort",
        "adaptivebee",
        "unruy",
        "iobit",
        "dropper",
        "trojanx",
        "artemis",
        "installcore",
        "webshell",
        "crack",
        "webtoolbar",
        "search live",
        "api blog",
        "docs pricing",
        "november",
        "de indicators",
        "domains",
        "hashes",
        "__convergedlogin_pcustomizationloader_44b450e8d543eb53930d",
        "malicious url",
        "financial",
        "blacknet rat",
        "azorult",
        "stealer",
        "deep scan",
        "blacklist https",
        "referrer",
        "collections kp",
        "incident ip",
        "sneaky server",
        "replacement",
        "unauthorized",
        "emotet",
        "noname057",
        "generic malware",
        "engineering",
        "cyber threat",
        "facebook",
        "paypal",
        "dropbox",
        "united",
        "america",
        "banking",
        "wells fargo",
        "steam",
        "twitter",
        "sliver",
        "daum",
        "swift",
        "runescape",
        "betabot",
        "district",
        "iframe",
        "alexa",
        "downldr",
        "agent",
        "presenoker",
        "bladabindi",
        "live",
        "conduit",
        "pony",
        "covid19",
        "malicious",
        "cobalt strike",
        "suppobox",
        "ramnit",
        "meterpreter",
        "virut",
        "njrat",
        "pykspa",
        "asyncrat",
        "downloader",
        "fakealert",
        "binder",
        "virustotal",
        "formbook",
        "necurs",
        "trojan",
        "msil",
        "hiloti",
        "vawtrak",
        "simda",
        "kraken",
        "solimba",
        "icedid",
        "redirector",
        "suspic",
        "amadey",
        "raccoon",
        "nanocore rat",
        "revenge rat",
        "genkryptik",
        "fuery",
        "wacatac",
        "service",
        "cloudeye",
        "tinba",
        "domaiq",
        "ave maria",
        "zeus",
        "ransomware",
        "zbot",
        "generic",
        "trojanspy",
        "states",
        "inmortal",
        "locky",
        "strike",
        "china cobalt",
        "keybase",
        "cutwail",
        "citadel",
        "radamant",
        "kovter",
        "bradesco",
        "nymaim",
        "amonetize",
        "bondat",
        "ghost rat",
        "vjw0rm",
        "bandoo",
        "matsnu",
        "dnspionage",
        "darkgate",
        "vidar",
        "keylogger",
        "remcos",
        "agenttesla",
        "detplock",
        "win64",
        "smokeloader",
        "agent tesla",
        "kgs0",
        "kls0",
        "urls",
        "type name",
        "dns replication",
        "date",
        "domain",
        "win32 exe",
        "files",
        "detections type",
        "name",
        "drpsuinstaller",
        "vdfsurfs",
        "opera",
        "icwrmind",
        "notepad",
        "installer",
        "miner",
        "unknown",
        "networm",
        "houdini",
        "quasar rat",
        "gamehack",
        "dbatloader",
        "qakbot",
        "ursnif",
        "CVE-2005-1790",
        "CVE-2009-3672",
        "CVE-2010-3962",
        "CVE-2012-3993",
        "CVE-2014-6332",
        "CVE-2017-11882",
        "CVE-2020-0601",
        "CVE-2020-0674",
        "hallrender.com",
        "brian sabey",
        "insurance",
        "botnetwork",
        "botmaster",
        "command_and_control",
        "CVE-2021-27065",
        "CVE-2021-40444",
        "CVE-2023-4966",
        "CVE-2017-0199",
        "CVE-2018-4893",
        "CVE-2010-3333",
        "CVE-2015-1641",
        "CVE-2017-0147",
        "CVE-2017-8570",
        "CVE-2018-0802",
        "CVE-2018-8373",
        "CVE-2017-8759",
        "CVE-2018-8453",
        "CVE-2014-3153",
        "CVE-2015-1650",
        "CVE-2017-0143",
        "CVE-2017-8464",
        "Icefog",
        "Delf.NBX",
        "$WebWatson",
        "Gen:Heur.Ransom.HiddenTears",
        "mobilekey.pw",
        "bitbucket.org",
        "Anomalous.100%",
        "malware distribution site",
        "gootkit",
        "edsaid",
        "rightsaided",
        "betabot",
        "cobaltstrike4.tk",
        "mas.to",
        "BehavesLike.YahLover",
        "srdvd16010404",
        "languageenu",
        "buildno",
        "channelisales",
        "vendorname2581",
        "osregion",
        "device",
        "systemlocale",
        "majorver16",
        "quasar",
        "find",
        "lockbit",
        "chaos",
        "ransomexx",
        "grandoreiro",
        "evilnum",
        "banker"
      ],
      "references": [
        "https://hybrid-analysis.com/sample/6765f47ea77c8274c8e4973ed95aedf59e75998c62f6029e23c58cdf36ed85ba/654afdbdc621e7037801cce7",
        "20.99.186.246 exploit source",
        "fp2e7a.wpc.2be4.phicdn.net",
        "https://www.anyxxxtube.net/search-porn/tsara-brashears/ (phishing, ELF, Prism.exe found)",
        "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian (password cracker)",
        "http://182.22.25.124:7878/182.22.25.124:443     (malicious dropper)",
        "init.ess.apple.com         (malicious code script)",
        "https://www.pornhub.com/video/search?search=tsara+brashears (Malicious PW cracker | stylebk.css stylesheets - not found )",
        "https://urlscan.io/result/a328d9ff-fb49-4078-960d-a757fd41404f/#indicators",
        "VirusTotal Link: https://www.virustotal.com/gui/ip-address/20.99.186.246/detection",
        "Abuse IPDB Link: https://www.abuseipdb.com/check/20.99.186.246",
        "IPv4 45.12.253.72.            command_and_control",
        "Hostname: ddos.dnsnb8.net                        command_and_control",
        "IPv4 95.213.186.51              command_and_control",
        "Hostname: www.supernetforme.com      command_and_control",
        "IPv4 103.224.182.246        command_and_control",
        "IPv4 72.251.233.245           command_and_control",
        "IPv4 63.251.106.25             command_and_control",
        "IPv4 45.15.156.208            command_and_control",
        "IPv4 104.247.81.51             command_and_control",
        "http://ambisexual.phone-sex-blogs.com/http:/ambisexual.phone-sex-blogs.com/images/thumbnails/pic118.jpg             (phishing)",
        "https://downloaddevtools.ir/     (phishing)",
        "happylifehappywife.com",
        "apples.encryptedwork.com        (Interesting in the blacknet)",
        "https://itunes.apple.com/app/apple-store/id284815942/us/app/samsung-galaxy-watch-gear-s/id1117310635.                   (iOS unlocker and hijacker)",
        "https://www.anyxxxtube.net/media/favicon/apple              (password cracker and iOS hijacker)",
        "https://www.apple.com/shop/browse/open/country_selector     (exploit)",
        "www.norad.mil   (federal tracking tool used by attorneys, law firms, and private investigators 'licensed or unlicensed') hi!",
        "http://init-p01st.push.apple.com/bag            (malicious web creator)",
        "opencve.djgummikuh.de        (CVE dispensary)",
        "Maltiverse Research Team",
        "URLscan.io",
        "Deep Research",
        "Hybrid Analysis",
        "URLhaus Abuse.ch",
        "Cyber Threat Coalition",
        "ThreatFox Abuse.ch"
      ],
      "public": 1,
      "adversary": "Lucky Mouse APT27 | NoName057(16) |  Unnamed",
      "targeted_countries": [
        "United States of America",
        "France",
        "Spain"
      ],
      "malware_families": [
        {
          "id": "Feodo",
          "display_name": "Feodo",
          "target": null
        },
        {
          "id": "Dridex",
          "display_name": "Dridex",
          "target": null
        },
        {
          "id": "Redline Stealer",
          "display_name": "Redline Stealer",
          "target": null
        },
        {
          "id": "Ramnit.N",
          "display_name": "Ramnit.N",
          "target": null
        },
        {
          "id": "Loki Bot",
          "display_name": "Loki Bot",
          "target": null
        },
        {
          "id": "Loki Password Stealer (PWS)",
          "display_name": "Loki Password Stealer (PWS)",
          "target": null
        },
        {
          "id": "AZORult",
          "display_name": "AZORult",
          "target": null
        },
        {
          "id": "Zbd Zeus",
          "display_name": "Zbd Zeus",
          "target": null
        },
        {
          "id": "Trojan:MSIL/Burkina",
          "display_name": "Trojan:MSIL/Burkina",
          "target": "/malware/Trojan:MSIL/Burkina"
        },
        {
          "id": "Generic.TrickBot.1",
          "display_name": "Generic.TrickBot.1",
          "target": null
        },
        {
          "id": "Exploit.CVE",
          "display_name": "Exploit.CVE",
          "target": null
        },
        {
          "id": "Injector.IS.gen",
          "display_name": "Injector.IS.gen",
          "target": null
        },
        {
          "id": "Gen:Variant.Razy",
          "display_name": "Gen:Variant.Razy",
          "target": null
        },
        {
          "id": "Trojan.Androm.Gen",
          "display_name": "Trojan.Androm.Gen",
          "target": null
        },
        {
          "id": "HEUR:Trojan.Linux.Agent",
          "display_name": "HEUR:Trojan.Linux.Agent",
          "target": null
        },
        {
          "id": "BScope.Trojan",
          "display_name": "BScope.Trojan",
          "target": null
        },
        {
          "id": "VBA.Downloader",
          "display_name": "VBA.Downloader",
          "target": null
        },
        {
          "id": "Trojan.Notifier",
          "display_name": "Trojan.Notifier",
          "target": null
        },
        {
          "id": "HEUR:Trojan.MSOffice.Alien",
          "display_name": "HEUR:Trojan.MSOffice.Alien",
          "target": null
        },
        {
          "id": "Unsafe.AI_Score_100%",
          "display_name": "Unsafe.AI_Score_100%",
          "target": null
        },
        {
          "id": "Gen:Variant.Johnnie",
          "display_name": "Gen:Variant.Johnnie",
          "target": null
        },
        {
          "id": "DangerousObject.Multi",
          "display_name": "DangerousObject.Multi",
          "target": null
        },
        {
          "id": "Trojan:Python/Downldr",
          "display_name": "Trojan:Python/Downldr",
          "target": "/malware/Trojan:Python/Downldr"
        },
        {
          "id": "Trojan:Linux/Downldr",
          "display_name": "Trojan:Linux/Downldr",
          "target": "/malware/Trojan:Linux/Downldr"
        },
        {
          "id": "Trojan:VBA/Downldr",
          "display_name": "Trojan:VBA/Downldr",
          "target": "/malware/Trojan:VBA/Downldr"
        },
        {
          "id": "TrojanDownloader:Linux/Downldr",
          "display_name": "TrojanDownloader:Linux/Downldr",
          "target": "/malware/TrojanDownloader:Linux/Downldr"
        },
        {
          "id": "Kryptik.FPH.gen",
          "display_name": "Kryptik.FPH.gen",
          "target": null
        },
        {
          "id": "TROJ_FRS.VSNTFK19",
          "display_name": "TROJ_FRS.VSNTFK19",
          "target": null
        },
        {
          "id": "Trojan.Ransom.GenericKD",
          "display_name": "Trojan.Ransom.GenericKD",
          "target": null
        },
        {
          "id": "Phish.JAT",
          "display_name": "Phish.JAT",
          "target": null
        },
        {
          "id": "Phishing.HTML",
          "display_name": "Phishing.HTML",
          "target": null
        },
        {
          "id": "Generic.ASMalwS",
          "display_name": "Generic.ASMalwS",
          "target": null
        },
        {
          "id": "Phish.AB",
          "display_name": "Phish.AB",
          "target": null
        },
        {
          "id": "Generic.Malware",
          "display_name": "Generic.Malware",
          "target": null
        },
        {
          "id": "ml.Generic",
          "display_name": "ml.Generic",
          "target": null
        },
        {
          "id": "Xegumumune.8596c22f",
          "display_name": "Xegumumune.8596c22f",
          "target": null
        },
        {
          "id": "Generic.Malware.SMYB",
          "display_name": "Generic.Malware.SMYB",
          "target": null
        },
        {
          "id": "malicious.moderate.ml",
          "display_name": "malicious.moderate.ml",
          "target": null
        },
        {
          "id": "Agent.NBAE",
          "display_name": "Agent.NBAE",
          "target": null
        },
        {
          "id": "AGEN.1045227",
          "display_name": "AGEN.1045227",
          "target": null
        },
        {
          "id": "Riskware.Agent",
          "display_name": "Riskware.Agent",
          "target": null
        },
        {
          "id": "Gen:Variant.Cerbu",
          "display_name": "Gen:Variant.Cerbu",
          "target": null
        },
        {
          "id": "IL:Trojan.MSILZilla",
          "display_name": "IL:Trojan.MSILZilla",
          "target": null
        },
        {
          "id": "Dropped:Generic.Ransom.DMR",
          "display_name": "Dropped:Generic.Ransom.DMR",
          "target": null
        },
        {
          "id": "Delf.NBX",
          "display_name": "Delf.NBX",
          "target": null
        },
        {
          "id": "malicious.f01f67",
          "display_name": "malicious.f01f67",
          "target": null
        },
        {
          "id": "AGEN.1144657",
          "display_name": "AGEN.1144657",
          "target": null
        },
        {
          "id": "Trojan.Heur",
          "display_name": "Trojan.Heur",
          "target": null
        },
        {
          "id": "Trojan.Malware.300983",
          "display_name": "Trojan.Malware.300983",
          "target": null
        },
        {
          "id": "SdBot.CAOC",
          "display_name": "SdBot.CAOC",
          "target": null
        },
        {
          "id": "Trojan.DelShad",
          "display_name": "Trojan.DelShad",
          "target": null
        },
        {
          "id": "Exploit CVE-2017-11882",
          "display_name": "Exploit CVE-2017-11882",
          "target": null
        },
        {
          "id": "GameHack.NL",
          "display_name": "GameHack.NL",
          "target": null
        },
        {
          "id": "JS:Trojan.HideLink",
          "display_name": "JS:Trojan.HideLink",
          "target": null
        },
        {
          "id": "Script.Agent",
          "display_name": "Script.Agent",
          "target": null
        },
        {
          "id": "Macro.Agent",
          "display_name": "Macro.Agent",
          "target": null
        },
        {
          "id": "Macro.Downloader.AMIP",
          "display_name": "Macro.Downloader.AMIP",
          "target": null
        },
        {
          "id": "Trojan.VBA",
          "display_name": "Trojan.VBA",
          "target": null
        },
        {
          "id": "HEUR.VBA.Trojan",
          "display_name": "HEUR.VBA.Trojan",
          "target": null
        },
        {
          "id": "VB.EmoooDldr.10",
          "display_name": "VB.EmoooDldr.10",
          "target": null
        },
        {
          "id": "VB:Trojan.Valyria",
          "display_name": "VB:Trojan.Valyria",
          "target": null
        },
        {
          "id": "OpenSubtitles.A",
          "display_name": "OpenSubtitles.A",
          "target": null
        },
        {
          "id": "VB.EmoDldr.4",
          "display_name": "VB.EmoDldr.4",
          "target": null
        },
        {
          "id": "Packed-GV",
          "display_name": "Packed-GV",
          "target": null
        },
        {
          "id": "Adware.InstallMonetizer",
          "display_name": "Adware.InstallMonetizer",
          "target": null
        },
        {
          "id": "Skynet",
          "display_name": "Skynet",
          "target": null
        },
        {
          "id": "HW32.Packed",
          "display_name": "HW32.Packed",
          "target": null
        },
        {
          "id": "Zpevdo.B",
          "display_name": "Zpevdo.B",
          "target": null
        },
        {
          "id": "Presenoker",
          "display_name": "Presenoker",
          "target": null
        },
        {
          "id": "SGeneric",
          "display_name": "SGeneric",
          "target": null
        },
        {
          "id": "GameHack.DOM",
          "display_name": "GameHack.DOM",
          "target": null
        },
        {
          "id": "BehavesLike.Ransom",
          "display_name": "BehavesLike.Ransom",
          "target": null
        },
        {
          "id": "CIL.StupidCryptor",
          "display_name": "CIL.StupidCryptor",
          "target": null
        },
        {
          "id": "Gen:Heur.Ransom.MSIL",
          "display_name": "Gen:Heur.Ransom.MSIL",
          "target": null
        },
        {
          "id": "Black.Gen2",
          "display_name": "Black.Gen2",
          "target": null
        },
        {
          "id": "GameHack.CRS",
          "display_name": "GameHack.CRS",
          "target": null
        },
        {
          "id": "Trojan.HTML.PHISH",
          "display_name": "Trojan.HTML.PHISH",
          "target": null
        },
        {
          "id": "Gen:Heur.MSIL.Inject",
          "display_name": "Gen:Heur.MSIL.Inject",
          "target": null
        },
        {
          "id": "Program.Unwanted",
          "display_name": "Program.Unwanted",
          "target": null
        },
        {
          "id": "HEUR/QVM42.3.72EB.Malware",
          "display_name": "HEUR/QVM42.3.72EB.Malware",
          "target": null
        },
        {
          "id": "suspicious.low.ml",
          "display_name": "suspicious.low.ml",
          "target": null
        },
        {
          "id": "JS:Trojan.Cryxos",
          "display_name": "JS:Trojan.Cryxos",
          "target": null
        },
        {
          "id": "Suspicious_GEN.F47V0520",
          "display_name": "Suspicious_GEN.F47V0520",
          "target": null
        },
        {
          "id": "Dropper.Trojan.Generic",
          "display_name": "Dropper.Trojan.Generic",
          "target": null
        },
        {
          "id": "Trojan.TrickBot",
          "display_name": "Trojan.TrickBot",
          "target": null
        },
        {
          "id": "Malware.Tk.Generic",
          "display_name": "Malware.Tk.Generic",
          "target": null
        },
        {
          "id": "TrojanSpy.Java",
          "display_name": "TrojanSpy.Java",
          "target": null
        },
        {
          "id": "Riskware.NetFilter",
          "display_name": "Riskware.NetFilter",
          "target": null
        },
        {
          "id": "RiskWare.Crack",
          "display_name": "RiskWare.Crack",
          "target": null
        },
        {
          "id": "BehavesLike.Exploit",
          "display_name": "BehavesLike.Exploit",
          "target": null
        },
        {
          "id": "Gen:NN.ZemsilF.34128",
          "display_name": "Gen:NN.ZemsilF.34128",
          "target": null
        },
        {
          "id": "Wacapew.C",
          "display_name": "Wacapew.C",
          "target": null
        },
        {
          "id": "Trojan.Malware.121218",
          "display_name": "Trojan.Malware.121218",
          "target": null
        },
        {
          "id": "RiskWare.HackTool.Agent",
          "display_name": "RiskWare.HackTool.Agent",
          "target": null
        },
        {
          "id": "Artemis",
          "display_name": "Artemis",
          "target": null
        },
        {
          "id": "Trojan.Generic",
          "display_name": "Trojan.Generic",
          "target": null
        },
        {
          "id": "W32.Trojan",
          "display_name": "W32.Trojan",
          "target": null
        },
        {
          "id": "BScope.Riskware",
          "display_name": "BScope.Riskware",
          "target": null
        },
        {
          "id": "Gen:Variant.Bulz",
          "display_name": "Gen:Variant.Bulz",
          "target": null
        },
        {
          "id": "Ransom:Win32/CVE-2017-0147",
          "display_name": "Ransom:Win32/CVE-2017-0147",
          "target": "/malware/Ransom:Win32/CVE-2017-0147"
        },
        {
          "id": "Virus.Ramnit",
          "display_name": "Virus.Ramnit",
          "target": null
        },
        {
          "id": "Virus.Virut",
          "display_name": "Virus.Virut",
          "target": null
        },
        {
          "id": "Adware.KuziTui",
          "display_name": "Adware.KuziTui",
          "target": null
        },
        {
          "id": "AGEN.1141126",
          "display_name": "AGEN.1141126",
          "target": null
        },
        {
          "id": "W32.AIDetect",
          "display_name": "W32.AIDetect",
          "target": null
        },
        {
          "id": "Trojan.Python",
          "display_name": "Trojan.Python",
          "target": null
        },
        {
          "id": "W32.AIDetectVM",
          "display_name": "W32.AIDetectVM",
          "target": null
        },
        {
          "id": "Suspicious.Save",
          "display_name": "Suspicious.Save",
          "target": null
        },
        {
          "id": "Adware.Downware",
          "display_name": "Adware.Downware",
          "target": null
        },
        {
          "id": "Ransom.Win64.Wacatac.oa",
          "display_name": "Ransom.Win64.Wacatac.oa",
          "target": null
        },
        {
          "id": "OpenSubtitles.A",
          "display_name": "OpenSubtitles.A",
          "target": null
        },
        {
          "id": "VB.EmoDldr.4",
          "display_name": "VB.EmoDldr.4",
          "target": null
        },
        {
          "id": "Gen:Variant.Midie",
