{
  "type": "URL",
  "indicator": "https://news.eventkrafton.com",
  "general": {
    "sections": [
      "general",
      "url_list",
      "http_scans",
      "screenshot"
    ],
    "indicator": "https://news.eventkrafton.com",
    "type": "url",
    "type_title": "URL",
    "validation": [],
    "base_indicator": {
      "id": 4195891547,
      "indicator": "https://news.eventkrafton.com",
      "type": "URL",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 50,
      "pulses": [
        {
          "id": "6a1da5461ecc1b4898544d19",
          "name": "Phishing | Jun 2, 2026 | Part 395/566",
          "description": "Phishing indicators. Date: Jun 2, 2026. Part 395/566. For more threat intelligence visit https://ltna.com.au/cyber",
          "modified": "2026-06-01T15:29:10.895000",
          "created": "2026-06-01T15:29:10.895000",
          "tags": [
            "phishing"
          ],
          "references": [
            "https://ltna.com.au/cyber"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "LTNA-Australia",
            "id": "380633",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 1998
          },
          "indicator_count": 1998,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 91,
          "modified_text": "2 hours ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6a1c4fdb770595cb5505f67f",
          "name": "Phishing | Jun 1, 2026 | Part 395/566",
          "description": "Phishing indicators. Date: Jun 1, 2026. Part 395/566. For more threat intelligence visit https://ltna.com.au/cyber",
          "modified": "2026-05-31T15:12:27.524000",
          "created": "2026-05-31T15:12:27.524000",
          "tags": [
            "phishing"
          ],
          "references": [
            "https://ltna.com.au/cyber"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "LTNA-Australia",
            "id": "380633",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 1998
          },
          "indicator_count": 1998,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 93,
          "modified_text": "1 day ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6a1aff769b6669f939b4b1c8",
          "name": "Phishing | May 31, 2026 | Part 395/566",
          "description": "Phishing indicators. Date: May 31, 2026. Part 395/566. For more threat intelligence visit https://ltna.com.au/cyber",
          "modified": "2026-05-30T15:17:10.272000",
          "created": "2026-05-30T15:17:10.272000",
          "tags": [
            "phishing"
          ],
          "references": [
            "https://ltna.com.au/cyber"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "LTNA-Australia",
            "id": "380633",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 1998
          },
          "indicator_count": 1998,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 93,
          "modified_text": "2 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6a19ad4e9b2839fb97dc556d",
          "name": "Phishing | May 30, 2026 | Part 395/566",
          "description": "Phishing indicators. Date: May 30, 2026. Part 395/566. For more threat intelligence visit https://ltna.com.au/cyber",
          "modified": "2026-05-29T15:14:22.246000",
          "created": "2026-05-29T15:14:22.246000",
          "tags": [
            "phishing"
          ],
          "references": [
            "https://ltna.com.au/cyber"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "LTNA-Australia",
            "id": "380633",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 1998
          },
          "indicator_count": 1998,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 93,
          "modified_text": "3 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6a1864f468f5deec400fd46e",
          "name": "Phishing | May 29, 2026 | Part 395/566",
          "description": "Phishing indicators. Date: May 29, 2026. Part 395/566. For more threat intelligence visit https://ltna.com.au/cyber",
          "modified": "2026-05-28T15:53:24.146000",
          "created": "2026-05-28T15:53:24.146000",
          "tags": [
            "phishing"
          ],
          "references": [
            "https://ltna.com.au/cyber"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "LTNA-Australia",
            "id": "380633",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 1998
          },
          "indicator_count": 1998,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 93,
          "modified_text": "4 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6a170cf13e2fd9b71d1f2b8b",
          "name": "Phishing | May 28, 2026 | Part 395/566",
          "description": "Phishing indicators. Date: May 28, 2026. Part 395/566. For more threat intelligence visit https://ltna.com.au/cyber",
          "modified": "2026-05-27T15:25:37.026000",
          "created": "2026-05-27T15:25:37.026000",
          "tags": [
            "phishing"
          ],
          "references": [
            "https://ltna.com.au/cyber"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "LTNA-Australia",
            "id": "380633",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 1998
          },
          "indicator_count": 1998,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 93,
          "modified_text": "5 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6a15b9b01ca27a2bdbc5b653",
          "name": "Phishing | May 27, 2026 | Part 395/566",
          "description": "Phishing indicators. Date: May 27, 2026. Part 395/566. For more threat intelligence visit https://ltna.com.au/cyber",
          "modified": "2026-05-26T15:18:08.338000",
          "created": "2026-05-26T15:18:08.338000",
          "tags": [
            "phishing"
          ],
          "references": [
            "https://ltna.com.au/cyber"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "LTNA-Australia",
            "id": "380633",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 1998
          },
          "indicator_count": 1998,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 93,
          "modified_text": "6 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6a1466db90fe091f094f7c2f",
          "name": "Phishing | May 26, 2026 | Part 395/566",
          "description": "Phishing indicators. Date: May 26, 2026. Part 395/566. For more threat intelligence visit https://ltna.com.au/cyber",
          "modified": "2026-05-25T15:12:27.586000",
          "created": "2026-05-25T15:12:27.586000",
          "tags": [
            "phishing"
          ],
          "references": [
            "https://ltna.com.au/cyber"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "LTNA-Australia",
            "id": "380633",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 1998
          },
          "indicator_count": 1998,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 93,
          "modified_text": "7 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6a13155a3eee46df14670b44",
          "name": "Phishing | May 25, 2026 | Part 395/566",
          "description": "Phishing indicators. Date: May 25, 2026. Part 395/566. For more threat intelligence visit https://ltna.com.au/cyber",
          "modified": "2026-05-24T15:12:26.222000",
          "created": "2026-05-24T15:12:26.222000",
          "tags": [
            "phishing"
          ],
          "references": [
            "https://ltna.com.au/cyber"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "LTNA-Australia",
            "id": "380633",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 1998
          },
          "indicator_count": 1998,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 93,
          "modified_text": "8 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6a11c365d31ea17c5d4e174e",
          "name": "Phishing | May 24, 2026 | Part 395/566",
          "description": "Phishing indicators. Date: May 24, 2026. Part 395/566. For more threat intelligence visit https://ltna.com.au/cyber",
          "modified": "2026-05-23T15:10:29.888000",
          "created": "2026-05-23T15:10:29.888000",
          "tags": [
            "phishing"
          ],
          "references": [
            "https://ltna.com.au/cyber"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "LTNA-Australia",
            "id": "380633",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 1998
          },
          "indicator_count": 1998,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 92,
          "modified_text": "9 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6a1073eaa4ff408211107463",
          "name": "Phishing | May 23, 2026 | Part 395/566",
          "description": "Phishing indicators. Date: May 23, 2026. Part 395/566. For more threat intelligence visit https://ltna.com.au/cyber",
          "modified": "2026-05-22T15:19:06.550000",
          "created": "2026-05-22T15:19:06.550000",
          "tags": [
            "phishing"
          ],
          "references": [