          "display_name": "Gen:Variant.Midie",
          "target": null
        },
        {
          "id": "HEUR/QVM41.2.DA9B.Malware",
          "display_name": "HEUR/QVM41.2.DA9B.Malware",
          "target": null
        },
        {
          "id": "Gen:Variant.Sirefef",
          "display_name": "Gen:Variant.Sirefef",
          "target": null
        },
        {
          "id": "Macro.Trojan.Dropperd",
          "display_name": "Macro.Trojan.Dropperd",
          "target": null
        },
        {
          "id": "BlackNET RAT",
          "display_name": "BlackNET RAT",
          "target": null
        },
        {
          "id": "Gen:Variant.Ursu",
          "display_name": "Gen:Variant.Ursu",
          "target": null
        },
        {
          "id": "Redcap.rlhse",
          "display_name": "Redcap.rlhse",
          "target": null
        },
        {
          "id": "Trojan.Trickster",
          "display_name": "Trojan.Trickster",
          "target": null
        },
        {
          "id": "HTML_REDIR.SMR",
          "display_name": "HTML_REDIR.SMR",
          "target": null
        },
        {
          "id": "TROJ_FRS.VSNTFK19",
          "display_name": "TROJ_FRS.VSNTFK19",
          "target": null
        },
        {
          "id": "Hoax.JS.Phish",
          "display_name": "Hoax.JS.Phish",
          "target": null
        },
        {
          "id": "JS:Iframe",
          "display_name": "JS:Iframe",
          "target": null
        },
        {
          "id": "Application.SQLCrack",
          "display_name": "Application.SQLCrack",
          "target": null
        },
        {
          "id": "susp.lnk",
          "display_name": "susp.lnk",
          "target": null
        },
        {
          "id": "QVM201.0.B70B.Malware",
          "display_name": "QVM201.0.B70B.Malware",
          "target": null
        },
        {
          "id": "Immortal Stealer",
          "display_name": "Immortal Stealer",
          "target": null
        },
        {
          "id": "WebMonitor RAT",
          "display_name": "WebMonitor RAT",
          "target": null
        },
        {
          "id": "Tor - S0183",
          "display_name": "Tor - S0183",
          "target": null
        },
        {
          "id": "WannaCry",
          "display_name": "WannaCry",
          "target": null
        },
        {
          "id": "WannaCryptor",
          "display_name": "WannaCryptor",
          "target": null
        },
        {
          "id": "WebToolbar",
          "display_name": "WebToolbar",
          "target": null
        },
        {
          "id": "BlackNET",
          "display_name": "BlackNET",
          "target": null
        },
        {
          "id": "DeepScan:Generic.Ransom.GandCrab5",
          "display_name": "DeepScan:Generic.Ransom.GandCrab5",
          "target": null
        },
        {
          "id": "TrojanSpy",
          "display_name": "TrojanSpy",
          "target": null
        },
        {
          "id": "States",
          "display_name": "States",
          "target": null
        },
        {
          "id": "Inmortal",
          "display_name": "Inmortal",
          "target": null
        },
        {
          "id": "Domains",
          "display_name": "Domains",
          "target": null
        },
        {
          "id": "Locky",
          "display_name": "Locky",
          "target": null
        },
        {
          "id": "Delf.NBX",
          "display_name": "Delf.NBX",
          "target": null
        },
        {
          "id": "Gen:NN.ZexaF.32515",
          "display_name": "Gen:NN.ZexaF.32515",
          "target": null
        },
        {
          "id": "FileRepMalware",
          "display_name": "FileRepMalware",
          "target": null
        },
        {
          "id": "Gen:Variant.MSILPerseus",
          "display_name": "Gen:Variant.MSILPerseus",
          "target": null
        },
        {
          "id": "Icefog",
          "display_name": "Icefog",
          "target": null
        },
        {
          "id": "$WebWatson",
          "display_name": "$WebWatson",
          "target": null
        },
        {
          "id": "Agent.AIK.gen",
          "display_name": "Agent.AIK.gen",
          "target": null
        },
        {
          "id": "Agent.AIK.genCIL.StupidCryptor",
          "display_name": "Agent.AIK.genCIL.StupidCryptor",
          "target": null
        },
        {
          "id": "Agent.YPEZ",
          "display_name": "Agent.YPEZ",
          "target": null
        },
        {
          "id": "Application.InnovativSol",
          "display_name": "Application.InnovativSol",
          "target": null
        },
        {
          "id": "Agent.ASO",
          "display_name": "Agent.ASO",
          "target": null
        },
        {
          "id": "S-b748adc5",
          "display_name": "S-b748adc5",
          "target": null
        },
        {
          "id": "W32.eHeur",
          "display_name": "W32.eHeur",
          "target": null
        },
        {
          "id": "Kryptik.GUCB",
          "display_name": "Kryptik.GUCB",
          "target": null
        },
        {
          "id": "AgentTesla",
          "display_name": "AgentTesla",
          "target": null
        },
        {
          "id": "Autoit.bimwt",
          "display_name": "Autoit.bimwt",
          "target": null
        },
        {
          "id": "HEUR:Trojan.OLE2.Alien",
          "display_name": "HEUR:Trojan.OLE2.Alien",
          "target": null
        },
        {
          "id": "AGEN.1038489",
          "display_name": "AGEN.1038489",
          "target": null
        },
        {
          "id": "Gen:Variant.Ser.Strictor",
          "display_name": "Gen:Variant.Ser.Strictor",
          "target": null
        },
        {
          "id": "Packed.Themida.Gen",
          "display_name": "Packed.Themida.Gen",
          "target": null
        },
        {
          "id": "AGEN.1043164",
          "display_name": "AGEN.1043164",
          "target": null
        },
        {
          "id": "TrickBot - S0266",
          "display_name": "TrickBot - S0266",
          "target": null
        },
        {
          "id": "Emotet",
          "display_name": "Emotet",
          "target": null
        },
        {
          "id": "Trojan.PornoAsset",
          "display_name": "Trojan.PornoAsset",
          "target": null
        },
        {
          "id": "Ransom.Win64.PORNOASSET.SM1",
          "display_name": "Ransom.Win64.PORNOASSET.SM1",
          "target": null
        },
        {
          "id": "Gen:Variant.Ulise",
          "display_name": "Gen:Variant.Ulise",
          "target": null
        },
        {
          "id": "Trojan.Win64",
          "display_name": "Trojan.Win64",
          "target": null
        },
        {
          "id": "Dropper.Trojan.Agent",
          "display_name": "Dropper.Trojan.Agent",
          "target": null
        },
        {
          "id": "Heur.BZC.YAX.Pantera.10",
          "display_name": "Heur.BZC.YAX.Pantera.10",
          "target": null
        },
        {
          "id": "malicious.high.ml",
          "display_name": "malicious.high.ml",
          "target": null
        },
        {
          "id": "CVE-2015-1650",
          "display_name": "CVE-2015-1650",
          "target": null
        },
        {
          "id": "Worm.Win64.AutoRun",
          "display_name": "Worm.Win64.AutoRun",
          "target": null
        },
        {
          "id": "AIT.Heur.Cottonmouth.8.78F19BD7",
          "display_name": "AIT.Heur.Cottonmouth.8.78F19BD7",
          "target": null
        },
        {
          "id": "Gen:Variant.Mikey",
          "display_name": "Gen:Variant.Mikey",
          "target": null
        },
        {
          "id": "Trojan.Agent",
          "display_name": "Trojan.Agent",
          "target": null
        },
        {
          "id": "Pua.Gen",
          "display_name": "Pua.Gen",
          "target": null
        },
        {
          "id": "Trojan.Downloader.Generic",
          "display_name": "Trojan.Downloader.Generic",
          "target": null
        },
        {
          "id": "Suspected of Trojan.Downloader.gen",
          "display_name": "Suspected of Trojan.Downloader.gen",
          "target": null
        },
        {
          "id": "HEUR:RemoteAdmin.Generic",
          "display_name": "HEUR:RemoteAdmin.Generic",
          "target": null
        },
        {
          "id": "Gen:Heur.Ransom.HiddenTears",
          "display_name": "Gen:Heur.Ransom.HiddenTears",
          "target": null
        },
        {
          "id": "Nemucod.A",
          "display_name": "Nemucod.A",
          "target": null
        },
        {
          "id": "Backdoor.Hupigon",
          "display_name": "Backdoor.Hupigon",
          "target": null
        },
        {
          "id": "Trojan.Starter JS.Iframe",
          "display_name": "Trojan.Starter JS.Iframe",
          "target": null
        },
        {
          "id": "fake ,promethiumm ,strongpity",
          "display_name": "fake ,promethiumm ,strongpity",
          "target": null
        },
        {
          "id": "PUA.Reg1staid",
          "display_name": "PUA.Reg1staid",
          "target": null
        },
        {
          "id": "Malware.Heur_Generic.A",
          "display_name": "Malware.Heur_Generic.A",
          "target": null
        },
        {
          "id": "Bladabindi.Q",
          "display_name": "Bladabindi.Q",
          "target": null
        },
        {
          "id": "W32.eHeur",
          "display_name": "W32.eHeur",
          "target": null
        },
        {
          "id": "malicious.6e0700",
          "display_name": "malicious.6e0700",
          "target": null
        },
        {
          "id": "Trojan.Inject",
          "display_name": "Trojan.Inject",
          "target": null
        },
        {
          "id": "TSGeneric",
          "display_name": "TSGeneric",
          "target": null
        },
        {
          "id": "RedCap.vneda",
          "display_name": "RedCap.vneda",
          "target": null
        },
        {
          "id": "Trojan.Indiloadz",
          "display_name": "Trojan.Indiloadz",
          "target": null
        },
        {
          "id": "Trojan.Ekstak",
          "display_name": "Trojan.Ekstak",
          "target": null
        },
        {
          "id": "staticrr.paleokits.net",
          "display_name": "staticrr.paleokits.net",
          "target": null
        },
        {
          "id": "MSIL.Downloader",
          "display_name": "MSIL.Downloader",
          "target": null
        },
        {
          "id": "Trojan.Autoruns.GenericKDS",
          "display_name": "Trojan.Autoruns.GenericKDS",
          "target": null
        },
        {
          "id": "MSIL.Trojan.BSE",
          "display_name": "MSIL.Trojan.BSE",
          "target": null
        },
        {
          "id": "Adload.AD81",
          "display_name": "Adload.AD81",
          "target": null
        },
        {
          "id": "Packed.Asprotect",
          "display_name": "Packed.Asprotect",
          "target": null
        },
        {
          "id": "Gen:NN.ZemsilF.34062",
          "display_name": "Gen:NN.ZemsilF.34062",
          "target": null
        },
        {
          "id": "Evo",
          "display_name": "Evo",
          "target": null
        },
        {
          "id": "Agent.pwc",
          "display_name": "Agent.pwc",
          "target": null
        },
        {
          "id": "RiskTool.Phpw",
          "display_name": "RiskTool.Phpw",
          "target": null
        },
        {
          "id": "Gen:Variant.Symmi",
          "display_name": "Gen:Variant.Symmi",
          "target": null
        },
        {
          "id": "Trojan.PWS",
          "display_name": "Trojan.PWS",
          "target": null
        },
        {
          "id": "Generic.BitCoinMiner.3",
          "display_name": "Generic.BitCoinMiner.3",
          "target": null
        },
        {
          "id": "Trojan.Tasker",
          "display_name": "Trojan.Tasker",
          "target": null
        },
        {
          "id": "Gen:NN",
          "display_name": "Gen:NN",
          "target": null
        },
        {
          "id": "Downloader.CertutilURLCache",
          "display_name": "Downloader.CertutilURLCache",
          "target": null
        },
        {
          "id": "Elf",
          "display_name": "Elf",
          "target": null
        },
        {
          "id": "Gen:Heur.MSIL.Androm",
          "display_name": "Gen:Heur.MSIL.Androm",
          "target": null
        },
        {
          "id": "Kryptik.NRD",
          "display_name": "Kryptik.NRD",
          "target": null
        },
        {
          "id": "Riskware",
          "display_name": "Riskware",
          "target": null
        },
        {
          "id": "Kuluoz.B.gen",
          "display_name": "Kuluoz.B.gen",
          "target": null
        },
        {
          "id": "Gen:Variant.RevengeRat",
          "display_name": "Gen:Variant.RevengeRat",
          "target": null
        },
        {
          "id": "Gen:Variant.Mikey",
          "display_name": "Gen:Variant.Mikey",
          "target": null
        },
        {
          "id": "VB.Chronos.7",
          "display_name": "VB.Chronos.7",
          "target": null
        },
        {
          "id": "Kryptik.NOE",
          "display_name": "Kryptik.NOE",
          "target": null
        },
        {
          "id": "HEUR:WebToolbar.Generic",
          "display_name": "HEUR:WebToolbar.Generic",
          "target": null
        },
        {
          "id": "Gen:Variant.Barys",
          "display_name": "Gen:Variant.Barys",
          "target": null
        },
        {
          "id": "Backdoor.Xtreme",
          "display_name": "Backdoor.Xtreme",
          "target": null
        },
        {
          "id": "Trojan.MSIL",
          "display_name": "Trojan.MSIL",
          "target": null
        },
        {
          "id": "Gen:Variant.Graftor",
          "display_name": "Gen:Variant.Graftor",
          "target": null
        },
        {
          "id": "Backdoor.Agent",
          "display_name": "Backdoor.Agent",
          "target": null
        },
        {
          "id": "Unsafe",
          "display_name": "Unsafe",
          "target": null
        },
        {
          "id": "Trojan.PHP.Agent",
          "display_name": "Trojan.PHP.Agent",
          "target": null
        },
        {
          "id": "Trojan.Agent",
          "display_name": "Trojan.Agent",
          "target": null
        },
        {
          "id": "HEUR:Exploit.Generic",
          "display_name": "HEUR:Exploit.Generic",
          "target": null
        },
        {
          "id": "Ransom_WCRY.SMALYM",
          "display_name": "Ransom_WCRY.SMALYM",
          "target": null
        },
        {
          "id": "Ransom_WCRY.SMJ",
          "display_name": "Ransom_WCRY.SMJ",
          "target": null
        },
        {
          "id": "Auslogics",
          "display_name": "Auslogics",
          "target": null
        },
        {
          "id": "Gen:Variant.Jaiko",
          "display_name": "Gen:Variant.Jaiko",
          "target": null
        },
        {
          "id": "Exploit.W32.Agent",
          "display_name": "Exploit.W32.Agent",
          "target": null
        },
        {
          "id": "Trojan.Cud.Gen",
          "display_name": "Trojan.Cud.Gen",
          "target": null
        },
        {
          "id": "Trojan.DOC.Downloader",
          "display_name": "Trojan.DOC.Downloader",
          "target": null
        },
        {
          "id": "Backdoor.MSIL.Agent",
          "display_name": "Backdoor.MSIL.Agent",
          "target": null
        },
        {
          "id": "Gen:Trojan.Heur2.LPTbHW@W64.HfsAutoB",
          "display_name": "Gen:Trojan.Heur2.LPTbHW@W64.HfsAutoB",
          "target": null
        },
        {
          "id": "Gen:Variant.Kazy",
          "display_name": "Gen:Variant.Kazy",
          "target": null
        },
        {
          "id": "Gen:Variant.Zusy",
          "display_name": "Gen:Variant.Zusy",
          "target": null
        },
        {
          "id": "Ransom.WannaCrypt",
          "display_name": "Ransom.WannaCrypt",
          "target": null
        },
        {
          "id": "Generic.ServStart.A",
          "display_name": "Generic.ServStart.A",
          "target": null
        },
        {
          "id": "Trojan.Wanna",
          "display_name": "Trojan.Wanna",
          "target": null
        },
        {
          "id": "Generic.MSIL.Bladabindi",
          "display_name": "Generic.MSIL.Bladabindi",
          "target": null
        },
        {
          "id": "TROJ_GEN.R002C0OG518",
          "display_name": "TROJ_GEN.R002C0OG518",
          "target": null
        },
        {
          "id": "Trojan.Chapak",
          "display_name": "Trojan.Chapak",
          "target": null
        },
        {
          "id": "Indiloadz.BB",
          "display_name": "Indiloadz.BB",
          "target": null
        },
        {
          "id": "BehavBehavesLike.PUPXBI",
          "display_name": "BehavBehavesLike.PUPXBI",
          "target": null
        },
        {
          "id": "DeepScan:Generic.SpyAgent.6",
          "display_name": "DeepScan:Generic.SpyAgent.6",
          "target": null
        },
        {
          "id": "Python.KeyLogger",
          "display_name": "Python.KeyLogger",
          "target": null
        },
        {
          "id": "GameHack.CRS",
          "display_name": "GameHack.CRS",
          "target": null
        },
        {
          "id": "Generic.MSIL.PasswordStealer",
          "display_name": "Generic.MSIL.PasswordStealer",
          "target": null
        },
        {
          "id": "PSW.Agent",
          "display_name": "PSW.Agent",
          "target": null
        },
        {
          "id": "malicious.8c45ba",
          "display_name": "malicious.8c45ba",
          "target": null
        },
        {
          "id": "Dropper.Binder",
          "display_name": "Dropper.Binder",
          "target": null
        },
        {
          "id": "Constructor.MSIL",
          "display_name": "Constructor.MSIL",
          "target": null
        },
        {
          "id": "Linux.Agent",
          "display_name": "Linux.Agent",
          "target": null
        },
        {
          "id": "Virus.3DMax.Script",
          "display_name": "Virus.3DMax.Script",
          "target": null
        },
        {
          "id": "ScrInject.B",
          "display_name": "ScrInject.B",
          "target": null
        },
        {
          "id": "Trojan.WisdomEyes.16070401.9500",
          "display_name": "Trojan.WisdomEyes.16070401.9500",
          "target": null
        },
        {
          "id": "Application.SearchProtect",
          "display_name": "Application.SearchProtect",
          "target": null
        },
        {
          "id": "JS:Trojan.Clicker",
          "display_name": "JS:Trojan.Clicker",
          "target": null
        },
        {
          "id": "Faceliker.A",
          "display_name": "Faceliker.A",
          "target": null
        },
        {
          "id": "JS:Trojan.JS.Faceliker",
          "display_name": "JS:Trojan.JS.Faceliker",
          "target": null
        },
        {
          "id": "Constructor.MSIL  Linux.Agent",
          "display_name": "Constructor.MSIL  Linux.Agent",
          "target": null
        },
        {
          "id": "PowerShell.Trojan",
          "display_name": "PowerShell.Trojan",
          "target": null
        },
        {
          "id": "HTML:Script",
          "display_name": "HTML:Script",
          "target": null
        },
        {
          "id": "ScrInject.B",
          "display_name": "ScrInject.B",
          "target": null
        },
        {
          "id": "W32.AIDetectVM",
          "display_name": "W32.AIDetectVM",
          "target": null
        },
        {
          "id": "HackTool.CheatEngine",
          "display_name": "HackTool.CheatEngine",
          "target": null
        },
        {
          "id": "Injector.CLDS",
          "display_name": "Injector.CLDS",
          "target": null
        },
        {
          "id": "VB.Downloader.2",
          "display_name": "VB.Downloader.2",
          "target": null
        },
        {
          "id": "malicious.3e78cc",
          "display_name": "malicious.3e78cc",
          "target": null
        },
        {
          "id": "malicious.d800d6",
          "display_name": "malicious.d800d6",
          "target": null
        },
        {
          "id": "VB.PwShell.2",
          "display_name": "VB.PwShell.2",
          "target": null
        },
        {
          "id": "Backdoor.RBot",
          "display_name": "Backdoor.RBot",
          "target": null
        },
        {
          "id": "malicious.71b1a8",
          "display_name": "malicious.71b1a8",
          "target": null
        },
        {
          "id": "TrojanSpy.KeyLogger",
          "display_name": "TrojanSpy.KeyLogger",
          "target": null
        },
        {
          "id": "Injector.JDO",
          "display_name": "Injector.JDO",
          "target": null
        },
        {
          "id": "Heur.Msword.Gen",
          "display_name": "Heur.Msword.Gen",
          "target": null
        },
        {
          "id": "PSW.Discord",
          "display_name": "PSW.Discord",
          "target": null
        },
        {
          "id": "Packed.VMProtect",
          "display_name": "Packed.VMProtect",
          "target": null
        },
        {
          "id": "HEUR:AdWare.StartSurf",
          "display_name": "HEUR:AdWare.StartSurf",
          "target": null
        },
        {
          "id": "Gen:Heur.NoobyProtect",
          "display_name": "Gen:Heur.NoobyProtect",
          "target": null
        },
        {
          "id": "CIL.HeapOverride",
          "display_name": "CIL.HeapOverride",
          "target": null
        },
        {
          "id": "HEUR:Trojan.Tasker",
          "display_name": "HEUR:Trojan.Tasker",
          "target": null
        },
        {
          "id": "XLM.Trojan.Abracadabra.27",
          "display_name": "XLM.Trojan.Abracadabra.27",
          "target": null
        },
        {
          "id": "HEUR:Backdoor.MSIL.NanoBot",
          "display_name": "HEUR:Backdoor.MSIL.NanoBot",
          "target": null
        },
        {
          "id": "Trojan.PSW.Mimikatz",
          "display_name": "Trojan.PSW.Mimikatz",
          "target": null
        },
        {
          "id": "TrojanSpy.Python",
          "display_name": "TrojanSpy.Python",
          "target": null
        },
        {
          "id": "Trojan.Ole2.Vbs",
          "display_name": "Trojan.Ole2.Vbs",
          "target": null
        },
        {
          "id": "Exploit.MSOffice",
          "display_name": "Exploit.MSOffice",
          "target": null
        },
        {
          "id": "DeepScan:Generic.Ransom.AmnesiaE",
          "display_name": "DeepScan:Generic.Ransom.AmnesiaE",
          "target": null
        },
        {
          "id": "Wacatac.D6",
          "display_name": "Wacatac.D6",
          "target": null
        },
        {
          "id": "Backdoor.Androm",
          "display_name": "Backdoor.Androm",
          "target": null
        },
        {
          "id": "Packed.NetSeal",
          "display_name": "Packed.NetSeal",
          "target": null
        },
        {
          "id": "Trojan.MSIL.Injector",
          "display_name": "Trojan.MSIL.Injector",
          "target": null
        },
        {
          "id": "Trojan.PWS.Agent",
          "display_name": "Trojan.PWS.Agent",
          "target": null
        },
        {
          "id": "TScope.Trojan",
          "display_name": "TScope.Trojan",
          "target": null
        },
        {
          "id": "PSW.Stealer",
          "display_name": "PSW.Stealer",
          "target": null
        },
        {
          "id": "Trojan.PackedNET",
          "display_name": "Trojan.PackedNET",
          "target": null
        },
        {
          "id": "Trojan.Java",
          "display_name": "Trojan.Java",
          "target": null
        },
        {
          "id": "MalwareX",
          "display_name": "MalwareX",
          "target": null
        },
        {
          "id": "Trojan.PSW.Python",
          "display_name": "Trojan.PSW.Python",
          "target": null
        },
        {
          "id": "malicious.11abfc",
          "display_name": "malicious.11abfc",
          "target": null
        },
        {
          "id": "Generic.ASMalwS",
          "display_name": "Generic.ASMalwS",
          "target": null
        },
        {
          "id": "HEUR:Trojan.MSIL.Tasker",
          "display_name": "HEUR:Trojan.MSIL.Tasker",
          "target": null
        },
        {
          "id": "PossibleThreat.PALLAS",
          "display_name": "PossibleThreat.PALLAS",
          "target": null
        },
        {
          "id": "Backdoor.Poison",
          "display_name": "Backdoor.Poison",
          "target": null
        },
        {
          "id": "Generic.MSIL.LimeRAT",
          "display_name": "Generic.MSIL.LimeRAT",
          "target": null
        },
        {
          "id": "PWS-FCZZ",
          "display_name": "PWS-FCZZ",
          "target": null
        },
        {
          "id": "Trojan.Script",
          "display_name": "Trojan.Script",
          "target": null
        },
        {
          "id": "Gen:Heur.MSIL.Inject",
          "display_name": "Gen:Heur.MSIL.Inject",
          "target": null
        },
        {
          "id": "Trojan.PWS.Growtopia",
          "display_name": "Trojan.PWS.Growtopia",
          "target": null
        },
        {
          "id": "Spyware.Bobik",
          "display_name": "Spyware.Bobik",
          "target": null
        },
        {
          "id": "HackTool.BruteForce",
          "display_name": "HackTool.BruteForce",
          "target": null
        },
        {
          "id": "Hack.Patcher",
          "display_name": "Hack.Patcher",
          "target": null
        },
        {
          "id": "PWS.p",
          "display_name": "PWS.p",
          "target": null
        },
        {
          "id": "Suppobox",
          "display_name": "Suppobox",
          "target": null
        },
        {
          "id": "index.php",
          "display_name": "index.php",
          "target": null
        },
        {
          "id": "Packed.VMProtect",
          "display_name": "Packed.VMProtect",
          "target": null
        },
        {
          "id": "SmokeLoader",
          "display_name": "SmokeLoader",
          "target": null
        },
        {
          "id": "Generic.Malware",
          "display_name": "Generic.Malware",
          "target": null
        },
        {
          "id": "SNH:Script [Dropper]",
          "display_name": "SNH:Script [Dropper]",
          "target": null
        },
        {
          "id": "HEUR:Trojan.MSOffice.SAgent",
          "display_name": "HEUR:Trojan.MSOffice.SAgent",
          "target": null
        },
        {
          "id": "Script.INF",
          "display_name": "Script.INF",
          "target": null
        },
        {
          "id": "JS:Trojan.JS.Likejack",
          "display_name": "JS:Trojan.JS.Likejack",
          "target": null
        },
        {
          "id": "SNH:Script [Dropper]",
          "display_name": "SNH:Script [Dropper]",
          "target": null
        },
        {
          "id": "Trojan.JS.Agent",
          "display_name": "Trojan.JS.Agent",
          "target": null
        },
        {
          "id": "APT Notes",
          "display_name": "APT Notes",
          "target": null
        },
        {
          "id": "susp.rtf.objupdate",
          "display_name": "susp.rtf.objupdate",
          "target": null
        },
        {
          "id": "RedCap.zoohz",
          "display_name": "RedCap.zoohz",
          "target": null
        },
        {
          "id": "Trojan.Tasker",
          "display_name": "Trojan.Tasker",
          "target": null
        },
        {
          "id": "virus.office.qexvmc",
          "display_name": "virus.office.qexvmc",
          "target": null
        },
        {
          "id": "Trojan.KillProc",
          "display_name": "Trojan.KillProc",
          "target": null
        },
        {
          "id": "Generic.MSIL.GrwtpStealer.1",
          "display_name": "Generic.MSIL.GrwtpStealer.1",
          "target": null
        },
        {
          "id": "Suspicious.Cloud",
          "display_name": "Suspicious.Cloud",
          "target": null
        },
        {
          "id": "PowerShell.DownLoader",
          "display_name": "PowerShell.DownLoader",
          "target": null
        },
        {
          "id": "Downldr.gen",
          "display_name": "Downldr.gen",
          "target": null
        },
        {
          "id": "AGEN.1030939",
          "display_name": "AGEN.1030939",
          "target": null
        },
        {
          "id": "HackTool.Binder",
          "display_name": "HackTool.Binder",
          "target": null
        },
        {
          "id": "Trojan.Inject",
          "display_name": "Trojan.Inject",
          "target": null
        },
        {
          "id": "Dldr.Agent",
          "display_name": "Dldr.Agent",
          "target": null
        },
        {
          "id": "Dropper.MSIL",
          "display_name": "Dropper.MSIL",
          "target": null
        },
        {
          "id": "Trojan.VBKryjetor",
          "display_name": "Trojan.VBKryjetor",
          "target": null
        },
        {
          "id": "PWSX",
          "display_name": "PWSX",
          "target": null
        },
        {
          "id": "VB:Trojan.VBA.Agent",
          "display_name": "VB:Trojan.VBA.Agent",
          "target": null
        },
        {
          "id": "HEUR:Trojan.MSOffice.Stratos",
          "display_name": "HEUR:Trojan.MSOffice.Stratos",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1071.001",
          "name": "Web Protocols",
          "display_name": "T1071.001 - Web Protocols"
        },
        {
          "id": "T1071.004",
          "name": "DNS",
          "display_name": "T1071.004 - DNS"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1059.007",
          "name": "JavaScript",
          "display_name": "T1059.007 - JavaScript"
        },
        {
          "id": "T1497",
          "name": "Virtualization/Sandbox Evasion",
          "display_name": "T1497 - Virtualization/Sandbox Evasion"
        },
        {
          "id": "T1068",
          "name": "Exploitation for Privilege Escalation",
          "display_name": "T1068 - Exploitation for Privilege Escalation"
        },
        {
          "id": "TA0029",
          "name": "Privilege Escalation",
          "display_name": "TA0029 - Privilege Escalation"
        },
        {
          "id": "T1449",
          "name": "Exploit SS7 to Redirect Phone Calls/SMS",
          "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
        },
        {
          "id": "T1190",
          "name": "Exploit Public-Facing Application",
          "display_name": "T1190 - Exploit Public-Facing Application"
        },
        {
          "id": "T1210",
          "name": "Exploitation of Remote Services",
          "display_name": "T1210 - Exploitation of Remote Services"
        },
        {
          "id": "T1450",
          "name": "Exploit SS7 to Track Device Location",
          "display_name": "T1450 - Exploit SS7 to Track Device Location"
        },
        {
          "id": "T1211",
          "name": "Exploitation for Defense Evasion",
          "display_name": "T1211 - Exploitation for Defense Evasion"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "TA0011",
          "name": "Command and Control",
          "display_name": "TA0011 - Command and Control"
        },
        {
          "id": "T1412",
          "name": "Capture SMS Messages",
          "display_name": "T1412 - Capture SMS Messages"
        },
        {
          "id": "T1454",
          "name": "Malicious SMS Message",
          "display_name": "T1454 - Malicious SMS Message"
        },
        {
          "id": "T1001",
          "name": "Data Obfuscation",
          "display_name": "T1001 - Data Obfuscation"
        },
        {
          "id": "T1114",
          "name": "Email Collection",
          "display_name": "T1114 - Email Collection"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1498",
          "name": "Network Denial of Service",
          "display_name": "T1498 - Network Denial of Service"
        },
        {
          "id": "T1496",
          "name": "Resource Hijacking",
          "display_name": "T1496 - Resource Hijacking"
        },
        {
          "id": "T1176",
          "name": "Browser Extensions",
          "display_name": "T1176 - Browser Extensions"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 338,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 1184,
        "FileHash-SHA1": 949,
        "FileHash-SHA256": 3712,
        "URL": 2925,
        "domain": 627,
        "hostname": 1319,
        "CVE": 26,
        "email": 8,
        "CIDR": 2
      },
      "indicator_count": 10752,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 223,
      "modified_text": "904 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "654d29ff31857aafba0358e1",
      "name": "Lucky Mouse APT27 | Feodo Tracker | Malicious Tor Server | Apple iOS",
      "description": "",
      "modified": "2023-12-09T03:01:57.989000",
      "created": "2023-11-09T18:50:39.675000",
      "tags": [
        "ssl certificate",
        "historical ssl",
        "communicating",
        "contacted",
        "resolutions",
        "whois record",
        "whois whois",
        "whois parent",
        "whois siblings",
        "skynet",
        "threat report",
        "ip summary",
        "url summary",
        "summary",
        "sample",
        "samples",
        "detection list",
        "blacklist",
        "cisco umbrella",
        "site",
        "safe site",
        "million",
        "team",
        "microsoft",
        "back",
        "download",
        "phishing",
        "union",
        "bank",
        "malicious site",
        "blacklist http",
        "exit",
        "traffic",
        "node tcp",
        "tor known",
        "tor relayrouter",
        "et tor",
        "known tor",
        "relayrouter",
        "anonymizer",
        "spammer",
        "malware",
        "dropped",
        "unlocker",
        "http",
        "critical risk",
        "redline stealer",
        "core",
        "hacktool",
        "execution",
        "type win32",
        "exe size",
        "first seen",
        "file name",
        "avast win32",
        "win32",
        "avg win32",
        "fortinet",
        "vitro",
        "mb first",
        "rmndrp",
        "clean mx",
        "undetected dns8",
        "undetected vx",
        "sophos",
        "vault",
        "zdb zeus",
        "cmc threat",
        "snort ip",
        "feodo tracker",
        "cybereason",
        "send bug",
        "pe yandex",
        "no data",
        "tag count",
        "count blacklist",
        "tag tag",
        "algorithm",
        "v3 serial",
        "number",
        "issuer",
        "cus cnr3",
        "olet",
        "subject public",
        "key info",
        "key algorithm",
        "key identifier",
        "first",
        "seen",
        "valid",
        "no na",
        "no no",
        "ip security",
        "cndst root",
        "ca x3",
        "ca id",
        "research group",
        "cnisrg root",
        "no expired",
        "mozilla",
        "android",
        "malicious red team",
        "tsara brashears",
        "cyber stalking",
        "malvertizing",
        "invasion of privacy",
        "threat",
        "adult content",
        "apple",
        "iphone unlocker",
        "android",
        "exploited spyware",
        "malware host",
        "brute force",
        "revenge-rat",
        "banker",
        "evasive",
        "domain",
        "redline",
        "stealer",
        "phishing",
        "ramnit",
        "unreliable subdomains",
        "dridex",
        "gating",
        "msil",
        "rat",
        "loki",
        "network",
        "hacking",
        "sinkhole",
        "azorult",
        "c2",
        "historicalandnew",
        "targeted attack",
        "puffstealer",
        "rultazo",
        "lokibot",
        "loki pws",
        "burkina",
        "banker,dde,dridex,exploit",
        "banker,dridex,evasive",
        "trickbot",
        "ransomware,torrentlocker",
        "exploit_source",
        "blacknet",
        "FileRepMalware",
        "linux agent",
        "blacknet",
        "ios",
        "phishing paypal",
        "tagging",
        "defacement",
        "hit",
        "bounty",
        "phishing site",
        "malware site",
        "malware download",
        "endangerment",
        "Malicious domain - SANS Internet Storm Center",
        "evasive,msil,rat,revenge-rat",
        "prism_setting",
        "prism_object",
        "static engine",
        "social engineering",
        "jansky",
        "worm",
        "network rat",
        "networm",
        "Loki Password Stealer (PWS)",
        "South Carolina Federal Credit Union phishing",
        "darkweb",
        "yandex",
        "redirectors",
        "blacknet threats",
        "phishing,ransomware,sinkhole",
        "wanacrypt0r,wannacry,wcry",
        "tor c++",
        "tor c++ client",
        "python user",
        "js user",
        "hacker",
        "hijacker",
        "heur",
        "maltiverse",
        "alexa top",
        "exploit",
        "riskware",
        "unsafe",
        "outbreak",
        "downer",
        "shell",
        "mediamagnet",
        "sality",
        "swrort",
        "adaptivebee",
        "unruy",
        "iobit",
        "dropper",
        "trojanx",
        "artemis",
        "installcore",
        "webshell",
        "crack",
        "webtoolbar",
        "search live",
        "api blog",
        "docs pricing",
        "november",
        "de indicators",
        "domains",
        "hashes",
        "__convergedlogin_pcustomizationloader_44b450e8d543eb53930d",
        "malicious url",
        "financial",
        "blacknet rat",
        "azorult",
        "stealer",
        "deep scan",
        "blacklist https",
        "referrer",
        "collections kp",
        "incident ip",
        "sneaky server",
        "replacement",
        "unauthorized",
        "emotet",
        "noname057",
        "generic malware",
        "engineering",
        "cyber threat",
        "facebook",
        "paypal",
        "dropbox",
        "united",
        "america",
        "banking",
        "wells fargo",
        "steam",
        "twitter",
        "sliver",
        "daum",
        "swift",
        "runescape",
        "betabot",
        "district",
        "iframe",
        "alexa",
        "downldr",
        "agent",
        "presenoker",
        "bladabindi",
        "live",
        "conduit",
        "pony",
        "covid19",
        "malicious",
        "cobalt strike",
        "suppobox",
        "ramnit",
        "meterpreter",
        "virut",
        "njrat",
        "pykspa",
        "asyncrat",
        "downloader",
        "fakealert",
        "binder",
        "virustotal",
        "formbook",
        "necurs",
        "trojan",
        "msil",
        "hiloti",
        "vawtrak",
        "simda",
        "kraken",
        "solimba",
        "icedid",
        "redirector",
        "suspic",
        "amadey",
        "raccoon",
        "nanocore rat",
        "revenge rat",
        "genkryptik",
        "fuery",
        "wacatac",
        "service",
        "cloudeye",
        "tinba",
        "domaiq",
        "ave maria",
        "zeus",
        "ransomware",
        "zbot",
        "generic",
        "trojanspy",
        "states",
        "inmortal",
        "locky",
        "strike",
        "china cobalt",
        "keybase",
        "cutwail",
        "citadel",
        "radamant",
        "kovter",
        "bradesco",
        "nymaim",
        "amonetize",
        "bondat",
        "ghost rat",
        "vjw0rm",
        "bandoo",
        "matsnu",
        "dnspionage",
        "darkgate",
        "vidar",
        "keylogger",
        "remcos",
        "agenttesla",
        "detplock",
        "win64",
        "smokeloader",
        "agent tesla",
        "kgs0",
        "kls0",
        "urls",
        "type name",
        "dns replication",
        "date",
        "domain",
        "win32 exe",
        "files",
        "detections type",
        "name",
        "drpsuinstaller",
        "vdfsurfs",
        "opera",
        "icwrmind",
        "notepad",
        "installer",
        "miner",
        "unknown",
        "networm",
        "houdini",
        "quasar rat",
        "gamehack",
        "dbatloader",
        "qakbot",
        "ursnif",
        "CVE-2005-1790",
        "CVE-2009-3672",
        "CVE-2010-3962",
        "CVE-2012-3993",
        "CVE-2014-6332",
        "CVE-2017-11882",
        "CVE-2020-0601",
        "CVE-2020-0674",
        "hallrender.com",
        "brian sabey",
        "insurance",
        "botnetwork",
        "botmaster",
        "command_and_control",
        "CVE-2021-27065",
        "CVE-2021-40444",
        "CVE-2023-4966",
        "CVE-2017-0199",
        "CVE-2018-4893",
        "CVE-2010-3333",
        "CVE-2015-1641",
        "CVE-2017-0147",
        "CVE-2017-8570",
        "CVE-2018-0802",
        "CVE-2018-8373",
        "CVE-2017-8759",
        "CVE-2018-8453",
        "CVE-2014-3153",
        "CVE-2015-1650",
        "CVE-2017-0143",
        "CVE-2017-8464",
        "Icefog",
        "Delf.NBX",
        "$WebWatson",
        "Gen:Heur.Ransom.HiddenTears",
        "mobilekey.pw",
        "bitbucket.org",
        "Anomalous.100%",
        "malware distribution site",
        "gootkit",
        "edsaid",
        "rightsaided",
        "betabot",
        "cobaltstrike4.tk",
        "mas.to",
        "BehavesLike.YahLover",
        "srdvd16010404",
        "languageenu",
        "buildno",
        "channelisales",
        "vendorname2581",
        "osregion",
        "device",
        "systemlocale",
        "majorver16",
        "quasar",
        "find",
        "lockbit",
        "chaos",
        "ransomexx",
        "grandoreiro",
        "evilnum",
        "banker"
      ],
      "references": [
        "https://hybrid-analysis.com/sample/6765f47ea77c8274c8e4973ed95aedf59e75998c62f6029e23c58cdf36ed85ba/654afdbdc621e7037801cce7",
        "20.99.186.246 exploit source",
        "fp2e7a.wpc.2be4.phicdn.net",
        "https://www.anyxxxtube.net/search-porn/tsara-brashears/ (phishing, ELF, Prism.exe found)",
        "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian (password cracker)",
        "http://182.22.25.124:7878/182.22.25.124:443     (malicious dropper)",
        "init.ess.apple.com         (malicious code script)",
        "https://www.pornhub.com/video/search?search=tsara+brashears (Malicious PW cracker | stylebk.css stylesheets - not found )",
        "https://urlscan.io/result/a328d9ff-fb49-4078-960d-a757fd41404f/#indicators",
        "VirusTotal Link: https://www.virustotal.com/gui/ip-address/20.99.186.246/detection",
        "Abuse IPDB Link: https://www.abuseipdb.com/check/20.99.186.246",
        "IPv4 45.12.253.72.            command_and_control",
        "Hostname: ddos.dnsnb8.net                        command_and_control",
        "IPv4 95.213.186.51              command_and_control",
        "Hostname: www.supernetforme.com      command_and_control",
        "IPv4 103.224.182.246        command_and_control",