            "https://ltna.com.au/cyber"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "LTNA-Australia",
            "id": "380633",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 1998
          },
          "indicator_count": 1998,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 93,
          "modified_text": "10 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6a0f265fe14b468850a451e8",
          "name": "Phishing | May 22, 2026 | Part 395/566",
          "description": "Phishing indicators. Date: May 22, 2026. Part 395/566. For more threat intelligence visit https://ltna.com.au/cyber",
          "modified": "2026-05-21T15:35:59.370000",
          "created": "2026-05-21T15:35:59.370000",
          "tags": [
            "phishing"
          ],
          "references": [
            "https://ltna.com.au/cyber"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "LTNA-Australia",
            "id": "380633",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 1998
          },
          "indicator_count": 1998,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 93,
          "modified_text": "11 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6a0deacf5daf1b0a9c4921fc",
          "name": "Phishing | May 21, 2026 | Part 395/566",
          "description": "Phishing indicators. Date: May 21, 2026. Part 395/566. For more threat intelligence visit https://ltna.com.au/cyber",
          "modified": "2026-05-20T17:09:35.297000",
          "created": "2026-05-20T17:09:35.297000",
          "tags": [
            "phishing"
          ],
          "references": [
            "https://ltna.com.au/cyber"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "LTNA-Australia",
            "id": "380633",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 1998
          },
          "indicator_count": 1998,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 93,
          "modified_text": "12 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6a0c85f677fba41009121928",
          "name": "Phishing | May 20, 2026 | Part 395/566",
          "description": "Phishing indicators. Date: May 20, 2026. Part 395/566. For more threat intelligence visit https://ltna.com.au/cyber",
          "modified": "2026-05-19T15:47:01.986000",
          "created": "2026-05-19T15:47:01.986000",
          "tags": [
            "phishing"
          ],
          "references": [
            "https://ltna.com.au/cyber"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "LTNA-Australia",
            "id": "380633",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 1998
          },
          "indicator_count": 1998,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 93,
          "modified_text": "13 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6a0b2fce22bffe019e83452c",
          "name": "Phishing | May 19, 2026 | Part 395/566",
          "description": "Phishing indicators. Date: May 19, 2026. Part 395/566. For more threat intelligence visit https://ltna.com.au/cyber",
          "modified": "2026-05-18T15:27:10.345000",
          "created": "2026-05-18T15:27:10.345000",
          "tags": [
            "phishing"
          ],
          "references": [
            "https://ltna.com.au/cyber"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "LTNA-Australia",
            "id": "380633",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 1998
          },
          "indicator_count": 1998,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 93,
          "modified_text": "14 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6a09dc0034a928b095e6a681",
          "name": "Phishing | May 18, 2026 | Part 395/566",
          "description": "Phishing indicators. Date: May 18, 2026. Part 395/566. For more threat intelligence visit https://ltna.com.au/cyber",
          "modified": "2026-05-17T15:17:20.611000",
          "created": "2026-05-17T15:17:20.611000",
          "tags": [
            "phishing"
          ],
          "references": [
            "https://ltna.com.au/cyber"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "LTNA-Australia",
            "id": "380633",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 1998
          },
          "indicator_count": 1998,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 93,
          "modified_text": "15 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6a088972742c389f9aa7fda3",
          "name": "Phishing | May 17, 2026 | Part 395/566",
          "description": "Phishing indicators. Date: May 17, 2026. Part 395/566. For more threat intelligence visit https://ltna.com.au/cyber",
          "modified": "2026-05-16T15:12:50.365000",
          "created": "2026-05-16T15:12:50.365000",
          "tags": [
            "phishing"
          ],
          "references": [
            "https://ltna.com.au/cyber"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "LTNA-Australia",
            "id": "380633",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 1998
          },
          "indicator_count": 1998,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 93,
          "modified_text": "16 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6a07397c203ccabd1fc5b106",
          "name": "Phishing | May 16, 2026 | Part 395/566",
          "description": "Phishing indicators. Date: May 16, 2026. Part 395/566. For more threat intelligence visit https://ltna.com.au/cyber",
          "modified": "2026-05-15T15:19:24.370000",
          "created": "2026-05-15T15:19:24.370000",
          "tags": [
            "phishing"
          ],
          "references": [
            "https://ltna.com.au/cyber"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "LTNA-Australia",
            "id": "380633",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 1998
          },
          "indicator_count": 1998,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 93,
          "modified_text": "17 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6a05eb34a0af98a4dfb7c5bc",
          "name": "Phishing | May 15, 2026 | Part 395/566",
          "description": "Phishing indicators. Date: May 15, 2026. Part 395/566. For more threat intelligence visit https://ltna.com.au/cyber",
          "modified": "2026-05-14T15:33:08.929000",
          "created": "2026-05-14T15:33:08.929000",
          "tags": [
            "phishing"
          ],
          "references": [
            "https://ltna.com.au/cyber"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "LTNA-Australia",
            "id": "380633",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 1998
          },
          "indicator_count": 1998,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 93,
          "modified_text": "18 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6a0496eb24ff148fe1eaefca",
          "name": "Phishing | May 14, 2026 | Part 395/566",
          "description": "Phishing indicators. Date: May 14, 2026. Part 395/566. For more threat intelligence visit https://ltna.com.au/cyber",
          "modified": "2026-05-13T15:21:15.779000",
          "created": "2026-05-13T15:21:15.779000",
          "tags": [
            "phishing"
          ],
          "references": [
            "https://ltna.com.au/cyber"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "LTNA-Australia",
            "id": "380633",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 1998
          },
          "indicator_count": 1998,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 92,
          "modified_text": "19 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6a03437f50345fad20966b85",
          "name": "Phishing | May 13, 2026 | Part 395/566",
          "description": "Phishing indicators. Date: May 13, 2026. Part 395/566. For more threat intelligence visit https://ltna.com.au/cyber",
          "modified": "2026-05-12T15:13:03.516000",
          "created": "2026-05-12T15:13:03.516000",
          "tags": [
            "phishing"
          ],
          "references": [
            "https://ltna.com.au/cyber"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "LTNA-Australia",
            "id": "380633",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 1998
          },
          "indicator_count": 1998,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 93,
          "modified_text": "20 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6a01f2b26654227c2464dba1",
          "name": "Phishing | May 12, 2026 | Part 395/566",
          "description": "Phishing indicators. Date: May 12, 2026. Part 395/566. For more threat intelligence visit https://ltna.com.au/cyber",
          "modified": "2026-05-11T15:16:02.561000",
          "created": "2026-05-11T15:16:02.561000",
          "tags": [
            "phishing"
          ],
          "references": [
            "https://ltna.com.au/cyber"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "LTNA-Australia",