        "IPv4 72.251.233.245           command_and_control",
        "IPv4 63.251.106.25             command_and_control",
        "IPv4 45.15.156.208            command_and_control",
        "IPv4 104.247.81.51             command_and_control",
        "http://ambisexual.phone-sex-blogs.com/http:/ambisexual.phone-sex-blogs.com/images/thumbnails/pic118.jpg             (phishing)",
        "https://downloaddevtools.ir/     (phishing)",
        "happylifehappywife.com",
        "apples.encryptedwork.com        (Interesting in the blacknet)",
        "https://itunes.apple.com/app/apple-store/id284815942/us/app/samsung-galaxy-watch-gear-s/id1117310635.                   (iOS unlocker and hijacker)",
        "https://www.anyxxxtube.net/media/favicon/apple              (password cracker and iOS hijacker)",
        "https://www.apple.com/shop/browse/open/country_selector     (exploit)",
        "www.norad.mil   (federal tracking tool used by attorneys, law firms, and private investigators 'licensed or unlicensed') hi!",
        "http://init-p01st.push.apple.com/bag            (malicious web creator)",
        "opencve.djgummikuh.de        (CVE dispensary)",
        "Maltiverse Research Team",
        "URLscan.io",
        "Deep Research",
        "Hybrid Analysis",
        "URLhaus Abuse.ch",
        "Cyber Threat Coalition",
        "ThreatFox Abuse.ch"
      ],
      "public": 1,
      "adversary": "Lucky Mouse APT27 | NoName057(16) |  Unnamed",
      "targeted_countries": [
        "United States of America",
        "France",
        "Spain"
      ],
      "malware_families": [
        {
          "id": "Feodo",
          "display_name": "Feodo",
          "target": null
        },
        {
          "id": "Dridex",
          "display_name": "Dridex",
          "target": null
        },
        {
          "id": "Redline Stealer",
          "display_name": "Redline Stealer",
          "target": null
        },
        {
          "id": "Ramnit.N",
          "display_name": "Ramnit.N",
          "target": null
        },
        {
          "id": "Loki Bot",
          "display_name": "Loki Bot",
          "target": null
        },
        {
          "id": "Loki Password Stealer (PWS)",
          "display_name": "Loki Password Stealer (PWS)",
          "target": null
        },
        {
          "id": "AZORult",
          "display_name": "AZORult",
          "target": null
        },
        {
          "id": "Zbd Zeus",
          "display_name": "Zbd Zeus",
          "target": null
        },
        {
          "id": "Trojan:MSIL/Burkina",
          "display_name": "Trojan:MSIL/Burkina",
          "target": "/malware/Trojan:MSIL/Burkina"
        },
        {
          "id": "Generic.TrickBot.1",
          "display_name": "Generic.TrickBot.1",
          "target": null
        },
        {
          "id": "Exploit.CVE",
          "display_name": "Exploit.CVE",
          "target": null
        },
        {
          "id": "Injector.IS.gen",
          "display_name": "Injector.IS.gen",
          "target": null
        },
        {
          "id": "Gen:Variant.Razy",
          "display_name": "Gen:Variant.Razy",
          "target": null
        },
        {
          "id": "Trojan.Androm.Gen",
          "display_name": "Trojan.Androm.Gen",
          "target": null
        },
        {
          "id": "HEUR:Trojan.Linux.Agent",
          "display_name": "HEUR:Trojan.Linux.Agent",
          "target": null
        },
        {
          "id": "BScope.Trojan",
          "display_name": "BScope.Trojan",
          "target": null
        },
        {
          "id": "VBA.Downloader",
          "display_name": "VBA.Downloader",
          "target": null
        },
        {
          "id": "Trojan.Notifier",
          "display_name": "Trojan.Notifier",
          "target": null
        },
        {
          "id": "HEUR:Trojan.MSOffice.Alien",
          "display_name": "HEUR:Trojan.MSOffice.Alien",
          "target": null
        },
        {
          "id": "Unsafe.AI_Score_100%",
          "display_name": "Unsafe.AI_Score_100%",
          "target": null
        },
        {
          "id": "Gen:Variant.Johnnie",
          "display_name": "Gen:Variant.Johnnie",
          "target": null
        },
        {
          "id": "DangerousObject.Multi",
          "display_name": "DangerousObject.Multi",
          "target": null
        },
        {
          "id": "Trojan:Python/Downldr",
          "display_name": "Trojan:Python/Downldr",
          "target": "/malware/Trojan:Python/Downldr"
        },
        {
          "id": "Trojan:Linux/Downldr",
          "display_name": "Trojan:Linux/Downldr",
          "target": "/malware/Trojan:Linux/Downldr"
        },
        {
          "id": "Trojan:VBA/Downldr",
          "display_name": "Trojan:VBA/Downldr",
          "target": "/malware/Trojan:VBA/Downldr"
        },
        {
          "id": "TrojanDownloader:Linux/Downldr",
          "display_name": "TrojanDownloader:Linux/Downldr",
          "target": "/malware/TrojanDownloader:Linux/Downldr"
        },
        {
          "id": "Kryptik.FPH.gen",
          "display_name": "Kryptik.FPH.gen",
          "target": null
        },
        {
          "id": "TROJ_FRS.VSNTFK19",
          "display_name": "TROJ_FRS.VSNTFK19",
          "target": null
        },
        {
          "id": "Trojan.Ransom.GenericKD",
          "display_name": "Trojan.Ransom.GenericKD",
          "target": null
        },
        {
          "id": "Phish.JAT",
          "display_name": "Phish.JAT",
          "target": null
        },
        {
          "id": "Phishing.HTML",
          "display_name": "Phishing.HTML",
          "target": null
        },
        {
          "id": "Generic.ASMalwS",
          "display_name": "Generic.ASMalwS",
          "target": null
        },
        {
          "id": "Phish.AB",
          "display_name": "Phish.AB",
          "target": null
        },
        {
          "id": "Generic.Malware",
          "display_name": "Generic.Malware",
          "target": null
        },
        {
          "id": "ml.Generic",
          "display_name": "ml.Generic",
          "target": null
        },
        {
          "id": "Xegumumune.8596c22f",
          "display_name": "Xegumumune.8596c22f",
          "target": null
        },
        {
          "id": "Generic.Malware.SMYB",
          "display_name": "Generic.Malware.SMYB",
          "target": null
        },
        {
          "id": "malicious.moderate.ml",
          "display_name": "malicious.moderate.ml",
          "target": null
        },
        {
          "id": "Agent.NBAE",
          "display_name": "Agent.NBAE",
          "target": null
        },
        {
          "id": "AGEN.1045227",
          "display_name": "AGEN.1045227",
          "target": null
        },
        {
          "id": "Riskware.Agent",
          "display_name": "Riskware.Agent",
          "target": null
        },
        {
          "id": "Gen:Variant.Cerbu",
          "display_name": "Gen:Variant.Cerbu",
          "target": null
        },
        {
          "id": "IL:Trojan.MSILZilla",
          "display_name": "IL:Trojan.MSILZilla",
          "target": null
        },
        {
          "id": "Dropped:Generic.Ransom.DMR",
          "display_name": "Dropped:Generic.Ransom.DMR",
          "target": null
        },
        {
          "id": "Delf.NBX",
          "display_name": "Delf.NBX",
          "target": null
        },
        {
          "id": "malicious.f01f67",
          "display_name": "malicious.f01f67",
          "target": null
        },
        {
          "id": "AGEN.1144657",
          "display_name": "AGEN.1144657",
          "target": null
        },
        {
          "id": "Trojan.Heur",
          "display_name": "Trojan.Heur",
          "target": null
        },
        {
          "id": "Trojan.Malware.300983",
          "display_name": "Trojan.Malware.300983",
          "target": null
        },
        {
          "id": "SdBot.CAOC",
          "display_name": "SdBot.CAOC",
          "target": null
        },
        {
          "id": "Trojan.DelShad",
          "display_name": "Trojan.DelShad",
          "target": null
        },
        {
          "id": "Exploit CVE-2017-11882",
          "display_name": "Exploit CVE-2017-11882",
          "target": null
        },
        {
          "id": "GameHack.NL",
          "display_name": "GameHack.NL",
          "target": null
        },
        {
          "id": "JS:Trojan.HideLink",
          "display_name": "JS:Trojan.HideLink",
          "target": null
        },
        {
          "id": "Script.Agent",
          "display_name": "Script.Agent",
          "target": null
        },
        {
          "id": "Macro.Agent",
          "display_name": "Macro.Agent",
          "target": null
        },
        {
          "id": "Macro.Downloader.AMIP",
          "display_name": "Macro.Downloader.AMIP",
          "target": null
        },
        {
          "id": "Trojan.VBA",
          "display_name": "Trojan.VBA",
          "target": null
        },
        {
          "id": "HEUR.VBA.Trojan",
          "display_name": "HEUR.VBA.Trojan",
          "target": null
        },
        {
          "id": "VB.EmoooDldr.10",
          "display_name": "VB.EmoooDldr.10",
          "target": null
        },
        {
          "id": "VB:Trojan.Valyria",
          "display_name": "VB:Trojan.Valyria",
          "target": null
        },
        {
          "id": "OpenSubtitles.A",
          "display_name": "OpenSubtitles.A",
          "target": null
        },
        {
          "id": "VB.EmoDldr.4",
          "display_name": "VB.EmoDldr.4",
          "target": null
        },
        {
          "id": "Packed-GV",
          "display_name": "Packed-GV",
          "target": null
        },
        {
          "id": "Adware.InstallMonetizer",
          "display_name": "Adware.InstallMonetizer",
          "target": null
        },
        {
          "id": "Skynet",
          "display_name": "Skynet",
          "target": null
        },
        {
          "id": "HW32.Packed",
          "display_name": "HW32.Packed",
          "target": null
        },
        {
          "id": "Zpevdo.B",
          "display_name": "Zpevdo.B",
          "target": null
        },
        {
          "id": "Presenoker",
          "display_name": "Presenoker",
          "target": null
        },
        {
          "id": "SGeneric",
          "display_name": "SGeneric",
          "target": null
        },
        {
          "id": "GameHack.DOM",
          "display_name": "GameHack.DOM",
          "target": null
        },
        {
          "id": "BehavesLike.Ransom",
          "display_name": "BehavesLike.Ransom",
          "target": null
        },
        {
          "id": "CIL.StupidCryptor",
          "display_name": "CIL.StupidCryptor",
          "target": null
        },
        {
          "id": "Gen:Heur.Ransom.MSIL",
          "display_name": "Gen:Heur.Ransom.MSIL",
          "target": null
        },
        {
          "id": "Black.Gen2",
          "display_name": "Black.Gen2",
          "target": null
        },
        {
          "id": "GameHack.CRS",
          "display_name": "GameHack.CRS",
          "target": null
        },
        {
          "id": "Trojan.HTML.PHISH",
          "display_name": "Trojan.HTML.PHISH",
          "target": null
        },
        {
          "id": "Gen:Heur.MSIL.Inject",
          "display_name": "Gen:Heur.MSIL.Inject",
          "target": null
        },
        {
          "id": "Program.Unwanted",
          "display_name": "Program.Unwanted",
          "target": null
        },
        {
          "id": "HEUR/QVM42.3.72EB.Malware",
          "display_name": "HEUR/QVM42.3.72EB.Malware",
          "target": null
        },
        {
          "id": "suspicious.low.ml",
          "display_name": "suspicious.low.ml",
          "target": null
        },
        {
          "id": "JS:Trojan.Cryxos",
          "display_name": "JS:Trojan.Cryxos",
          "target": null
        },
        {
          "id": "Suspicious_GEN.F47V0520",
          "display_name": "Suspicious_GEN.F47V0520",
          "target": null
        },
        {
          "id": "Dropper.Trojan.Generic",
          "display_name": "Dropper.Trojan.Generic",
          "target": null
        },
        {
          "id": "Trojan.TrickBot",
          "display_name": "Trojan.TrickBot",
          "target": null
        },
        {
          "id": "Malware.Tk.Generic",
          "display_name": "Malware.Tk.Generic",
          "target": null
        },
        {
          "id": "TrojanSpy.Java",
          "display_name": "TrojanSpy.Java",
          "target": null
        },
        {
          "id": "Riskware.NetFilter",
          "display_name": "Riskware.NetFilter",
          "target": null
        },
        {
          "id": "RiskWare.Crack",
          "display_name": "RiskWare.Crack",
          "target": null
        },
        {
          "id": "BehavesLike.Exploit",
          "display_name": "BehavesLike.Exploit",
          "target": null
        },
        {
          "id": "Gen:NN.ZemsilF.34128",
          "display_name": "Gen:NN.ZemsilF.34128",
          "target": null
        },
        {
          "id": "Wacapew.C",
          "display_name": "Wacapew.C",
          "target": null
        },
        {
          "id": "Trojan.Malware.121218",
          "display_name": "Trojan.Malware.121218",
          "target": null
        },
        {
          "id": "RiskWare.HackTool.Agent",
          "display_name": "RiskWare.HackTool.Agent",
          "target": null
        },
        {
          "id": "Artemis",
          "display_name": "Artemis",
          "target": null
        },
        {
          "id": "Trojan.Generic",
          "display_name": "Trojan.Generic",
          "target": null
        },
        {
          "id": "W32.Trojan",
          "display_name": "W32.Trojan",
          "target": null
        },
        {
          "id": "BScope.Riskware",
          "display_name": "BScope.Riskware",
          "target": null
        },
        {
          "id": "Gen:Variant.Bulz",
          "display_name": "Gen:Variant.Bulz",
          "target": null
        },
        {
          "id": "Ransom:Win32/CVE-2017-0147",
          "display_name": "Ransom:Win32/CVE-2017-0147",
          "target": "/malware/Ransom:Win32/CVE-2017-0147"
        },
        {
          "id": "Virus.Ramnit",
          "display_name": "Virus.Ramnit",
          "target": null
        },
        {
          "id": "Virus.Virut",
          "display_name": "Virus.Virut",
          "target": null
        },
        {
          "id": "Adware.KuziTui",
          "display_name": "Adware.KuziTui",
          "target": null
        },
        {
          "id": "AGEN.1141126",
          "display_name": "AGEN.1141126",
          "target": null
        },
        {
          "id": "W32.AIDetect",
          "display_name": "W32.AIDetect",
          "target": null
        },
        {
          "id": "Trojan.Python",
          "display_name": "Trojan.Python",
          "target": null
        },
        {
          "id": "W32.AIDetectVM",
          "display_name": "W32.AIDetectVM",
          "target": null
        },
        {
          "id": "Suspicious.Save",
          "display_name": "Suspicious.Save",
          "target": null
        },
        {
          "id": "Adware.Downware",
          "display_name": "Adware.Downware",
          "target": null
        },
        {
          "id": "Ransom.Win64.Wacatac.oa",
          "display_name": "Ransom.Win64.Wacatac.oa",
          "target": null
        },
        {
          "id": "OpenSubtitles.A",
          "display_name": "OpenSubtitles.A",
          "target": null
        },
        {
          "id": "VB.EmoDldr.4",
          "display_name": "VB.EmoDldr.4",
          "target": null
        },
        {
          "id": "Gen:Variant.Midie",
          "display_name": "Gen:Variant.Midie",
          "target": null
        },
        {
          "id": "HEUR/QVM41.2.DA9B.Malware",
          "display_name": "HEUR/QVM41.2.DA9B.Malware",
          "target": null
        },
        {
          "id": "Gen:Variant.Sirefef",
          "display_name": "Gen:Variant.Sirefef",
          "target": null
        },
        {
          "id": "Macro.Trojan.Dropperd",
          "display_name": "Macro.Trojan.Dropperd",
          "target": null
        },
        {
          "id": "BlackNET RAT",
          "display_name": "BlackNET RAT",
          "target": null
        },
        {
          "id": "Gen:Variant.Ursu",
          "display_name": "Gen:Variant.Ursu",
          "target": null
        },
        {
          "id": "Redcap.rlhse",
          "display_name": "Redcap.rlhse",
          "target": null
        },
        {
          "id": "Trojan.Trickster",
          "display_name": "Trojan.Trickster",
          "target": null
        },
        {
          "id": "HTML_REDIR.SMR",
          "display_name": "HTML_REDIR.SMR",
          "target": null
        },
        {
          "id": "TROJ_FRS.VSNTFK19",
          "display_name": "TROJ_FRS.VSNTFK19",
          "target": null
        },
        {
          "id": "Hoax.JS.Phish",
          "display_name": "Hoax.JS.Phish",
          "target": null
        },
        {
          "id": "JS:Iframe",
          "display_name": "JS:Iframe",
          "target": null
        },
        {
          "id": "Application.SQLCrack",
          "display_name": "Application.SQLCrack",
          "target": null
        },
        {
          "id": "susp.lnk",
          "display_name": "susp.lnk",
          "target": null
        },
        {
          "id": "QVM201.0.B70B.Malware",
          "display_name": "QVM201.0.B70B.Malware",
          "target": null
        },
        {
          "id": "Immortal Stealer",
          "display_name": "Immortal Stealer",
          "target": null
        },
        {
          "id": "WebMonitor RAT",
          "display_name": "WebMonitor RAT",
          "target": null
        },
        {
          "id": "Tor - S0183",
          "display_name": "Tor - S0183",
          "target": null
        },
        {
          "id": "WannaCry",
          "display_name": "WannaCry",
          "target": null
        },
        {
          "id": "WannaCryptor",
          "display_name": "WannaCryptor",
          "target": null
        },
        {
          "id": "WebToolbar",
          "display_name": "WebToolbar",
          "target": null
        },
        {
          "id": "BlackNET",
          "display_name": "BlackNET",
          "target": null
        },
        {
          "id": "DeepScan:Generic.Ransom.GandCrab5",
          "display_name": "DeepScan:Generic.Ransom.GandCrab5",
          "target": null
        },
        {
          "id": "TrojanSpy",
          "display_name": "TrojanSpy",
          "target": null
        },
        {
          "id": "States",
          "display_name": "States",
          "target": null
        },
        {
          "id": "Inmortal",
          "display_name": "Inmortal",
          "target": null
        },
        {
          "id": "Domains",
          "display_name": "Domains",
          "target": null
        },
        {
          "id": "Locky",
          "display_name": "Locky",
          "target": null
        },
        {
          "id": "Delf.NBX",
          "display_name": "Delf.NBX",
          "target": null
        },
        {
          "id": "Gen:NN.ZexaF.32515",
          "display_name": "Gen:NN.ZexaF.32515",
          "target": null
        },
        {
          "id": "FileRepMalware",
          "display_name": "FileRepMalware",
          "target": null
        },
        {
          "id": "Gen:Variant.MSILPerseus",
          "display_name": "Gen:Variant.MSILPerseus",
          "target": null
        },
        {
          "id": "Icefog",
          "display_name": "Icefog",
          "target": null
        },
        {
          "id": "$WebWatson",
          "display_name": "$WebWatson",
          "target": null
        },
        {
          "id": "Agent.AIK.gen",
          "display_name": "Agent.AIK.gen",
          "target": null
        },
        {
          "id": "Agent.AIK.genCIL.StupidCryptor",
          "display_name": "Agent.AIK.genCIL.StupidCryptor",
          "target": null
        },
        {
          "id": "Agent.YPEZ",
          "display_name": "Agent.YPEZ",
          "target": null
        },
        {
          "id": "Application.InnovativSol",
          "display_name": "Application.InnovativSol",
          "target": null
        },
        {
          "id": "Agent.ASO",
          "display_name": "Agent.ASO",
          "target": null
        },
        {
          "id": "S-b748adc5",
          "display_name": "S-b748adc5",
          "target": null
        },
        {
          "id": "W32.eHeur",
          "display_name": "W32.eHeur",
          "target": null
        },
        {
          "id": "Kryptik.GUCB",
          "display_name": "Kryptik.GUCB",
          "target": null
        },
        {
          "id": "AgentTesla",
          "display_name": "AgentTesla",
          "target": null
        },
        {
          "id": "Autoit.bimwt",
          "display_name": "Autoit.bimwt",
          "target": null
        },
        {
          "id": "HEUR:Trojan.OLE2.Alien",
          "display_name": "HEUR:Trojan.OLE2.Alien",
          "target": null
        },
        {
          "id": "AGEN.1038489",
          "display_name": "AGEN.1038489",
          "target": null
        },
        {
          "id": "Gen:Variant.Ser.Strictor",
          "display_name": "Gen:Variant.Ser.Strictor",
          "target": null
        },
        {
          "id": "Packed.Themida.Gen",
          "display_name": "Packed.Themida.Gen",
          "target": null
        },
        {
          "id": "AGEN.1043164",
          "display_name": "AGEN.1043164",