            "id": "380633",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 1998
          },
          "indicator_count": 1998,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 93,
          "modified_text": "21 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6a00a1143f3387d09f7113c8",
          "name": "Phishing | May 11, 2026 | Part 395/566",
          "description": "Phishing indicators. Date: May 11, 2026. Part 395/566. For more threat intelligence visit https://ltna.com.au/cyber",
          "modified": "2026-05-10T15:15:32.657000",
          "created": "2026-05-10T15:15:32.657000",
          "tags": [
            "phishing"
          ],
          "references": [
            "https://ltna.com.au/cyber"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "LTNA-Australia",
            "id": "380633",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 1997
          },
          "indicator_count": 1997,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 93,
          "modified_text": "22 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "69ff501997d552baf9ddcf26",
          "name": "Phishing | May 10, 2026 | Part 395/566",
          "description": "Phishing indicators. Date: May 10, 2026. Part 395/566. For more threat intelligence visit https://ltna.com.au/cyber",
          "modified": "2026-05-09T15:17:45.460000",
          "created": "2026-05-09T15:17:45.460000",
          "tags": [
            "phishing"
          ],
          "references": [
            "https://ltna.com.au/cyber"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "LTNA-Australia",
            "id": "380633",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 1997
          },
          "indicator_count": 1997,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 93,
          "modified_text": "23 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "69fdff6d318d7c47c25b841d",
          "name": "Phishing | May 9, 2026 | Part 395/566",
          "description": "Phishing indicators. Date: May 9, 2026. Part 395/566. For more threat intelligence visit https://ltna.com.au/cyber",
          "modified": "2026-05-08T15:21:17.158000",
          "created": "2026-05-08T15:21:17.158000",
          "tags": [
            "phishing"
          ],
          "references": [
            "https://ltna.com.au/cyber"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "LTNA-Australia",
            "id": "380633",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 1997
          },
          "indicator_count": 1997,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 93,
          "modified_text": "24 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "69fcac1d19ba771fa880e1ac",
          "name": "Phishing | May 8, 2026 | Part 395/566",
          "description": "Phishing indicators. Date: May 8, 2026. Part 395/566. For more threat intelligence visit https://ltna.com.au/cyber",
          "modified": "2026-05-07T15:13:33.839000",
          "created": "2026-05-07T15:13:33.839000",
          "tags": [
            "phishing"
          ],
          "references": [
            "https://ltna.com.au/cyber"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "LTNA-Australia",
            "id": "380633",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 1997
          },
          "indicator_count": 1997,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 93,
          "modified_text": "25 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "69fb5b737e0cebaf6a2fe973",
          "name": "Phishing | May 7, 2026 | Part 395/566",
          "description": "Phishing indicators. Date: May 7, 2026. Part 395/566. For more threat intelligence visit https://ltna.com.au/cyber",
          "modified": "2026-05-06T15:17:07.310000",
          "created": "2026-05-06T15:17:07.310000",
          "tags": [
            "phishing"
          ],
          "references": [
            "https://ltna.com.au/cyber"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "LTNA-Australia",
            "id": "380633",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 1997
          },
          "indicator_count": 1997,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 93,
          "modified_text": "26 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "69fa096baf6105f8b76191ed",
          "name": "Phishing | May 6, 2026 | Part 395/566",
          "description": "Phishing indicators. Date: May 6, 2026. Part 395/566. For more threat intelligence visit https://ltna.com.au/cyber",
          "modified": "2026-05-05T15:14:51.863000",
          "created": "2026-05-05T15:14:51.863000",
          "tags": [
            "phishing"
          ],
          "references": [
            "https://ltna.com.au/cyber"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "LTNA-Australia",
            "id": "380633",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 1997
          },
          "indicator_count": 1997,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 93,
          "modified_text": "27 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "69f8b7919248a0597a349096",
          "name": "Phishing | May 5, 2026 | Part 395/566",
          "description": "Phishing indicators. Date: May 5, 2026. Part 395/566. For more threat intelligence visit https://ltna.com.au/cyber",
          "modified": "2026-05-04T15:13:21.057000",
          "created": "2026-05-04T15:13:21.057000",
          "tags": [
            "phishing"
          ],
          "references": [
            "https://ltna.com.au/cyber"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "LTNA-Australia",
            "id": "380633",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 1997
          },
          "indicator_count": 1997,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 92,
          "modified_text": "28 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "69f77d2af91215ff647101e0",
          "name": "Phishing | May 4, 2026 | Part 395/566",
          "description": "Phishing indicators. Date: May 4, 2026. Part 395/566. For more threat intelligence visit https://ltna.com.au/cyber",
          "modified": "2026-05-03T16:51:54.972000",
          "created": "2026-05-03T16:51:54.972000",
          "tags": [
            "phishing"
          ],
          "references": [
            "https://ltna.com.au/cyber"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "LTNA-Australia",
            "id": "380633",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 1997
          },
          "indicator_count": 1997,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 93,
          "modified_text": "29 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "69f62a5c9663ac4cecd12231",
          "name": "Phishing | May 3, 2026 | Part 395/566",
          "description": "Phishing indicators. Date: May 3, 2026. Part 395/566. For more threat intelligence visit https://ltna.com.au/cyber",
          "modified": "2026-05-02T16:46:20.241000",
          "created": "2026-05-02T16:46:20.241000",
          "tags": [
            "phishing"
          ],
          "references": [
            "https://ltna.com.au/cyber"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "LTNA-Australia",
            "id": "380633",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 1997
          },
          "indicator_count": 1997,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 93,
          "modified_text": "30 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "69f4d7629e84a25bd5be59b4",
          "name": "Phishing | May 2, 2026 | Part 395/566",
          "description": "Phishing indicators. Date: May 2, 2026. Part 395/566. For more threat intelligence visit https://ltna.com.au/cyber",
          "modified": "2026-05-01T16:40:02.117000",
          "created": "2026-05-01T16:40:02.117000",
          "tags": [
            "phishing"
          ],
          "references": [
            "https://ltna.com.au/cyber"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "LTNA-Australia",
            "id": "380633",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 1997
          },
          "indicator_count": 1997,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 91,
          "modified_text": "31 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "69f385bc7839cc6f09653e94",
          "name": "Phishing | May 1, 2026 | Part 395/566",
          "description": "Phishing indicators. Date: May 1, 2026. Part 395/566. For more threat intelligence visit https://ltna.com.au/cyber",
          "modified": "2026-04-30T16:39:24.175000",
          "created": "2026-04-30T16:39:24.175000",
          "tags": [
            "phishing"
          ],
          "references": [
            "https://ltna.com.au/cyber"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "LTNA-Australia",
            "id": "380633",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 1997
          },