          "target": null
        },
        {
          "id": "TrickBot - S0266",
          "display_name": "TrickBot - S0266",
          "target": null
        },
        {
          "id": "Emotet",
          "display_name": "Emotet",
          "target": null
        },
        {
          "id": "Trojan.PornoAsset",
          "display_name": "Trojan.PornoAsset",
          "target": null
        },
        {
          "id": "Ransom.Win64.PORNOASSET.SM1",
          "display_name": "Ransom.Win64.PORNOASSET.SM1",
          "target": null
        },
        {
          "id": "Gen:Variant.Ulise",
          "display_name": "Gen:Variant.Ulise",
          "target": null
        },
        {
          "id": "Trojan.Win64",
          "display_name": "Trojan.Win64",
          "target": null
        },
        {
          "id": "Dropper.Trojan.Agent",
          "display_name": "Dropper.Trojan.Agent",
          "target": null
        },
        {
          "id": "Heur.BZC.YAX.Pantera.10",
          "display_name": "Heur.BZC.YAX.Pantera.10",
          "target": null
        },
        {
          "id": "malicious.high.ml",
          "display_name": "malicious.high.ml",
          "target": null
        },
        {
          "id": "CVE-2015-1650",
          "display_name": "CVE-2015-1650",
          "target": null
        },
        {
          "id": "Worm.Win64.AutoRun",
          "display_name": "Worm.Win64.AutoRun",
          "target": null
        },
        {
          "id": "AIT.Heur.Cottonmouth.8.78F19BD7",
          "display_name": "AIT.Heur.Cottonmouth.8.78F19BD7",
          "target": null
        },
        {
          "id": "Gen:Variant.Mikey",
          "display_name": "Gen:Variant.Mikey",
          "target": null
        },
        {
          "id": "Trojan.Agent",
          "display_name": "Trojan.Agent",
          "target": null
        },
        {
          "id": "Pua.Gen",
          "display_name": "Pua.Gen",
          "target": null
        },
        {
          "id": "Trojan.Downloader.Generic",
          "display_name": "Trojan.Downloader.Generic",
          "target": null
        },
        {
          "id": "Suspected of Trojan.Downloader.gen",
          "display_name": "Suspected of Trojan.Downloader.gen",
          "target": null
        },
        {
          "id": "HEUR:RemoteAdmin.Generic",
          "display_name": "HEUR:RemoteAdmin.Generic",
          "target": null
        },
        {
          "id": "Gen:Heur.Ransom.HiddenTears",
          "display_name": "Gen:Heur.Ransom.HiddenTears",
          "target": null
        },
        {
          "id": "Nemucod.A",
          "display_name": "Nemucod.A",
          "target": null
        },
        {
          "id": "Backdoor.Hupigon",
          "display_name": "Backdoor.Hupigon",
          "target": null
        },
        {
          "id": "Trojan.Starter JS.Iframe",
          "display_name": "Trojan.Starter JS.Iframe",
          "target": null
        },
        {
          "id": "fake ,promethiumm ,strongpity",
          "display_name": "fake ,promethiumm ,strongpity",
          "target": null
        },
        {
          "id": "PUA.Reg1staid",
          "display_name": "PUA.Reg1staid",
          "target": null
        },
        {
          "id": "Malware.Heur_Generic.A",
          "display_name": "Malware.Heur_Generic.A",
          "target": null
        },
        {
          "id": "Bladabindi.Q",
          "display_name": "Bladabindi.Q",
          "target": null
        },
        {
          "id": "W32.eHeur",
          "display_name": "W32.eHeur",
          "target": null
        },
        {
          "id": "malicious.6e0700",
          "display_name": "malicious.6e0700",
          "target": null
        },
        {
          "id": "Trojan.Inject",
          "display_name": "Trojan.Inject",
          "target": null
        },
        {
          "id": "TSGeneric",
          "display_name": "TSGeneric",
          "target": null
        },
        {
          "id": "RedCap.vneda",
          "display_name": "RedCap.vneda",
          "target": null
        },
        {
          "id": "Trojan.Indiloadz",
          "display_name": "Trojan.Indiloadz",
          "target": null
        },
        {
          "id": "Trojan.Ekstak",
          "display_name": "Trojan.Ekstak",
          "target": null
        },
        {
          "id": "staticrr.paleokits.net",
          "display_name": "staticrr.paleokits.net",
          "target": null
        },
        {
          "id": "MSIL.Downloader",
          "display_name": "MSIL.Downloader",
          "target": null
        },
        {
          "id": "Trojan.Autoruns.GenericKDS",
          "display_name": "Trojan.Autoruns.GenericKDS",
          "target": null
        },
        {
          "id": "MSIL.Trojan.BSE",
          "display_name": "MSIL.Trojan.BSE",
          "target": null
        },
        {
          "id": "Adload.AD81",
          "display_name": "Adload.AD81",
          "target": null
        },
        {
          "id": "Packed.Asprotect",
          "display_name": "Packed.Asprotect",
          "target": null
        },
        {
          "id": "Gen:NN.ZemsilF.34062",
          "display_name": "Gen:NN.ZemsilF.34062",
          "target": null
        },
        {
          "id": "Evo",
          "display_name": "Evo",
          "target": null
        },
        {
          "id": "Agent.pwc",
          "display_name": "Agent.pwc",
          "target": null
        },
        {
          "id": "RiskTool.Phpw",
          "display_name": "RiskTool.Phpw",
          "target": null
        },
        {
          "id": "Gen:Variant.Symmi",
          "display_name": "Gen:Variant.Symmi",
          "target": null
        },
        {
          "id": "Trojan.PWS",
          "display_name": "Trojan.PWS",
          "target": null
        },
        {
          "id": "Generic.BitCoinMiner.3",
          "display_name": "Generic.BitCoinMiner.3",
          "target": null
        },
        {
          "id": "Trojan.Tasker",
          "display_name": "Trojan.Tasker",
          "target": null
        },
        {
          "id": "Gen:NN",
          "display_name": "Gen:NN",
          "target": null
        },
        {
          "id": "Downloader.CertutilURLCache",
          "display_name": "Downloader.CertutilURLCache",
          "target": null
        },
        {
          "id": "Elf",
          "display_name": "Elf",
          "target": null
        },
        {
          "id": "Gen:Heur.MSIL.Androm",
          "display_name": "Gen:Heur.MSIL.Androm",
          "target": null
        },
        {
          "id": "Kryptik.NRD",
          "display_name": "Kryptik.NRD",
          "target": null
        },
        {
          "id": "Riskware",
          "display_name": "Riskware",
          "target": null
        },
        {
          "id": "Kuluoz.B.gen",
          "display_name": "Kuluoz.B.gen",
          "target": null
        },
        {
          "id": "Gen:Variant.RevengeRat",
          "display_name": "Gen:Variant.RevengeRat",
          "target": null
        },
        {
          "id": "Gen:Variant.Mikey",
          "display_name": "Gen:Variant.Mikey",
          "target": null
        },
        {
          "id": "VB.Chronos.7",
          "display_name": "VB.Chronos.7",
          "target": null
        },
        {
          "id": "Kryptik.NOE",
          "display_name": "Kryptik.NOE",
          "target": null
        },
        {
          "id": "HEUR:WebToolbar.Generic",
          "display_name": "HEUR:WebToolbar.Generic",
          "target": null
        },
        {
          "id": "Gen:Variant.Barys",
          "display_name": "Gen:Variant.Barys",
          "target": null
        },
        {
          "id": "Backdoor.Xtreme",
          "display_name": "Backdoor.Xtreme",
          "target": null
        },
        {
          "id": "Trojan.MSIL",
          "display_name": "Trojan.MSIL",
          "target": null
        },
        {
          "id": "Gen:Variant.Graftor",
          "display_name": "Gen:Variant.Graftor",
          "target": null
        },
        {
          "id": "Backdoor.Agent",
          "display_name": "Backdoor.Agent",
          "target": null
        },
        {
          "id": "Unsafe",
          "display_name": "Unsafe",
          "target": null
        },
        {
          "id": "Trojan.PHP.Agent",
          "display_name": "Trojan.PHP.Agent",
          "target": null
        },
        {
          "id": "Trojan.Agent",
          "display_name": "Trojan.Agent",
          "target": null
        },
        {
          "id": "HEUR:Exploit.Generic",
          "display_name": "HEUR:Exploit.Generic",
          "target": null
        },
        {
          "id": "Ransom_WCRY.SMALYM",
          "display_name": "Ransom_WCRY.SMALYM",
          "target": null
        },
        {
          "id": "Ransom_WCRY.SMJ",
          "display_name": "Ransom_WCRY.SMJ",
          "target": null
        },
        {
          "id": "Auslogics",
          "display_name": "Auslogics",
          "target": null
        },
        {
          "id": "Gen:Variant.Jaiko",
          "display_name": "Gen:Variant.Jaiko",
          "target": null
        },
        {
          "id": "Exploit.W32.Agent",
          "display_name": "Exploit.W32.Agent",
          "target": null
        },
        {
          "id": "Trojan.Cud.Gen",
          "display_name": "Trojan.Cud.Gen",
          "target": null
        },
        {
          "id": "Trojan.DOC.Downloader",
          "display_name": "Trojan.DOC.Downloader",
          "target": null
        },
        {
          "id": "Backdoor.MSIL.Agent",
          "display_name": "Backdoor.MSIL.Agent",
          "target": null
        },
        {
          "id": "Gen:Trojan.Heur2.LPTbHW@W64.HfsAutoB",
          "display_name": "Gen:Trojan.Heur2.LPTbHW@W64.HfsAutoB",
          "target": null
        },
        {
          "id": "Gen:Variant.Kazy",
          "display_name": "Gen:Variant.Kazy",
          "target": null
        },
        {
          "id": "Gen:Variant.Zusy",
          "display_name": "Gen:Variant.Zusy",
          "target": null
        },
        {
          "id": "Ransom.WannaCrypt",
          "display_name": "Ransom.WannaCrypt",
          "target": null
        },
        {
          "id": "Generic.ServStart.A",
          "display_name": "Generic.ServStart.A",
          "target": null
        },
        {
          "id": "Trojan.Wanna",
          "display_name": "Trojan.Wanna",
          "target": null
        },
        {
          "id": "Generic.MSIL.Bladabindi",
          "display_name": "Generic.MSIL.Bladabindi",
          "target": null
        },
        {
          "id": "TROJ_GEN.R002C0OG518",
          "display_name": "TROJ_GEN.R002C0OG518",
          "target": null
        },
        {
          "id": "Trojan.Chapak",
          "display_name": "Trojan.Chapak",
          "target": null
        },
        {
          "id": "Indiloadz.BB",
          "display_name": "Indiloadz.BB",
          "target": null
        },
        {
          "id": "BehavBehavesLike.PUPXBI",
          "display_name": "BehavBehavesLike.PUPXBI",
          "target": null
        },
        {
          "id": "DeepScan:Generic.SpyAgent.6",
          "display_name": "DeepScan:Generic.SpyAgent.6",
          "target": null
        },
        {
          "id": "Python.KeyLogger",
          "display_name": "Python.KeyLogger",
          "target": null
        },
        {
          "id": "GameHack.CRS",
          "display_name": "GameHack.CRS",
          "target": null
        },
        {
          "id": "Generic.MSIL.PasswordStealer",
          "display_name": "Generic.MSIL.PasswordStealer",
          "target": null
        },
        {
          "id": "PSW.Agent",
          "display_name": "PSW.Agent",
          "target": null
        },
        {
          "id": "malicious.8c45ba",
          "display_name": "malicious.8c45ba",
          "target": null
        },
        {
          "id": "Dropper.Binder",
          "display_name": "Dropper.Binder",
          "target": null
        },
        {
          "id": "Constructor.MSIL",
          "display_name": "Constructor.MSIL",
          "target": null
        },
        {
          "id": "Linux.Agent",
          "display_name": "Linux.Agent",
          "target": null
        },
        {
          "id": "Virus.3DMax.Script",
          "display_name": "Virus.3DMax.Script",
          "target": null
        },
        {
          "id": "ScrInject.B",
          "display_name": "ScrInject.B",
          "target": null
        },
        {
          "id": "Trojan.WisdomEyes.16070401.9500",
          "display_name": "Trojan.WisdomEyes.16070401.9500",
          "target": null
        },
        {
          "id": "Application.SearchProtect",
          "display_name": "Application.SearchProtect",
          "target": null
        },
        {
          "id": "JS:Trojan.Clicker",
          "display_name": "JS:Trojan.Clicker",
          "target": null
        },
        {
          "id": "Faceliker.A",
          "display_name": "Faceliker.A",
          "target": null
        },
        {
          "id": "JS:Trojan.JS.Faceliker",
          "display_name": "JS:Trojan.JS.Faceliker",
          "target": null
        },
        {
          "id": "Constructor.MSIL  Linux.Agent",
          "display_name": "Constructor.MSIL  Linux.Agent",
          "target": null
        },
        {
          "id": "PowerShell.Trojan",
          "display_name": "PowerShell.Trojan",
          "target": null
        },
        {
          "id": "HTML:Script",
          "display_name": "HTML:Script",
          "target": null
        },
        {
          "id": "ScrInject.B",
          "display_name": "ScrInject.B",
          "target": null
        },
        {
          "id": "W32.AIDetectVM",
          "display_name": "W32.AIDetectVM",
          "target": null
        },
        {
          "id": "HackTool.CheatEngine",
          "display_name": "HackTool.CheatEngine",
          "target": null
        },
        {
          "id": "Injector.CLDS",
          "display_name": "Injector.CLDS",
          "target": null
        },
        {
          "id": "VB.Downloader.2",
          "display_name": "VB.Downloader.2",
          "target": null
        },
        {
          "id": "malicious.3e78cc",
          "display_name": "malicious.3e78cc",
          "target": null
        },
        {
          "id": "malicious.d800d6",
          "display_name": "malicious.d800d6",
          "target": null
        },
        {
          "id": "VB.PwShell.2",
          "display_name": "VB.PwShell.2",
          "target": null
        },
        {
          "id": "Backdoor.RBot",
          "display_name": "Backdoor.RBot",
          "target": null
        },
        {
          "id": "malicious.71b1a8",
          "display_name": "malicious.71b1a8",
          "target": null
        },
        {
          "id": "TrojanSpy.KeyLogger",
          "display_name": "TrojanSpy.KeyLogger",
          "target": null
        },
        {
          "id": "Injector.JDO",
          "display_name": "Injector.JDO",
          "target": null
        },
        {
          "id": "Heur.Msword.Gen",
          "display_name": "Heur.Msword.Gen",
          "target": null
        },
        {
          "id": "PSW.Discord",
          "display_name": "PSW.Discord",
          "target": null
        },
        {
          "id": "Packed.VMProtect",
          "display_name": "Packed.VMProtect",
          "target": null
        },
        {
          "id": "HEUR:AdWare.StartSurf",
          "display_name": "HEUR:AdWare.StartSurf",
          "target": null
        },
        {
          "id": "Gen:Heur.NoobyProtect",
          "display_name": "Gen:Heur.NoobyProtect",
          "target": null
        },
        {
          "id": "CIL.HeapOverride",
          "display_name": "CIL.HeapOverride",
          "target": null
        },
        {
          "id": "HEUR:Trojan.Tasker",
          "display_name": "HEUR:Trojan.Tasker",
          "target": null
        },
        {
          "id": "XLM.Trojan.Abracadabra.27",
          "display_name": "XLM.Trojan.Abracadabra.27",
          "target": null
        },
        {
          "id": "HEUR:Backdoor.MSIL.NanoBot",
          "display_name": "HEUR:Backdoor.MSIL.NanoBot",
          "target": null
        },
        {
          "id": "Trojan.PSW.Mimikatz",
          "display_name": "Trojan.PSW.Mimikatz",
          "target": null
        },
        {
          "id": "TrojanSpy.Python",
          "display_name": "TrojanSpy.Python",
          "target": null
        },
        {
          "id": "Trojan.Ole2.Vbs",
          "display_name": "Trojan.Ole2.Vbs",
          "target": null
        },
        {
          "id": "Exploit.MSOffice",
          "display_name": "Exploit.MSOffice",
          "target": null
        },
        {
          "id": "DeepScan:Generic.Ransom.AmnesiaE",
          "display_name": "DeepScan:Generic.Ransom.AmnesiaE",
          "target": null
        },
        {
          "id": "Wacatac.D6",
          "display_name": "Wacatac.D6",
          "target": null
        },
        {
          "id": "Backdoor.Androm",
          "display_name": "Backdoor.Androm",
          "target": null
        },
        {
          "id": "Packed.NetSeal",
          "display_name": "Packed.NetSeal",
          "target": null
        },
        {
          "id": "Trojan.MSIL.Injector",
          "display_name": "Trojan.MSIL.Injector",
          "target": null
        },
        {
          "id": "Trojan.PWS.Agent",
          "display_name": "Trojan.PWS.Agent",
          "target": null
        },
        {
          "id": "TScope.Trojan",
          "display_name": "TScope.Trojan",
          "target": null
        },
        {
          "id": "PSW.Stealer",
          "display_name": "PSW.Stealer",
          "target": null
        },
        {
          "id": "Trojan.PackedNET",
          "display_name": "Trojan.PackedNET",
          "target": null
        },
        {
          "id": "Trojan.Java",
          "display_name": "Trojan.Java",
          "target": null
        },
        {
          "id": "MalwareX",
          "display_name": "MalwareX",
          "target": null
        },
        {
          "id": "Trojan.PSW.Python",
          "display_name": "Trojan.PSW.Python",
          "target": null
        },
        {
          "id": "malicious.11abfc",
          "display_name": "malicious.11abfc",
          "target": null
        },
        {
          "id": "Generic.ASMalwS",
          "display_name": "Generic.ASMalwS",
          "target": null
        },
        {
          "id": "HEUR:Trojan.MSIL.Tasker",
          "display_name": "HEUR:Trojan.MSIL.Tasker",
          "target": null
        },
        {
          "id": "PossibleThreat.PALLAS",
          "display_name": "PossibleThreat.PALLAS",
          "target": null
        },
        {
          "id": "Backdoor.Poison",
          "display_name": "Backdoor.Poison",
          "target": null
        },
        {
          "id": "Generic.MSIL.LimeRAT",
          "display_name": "Generic.MSIL.LimeRAT",
          "target": null
        },
        {
          "id": "PWS-FCZZ",
          "display_name": "PWS-FCZZ",
          "target": null
        },
        {
          "id": "Trojan.Script",
          "display_name": "Trojan.Script",
          "target": null
        },
        {
          "id": "Gen:Heur.MSIL.Inject",
          "display_name": "Gen:Heur.MSIL.Inject",
          "target": null
        },
        {
          "id": "Trojan.PWS.Growtopia",
          "display_name": "Trojan.PWS.Growtopia",
          "target": null
        },
        {
          "id": "Spyware.Bobik",
          "display_name": "Spyware.Bobik",
          "target": null
        },
        {
          "id": "HackTool.BruteForce",
          "display_name": "HackTool.BruteForce",
          "target": null
        },
        {
          "id": "Hack.Patcher",
          "display_name": "Hack.Patcher",
          "target": null
        },
        {
          "id": "PWS.p",
          "display_name": "PWS.p",
          "target": null
        },
        {
          "id": "Suppobox",
          "display_name": "Suppobox",
          "target": null
        },
        {
          "id": "index.php",
          "display_name": "index.php",
          "target": null
        },
        {
          "id": "Packed.VMProtect",
          "display_name": "Packed.VMProtect",
          "target": null
        },
        {
          "id": "SmokeLoader",
          "display_name": "SmokeLoader",
          "target": null
        },
        {
          "id": "Generic.Malware",
          "display_name": "Generic.Malware",
          "target": null
        },
        {
          "id": "SNH:Script [Dropper]",
          "display_name": "SNH:Script [Dropper]",
          "target": null
        },
        {
          "id": "HEUR:Trojan.MSOffice.SAgent",
          "display_name": "HEUR:Trojan.MSOffice.SAgent",
          "target": null
        },
        {
          "id": "Script.INF",
          "display_name": "Script.INF",
          "target": null
        },
        {
          "id": "JS:Trojan.JS.Likejack",
          "display_name": "JS:Trojan.JS.Likejack",
          "target": null
        },
        {
          "id": "SNH:Script [Dropper]",
          "display_name": "SNH:Script [Dropper]",
          "target": null
        },
        {
          "id": "Trojan.JS.Agent",
          "display_name": "Trojan.JS.Agent",
          "target": null
        },
        {
          "id": "APT Notes",
          "display_name": "APT Notes",
          "target": null
        },
        {
          "id": "susp.rtf.objupdate",
          "display_name": "susp.rtf.objupdate",
          "target": null
        },
        {
          "id": "RedCap.zoohz",