          "indicator_count": 1997,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 92,
          "modified_text": "32 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "69f233cc27253667353b0cf4",
          "name": "Phishing | Apr 30, 2026 | Part 395/566",
          "description": "Phishing indicators. Date: Apr 30, 2026. Part 395/566. For more threat intelligence visit https://ltna.com.au/cyber",
          "modified": "2026-04-29T16:37:32.436000",
          "created": "2026-04-29T16:37:32.436000",
          "tags": [
            "phishing"
          ],
          "references": [
            "https://ltna.com.au/cyber"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "LTNA-Australia",
            "id": "380633",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 1997
          },
          "indicator_count": 1997,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 91,
          "modified_text": "33 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "69f0e8be85076bec5041c4ad",
          "name": "Phishing | Apr 29, 2026 | Part 395/566",
          "description": "Phishing indicators. Date: Apr 29, 2026. Part 395/566. For more threat intelligence visit https://ltna.com.au/cyber",
          "modified": "2026-04-28T17:05:02.231000",
          "created": "2026-04-28T17:05:02.231000",
          "tags": [
            "phishing"
          ],
          "references": [
            "https://ltna.com.au/cyber"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "LTNA-Australia",
            "id": "380633",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 1997
          },
          "indicator_count": 1997,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 92,
          "modified_text": "34 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "69ef95a0bf4f09ba1d8e0dd3",
          "name": "Phishing | Apr 28, 2026 | Part 395/566",
          "description": "Phishing indicators. Date: Apr 28, 2026. Part 395/566. For more threat intelligence visit https://ltna.com.au/cyber",
          "modified": "2026-04-27T16:58:08.259000",
          "created": "2026-04-27T16:58:08.259000",
          "tags": [
            "phishing"
          ],
          "references": [
            "https://ltna.com.au/cyber"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "LTNA-Australia",
            "id": "380633",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 1997
          },
          "indicator_count": 1997,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 92,
          "modified_text": "35 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "69ee4185bc928647a4baf251",
          "name": "Phishing | Apr 27, 2026 | Part 395/566",
          "description": "Phishing indicators. Date: Apr 27, 2026. Part 395/566. For more threat intelligence visit https://ltna.com.au/cyber",
          "modified": "2026-04-26T16:47:01.404000",
          "created": "2026-04-26T16:47:01.404000",
          "tags": [
            "phishing"
          ],
          "references": [
            "https://ltna.com.au/cyber"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "LTNA-Australia",
            "id": "380633",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 1997
          },
          "indicator_count": 1997,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 92,
          "modified_text": "36 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "69ecefa86ecdee3aa3aadf52",
          "name": "Phishing | Apr 26, 2026 | Part 395/566",
          "description": "Phishing indicators. Date: Apr 26, 2026. Part 395/566. For more threat intelligence visit https://ltna.com.au/cyber",
          "modified": "2026-04-25T16:45:27.988000",
          "created": "2026-04-25T16:45:27.988000",
          "tags": [
            "phishing"
          ],
          "references": [
            "https://ltna.com.au/cyber"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "LTNA-Australia",
            "id": "380633",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 1997
          },
          "indicator_count": 1997,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 92,
          "modified_text": "37 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "69eba03b9bcdba10fdccfd03",
          "name": "Phishing | Apr 25, 2026 | Part 395/566",
          "description": "Phishing indicators. Date: Apr 25, 2026. Part 395/566. For more threat intelligence visit https://ltna.com.au/cyber",
          "modified": "2026-04-24T16:54:19.164000",
          "created": "2026-04-24T16:54:19.164000",
          "tags": [
            "phishing"
          ],
          "references": [
            "https://ltna.com.au/cyber"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "LTNA-Australia",
            "id": "380633",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 1997
          },
          "indicator_count": 1997,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 92,
          "modified_text": "38 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "69ea4e36437bfa4ad4487f8b",
          "name": "Phishing | Apr 24, 2026 | Part 395/566",
          "description": "Phishing indicators. Date: Apr 24, 2026. Part 395/566. For more threat intelligence visit https://ltna.com.au/cyber",
          "modified": "2026-04-23T16:52:06.616000",
          "created": "2026-04-23T16:52:06.616000",
          "tags": [
            "phishing"
          ],
          "references": [
            "https://ltna.com.au/cyber"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "LTNA-Australia",
            "id": "380633",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 1997
          },
          "indicator_count": 1997,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 92,
          "modified_text": "39 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "69e90329883d623345b56089",
          "name": "Phishing | Apr 23, 2026 | Part 395/566",
          "description": "Phishing indicators. Date: Apr 23, 2026. Part 395/566. For more threat intelligence visit https://ltna.com.au/cyber",
          "modified": "2026-04-22T17:19:37.064000",
          "created": "2026-04-22T17:19:37.064000",
          "tags": [
            "phishing"
          ],
          "references": [
            "https://ltna.com.au/cyber"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "LTNA-Australia",
            "id": "380633",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 1997
          },
          "indicator_count": 1997,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 91,
          "modified_text": "40 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "69c06ca9341d6c063f652e33",
          "name": "ETERNALBLUE Probe MS17-010 | Wannacry Ransomware Domain - related to NSO Group Pegasus",
          "description": "Quasi governmental, Healthcare Law Firms , legal entities , as well as direct safety threats such as NSO Group Pegasus, Enterprise Cellebrite (in references) and other dangerous intimidation and life endangering tactics directed against a crime victim. Continuous harassment and threats of violence against victims family including 83 yo father. Veteran & hand picked  Sr Systems Analyst and Engineer for Aegis Weapon System Team of 24. You\u2019re welcome America.. Victim left zero evidence with family. Documents shredded. Data stolen by parties named. She isn\u2019t the only one. These people do this for a living. Abuse of Palantir & Foundry tools.",
          "modified": "2026-04-21T22:07:35.710000",
          "created": "2026-03-22T22:26:49.205000",
          "tags": [
            "ransomware",
            "united",
            "search",
            "asnone",
            "regsetvalueexa",
            "service",
            "regdword",
            "medium",
            "get na",
            "malware",
            "dock",
            "push",
            "write",
            "win32",
            "playgame",
            "unknown",
            "exploit",
            "cve",
            "wncry",
            "wannacry",
            "passive dns",
            "urls",
            "british virgin",
            "all url",
            "http",
            "ip address",
            "related nids",
            "files location",
            "virgin islands",
            "islands",
            "bgp",
            "virgin islands",
            "hijacked",
            "data upload",
            "extraction",
            "failed",
            "review iocs",
            "include ovo",
            "tovary review",
            "ids detec",
            "yara dete",
            "trior texarag",
            "drop or",
            "rrowse",
            "type",
            "extra data",
            "hurricane electric",
            "p2404",
            "p11629470400",
            "p11629107633",
            "artifacts v",
            "full reports",
            "v help",
            "info",
            "low l",
            "high ta0002",
            "techniques",
            "t1053",
            "command",