          "display_name": "RedCap.zoohz",
          "target": null
        },
        {
          "id": "Trojan.Tasker",
          "display_name": "Trojan.Tasker",
          "target": null
        },
        {
          "id": "virus.office.qexvmc",
          "display_name": "virus.office.qexvmc",
          "target": null
        },
        {
          "id": "Trojan.KillProc",
          "display_name": "Trojan.KillProc",
          "target": null
        },
        {
          "id": "Generic.MSIL.GrwtpStealer.1",
          "display_name": "Generic.MSIL.GrwtpStealer.1",
          "target": null
        },
        {
          "id": "Suspicious.Cloud",
          "display_name": "Suspicious.Cloud",
          "target": null
        },
        {
          "id": "PowerShell.DownLoader",
          "display_name": "PowerShell.DownLoader",
          "target": null
        },
        {
          "id": "Downldr.gen",
          "display_name": "Downldr.gen",
          "target": null
        },
        {
          "id": "AGEN.1030939",
          "display_name": "AGEN.1030939",
          "target": null
        },
        {
          "id": "HackTool.Binder",
          "display_name": "HackTool.Binder",
          "target": null
        },
        {
          "id": "Trojan.Inject",
          "display_name": "Trojan.Inject",
          "target": null
        },
        {
          "id": "Dldr.Agent",
          "display_name": "Dldr.Agent",
          "target": null
        },
        {
          "id": "Dropper.MSIL",
          "display_name": "Dropper.MSIL",
          "target": null
        },
        {
          "id": "Trojan.VBKryjetor",
          "display_name": "Trojan.VBKryjetor",
          "target": null
        },
        {
          "id": "PWSX",
          "display_name": "PWSX",
          "target": null
        },
        {
          "id": "VB:Trojan.VBA.Agent",
          "display_name": "VB:Trojan.VBA.Agent",
          "target": null
        },
        {
          "id": "HEUR:Trojan.MSOffice.Stratos",
          "display_name": "HEUR:Trojan.MSOffice.Stratos",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1071.001",
          "name": "Web Protocols",
          "display_name": "T1071.001 - Web Protocols"
        },
        {
          "id": "T1071.004",
          "name": "DNS",
          "display_name": "T1071.004 - DNS"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1059.007",
          "name": "JavaScript",
          "display_name": "T1059.007 - JavaScript"
        },
        {
          "id": "T1497",
          "name": "Virtualization/Sandbox Evasion",
          "display_name": "T1497 - Virtualization/Sandbox Evasion"
        },
        {
          "id": "T1068",
          "name": "Exploitation for Privilege Escalation",
          "display_name": "T1068 - Exploitation for Privilege Escalation"
        },
        {
          "id": "TA0029",
          "name": "Privilege Escalation",
          "display_name": "TA0029 - Privilege Escalation"
        },
        {
          "id": "T1449",
          "name": "Exploit SS7 to Redirect Phone Calls/SMS",
          "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
        },
        {
          "id": "T1190",
          "name": "Exploit Public-Facing Application",
          "display_name": "T1190 - Exploit Public-Facing Application"
        },
        {
          "id": "T1210",
          "name": "Exploitation of Remote Services",
          "display_name": "T1210 - Exploitation of Remote Services"
        },
        {
          "id": "T1450",
          "name": "Exploit SS7 to Track Device Location",
          "display_name": "T1450 - Exploit SS7 to Track Device Location"
        },
        {
          "id": "T1211",
          "name": "Exploitation for Defense Evasion",
          "display_name": "T1211 - Exploitation for Defense Evasion"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "TA0011",
          "name": "Command and Control",
          "display_name": "TA0011 - Command and Control"
        },
        {
          "id": "T1412",
          "name": "Capture SMS Messages",
          "display_name": "T1412 - Capture SMS Messages"
        },
        {
          "id": "T1454",
          "name": "Malicious SMS Message",
          "display_name": "T1454 - Malicious SMS Message"
        },
        {
          "id": "T1001",
          "name": "Data Obfuscation",
          "display_name": "T1001 - Data Obfuscation"
        },
        {
          "id": "T1114",
          "name": "Email Collection",
          "display_name": "T1114 - Email Collection"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1498",
          "name": "Network Denial of Service",
          "display_name": "T1498 - Network Denial of Service"
        },
        {
          "id": "T1496",
          "name": "Resource Hijacking",
          "display_name": "T1496 - Resource Hijacking"
        },
        {
          "id": "T1176",
          "name": "Browser Extensions",
          "display_name": "T1176 - Browser Extensions"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": "654c597a4a45c8d84f0b15c1",
      "export_count": 341,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "scoreblue",
        "id": "254100",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 1184,
        "FileHash-SHA1": 949,
        "FileHash-SHA256": 3712,
        "URL": 2925,
        "domain": 627,
        "hostname": 1319,
        "CVE": 26,
        "email": 8,
        "CIDR": 2
      },
      "indicator_count": 10752,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 231,
      "modified_text": "904 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6558126013aef7ce80968842",
      "name": "PuffStealer",
      "description": "",
      "modified": "2023-12-09T03:01:57.989000",
      "created": "2023-11-18T01:24:48.887000",
      "tags": [
        "ssl certificate",
        "historical ssl",
        "communicating",
        "contacted",
        "resolutions",
        "whois record",
        "whois whois",
        "whois parent",
        "whois siblings",
        "skynet",
        "threat report",
        "ip summary",
        "url summary",
        "summary",
        "sample",
        "samples",
        "detection list",
        "blacklist",
        "cisco umbrella",
        "site",
        "safe site",
        "million",
        "team",
        "microsoft",
        "back",
        "download",
        "phishing",
        "union",
        "bank",
        "malicious site",
        "blacklist http",
        "exit",
        "traffic",
        "node tcp",
        "tor known",
        "tor relayrouter",
        "et tor",
        "known tor",
        "relayrouter",
        "anonymizer",
        "spammer",
        "malware",
        "dropped",
        "unlocker",
        "http",
        "critical risk",
        "redline stealer",
        "core",
        "hacktool",
        "execution",
        "type win32",
        "exe size",
        "first seen",
        "file name",
        "avast win32",
        "win32",
        "avg win32",
        "fortinet",
        "vitro",
        "mb first",
        "rmndrp",
        "clean mx",
        "undetected dns8",
        "undetected vx",
        "sophos",
        "vault",
        "zdb zeus",
        "cmc threat",
        "snort ip",
        "feodo tracker",
        "cybereason",
        "send bug",
        "pe yandex",
        "no data",
        "tag count",
        "count blacklist",
        "tag tag",
        "algorithm",
        "v3 serial",
        "number",
        "issuer",
        "cus cnr3",
        "olet",
        "subject public",
        "key info",
        "key algorithm",
        "key identifier",
        "first",
        "seen",
        "valid",
        "no na",
        "no no",
        "ip security",
        "cndst root",
        "ca x3",
        "ca id",
        "research group",
        "cnisrg root",
        "no expired",
        "mozilla",
        "android",
        "malicious red team",
        "tsara brashears",
        "cyber stalking",
        "malvertizing",
        "invasion of privacy",
        "threat",
        "adult content",
        "apple",
        "iphone unlocker",
        "android",
        "exploited spyware",
        "malware host",
        "brute force",
        "revenge-rat",
        "banker",
        "evasive",
        "domain",
        "redline",
        "stealer",
        "phishing",
        "ramnit",
        "unreliable subdomains",
        "dridex",
        "gating",
        "msil",
        "rat",
        "loki",
        "network",
        "hacking",
        "sinkhole",
        "azorult",
        "c2",
        "historicalandnew",
        "targeted attack",
        "puffstealer",
        "rultazo",
        "lokibot",
        "loki pws",
        "burkina",
        "banker,dde,dridex,exploit",
        "banker,dridex,evasive",
        "trickbot",
        "ransomware,torrentlocker",
        "exploit_source",
        "blacknet",
        "FileRepMalware",
        "linux agent",
        "blacknet",
        "ios",
        "phishing paypal",
        "tagging",
        "defacement",
        "hit",
        "bounty",
        "phishing site",
        "malware site",
        "malware download",
        "endangerment",
        "Malicious domain - SANS Internet Storm Center",
        "evasive,msil,rat,revenge-rat",
        "prism_setting",
        "prism_object",
        "static engine",
        "social engineering",
        "jansky",
        "worm",
        "network rat",
        "networm",
        "Loki Password Stealer (PWS)",
        "South Carolina Federal Credit Union phishing",
        "darkweb",
        "yandex",
        "redirectors",
        "blacknet threats",
        "phishing,ransomware,sinkhole",
        "wanacrypt0r,wannacry,wcry",
        "tor c++",
        "tor c++ client",
        "python user",
        "js user",
        "hacker",
        "hijacker",
        "heur",
        "maltiverse",
        "alexa top",
        "exploit",
        "riskware",
        "unsafe",
        "outbreak",
        "downer",
        "shell",
        "mediamagnet",
        "sality",
        "swrort",
        "adaptivebee",
        "unruy",
        "iobit",
        "dropper",
        "trojanx",
        "artemis",
        "installcore",
        "webshell",
        "crack",
        "webtoolbar",
        "search live",
        "api blog",
        "docs pricing",
        "november",
        "de indicators",
        "domains",
        "hashes",
        "__convergedlogin_pcustomizationloader_44b450e8d543eb53930d",
        "malicious url",
        "financial",
        "blacknet rat",
        "azorult",
        "stealer",
        "deep scan",
        "blacklist https",
        "referrer",
        "collections kp",
        "incident ip",
        "sneaky server",
        "replacement",
        "unauthorized",
        "emotet",
        "noname057",
        "generic malware",
        "engineering",
        "cyber threat",
        "facebook",
        "paypal",
        "dropbox",
        "united",
        "america",
        "banking",
        "wells fargo",
        "steam",
        "twitter",
        "sliver",
        "daum",
        "swift",
        "runescape",
        "betabot",
        "district",
        "iframe",
        "alexa",
        "downldr",
        "agent",
        "presenoker",
        "bladabindi",
        "live",
        "conduit",
        "pony",
        "covid19",
        "malicious",
        "cobalt strike",
        "suppobox",
        "ramnit",
        "meterpreter",
        "virut",
        "njrat",
        "pykspa",
        "asyncrat",
        "downloader",
        "fakealert",
        "binder",
        "virustotal",
        "formbook",
        "necurs",
        "trojan",
        "msil",
        "hiloti",
        "vawtrak",
        "simda",
        "kraken",
        "solimba",
        "icedid",
        "redirector",
        "suspic",
        "amadey",
        "raccoon",
        "nanocore rat",
        "revenge rat",
        "genkryptik",
        "fuery",
        "wacatac",
        "service",
        "cloudeye",
        "tinba",
        "domaiq",
        "ave maria",
        "zeus",
        "ransomware",
        "zbot",
        "generic",
        "trojanspy",
        "states",
        "inmortal",
        "locky",
        "strike",
        "china cobalt",
        "keybase",
        "cutwail",
        "citadel",
        "radamant",
        "kovter",
        "bradesco",
        "nymaim",
        "amonetize",
        "bondat",
        "ghost rat",
        "vjw0rm",
        "bandoo",
        "matsnu",
        "dnspionage",
        "darkgate",
        "vidar",
        "keylogger",
        "remcos",
        "agenttesla",
        "detplock",
        "win64",
        "smokeloader",
        "agent tesla",
        "kgs0",
        "kls0",
        "urls",
        "type name",
        "dns replication",
        "date",
        "domain",
        "win32 exe",
        "files",
        "detections type",
        "name",
        "drpsuinstaller",
        "vdfsurfs",
        "opera",
        "icwrmind",
        "notepad",
        "installer",
        "miner",
        "unknown",
        "networm",
        "houdini",
        "quasar rat",
        "gamehack",
        "dbatloader",
        "qakbot",
        "ursnif",
        "CVE-2005-1790",
        "CVE-2009-3672",
        "CVE-2010-3962",
        "CVE-2012-3993",
        "CVE-2014-6332",
        "CVE-2017-11882",
        "CVE-2020-0601",
        "CVE-2020-0674",
        "hallrender.com",
        "brian sabey",
        "insurance",
        "botnetwork",
        "botmaster",
        "command_and_control",
        "CVE-2021-27065",
        "CVE-2021-40444",
        "CVE-2023-4966",
        "CVE-2017-0199",
        "CVE-2018-4893",
        "CVE-2010-3333",
        "CVE-2015-1641",
        "CVE-2017-0147",
        "CVE-2017-8570",
        "CVE-2018-0802",
        "CVE-2018-8373",
        "CVE-2017-8759",
        "CVE-2018-8453",
        "CVE-2014-3153",
        "CVE-2015-1650",
        "CVE-2017-0143",
        "CVE-2017-8464",
        "Icefog",
        "Delf.NBX",
        "$WebWatson",
        "Gen:Heur.Ransom.HiddenTears",
        "mobilekey.pw",
        "bitbucket.org",
        "Anomalous.100%",
        "malware distribution site",
        "gootkit",
        "edsaid",
        "rightsaided",
        "betabot",
        "cobaltstrike4.tk",
        "mas.to",
        "BehavesLike.YahLover",
        "srdvd16010404",
        "languageenu",
        "buildno",
        "channelisales",
        "vendorname2581",
        "osregion",
        "device",
        "systemlocale",
        "majorver16",
        "quasar",
        "find",
        "lockbit",
        "chaos",
        "ransomexx",
        "grandoreiro",
        "evilnum",
        "banker"
      ],
      "references": [
        "https://hybrid-analysis.com/sample/6765f47ea77c8274c8e4973ed95aedf59e75998c62f6029e23c58cdf36ed85ba/654afdbdc621e7037801cce7",
        "20.99.186.246 exploit source",
        "fp2e7a.wpc.2be4.phicdn.net",
        "https://www.anyxxxtube.net/search-porn/tsara-brashears/ (phishing, ELF, Prism.exe found)",
        "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian (password cracker)",
        "http://182.22.25.124:7878/182.22.25.124:443     (malicious dropper)",
        "init.ess.apple.com         (malicious code script)",
        "https://www.pornhub.com/video/search?search=tsara+brashears (Malicious PW cracker | stylebk.css stylesheets - not found )",
        "https://urlscan.io/result/a328d9ff-fb49-4078-960d-a757fd41404f/#indicators",
        "VirusTotal Link: https://www.virustotal.com/gui/ip-address/20.99.186.246/detection",
        "Abuse IPDB Link: https://www.abuseipdb.com/check/20.99.186.246",
        "IPv4 45.12.253.72.            command_and_control",
        "Hostname: ddos.dnsnb8.net                        command_and_control",
        "IPv4 95.213.186.51              command_and_control",
        "Hostname: www.supernetforme.com      command_and_control",
        "IPv4 103.224.182.246        command_and_control",
        "IPv4 72.251.233.245           command_and_control",
        "IPv4 63.251.106.25             command_and_control",
        "IPv4 45.15.156.208            command_and_control",
        "IPv4 104.247.81.51             command_and_control",
        "http://ambisexual.phone-sex-blogs.com/http:/ambisexual.phone-sex-blogs.com/images/thumbnails/pic118.jpg             (phishing)",
        "https://downloaddevtools.ir/     (phishing)",
        "happylifehappywife.com",
        "apples.encryptedwork.com        (Interesting in the blacknet)",
        "https://itunes.apple.com/app/apple-store/id284815942/us/app/samsung-galaxy-watch-gear-s/id1117310635.                   (iOS unlocker and hijacker)",
        "https://www.anyxxxtube.net/media/favicon/apple              (password cracker and iOS hijacker)",
        "https://www.apple.com/shop/browse/open/country_selector     (exploit)",
        "www.norad.mil   (federal tracking tool used by attorneys, law firms, and private investigators 'licensed or unlicensed') hi!",
        "http://init-p01st.push.apple.com/bag            (malicious web creator)",
        "opencve.djgummikuh.de        (CVE dispensary)",
        "Maltiverse Research Team",
        "URLscan.io",
        "Deep Research",
        "Hybrid Analysis",
        "URLhaus Abuse.ch",
        "Cyber Threat Coalition",
        "ThreatFox Abuse.ch"
      ],
      "public": 1,
      "adversary": "Lucky Mouse APT27 | NoName057(16) |  Unnamed",
      "targeted_countries": [
        "United States of America",
        "France",
        "Spain"
      ],
      "malware_families": [
        {
          "id": "Feodo",
          "display_name": "Feodo",
          "target": null
        },
        {
          "id": "Dridex",
          "display_name": "Dridex",
          "target": null
        },
        {
          "id": "Redline Stealer",
          "display_name": "Redline Stealer",
          "target": null
        },
        {
          "id": "Ramnit.N",
          "display_name": "Ramnit.N",
          "target": null
        },
        {
          "id": "Loki Bot",
          "display_name": "Loki Bot",
          "target": null
        },
        {
          "id": "Loki Password Stealer (PWS)",
          "display_name": "Loki Password Stealer (PWS)",
          "target": null
        },
        {
          "id": "AZORult",
          "display_name": "AZORult",
          "target": null
        },
        {
          "id": "Zbd Zeus",
          "display_name": "Zbd Zeus",
          "target": null
        },
        {
          "id": "Trojan:MSIL/Burkina",
          "display_name": "Trojan:MSIL/Burkina",
          "target": "/malware/Trojan:MSIL/Burkina"
        },
        {
          "id": "Generic.TrickBot.1",
          "display_name": "Generic.TrickBot.1",
          "target": null
        },
        {
          "id": "Exploit.CVE",
          "display_name": "Exploit.CVE",
          "target": null
        },
        {
          "id": "Injector.IS.gen",
          "display_name": "Injector.IS.gen",
          "target": null
        },
        {
          "id": "Gen:Variant.Razy",
          "display_name": "Gen:Variant.Razy",
          "target": null
        },
        {
          "id": "Trojan.Androm.Gen",
          "display_name": "Trojan.Androm.Gen",
          "target": null
        },
        {
          "id": "HEUR:Trojan.Linux.Agent",
          "display_name": "HEUR:Trojan.Linux.Agent",
          "target": null
        },
        {
          "id": "BScope.Trojan",
          "display_name": "BScope.Trojan",
          "target": null
        },
        {
          "id": "VBA.Downloader",
          "display_name": "VBA.Downloader",
          "target": null
        },
        {
          "id": "Trojan.Notifier",
          "display_name": "Trojan.Notifier",
          "target": null
        },
        {
          "id": "HEUR:Trojan.MSOffice.Alien",
          "display_name": "HEUR:Trojan.MSOffice.Alien",
          "target": null
        },
        {
          "id": "Unsafe.AI_Score_100%",
          "display_name": "Unsafe.AI_Score_100%",
          "target": null
        },
        {
          "id": "Gen:Variant.Johnnie",
          "display_name": "Gen:Variant.Johnnie",
          "target": null
        },
        {
          "id": "DangerousObject.Multi",
          "display_name": "DangerousObject.Multi",
          "target": null
        },
        {
          "id": "Trojan:Python/Downldr",
          "display_name": "Trojan:Python/Downldr",
          "target": "/malware/Trojan:Python/Downldr"
        },
        {
          "id": "Trojan:Linux/Downldr",
          "display_name": "Trojan:Linux/Downldr",
          "target": "/malware/Trojan:Linux/Downldr"
        },
        {
          "id": "Trojan:VBA/Downldr",
          "display_name": "Trojan:VBA/Downldr",
          "target": "/malware/Trojan:VBA/Downldr"
        },
        {
          "id": "TrojanDownloader:Linux/Downldr",
          "display_name": "TrojanDownloader:Linux/Downldr",
          "target": "/malware/TrojanDownloader:Linux/Downldr"
        },
        {
          "id": "Kryptik.FPH.gen",
          "display_name": "Kryptik.FPH.gen",
          "target": null
        },
        {
          "id": "TROJ_FRS.VSNTFK19",
          "display_name": "TROJ_FRS.VSNTFK19",
          "target": null
        },
        {
          "id": "Trojan.Ransom.GenericKD",
          "display_name": "Trojan.Ransom.GenericKD",
          "target": null
        },
        {
          "id": "Phish.JAT",
          "display_name": "Phish.JAT",
          "target": null
        },
        {
          "id": "Phishing.HTML",
          "display_name": "Phishing.HTML",
          "target": null
        },
        {
          "id": "Generic.ASMalwS",
          "display_name": "Generic.ASMalwS",
          "target": null
        },
        {
          "id": "Phish.AB",
          "display_name": "Phish.AB",
          "target": null
        },
        {
          "id": "Generic.Malware",
          "display_name": "Generic.Malware",
          "target": null
        },
        {
          "id": "ml.Generic",
          "display_name": "ml.Generic",
          "target": null
        },
        {
          "id": "Xegumumune.8596c22f",
          "display_name": "Xegumumune.8596c22f",
          "target": null
        },
        {
          "id": "Generic.Malware.SMYB",
          "display_name": "Generic.Malware.SMYB",
          "target": null
        },
        {
          "id": "malicious.moderate.ml",
          "display_name": "malicious.moderate.ml",
          "target": null
        },
        {
          "id": "Agent.NBAE",
          "display_name": "Agent.NBAE",
          "target": null
        },
        {
          "id": "AGEN.1045227",
          "display_name": "AGEN.1045227",
          "target": null
        },
        {
          "id": "Riskware.Agent",
          "display_name": "Riskware.Agent",
          "target": null
        },
        {
          "id": "Gen:Variant.Cerbu",
          "display_name": "Gen:Variant.Cerbu",
          "target": null
        },
        {
          "id": "IL:Trojan.MSILZilla",
          "display_name": "IL:Trojan.MSILZilla",
          "target": null
        },
        {
          "id": "Dropped:Generic.Ransom.DMR",
          "display_name": "Dropped:Generic.Ransom.DMR",
          "target": null
        },
        {
          "id": "Delf.NBX",
          "display_name": "Delf.NBX",
          "target": null
        },
        {
          "id": "malicious.f01f67",
          "display_name": "malicious.f01f67",
          "target": null
        },
        {
          "id": "AGEN.1144657",
          "display_name": "AGEN.1144657",
          "target": null
        },
        {
          "id": "Trojan.Heur",
          "display_name": "Trojan.Heur",
          "target": null
        },
        {
          "id": "Trojan.Malware.300983",
          "display_name": "Trojan.Malware.300983",
          "target": null
        },
        {
          "id": "SdBot.CAOC",
          "display_name": "SdBot.CAOC",
          "target": null
        },
        {
          "id": "Trojan.DelShad",
          "display_name": "Trojan.DelShad",
          "target": null
        },
        {
          "id": "Exploit CVE-2017-11882",
          "display_name": "Exploit CVE-2017-11882",
          "target": null
        },
        {
          "id": "GameHack.NL",
          "display_name": "GameHack.NL",
          "target": null
        },
        {
          "id": "JS:Trojan.HideLink",
          "display_name": "JS:Trojan.HideLink",
          "target": null
        },
        {
          "id": "Script.Agent",
          "display_name": "Script.Agent",
          "target": null
        },
        {
          "id": "Macro.Agent",
          "display_name": "Macro.Agent",
          "target": null
        },
        {
          "id": "Macro.Downloader.AMIP",
          "display_name": "Macro.Downloader.AMIP",
          "target": null
        },
        {
          "id": "Trojan.VBA",
          "display_name": "Trojan.VBA",
          "target": null
        },
        {
          "id": "HEUR.VBA.Trojan",
          "display_name": "HEUR.VBA.Trojan",
          "target": null
        },
        {
          "id": "VB.EmoooDldr.10",
          "display_name": "VB.EmoooDldr.10",
          "target": null
        },
        {
          "id": "VB:Trojan.Valyria",
          "display_name": "VB:Trojan.Valyria",
          "target": null
        },
        {
          "id": "OpenSubtitles.A",
          "display_name": "OpenSubtitles.A",
          "target": null
        },
        {
          "id": "VB.EmoDldr.4",
          "display_name": "VB.EmoDldr.4",
          "target": null
        },
        {
          "id": "Packed-GV",
          "display_name": "Packed-GV",
          "target": null
        },
        {
          "id": "Adware.InstallMonetizer",
          "display_name": "Adware.InstallMonetizer",
          "target": null
        },
        {
          "id": "Skynet",
          "display_name": "Skynet",
          "target": null
        },
        {
          "id": "HW32.Packed",
          "display_name": "HW32.Packed",
          "target": null
        },
        {
          "id": "Zpevdo.B",
          "display_name": "Zpevdo.B",
          "target": null
        },
        {
          "id": "Presenoker",
          "display_name": "Presenoker",
          "target": null
        },
        {
          "id": "SGeneric",
          "display_name": "SGeneric",
          "target": null
        },
        {
          "id": "GameHack.DOM",
          "display_name": "GameHack.DOM",
          "target": null
        },
        {
          "id": "BehavesLike.Ransom",
          "display_name": "BehavesLike.Ransom",
          "target": null
        },
        {
          "id": "CIL.StupidCryptor",
          "display_name": "CIL.StupidCryptor",
          "target": null
        },
        {
          "id": "Gen:Heur.Ransom.MSIL",
          "display_name": "Gen:Heur.Ransom.MSIL",
          "target": null
        },
        {
          "id": "Black.Gen2",
          "display_name": "Black.Gen2",
          "target": null
        },
        {
          "id": "GameHack.CRS",
          "display_name": "GameHack.CRS",
          "target": null
        },
        {
          "id": "Trojan.HTML.PHISH",
          "display_name": "Trojan.HTML.PHISH",
          "target": null
        },
        {
          "id": "Gen:Heur.MSIL.Inject",
          "display_name": "Gen:Heur.MSIL.Inject",
          "target": null
        },
        {
          "id": "Program.Unwanted",
          "display_name": "Program.Unwanted",
          "target": null
        },
        {
          "id": "HEUR/QVM42.3.72EB.Malware",
          "display_name": "HEUR/QVM42.3.72EB.Malware",
          "target": null
        },
        {
          "id": "suspicious.low.ml",
          "display_name": "suspicious.low.ml",
          "target": null
        },
        {
          "id": "JS:Trojan.Cryxos",
          "display_name": "JS:Trojan.Cryxos",
          "target": null
        },
        {
          "id": "Suspicious_GEN.F47V0520",
          "display_name": "Suspicious_GEN.F47V0520",
          "target": null
        },
        {
          "id": "Dropper.Trojan.Generic",
          "display_name": "Dropper.Trojan.Generic",
          "target": null
        },
        {
          "id": "Trojan.TrickBot",
          "display_name": "Trojan.TrickBot",
          "target": null
        },
        {
          "id": "Malware.Tk.Generic",
          "display_name": "Malware.Tk.Generic",
          "target": null
        },
        {
          "id": "TrojanSpy.Java",
          "display_name": "TrojanSpy.Java",
          "target": null
        },
        {
          "id": "Riskware.NetFilter",
          "display_name": "Riskware.NetFilter",
          "target": null
        },
        {
          "id": "RiskWare.Crack",
          "display_name": "RiskWare.Crack",
          "target": null
        },
        {
          "id": "BehavesLike.Exploit",
          "display_name": "BehavesLike.Exploit",
          "target": null
        },
        {
          "id": "Gen:NN.ZemsilF.34128",
          "display_name": "Gen:NN.ZemsilF.34128",
          "target": null
        },
        {
          "id": "Wacapew.C",
          "display_name": "Wacapew.C",
          "target": null
        },
        {
          "id": "Trojan.Malware.121218",
          "display_name": "Trojan.Malware.121218",
          "target": null
        },
        {
          "id": "RiskWare.HackTool.Agent",
          "display_name": "RiskWare.HackTool.Agent",
          "target": null
        },
        {
          "id": "Artemis",
          "display_name": "Artemis",
          "target": null
        },
        {
          "id": "Trojan.Generic",
          "display_name": "Trojan.Generic",
          "target": null
        },
        {
          "id": "W32.Trojan",
          "display_name": "W32.Trojan",
          "target": null
        },
        {
          "id": "BScope.Riskware",
          "display_name": "BScope.Riskware",
          "target": null
        },
        {
          "id": "Gen:Variant.Bulz",
          "display_name": "Gen:Variant.Bulz",
          "target": null
        },
        {
          "id": "Ransom:Win32/CVE-2017-0147",
          "display_name": "Ransom:Win32/CVE-2017-0147",
          "target": "/malware/Ransom:Win32/CVE-2017-0147"
        },
        {
          "id": "Virus.Ramnit",
          "display_name": "Virus.Ramnit",
          "target": null
        },
        {
          "id": "Virus.Virut",
          "display_name": "Virus.Virut",
          "target": null
        },
        {
          "id": "Adware.KuziTui",
          "display_name": "Adware.KuziTui",
          "target": null
        },
        {
          "id": "AGEN.1141126",
          "display_name": "AGEN.1141126",
          "target": null
        },
        {
          "id": "W32.AIDetect",
          "display_name": "W32.AIDetect",
          "target": null
        },
        {
          "id": "Trojan.Python",
          "display_name": "Trojan.Python",
          "target": null
        },
        {
          "id": "W32.AIDetectVM",
          "display_name": "W32.AIDetectVM",
          "target": null
        },
        {
          "id": "Suspicious.Save",
          "display_name": "Suspicious.Save",
          "target": null
        },
        {
          "id": "Adware.Downware",
          "display_name": "Adware.Downware",
          "target": null
        },
        {
          "id": "Ransom.Win64.Wacatac.oa",
          "display_name": "Ransom.Win64.Wacatac.oa",
          "target": null
        },
        {
          "id": "OpenSubtitles.A",
          "display_name": "OpenSubtitles.A",
          "target": null
        },
        {
          "id": "VB.EmoDldr.4",
          "display_name": "VB.EmoDldr.4",
          "target": null
        },
        {
          "id": "Gen:Variant.Midie",
          "display_name": "Gen:Variant.Midie",
          "target": null
        },
        {
          "id": "HEUR/QVM41.2.DA9B.Malware",
          "display_name": "HEUR/QVM41.2.DA9B.Malware",
          "target": null
        },
        {
          "id": "Gen:Variant.Sirefef",
          "display_name": "Gen:Variant.Sirefef",
          "target": null
        },
        {
          "id": "Macro.Trojan.Dropperd",
          "display_name": "Macro.Trojan.Dropperd",
          "target": null
        },
        {
          "id": "BlackNET RAT",
          "display_name": "BlackNET RAT",
          "target": null
        },
        {
          "id": "Gen:Variant.Ursu",
          "display_name": "Gen:Variant.Ursu",
          "target": null
        },
        {
          "id": "Redcap.rlhse",
          "display_name": "Redcap.rlhse",
          "target": null
        },
        {
          "id": "Trojan.Trickster",
          "display_name": "Trojan.Trickster",
          "target": null
        },
        {
          "id": "HTML_REDIR.SMR",
          "display_name": "HTML_REDIR.SMR",
          "target": null
        },
        {
          "id": "TROJ_FRS.VSNTFK19",
          "display_name": "TROJ_FRS.VSNTFK19",
          "target": null
        },
        {
          "id": "Hoax.JS.Phish",
          "display_name": "Hoax.JS.Phish",
          "target": null
        },
        {
          "id": "JS:Iframe",
          "display_name": "JS:Iframe",
          "target": null
        },
        {
          "id": "Application.SQLCrack",
          "display_name": "Application.SQLCrack",
          "target": null
        },
        {
          "id": "susp.lnk",
          "display_name": "susp.lnk",
          "target": null
        },
        {
          "id": "QVM201.0.B70B.Malware",
          "display_name": "QVM201.0.B70B.Malware",
          "target": null
        },
        {
          "id": "Immortal Stealer",
          "display_name": "Immortal Stealer",
          "target": null
        },
        {
          "id": "WebMonitor RAT",
          "display_name": "WebMonitor RAT",
          "target": null
        },
        {
          "id": "Tor - S0183",
          "display_name": "Tor - S0183",
          "target": null
        },
        {
          "id": "WannaCry",
          "display_name": "WannaCry",
          "target": null
        },
        {
          "id": "WannaCryptor",
          "display_name": "WannaCryptor",
          "target": null
        },
        {
          "id": "WebToolbar",
          "display_name": "WebToolbar",
          "target": null
        },
        {
          "id": "BlackNET",
          "display_name": "BlackNET",
          "target": null
        },
        {
          "id": "DeepScan:Generic.Ransom.GandCrab5",
          "display_name": "DeepScan:Generic.Ransom.GandCrab5",
          "target": null
        },
        {
          "id": "TrojanSpy",
          "display_name": "TrojanSpy",
          "target": null
        },
        {
          "id": "States",
          "display_name": "States",
          "target": null
        },
        {
          "id": "Inmortal",
          "display_name": "Inmortal",
          "target": null
        },
        {
          "id": "Domains",
          "display_name": "Domains",
          "target": null
        },
        {
          "id": "Locky",
          "display_name": "Locky",
          "target": null
        },
        {
          "id": "Delf.NBX",
          "display_name": "Delf.NBX",
          "target": null
        },
        {
          "id": "Gen:NN.ZexaF.32515",
          "display_name": "Gen:NN.ZexaF.32515",
          "target": null
        },
        {
          "id": "FileRepMalware",
          "display_name": "FileRepMalware",
          "target": null
        },
        {
          "id": "Gen:Variant.MSILPerseus",
          "display_name": "Gen:Variant.MSILPerseus",
          "target": null
        },
        {
          "id": "Icefog",
          "display_name": "Icefog",
          "target": null
        },
        {
          "id": "$WebWatson",
          "display_name": "$WebWatson",
          "target": null
        },
        {
          "id": "Agent.AIK.gen",
          "display_name": "Agent.AIK.gen",
          "target": null
        },
        {
          "id": "Agent.AIK.genCIL.StupidCryptor",
          "display_name": "Agent.AIK.genCIL.StupidCryptor",
          "target": null
        },
        {
          "id": "Agent.YPEZ",
          "display_name": "Agent.YPEZ",
          "target": null
        },
        {
          "id": "Application.InnovativSol",
          "display_name": "Application.InnovativSol",
          "target": null
        },
        {
          "id": "Agent.ASO",
          "display_name": "Agent.ASO",
          "target": null
        },
        {
          "id": "S-b748adc5",
          "display_name": "S-b748adc5",
          "target": null
        },
        {
          "id": "W32.eHeur",
          "display_name": "W32.eHeur",
          "target": null
        },
        {
          "id": "Kryptik.GUCB",
          "display_name": "Kryptik.GUCB",
          "target": null
        },
        {
          "id": "AgentTesla",
          "display_name": "AgentTesla",
          "target": null
        },
        {
          "id": "Autoit.bimwt",
          "display_name": "Autoit.bimwt",
          "target": null
        },
        {
          "id": "HEUR:Trojan.OLE2.Alien",
          "display_name": "HEUR:Trojan.OLE2.Alien",
          "target": null
        },
        {
          "id": "AGEN.1038489",
          "display_name": "AGEN.1038489",
          "target": null
        },
        {
          "id": "Gen:Variant.Ser.Strictor",
          "display_name": "Gen:Variant.Ser.Strictor",
          "target": null
        },
        {
          "id": "Packed.Themida.Gen",
          "display_name": "Packed.Themida.Gen",
          "target": null
        },
        {
          "id": "AGEN.1043164",
          "display_name": "AGEN.1043164",
          "target": null
        },
        {
          "id": "TrickBot - S0266",
          "display_name": "TrickBot - S0266",
          "target": null
        },
        {
          "id": "Emotet",
          "display_name": "Emotet",
          "target": null
        },
        {
          "id": "Trojan.PornoAsset",
          "display_name": "Trojan.PornoAsset",
          "target": null
        },
        {
          "id": "Ransom.Win64.PORNOASSET.SM1",
          "display_name": "Ransom.Win64.PORNOASSET.SM1",
          "target": null
        },
        {
          "id": "Gen:Variant.Ulise",
          "display_name": "Gen:Variant.Ulise",
          "target": null
        },
        {
          "id": "Trojan.Win64",
          "display_name": "Trojan.Win64",
          "target": null
        },
        {
          "id": "Dropper.Trojan.Agent",
          "display_name": "Dropper.Trojan.Agent",
          "target": null
        },
        {
          "id": "Heur.BZC.YAX.Pantera.10",
          "display_name": "Heur.BZC.YAX.Pantera.10",
          "target": null
        },
        {
          "id": "malicious.high.ml",
          "display_name": "malicious.high.ml",
          "target": null
        },
        {
          "id": "CVE-2015-1650",
          "display_name": "CVE-2015-1650",
          "target": null
        },
        {
          "id": "Worm.Win64.AutoRun",
          "display_name": "Worm.Win64.AutoRun",
          "target": null
        },
        {
          "id": "AIT.Heur.Cottonmouth.8.78F19BD7",
          "display_name": "AIT.Heur.Cottonmouth.8.78F19BD7",
          "target": null
        },
        {
          "id": "Gen:Variant.Mikey",
          "display_name": "Gen:Variant.Mikey",
          "target": null
        },
        {
          "id": "Trojan.Agent",
          "display_name": "Trojan.Agent",
          "target": null
        },
        {
          "id": "Pua.Gen",
          "display_name": "Pua.Gen",
          "target": null
        },
        {
          "id": "Trojan.Downloader.Generic",
          "display_name": "Trojan.Downloader.Generic",
          "target": null
        },
        {
          "id": "Suspected of Trojan.Downloader.gen",
          "display_name": "Suspected of Trojan.Downloader.gen",
          "target": null
        },
        {
          "id": "HEUR:RemoteAdmin.Generic",
          "display_name": "HEUR:RemoteAdmin.Generic",
          "target": null
        },
        {
          "id": "Gen:Heur.Ransom.HiddenTears",
          "display_name": "Gen:Heur.Ransom.HiddenTears",
          "target": null
        },
        {
          "id": "Nemucod.A",
          "display_name": "Nemucod.A",
          "target": null
        },
        {
          "id": "Backdoor.Hupigon",
          "display_name": "Backdoor.Hupigon",
          "target": null
        },
        {
          "id": "Trojan.Starter JS.Iframe",
          "display_name": "Trojan.Starter JS.Iframe",
          "target": null
        },
        {
          "id": "fake ,promethiumm ,strongpity",
          "display_name": "fake ,promethiumm ,strongpity",
          "target": null
        },
        {
          "id": "PUA.Reg1staid",
          "display_name": "PUA.Reg1staid",
          "target": null
        },
        {
          "id": "Malware.Heur_Generic.A",
          "display_name": "Malware.Heur_Generic.A",
          "target": null
        },
        {
          "id": "Bladabindi.Q",
          "display_name": "Bladabindi.Q",
          "target": null
        },
        {
          "id": "W32.eHeur",
          "display_name": "W32.eHeur",
          "target": null
        },
        {
          "id": "malicious.6e0700",
          "display_name": "malicious.6e0700",
          "target": null
        },
        {
          "id": "Trojan.Inject",
          "display_name": "Trojan.Inject",
          "target": null
        },
        {
          "id": "TSGeneric",
          "display_name": "TSGeneric",
          "target": null
        },
        {
          "id": "RedCap.vneda",
          "display_name": "RedCap.vneda",
          "target": null
        },
        {
          "id": "Trojan.Indiloadz",
          "display_name": "Trojan.Indiloadz",
          "target": null
        },
        {
          "id": "Trojan.Ekstak",
          "display_name": "Trojan.Ekstak",
          "target": null
        },
        {
          "id": "staticrr.paleokits.net",
          "display_name": "staticrr.paleokits.net",
          "target": null
        },
        {
          "id": "MSIL.Downloader",
          "display_name": "MSIL.Downloader",
          "target": null
        },
        {
          "id": "Trojan.Autoruns.GenericKDS",
          "display_name": "Trojan.Autoruns.GenericKDS",
          "target": null
        },
        {
          "id": "MSIL.Trojan.BSE",
          "display_name": "MSIL.Trojan.BSE",
          "target": null
        },
        {
          "id": "Adload.AD81",
          "display_name": "Adload.AD81",
          "target": null
        },
        {
          "id": "Packed.Asprotect",
          "display_name": "Packed.Asprotect",
          "target": null
        },
        {
          "id": "Gen:NN.ZemsilF.34062",
          "display_name": "Gen:NN.ZemsilF.34062",
          "target": null
        },
        {
          "id": "Evo",
          "display_name": "Evo",
          "target": null
        },
        {
          "id": "Agent.pwc",
          "display_name": "Agent.pwc",
          "target": null
        },
        {
          "id": "RiskTool.Phpw",
          "display_name": "RiskTool.Phpw",
          "target": null
        },
        {
          "id": "Gen:Variant.Symmi",
          "display_name": "Gen:Variant.Symmi",
          "target": null
        },
        {
          "id": "Trojan.PWS",
          "display_name": "Trojan.PWS",
          "target": null
        },
        {