            "scripting inte",
            "low ta0003",
            "techniques high",
            "t1053 ite",
            "modify system",
            "pl t1543",
            "boot",
            "logon autostart",
            "ex t1547",
            "checks-disk-space",
            "checks-network-adapters",
            "detect-debug-environment",
            "direct-cpu-clock-access",
            "long-sleeps",
            "runtime-modules",
            "get http",
            "head http",
            "dns resolutions",
            "ip traffic",
            "53 tcp",
            "tls sni",
            "apple id",
            "webdisk",
            "expiration",
            "url http",
            "hostname",
            "no expiration",
            "iocs",
            "url https",
            "es included",
            "win32 exe",
            "pe32 executable",
            "ms windows",
            "intel",
            "ms visual",
            "win32 dynamic",
            "link library",
            "win16 ne",
            "learn",
            "ck id",
            "name tactics",
            "suspicious",
            "informative",
            "adversaries",
            "spawns",
            "t1204 user",
            "defense evasion",
            "over",
            "mitre att",
            "ck matrix",
            "ascii text",
            "hybrid",
            "general",
            "local",
            "path",
            "click",
            "strings",
            "javascript",
            "ssl certificate",
            "encrypt",
            "accept",
            "russia unknown",
            "meta",
            "record value",
            "aaaa",
            "link",
            "present jun",
            "apple",
            "remote access",
            "otx logo",
            "all ipv4",
            "url analysis",
            "files",
            "accept ch",
            "present dec",
            "content type",
            "x pcrew",
            "name servers",
            "present may",
            "body doctype",
            "title",
            "all domain",
            "servers",
            "china unknown",
            "found content",
            "gmt p3p",
            "cp oti",
            "dsp cor",
            "iva our",
            "ind com",
            "domain",
            "cname",
            "entries",
            "brian sabey",
            "hallrender",
            "christopher ahmann",
            "t1480 execution",
            "discovery att",
            "heur",
            "virtool",
            "win64",
            "mtb win32",
            "backdoor",
            "location china",
            "hangzhou",
            "china asn",
            "ransom",
            "wannadecryptor",
            "filehash",
            "yara detections",
            "msvisualcpp60",
            "related tags",
            "none file",
            "type pexe",
            "copy",
            "beginstring",
            "null",
            "refresh",
            "body",
            "span",
            "error",
            "tools",
            "look",
            "verify",
            "restart",
            "expl",
            "unknown cname",
            "hacktool",
            "domain address",
            "contacted hosts",
            "process details",
            "flag",
            "ipv4 add",
            "location united",
            "america flag",
            "exploit",
            "show",
            "all filehash",
            "expiration date",
            "gmt location",
            "gmt max",
            "domain add",
            "elite",
            "date",
            "cowboy",
            "United States",
            "present feb",
            "present oct",
            "creation date",
            "present nov",
            "moved",
            "emails"
          ],
          "references": [
            "http://ww17.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/",
            "Win32:CVE-2017-0147-B\\ [Expl] ,  Win.Ransomware.WannaCry-6313787-0 ,  Exploit:Win32/CVE-2017-0147.A",
            "IDS Detections: Observed WannaCry Domain (iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff .com in DNS Lookup)",
            "IDS Detections: Possible ETERNALBLUE Probe MS17-010 (MSF style) ETERNALBLUE Probe Vulnerable System Response MS17-010",
            "IDS Detections: Possible ETERNALBLUE Probe MS17-010 (Generic Flags)",
            "IDS Detections: Behavioral Unusual Port 445 traffic Potential Scan or Infection SMB-DS",
            "IDS Detections: IPC$ share access \u2022 SMB-DS IPC$ unicode share access \u2022 403 Forbidden",
            "Yara Detections: WannaCry_Ransomware ,  Wanna_Cry_Ransomware_Generic ,  WannaDecryptor",
            "Yara Detections: MS17_010_WanaCry_worm  ,  stack_string , MS_Visual_Cpp_6_0 ,  Armadillov1xxv2xx",
            "Alerts: network_icmp nolookup_communication persistence_autorun modifies_proxy_wpad",
            "Alerts: network_cnc_http network_http allocates_rwx creates_exe creates_hidden_file",
            "Alerts: creates_service stealth_window antivm_network_adapters checks_debugger",
            "Alerts:  peid_packer pe_unknown_resource_name",
            "IP\u2019s Contacted: 103.224.212.220  105.242.60.208  117.13.61.219  117.180.208.83  12.105.46.122",
            "IP\u2019s Contacted: 121.105.233.189  128.251.173.246  13.248.148.254  132.124.155.52  139.246.30.108",
            "Domains Contacted: www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com",
            "Domains Contacted: ww38.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com",
            "FileHash-SHA256 002dee2db8b07b98b543ad99d0dd4e3e0ba7624f956d719ba803f57b426e30e7",
            "Names: Photo.scr \u2022 85115B0142902832C864B3009CAB1A00.RS (names of FileHash above)",
            "Crowdsourced IDS: Matches rule MALWARE-CNC DNS",
            "Crowdsourced IDS: Fast Flux attempt Matches rule ET INFO EXE IsDebuggerPresent (Used in Malware Anti-Debugging)",
            "Crowdsourced IDS: Matches rule ET POLICY PE EXE or DLL Windows file download HTTP",
            "apple.com-index.php-account-locked-verification.test2.aptaforum.com.cn",
            "apple.com-verify.account.manage.test2.aptaforum.com.cn",
            "appleid.apple.com-signin-8491e.test2.aptaforum.com.cn",
            "appleid.apple.com.secure1account.pagelogin.test2.aptaforum.com.cn",
            "web-secure-appleid-login.com.test2.aptaforum.com.cn",
            "http://apple.com-verify.account.manage.test2.aptaforum.com.cn/",
            "http://appleid.apple.com-signin-8491e.test2.aptaforum.com.cn/",
            "http://apple.sweetycat.com/ \u2022 https://apple.sweetycat.com/",
            "findmy.apple-uk.live",
            "apple.haipaoapp.com \u2022 http://apple.haipaoapp.com \u2022 http://apple.haipaoapp.com/ \u2022 https://apple.haipaoapp.com/",
            "http://apple.com-index.php-account-locked-verification.test2.aptaforum.com.cn/",
            "http://appleid.apple.com.secure1account.pagelogin.test2.aptaforum.com.cn/",
            "http://web-secure-appleid-login.com.test2.aptaforum.com.cn/",
            "Trojan/JS.Redirector.QNO SHA256:9e6e93c05a9736b95426fe0f492a18a2ac409bd9fb572dd3c982cb6de3ba0dbc",
            "VO7MU1HA.htm : https://hybrid-analysis.com/sample/9e6e93c05a9736b95426fe0f492a18a2ac409bd9fb572dd3c982cb6de3ba0dbc",
            "https://hybrid-analysis.com/sample/a638ece11c81bcac0002363eb3f75de35a46ce0e080b5de41162093181079a6b/69c018efcb875e4fb30cdfcc",
            "https://hybrid-analysis.com/sample/09610b7c855ef132a31f2e0136b4d62b9dbb04c6fcb42160d6d8409ef6394e40/69c0189c5e0483a78907cc39",
            "KeenDNS | keendnsaclremote805717135272048.qeenetic.link",
            "https://fonts.googleapis.com/css",
            "http://e7.c.lencr.org/74.crl \u2022 http://e7.i.lencr.org/",
            "Quasi Gov - Law firms stole victims clouds. Evidence, $Intellectual property, Memories of & victims family. Merciless",
            "www.remoteaccess.allied-media.com",
            "apple.com-index.php-account-locked-verification.test2.aptaforum.com.cn",
            "aptaforum.com.cn   182.61.201.90 ,  182.61.201.91   China ASN AS38365 beijing baidu netcom science and technology co. ltd",
            "Emails:yejun.shou@yxips.com Name:\u7ebd\u8fea\u5e0c\u4e9a\u751f\u547d\u65e9\u671f\u8425\u517b\u54c1\u7ba1\u7406(\u4e0a\u6d77)\u6709\u9650\u516c\u53f8 Name Servers: dns17.hichina.com",
            "*unsigned Domain: aptaforum.com.cn  Name Servers: dns18.hichina.com Registrar: \u963f\u91cc\u4e91\u8ba1\u7b97\u6709\u9650\u516c\u53f8\uff08\u4e07\u7f51\uff09Status: ok",
            "dns17.hichina.com",
            "dropbox.com - deleted victims DB post assault. Sabey + Ahmann repeatedly erased DB (ILLEGAL)",
            "Protected:SA\u2019r Jeffrey Scott Reimer, Mark Montano MD, John T. Sasha MD, Frederick P. Scherr , others.",