          "id": "Generic.BitCoinMiner.3",
          "display_name": "Generic.BitCoinMiner.3",
          "target": null
        },
        {
          "id": "Trojan.Tasker",
          "display_name": "Trojan.Tasker",
          "target": null
        },
        {
          "id": "Gen:NN",
          "display_name": "Gen:NN",
          "target": null
        },
        {
          "id": "Downloader.CertutilURLCache",
          "display_name": "Downloader.CertutilURLCache",
          "target": null
        },
        {
          "id": "Elf",
          "display_name": "Elf",
          "target": null
        },
        {
          "id": "Gen:Heur.MSIL.Androm",
          "display_name": "Gen:Heur.MSIL.Androm",
          "target": null
        },
        {
          "id": "Kryptik.NRD",
          "display_name": "Kryptik.NRD",
          "target": null
        },
        {
          "id": "Riskware",
          "display_name": "Riskware",
          "target": null
        },
        {
          "id": "Kuluoz.B.gen",
          "display_name": "Kuluoz.B.gen",
          "target": null
        },
        {
          "id": "Gen:Variant.RevengeRat",
          "display_name": "Gen:Variant.RevengeRat",
          "target": null
        },
        {
          "id": "Gen:Variant.Mikey",
          "display_name": "Gen:Variant.Mikey",
          "target": null
        },
        {
          "id": "VB.Chronos.7",
          "display_name": "VB.Chronos.7",
          "target": null
        },
        {
          "id": "Kryptik.NOE",
          "display_name": "Kryptik.NOE",
          "target": null
        },
        {
          "id": "HEUR:WebToolbar.Generic",
          "display_name": "HEUR:WebToolbar.Generic",
          "target": null
        },
        {
          "id": "Gen:Variant.Barys",
          "display_name": "Gen:Variant.Barys",
          "target": null
        },
        {
          "id": "Backdoor.Xtreme",
          "display_name": "Backdoor.Xtreme",
          "target": null
        },
        {
          "id": "Trojan.MSIL",
          "display_name": "Trojan.MSIL",
          "target": null
        },
        {
          "id": "Gen:Variant.Graftor",
          "display_name": "Gen:Variant.Graftor",
          "target": null
        },
        {
          "id": "Backdoor.Agent",
          "display_name": "Backdoor.Agent",
          "target": null
        },
        {
          "id": "Unsafe",
          "display_name": "Unsafe",
          "target": null
        },
        {
          "id": "Trojan.PHP.Agent",
          "display_name": "Trojan.PHP.Agent",
          "target": null
        },
        {
          "id": "Trojan.Agent",
          "display_name": "Trojan.Agent",
          "target": null
        },
        {
          "id": "HEUR:Exploit.Generic",
          "display_name": "HEUR:Exploit.Generic",
          "target": null
        },
        {
          "id": "Ransom_WCRY.SMALYM",
          "display_name": "Ransom_WCRY.SMALYM",
          "target": null
        },
        {
          "id": "Ransom_WCRY.SMJ",
          "display_name": "Ransom_WCRY.SMJ",
          "target": null
        },
        {
          "id": "Auslogics",
          "display_name": "Auslogics",
          "target": null
        },
        {
          "id": "Gen:Variant.Jaiko",
          "display_name": "Gen:Variant.Jaiko",
          "target": null
        },
        {
          "id": "Exploit.W32.Agent",
          "display_name": "Exploit.W32.Agent",
          "target": null
        },
        {
          "id": "Trojan.Cud.Gen",
          "display_name": "Trojan.Cud.Gen",
          "target": null
        },
        {
          "id": "Trojan.DOC.Downloader",
          "display_name": "Trojan.DOC.Downloader",
          "target": null
        },
        {
          "id": "Backdoor.MSIL.Agent",
          "display_name": "Backdoor.MSIL.Agent",
          "target": null
        },
        {
          "id": "Gen:Trojan.Heur2.LPTbHW@W64.HfsAutoB",
          "display_name": "Gen:Trojan.Heur2.LPTbHW@W64.HfsAutoB",
          "target": null
        },
        {
          "id": "Gen:Variant.Kazy",
          "display_name": "Gen:Variant.Kazy",
          "target": null
        },
        {
          "id": "Gen:Variant.Zusy",
          "display_name": "Gen:Variant.Zusy",
          "target": null
        },
        {
          "id": "Ransom.WannaCrypt",
          "display_name": "Ransom.WannaCrypt",
          "target": null
        },
        {
          "id": "Generic.ServStart.A",
          "display_name": "Generic.ServStart.A",
          "target": null
        },
        {
          "id": "Trojan.Wanna",
          "display_name": "Trojan.Wanna",
          "target": null
        },
        {
          "id": "Generic.MSIL.Bladabindi",
          "display_name": "Generic.MSIL.Bladabindi",
          "target": null
        },
        {
          "id": "TROJ_GEN.R002C0OG518",
          "display_name": "TROJ_GEN.R002C0OG518",
          "target": null
        },
        {
          "id": "Trojan.Chapak",
          "display_name": "Trojan.Chapak",
          "target": null
        },
        {
          "id": "Indiloadz.BB",
          "display_name": "Indiloadz.BB",
          "target": null
        },
        {
          "id": "BehavBehavesLike.PUPXBI",
          "display_name": "BehavBehavesLike.PUPXBI",
          "target": null
        },
        {
          "id": "DeepScan:Generic.SpyAgent.6",
          "display_name": "DeepScan:Generic.SpyAgent.6",
          "target": null
        },
        {
          "id": "Python.KeyLogger",
          "display_name": "Python.KeyLogger",
          "target": null
        },
        {
          "id": "GameHack.CRS",
          "display_name": "GameHack.CRS",
          "target": null
        },
        {
          "id": "Generic.MSIL.PasswordStealer",
          "display_name": "Generic.MSIL.PasswordStealer",
          "target": null
        },
        {
          "id": "PSW.Agent",
          "display_name": "PSW.Agent",
          "target": null
        },
        {
          "id": "malicious.8c45ba",
          "display_name": "malicious.8c45ba",
          "target": null
        },
        {
          "id": "Dropper.Binder",
          "display_name": "Dropper.Binder",
          "target": null
        },
        {
          "id": "Constructor.MSIL",
          "display_name": "Constructor.MSIL",
          "target": null
        },
        {
          "id": "Linux.Agent",
          "display_name": "Linux.Agent",
          "target": null
        },
        {
          "id": "Virus.3DMax.Script",
          "display_name": "Virus.3DMax.Script",
          "target": null
        },
        {
          "id": "ScrInject.B",
          "display_name": "ScrInject.B",
          "target": null
        },
        {
          "id": "Trojan.WisdomEyes.16070401.9500",
          "display_name": "Trojan.WisdomEyes.16070401.9500",
          "target": null
        },
        {
          "id": "Application.SearchProtect",
          "display_name": "Application.SearchProtect",
          "target": null
        },
        {
          "id": "JS:Trojan.Clicker",
          "display_name": "JS:Trojan.Clicker",
          "target": null
        },
        {
          "id": "Faceliker.A",
          "display_name": "Faceliker.A",
          "target": null
        },
        {
          "id": "JS:Trojan.JS.Faceliker",
          "display_name": "JS:Trojan.JS.Faceliker",
          "target": null
        },
        {
          "id": "Constructor.MSIL  Linux.Agent",
          "display_name": "Constructor.MSIL  Linux.Agent",
          "target": null
        },
        {
          "id": "PowerShell.Trojan",
          "display_name": "PowerShell.Trojan",
          "target": null
        },
        {
          "id": "HTML:Script",
          "display_name": "HTML:Script",
          "target": null
        },
        {
          "id": "ScrInject.B",
          "display_name": "ScrInject.B",
          "target": null
        },
        {
          "id": "W32.AIDetectVM",
          "display_name": "W32.AIDetectVM",
          "target": null
        },
        {
          "id": "HackTool.CheatEngine",
          "display_name": "HackTool.CheatEngine",
          "target": null
        },
        {
          "id": "Injector.CLDS",
          "display_name": "Injector.CLDS",
          "target": null
        },
        {
          "id": "VB.Downloader.2",
          "display_name": "VB.Downloader.2",
          "target": null
        },
        {
          "id": "malicious.3e78cc",
          "display_name": "malicious.3e78cc",
          "target": null
        },
        {
          "id": "malicious.d800d6",
          "display_name": "malicious.d800d6",
          "target": null
        },
        {
          "id": "VB.PwShell.2",
          "display_name": "VB.PwShell.2",
          "target": null
        },
        {
          "id": "Backdoor.RBot",
          "display_name": "Backdoor.RBot",
          "target": null
        },
        {
          "id": "malicious.71b1a8",
          "display_name": "malicious.71b1a8",
          "target": null
        },
        {
          "id": "TrojanSpy.KeyLogger",
          "display_name": "TrojanSpy.KeyLogger",
          "target": null
        },
        {
          "id": "Injector.JDO",
          "display_name": "Injector.JDO",
          "target": null
        },
        {
          "id": "Heur.Msword.Gen",
          "display_name": "Heur.Msword.Gen",
          "target": null
        },
        {
          "id": "PSW.Discord",
          "display_name": "PSW.Discord",
          "target": null
        },
        {
          "id": "Packed.VMProtect",
          "display_name": "Packed.VMProtect",
          "target": null
        },
        {
          "id": "HEUR:AdWare.StartSurf",
          "display_name": "HEUR:AdWare.StartSurf",
          "target": null
        },
        {
          "id": "Gen:Heur.NoobyProtect",
          "display_name": "Gen:Heur.NoobyProtect",
          "target": null
        },
        {
          "id": "CIL.HeapOverride",
          "display_name": "CIL.HeapOverride",
          "target": null
        },
        {
          "id": "HEUR:Trojan.Tasker",
          "display_name": "HEUR:Trojan.Tasker",
          "target": null
        },
        {
          "id": "XLM.Trojan.Abracadabra.27",
          "display_name": "XLM.Trojan.Abracadabra.27",
          "target": null
        },
        {
          "id": "HEUR:Backdoor.MSIL.NanoBot",
          "display_name": "HEUR:Backdoor.MSIL.NanoBot",
          "target": null
        },
        {
          "id": "Trojan.PSW.Mimikatz",
          "display_name": "Trojan.PSW.Mimikatz",
          "target": null
        },
        {
          "id": "TrojanSpy.Python",
          "display_name": "TrojanSpy.Python",
          "target": null
        },
        {
          "id": "Trojan.Ole2.Vbs",
          "display_name": "Trojan.Ole2.Vbs",
          "target": null
        },
        {
          "id": "Exploit.MSOffice",
          "display_name": "Exploit.MSOffice",
          "target": null
        },
        {
          "id": "DeepScan:Generic.Ransom.AmnesiaE",
          "display_name": "DeepScan:Generic.Ransom.AmnesiaE",
          "target": null
        },
        {
          "id": "Wacatac.D6",
          "display_name": "Wacatac.D6",
          "target": null
        },
        {
          "id": "Backdoor.Androm",
          "display_name": "Backdoor.Androm",
          "target": null
        },
        {
          "id": "Packed.NetSeal",
          "display_name": "Packed.NetSeal",
          "target": null
        },
        {
          "id": "Trojan.MSIL.Injector",
          "display_name": "Trojan.MSIL.Injector",
          "target": null
        },
        {
          "id": "Trojan.PWS.Agent",
          "display_name": "Trojan.PWS.Agent",
          "target": null
        },
        {
          "id": "TScope.Trojan",
          "display_name": "TScope.Trojan",
          "target": null
        },
        {
          "id": "PSW.Stealer",
          "display_name": "PSW.Stealer",
          "target": null
        },
        {
          "id": "Trojan.PackedNET",
          "display_name": "Trojan.PackedNET",
          "target": null
        },
        {
          "id": "Trojan.Java",
          "display_name": "Trojan.Java",
          "target": null
        },
        {
          "id": "MalwareX",
          "display_name": "MalwareX",
          "target": null
        },
        {
          "id": "Trojan.PSW.Python",
          "display_name": "Trojan.PSW.Python",
          "target": null
        },
        {
          "id": "malicious.11abfc",
          "display_name": "malicious.11abfc",
          "target": null
        },
        {
          "id": "Generic.ASMalwS",
          "display_name": "Generic.ASMalwS",
          "target": null
        },
        {
          "id": "HEUR:Trojan.MSIL.Tasker",
          "display_name": "HEUR:Trojan.MSIL.Tasker",
          "target": null
        },
        {
          "id": "PossibleThreat.PALLAS",
          "display_name": "PossibleThreat.PALLAS",
          "target": null
        },
        {
          "id": "Backdoor.Poison",
          "display_name": "Backdoor.Poison",
          "target": null
        },
        {
          "id": "Generic.MSIL.LimeRAT",
          "display_name": "Generic.MSIL.LimeRAT",
          "target": null
        },
        {
          "id": "PWS-FCZZ",
          "display_name": "PWS-FCZZ",
          "target": null
        },
        {
          "id": "Trojan.Script",
          "display_name": "Trojan.Script",
          "target": null
        },
        {
          "id": "Gen:Heur.MSIL.Inject",
          "display_name": "Gen:Heur.MSIL.Inject",
          "target": null
        },
        {
          "id": "Trojan.PWS.Growtopia",
          "display_name": "Trojan.PWS.Growtopia",
          "target": null
        },
        {
          "id": "Spyware.Bobik",
          "display_name": "Spyware.Bobik",
          "target": null
        },
        {
          "id": "HackTool.BruteForce",
          "display_name": "HackTool.BruteForce",
          "target": null
        },
        {
          "id": "Hack.Patcher",
          "display_name": "Hack.Patcher",
          "target": null
        },
        {
          "id": "PWS.p",
          "display_name": "PWS.p",
          "target": null
        },
        {
          "id": "Suppobox",
          "display_name": "Suppobox",
          "target": null
        },
        {
          "id": "index.php",
          "display_name": "index.php",
          "target": null
        },
        {
          "id": "Packed.VMProtect",
          "display_name": "Packed.VMProtect",
          "target": null
        },
        {
          "id": "SmokeLoader",
          "display_name": "SmokeLoader",
          "target": null
        },
        {
          "id": "Generic.Malware",
          "display_name": "Generic.Malware",
          "target": null
        },
        {
          "id": "SNH:Script [Dropper]",
          "display_name": "SNH:Script [Dropper]",
          "target": null
        },
        {
          "id": "HEUR:Trojan.MSOffice.SAgent",
          "display_name": "HEUR:Trojan.MSOffice.SAgent",
          "target": null
        },
        {
          "id": "Script.INF",
          "display_name": "Script.INF",
          "target": null
        },
        {
          "id": "JS:Trojan.JS.Likejack",
          "display_name": "JS:Trojan.JS.Likejack",
          "target": null
        },
        {
          "id": "SNH:Script [Dropper]",
          "display_name": "SNH:Script [Dropper]",
          "target": null
        },
        {
          "id": "Trojan.JS.Agent",
          "display_name": "Trojan.JS.Agent",
          "target": null
        },
        {
          "id": "APT Notes",
          "display_name": "APT Notes",
          "target": null
        },
        {
          "id": "susp.rtf.objupdate",
          "display_name": "susp.rtf.objupdate",
          "target": null
        },
        {
          "id": "RedCap.zoohz",
          "display_name": "RedCap.zoohz",
          "target": null
        },
        {
          "id": "Trojan.Tasker",
          "display_name": "Trojan.Tasker",
          "target": null
        },
        {
          "id": "virus.office.qexvmc",
          "display_name": "virus.office.qexvmc",
          "target": null
        },
        {
          "id": "Trojan.KillProc",
          "display_name": "Trojan.KillProc",
          "target": null
        },
        {
          "id": "Generic.MSIL.GrwtpStealer.1",
          "display_name": "Generic.MSIL.GrwtpStealer.1",
          "target": null
        },
        {
          "id": "Suspicious.Cloud",
          "display_name": "Suspicious.Cloud",
          "target": null
        },
        {
          "id": "PowerShell.DownLoader",
          "display_name": "PowerShell.DownLoader",
          "target": null
        },
        {
          "id": "Downldr.gen",
          "display_name": "Downldr.gen",
          "target": null
        },
        {
          "id": "AGEN.1030939",
          "display_name": "AGEN.1030939",
          "target": null
        },
        {
          "id": "HackTool.Binder",
          "display_name": "HackTool.Binder",
          "target": null
        },
        {
          "id": "Trojan.Inject",
          "display_name": "Trojan.Inject",
          "target": null
        },
        {
          "id": "Dldr.Agent",
          "display_name": "Dldr.Agent",
          "target": null
        },
        {
          "id": "Dropper.MSIL",
          "display_name": "Dropper.MSIL",
          "target": null
        },
        {
          "id": "Trojan.VBKryjetor",
          "display_name": "Trojan.VBKryjetor",
          "target": null
        },
        {
          "id": "PWSX",
          "display_name": "PWSX",
          "target": null
        },
        {
          "id": "VB:Trojan.VBA.Agent",
          "display_name": "VB:Trojan.VBA.Agent",
          "target": null
        },
        {
          "id": "HEUR:Trojan.MSOffice.Stratos",
          "display_name": "HEUR:Trojan.MSOffice.Stratos",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1071.001",
          "name": "Web Protocols",
          "display_name": "T1071.001 - Web Protocols"
        },
        {
          "id": "T1071.004",
          "name": "DNS",
          "display_name": "T1071.004 - DNS"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1059.007",
          "name": "JavaScript",
          "display_name": "T1059.007 - JavaScript"
        },
        {
          "id": "T1497",
          "name": "Virtualization/Sandbox Evasion",
          "display_name": "T1497 - Virtualization/Sandbox Evasion"
        },
        {
          "id": "T1068",
          "name": "Exploitation for Privilege Escalation",
          "display_name": "T1068 - Exploitation for Privilege Escalation"
        },
        {
          "id": "TA0029",
          "name": "Privilege Escalation",
          "display_name": "TA0029 - Privilege Escalation"
        },
        {
          "id": "T1449",
          "name": "Exploit SS7 to Redirect Phone Calls/SMS",
          "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
        },
        {
          "id": "T1190",
          "name": "Exploit Public-Facing Application",
          "display_name": "T1190 - Exploit Public-Facing Application"
        },
        {
          "id": "T1210",
          "name": "Exploitation of Remote Services",
          "display_name": "T1210 - Exploitation of Remote Services"
        },
        {
          "id": "T1450",
          "name": "Exploit SS7 to Track Device Location",
          "display_name": "T1450 - Exploit SS7 to Track Device Location"
        },
        {
          "id": "T1211",
          "name": "Exploitation for Defense Evasion",
          "display_name": "T1211 - Exploitation for Defense Evasion"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "TA0011",
          "name": "Command and Control",
          "display_name": "TA0011 - Command and Control"
        },
        {
          "id": "T1412",
          "name": "Capture SMS Messages",
          "display_name": "T1412 - Capture SMS Messages"
        },
        {
          "id": "T1454",
          "name": "Malicious SMS Message",
          "display_name": "T1454 - Malicious SMS Message"
        },
        {
          "id": "T1001",
          "name": "Data Obfuscation",
          "display_name": "T1001 - Data Obfuscation"
        },
        {
          "id": "T1114",
          "name": "Email Collection",
          "display_name": "T1114 - Email Collection"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1498",
          "name": "Network Denial of Service",
          "display_name": "T1498 - Network Denial of Service"
        },
        {
          "id": "T1496",
          "name": "Resource Hijacking",
          "display_name": "T1496 - Resource Hijacking"
        },
        {
          "id": "T1176",
          "name": "Browser Extensions",
          "display_name": "T1176 - Browser Extensions"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": "654c5970817e6bf8b0e5b5ff",
      "export_count": 334,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "scoreblue",
        "id": "254100",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 1184,
        "FileHash-SHA1": 949,
        "FileHash-SHA256": 3712,
        "URL": 2925,
        "domain": 627,
        "hostname": 1319,
        "CVE": 26,
        "email": 8,
        "CIDR": 2
      },
      "indicator_count": 10752,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 228,
      "modified_text": "904 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "https://management.inwx.de/",
    "type": "URL"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "https://management.inwx.de/",
    "type": "URL",
    "found": false,
    "verdict": "clean",
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780246488.6580973
}