            "https://otx.alienvault.com/indicator/domain/qeenetic.link",
            "okg.and.googletagmanagers.com",
            "pcy.and.googletagmanagers.com",
            "pgj.and.googletagmanagers.com",
            "prb.and.googletagmanagers.com",
            "lkp.and.googletagmanagers.com",
            "jgw.and.googletagmanagers.com",
            "bzx.and.googletagmanagers.com",
            "msedge.b.tlu.dl.delivery.mp.microsoft.com",
            "http://prtests.ru/test.html?15%0Ahttp://profetest.ru/test.html?2%0Ahttp://qptest.ru/test.html?5%0Ahttp://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/3cf71a18-f999-4372-beac-67715d51bb62?P1=1629470400&P2=404&P3=2&P4=d%2520arRdiatcalmlQRKq2gm1LlFitNgIcLpnyzCIHYtf%2520ByXQF0JNptZ0rBDMKlLL%2520qsOzZdPICJjC7MWkkdm1Hg==%0Ahttp://stafftest.ru/test.html?0%0Ahttp://iqtesti.ru/test.html?17%0Ahttp://hrtests.ru/test.html?1%0Ahttp://pstests.ru/test.html?4%0Ahttp://prtests.ru/test.html?6%0Ahttp:/",
            "HallRender.com | Law Firm M. Brian Sabey Esq. | Pegasus related",
            "TAM Legal\u2019s Christopher P. \u2018Buzz\u2019 Ahmann Esq works for State Quasi Government in tandem w/ Hall Render",
            "https://otx.alienvault.com/pulse/69bf8e2663d5480917ddb699",
            "https://otx.alienvault.com/pulse/69bf261cc4e399447d78776c",
            "https://otx.alienvault.com/pulse/69bea426487bffa5384c6f38",
            "(?) https://living-sun.com/applescript/68281-is-there-a-way-to-disable-force-quit-while-applescript-application-is-still-running-applescript-quit.html",
            "https://otx.alienvault.com/pulse/69bf261cc4e399447d78776c",
            "https://otx.alienvault.com/pulse/69b49ad5dd40a24d83cd6a72"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "Ransomware",
              "display_name": "Ransomware",
              "target": null
            },
            {
              "id": "Win.Ransomware.WannaCry-6313787-0",
              "display_name": "Win.Ransomware.WannaCry-6313787-0",
              "target": null
            },
            {
              "id": "Exploit:Win32/CVE-2017-0147.A",
              "display_name": "Exploit:Win32/CVE-2017-0147.A",
              "target": "/malware/Exploit:Win32/CVE-2017-0147.A"
            },
            {
              "id": "Trojan/JS.Redirector.QNO",
              "display_name": "Trojan/JS.Redirector.QNO",
              "target": null
            },
            {
              "id": "Win.Trojan.Application-1955.",
              "display_name": "Win.Trojan.Application-1955.",
              "target": null
            },
            {
              "id": "Win32:Banker-LAA\\ [Trj]",
              "display_name": "Win32:Banker-LAA\\ [Trj]",
              "target": null
            },
            {
              "id": "Win.Malware.Snojan-6775202-0",
              "display_name": "Win.Malware.Snojan-6775202-0",
              "target": null
            },
            {
              "id": "Win32:Evo-gen\\ [Trj]",
              "display_name": "Win32:Evo-gen\\ [Trj]",
              "target": null
            },
            {
              "id": "Win64:Expiro-AJ\\ [Inf]",
              "display_name": "Win64:Expiro-AJ\\ [Inf]",
              "target": null
            },
            {
              "id": "Win.Trojan.Fugrafa-9733007-0",
              "display_name": "Win.Trojan.Fugrafa-9733007-0",
              "target": null
            },
            {
              "id": "Win32:TrojanX-gen\\ [Trj]",
              "display_name": "Win32:TrojanX-gen\\ [Trj]",
              "target": null
            },
            {
              "id": "Win.Trojan.VBGeneric-6989114-0",
              "display_name": "Win.Trojan.VBGeneric-6989114-0",
              "target": null
            },
            {
              "id": "VirTool:Win32/VBInject.YA!MTB",
              "display_name": "VirTool:Win32/VBInject.YA!MTB",
              "target": "/malware/VirTool:Win32/VBInject.YA!MTB"
            },
            {
              "id": "Win32:Dh-A\\ [Win32:FileInfector-C\\ [Heur]",
              "display_name": "Win32:Dh-A\\ [Win32:FileInfector-C\\ [Heur]",
              "target": null
            },
            {
              "id": "#VirTool:Win32/Obfuscator",
              "display_name": "#VirTool:Win32/Obfuscator",
              "target": "/malware/#VirTool:Win32/Obfuscator"
            },
            {
              "id": "Backdoor:Win32/Small.IR",
              "display_name": "Backdoor:Win32/Small.IR",
              "target": "/malware/Backdoor:Win32/Small.IR"
            },
            {
              "id": "Win64:Expiro-AJ\\ [Inf]",
              "display_name": "Win64:Expiro-AJ\\ [Inf]",
              "target": null
            },
            {
              "id": "Win32:Dh-A\\",
              "display_name": "Win32:Dh-A\\",
              "target": null
            },
            {
              "id": "CVE-2017-0147",
              "display_name": "CVE-2017-0147",
              "target": null
            },
            {
              "id": "Ransom:Win32/CVE-2017-0147.A",
              "display_name": "Ransom:Win32/CVE-2017-0147.A",
              "target": "/malware/Ransom:Win32/CVE-2017-0147.A"
            },
            {
              "id": "Win32:Malware-gen",
              "display_name": "Win32:Malware-gen",
              "target": null
            },
            {
              "id": "Win.Malware.Flystudio-6738927-0",
              "display_name": "Win.Malware.Flystudio-6738927-0",
              "target": null
            },
            {
              "id": "ALF:SpikeAexR.PEVPOPC",
              "display_name": "ALF:SpikeAexR.PEVPOPC",
              "target": null
            },
            {
              "id": "Sf:WNCryLdr-A\\ [Trj]",
              "display_name": "Sf:WNCryLdr-A\\ [Trj]",
              "target": null
            },
            {
              "id": "Win.Ransomware.WannaCry-6313787-0",
              "display_name": "Win.Ransomware.WannaCry-6313787-0",
              "target": null
            },
            {
              "id": "ransom:Win32/WannaCrypt.H",
              "display_name": "ransom:Win32/WannaCrypt.H",
              "target": "/malware/ransom:Win32/WannaCrypt.H"
            }
          ],
          "attack_ids": [
            {
              "id": "T1031",
              "name": "Modify Existing Service",
              "display_name": "T1031 - Modify Existing Service"
            },
            {
              "id": "T1040",
              "name": "Network Sniffing",
              "display_name": "T1040 - Network Sniffing"
            },
            {
              "id": "T1045",
              "name": "Software Packing",
              "display_name": "T1045 - Software Packing"
            },
            {
              "id": "T1053",
              "name": "Scheduled Task/Job",
              "display_name": "T1053 - Scheduled Task/Job"
            },
            {
              "id": "T1060",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1060 - Registry Run Keys / Startup Folder"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1143",
              "name": "Hidden Window",
              "display_name": "T1143 - Hidden Window"
            },
            {
              "id": "T1158",
              "name": "Hidden Files and Directories",
              "display_name": "T1158 - Hidden Files and Directories"
            },
            {
              "id": "T1198",
              "name": "SIP and Trust Provider Hijacking",
              "display_name": "T1198 - SIP and Trust Provider Hijacking"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1203",
              "name": "Exploitation for Client Execution",
              "display_name": "T1203 - Exploitation for Client Execution"
            },
            {
              "id": "T1543",
              "name": "Create or Modify System Process",
              "display_name": "T1543 - Create or Modify System Process"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1574",
              "name": "Hijack Execution Flow",
              "display_name": "T1574 - Hijack Execution Flow"
            },
            {
              "id": "T1048",
              "name": "Exfiltration Over Alternative Protocol",
              "display_name": "T1048 - Exfiltration Over Alternative Protocol"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1069",
              "name": "Permission Groups Discovery",
              "display_name": "T1069 - Permission Groups Discovery"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1204",
              "name": "User Execution",
              "display_name": "T1204 - User Execution"
            },
            {
              "id": "T1480",
              "name": "Execution Guardrails",
              "display_name": "T1480 - Execution Guardrails"
            },
            {
              "id": "T1568",
              "name": "Dynamic Resolution",
              "display_name": "T1568 - Dynamic Resolution"
            },
            {
              "id": "T1069.002",
              "name": "Domain Groups",
              "display_name": "T1069.002 - Domain Groups"
            },
            {
              "id": "T1568.002",
              "name": "Domain Generation Algorithms",
              "display_name": "T1568.002 - Domain Generation Algorithms"
            },
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1071.004",
              "name": "DNS",
              "display_name": "T1071.004 - DNS"
            },
            {
              "id": "T1048.003",
              "name": "Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol",
              "display_name": "T1048.003 - Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol"
            },
            {
              "id": "T1189",
              "name": "Drive-by Compromise",
              "display_name": "T1189 - Drive-by Compromise"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1583",
              "name": "Acquire Infrastructure",
              "display_name": "T1583 - Acquire Infrastructure"
            },
            {
              "id": "T1543.001",
              "name": "Launch Agent",
              "display_name": "T1543.001 - Launch Agent"
            },
            {
              "id": "T1210",
              "name": "Exploitation of Remote Services",
              "display_name": "T1210 - Exploitation of Remote Services"
            },
            {
              "id": "T1022",
              "name": "Data Encrypted",
              "display_name": "T1022 - Data Encrypted"
            }
          ],
          "industries": [
            "Government",
            "Legal",
            "Technology",
            "Healthcare"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 3,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 2,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Q.Vashti",
            "id": "337942",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 3779,
            "FileHash-MD5": 422,
            "FileHash-SHA1": 411,
            "FileHash-SHA256": 1824,
            "domain": 979,
            "hostname": 2082,
            "CVE": 1,
            "BitcoinAddress": 3,
            "SSLCertFingerprint": 6,
            "email": 8
          },
          "indicator_count": 9515,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 143,
          "modified_text": "40 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "69e7ac4c50ed2999e5937d1d",
          "name": "Phishing | Apr 22, 2026 | Part 395/566",
          "description": "Phishing indicators. Date: Apr 22, 2026. Part 395/566. For more threat intelligence visit https://ltna.com.au/cyber",
          "modified": "2026-04-21T16:56:44.321000",
          "created": "2026-04-21T16:56:44.321000",
          "tags": [
            "phishing"
          ],
          "references": [
            "https://ltna.com.au/cyber"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "LTNA-Australia",
            "id": "380633",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 1997
          },
          "indicator_count": 1997,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 91,
          "modified_text": "41 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "69e65cdf4393072afc212208",
          "name": "Phishing | Apr 21, 2026 | Part 395/566",
          "description": "Phishing indicators. Date: Apr 21, 2026. Part 395/566. For more threat intelligence visit https://ltna.com.au/cyber",
          "modified": "2026-04-20T17:05:35.165000",
          "created": "2026-04-20T17:05:35.165000",
          "tags": [
            "phishing"
          ],
          "references": [
            "https://ltna.com.au/cyber"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "LTNA-Australia",
            "id": "380633",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 1997
          },
          "indicator_count": 1997,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 92,
          "modified_text": "42 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "69e50759381da3c88ba3426c",
          "name": "Phishing | Apr 20, 2026 | Part 395/566",
          "description": "Phishing indicators. Date: Apr 20, 2026. Part 395/566. For more threat intelligence visit https://ltna.com.au/cyber",
          "modified": "2026-04-19T16:48:25.120000",
          "created": "2026-04-19T16:48:25.120000",
          "tags": [
            "phishing"
          ],
          "references": [
            "https://ltna.com.au/cyber"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "LTNA-Australia",
            "id": "380633",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 1997
          },
          "indicator_count": 1997,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 92,
          "modified_text": "43 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "69e3b651b57502d67bd36ce6",
          "name": "Phishing | Apr 19, 2026 | Part 395/566",
          "description": "Phishing indicators. Date: Apr 19, 2026. Part 395/566. For more threat intelligence visit https://ltna.com.au/cyber",
          "modified": "2026-04-18T16:50:25.585000",
          "created": "2026-04-18T16:50:25.585000",
          "tags": [
            "phishing"
          ],
          "references": [
            "https://ltna.com.au/cyber"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "LTNA-Australia",
            "id": "380633",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 1997
          },
          "indicator_count": 1997,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 92,
          "modified_text": "44 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "69e265e726e950122d41bc59",
          "name": "Phishing | Apr 18, 2026 | Part 395/566",
          "description": "Phishing indicators. Date: Apr 18, 2026. Part 395/566. For more threat intelligence visit https://ltna.com.au/cyber",
          "modified": "2026-04-17T16:55:03.751000",
          "created": "2026-04-17T16:55:03.751000",
          "tags": [
            "phishing"
          ],
          "references": [
            "https://ltna.com.au/cyber"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "LTNA-Australia",
            "id": "380633",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 1997
          },
          "indicator_count": 1997,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 92,
          "modified_text": "45 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "69e11765e63a9ae2b9e1f164",
          "name": "Phishing | Apr 17, 2026 | Part 395/566",
          "description": "Phishing indicators. Date: Apr 17, 2026. Part 395/566. For more threat intelligence visit https://ltna.com.au/cyber",
          "modified": "2026-04-16T17:07:49.977000",
          "created": "2026-04-16T17:07:49.977000",
          "tags": [
            "phishing"
          ],
          "references": [
            "https://ltna.com.au/cyber"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "LTNA-Australia",
            "id": "380633",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 1997
          },
          "indicator_count": 1997,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 92,
          "modified_text": "46 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "69dfc6dcac6be3ab5e7b847b",
          "name": "Phishing | Apr 16, 2026 | Part 395/566",
          "description": "Phishing indicators. Date: Apr 16, 2026. Part 395/566. For more threat intelligence visit https://ltna.com.au/cyber",
          "modified": "2026-04-15T17:11:56.282000",
          "created": "2026-04-15T17:11:56.282000",
          "tags": [
            "phishing"
          ],
          "references": [
            "https://ltna.com.au/cyber"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "LTNA-Australia",
            "id": "380633",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 1997
          },
          "indicator_count": 1997,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 91,
          "modified_text": "47 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "69de6ff7606de486b9dda573",
          "name": "Phishing | Apr 15, 2026 | Part 395/566",
          "description": "Phishing indicators. Date: Apr 15, 2026. Part 395/566. For more threat intelligence visit https://ltna.com.au/cyber",
          "modified": "2026-04-14T16:48:55.022000",
          "created": "2026-04-14T16:48:55.022000",
          "tags": [
            "phishing"
          ],
          "references": [
            "https://ltna.com.au/cyber"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "LTNA-Australia",
            "id": "380633",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 1997
          },
          "indicator_count": 1997,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 93,
          "modified_text": "48 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "Names: Photo.scr \u2022 85115B0142902832C864B3009CAB1A00.RS (names of FileHash above)",
        "dropbox.com - deleted victims DB post assault. Sabey + Ahmann repeatedly erased DB (ILLEGAL)",
        "TAM Legal\u2019s Christopher P. \u2018Buzz\u2019 Ahmann Esq works for State Quasi Government in tandem w/ Hall Render",
        "Alerts: network_icmp nolookup_communication persistence_autorun modifies_proxy_wpad",
        "Crowdsourced IDS: Matches rule ET POLICY PE EXE or DLL Windows file download HTTP",
        "Yara Detections: MS17_010_WanaCry_worm  ,  stack_string , MS_Visual_Cpp_6_0 ,  Armadillov1xxv2xx",
        "http://apple.com-index.php-account-locked-verification.test2.aptaforum.com.cn/",
        "https://hybrid-analysis.com/sample/a638ece11c81bcac0002363eb3f75de35a46ce0e080b5de41162093181079a6b/69c018efcb875e4fb30cdfcc",
        "IDS Detections: Behavioral Unusual Port 445 traffic Potential Scan or Infection SMB-DS",
        "https://otx.alienvault.com/pulse/69bf8e2663d5480917ddb699",
        "https://otx.alienvault.com/pulse/69bea426487bffa5384c6f38",
        "Protected:SA\u2019r Jeffrey Scott Reimer, Mark Montano MD, John T. Sasha MD, Frederick P. Scherr , others.",
        "http://appleid.apple.com-signin-8491e.test2.aptaforum.com.cn/",
        "Quasi Gov - Law firms stole victims clouds. Evidence, $Intellectual property, Memories of & victims family. Merciless",
        "http://apple.sweetycat.com/ \u2022 https://apple.sweetycat.com/",
        "HallRender.com | Law Firm M. Brian Sabey Esq. | Pegasus related",
        "Yara Detections: WannaCry_Ransomware ,  Wanna_Cry_Ransomware_Generic ,  WannaDecryptor",
        "Emails:yejun.shou@yxips.com Name:\u7ebd\u8fea\u5e0c\u4e9a\u751f\u547d\u65e9\u671f\u8425\u517b\u54c1\u7ba1\u7406(\u4e0a\u6d77)\u6709\u9650\u516c\u53f8 Name Servers: dns17.hichina.com",
        "jgw.and.googletagmanagers.com",
        "msedge.b.tlu.dl.delivery.mp.microsoft.com",
        "*unsigned Domain: aptaforum.com.cn  Name Servers: dns18.hichina.com Registrar: \u963f\u91cc\u4e91\u8ba1\u7b97\u6709\u9650\u516c\u53f8\uff08\u4e07\u7f51\uff09Status: ok",
        "bzx.and.googletagmanagers.com",
        "IP\u2019s Contacted: 121.105.233.189  128.251.173.246  13.248.148.254  132.124.155.52  139.246.30.108",
        "appleid.apple.com-signin-8491e.test2.aptaforum.com.cn",
        "https://otx.alienvault.com/indicator/domain/qeenetic.link",
        "apple.haipaoapp.com \u2022 http://apple.haipaoapp.com \u2022 http://apple.haipaoapp.com/ \u2022 https://apple.haipaoapp.com/",
        "http://prtests.ru/test.html?15%0Ahttp://profetest.ru/test.html?2%0Ahttp://qptest.ru/test.html?5%0Ahttp://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/3cf71a18-f999-4372-beac-67715d51bb62?P1=1629470400&P2=404&P3=2&P4=d%2520arRdiatcalmlQRKq2gm1LlFitNgIcLpnyzCIHYtf%2520ByXQF0JNptZ0rBDMKlLL%2520qsOzZdPICJjC7MWkkdm1Hg==%0Ahttp://stafftest.ru/test.html?0%0Ahttp://iqtesti.ru/test.html?17%0Ahttp://hrtests.ru/test.html?1%0Ahttp://pstests.ru/test.html?4%0Ahttp://prtests.ru/test.html?6%0Ahttp:/",
        "IDS Detections: Observed WannaCry Domain (iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff .com in DNS Lookup)",
        "pgj.and.googletagmanagers.com",
        "Alerts:  peid_packer pe_unknown_resource_name",
        "IDS Detections: Possible ETERNALBLUE Probe MS17-010 (Generic Flags)",
        "http://ww17.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com/",
        "IDS Detections: IPC$ share access \u2022 SMB-DS IPC$ unicode share access \u2022 403 Forbidden",
        "pcy.and.googletagmanagers.com",
        "lkp.and.googletagmanagers.com",
        "Crowdsourced IDS: Fast Flux attempt Matches rule ET INFO EXE IsDebuggerPresent (Used in Malware Anti-Debugging)",
        "https://hybrid-analysis.com/sample/09610b7c855ef132a31f2e0136b4d62b9dbb04c6fcb42160d6d8409ef6394e40/69c0189c5e0483a78907cc39",
        "Alerts: creates_service stealth_window antivm_network_adapters checks_debugger",
        "http://e7.c.lencr.org/74.crl \u2022 http://e7.i.lencr.org/",
        "http://appleid.apple.com.secure1account.pagelogin.test2.aptaforum.com.cn/",
        "Crowdsourced IDS: Matches rule MALWARE-CNC DNS",
        "appleid.apple.com.secure1account.pagelogin.test2.aptaforum.com.cn",
        "Win32:CVE-2017-0147-B\\ [Expl] ,  Win.Ransomware.WannaCry-6313787-0 ,  Exploit:Win32/CVE-2017-0147.A",
        "findmy.apple-uk.live",
        "https://otx.alienvault.com/pulse/69b49ad5dd40a24d83cd6a72",
        "Domains Contacted: www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com",
        "Alerts: network_cnc_http network_http allocates_rwx creates_exe creates_hidden_file",
        "Trojan/JS.Redirector.QNO SHA256:9e6e93c05a9736b95426fe0f492a18a2ac409bd9fb572dd3c982cb6de3ba0dbc",
        "VO7MU1HA.htm : https://hybrid-analysis.com/sample/9e6e93c05a9736b95426fe0f492a18a2ac409bd9fb572dd3c982cb6de3ba0dbc",
        "www.remoteaccess.allied-media.com",
        "prb.and.googletagmanagers.com",
        "dns17.hichina.com",
        "apple.com-verify.account.manage.test2.aptaforum.com.cn",
        "FileHash-SHA256 002dee2db8b07b98b543ad99d0dd4e3e0ba7624f956d719ba803f57b426e30e7",
        "https://ltna.com.au/cyber",
        "aptaforum.com.cn   182.61.201.90 ,  182.61.201.91   China ASN AS38365 beijing baidu netcom science and technology co. ltd",
        "apple.com-index.php-account-locked-verification.test2.aptaforum.com.cn",
        "Domains Contacted: ww38.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com",
        "KeenDNS | keendnsaclremote805717135272048.qeenetic.link",
        "okg.and.googletagmanagers.com",
        "http://apple.com-verify.account.manage.test2.aptaforum.com.cn/",
        "web-secure-appleid-login.com.test2.aptaforum.com.cn",
        "https://fonts.googleapis.com/css",
        "http://web-secure-appleid-login.com.test2.aptaforum.com.cn/",
        "IP\u2019s Contacted: 103.224.212.220  105.242.60.208  117.13.61.219  117.180.208.83  12.105.46.122",
        "https://otx.alienvault.com/pulse/69bf261cc4e399447d78776c",
        "IDS Detections: Possible ETERNALBLUE Probe MS17-010 (MSF style) ETERNALBLUE Probe Vulnerable System Response MS17-010",
        "(?) https://living-sun.com/applescript/68281-is-there-a-way-to-disable-force-quit-while-applescript-application-is-still-running-applescript-quit.html"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 0
        },
        "other": {
          "adversary": [],
          "malware_families": [
            "Ransom:win32/wannacrypt.h",
            "Trojan/js.redirector.qno",
            "Ransom:win32/cve-2017-0147.a",
            "Backdoor:win32/small.ir",
            "#virtool:win32/obfuscator",
            "Win64:expiro-aj\\ [inf]",
            "Win32:dh-a\\ [win32:fileinfector-c\\ [heur]",
            "Win32:dh-a\\",
            "Virtool:win32/vbinject.ya!mtb",
            "Ransomware",
            "Win.ransomware.wannacry-6313787-0",
            "Win.trojan.vbgeneric-6989114-0",
            "Win.trojan.application-1955.",
            "Win32:banker-laa\\ [trj]",
            "Exploit:win32/cve-2017-0147.a",
            "Win32:trojanx-gen\\ [trj]",
            "Win32:evo-gen\\ [trj]",
            "Cve-2017-0147",
            "Alf:spikeaexr.pevpopc",
            "Sf:wncryldr-a\\ [trj]",
            "Win32:malware-gen",
            "Win.malware.snojan-6775202-0",
            "Win.malware.flystudio-6738927-0",
            "Win.trojan.fugrafa-9733007-0"
          ],
          "industries": [
            "Legal",
            "Technology",
            "Healthcare",
            "Government"
          ],
          "unique_indicators": 12462
        }
      }
    },
    "false_positive": [],
    "alexa": "http://www.alexa.com/siteinfo/eventkrafton.com",
    "whois": "http://whois.domaintools.com/eventkrafton.com",
    "domain": "eventkrafton.com",
    "hostname": "news.eventkrafton.com"
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 50,
  "pulses": [
    {
      "id": "6a1da5461ecc1b4898544d19",
      "name": "Phishing | Jun 2, 2026 | Part 395/566",
      "description": "Phishing indicators. Date: Jun 2, 2026. Part 395/566. For more threat intelligence visit https://ltna.com.au/cyber",
      "modified": "2026-06-01T15:29:10.895000",
      "created": "2026-06-01T15:29:10.895000",
      "tags": [
        "phishing"
      ],
      "references": [
        "https://ltna.com.au/cyber"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "LTNA-Australia",
        "id": "380633",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 1998
      },
      "indicator_count": 1998,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 91,
      "modified_text": "2 hours ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6a1c4fdb770595cb5505f67f",
      "name": "Phishing | Jun 1, 2026 | Part 395/566",
      "description": "Phishing indicators. Date: Jun 1, 2026. Part 395/566. For more threat intelligence visit https://ltna.com.au/cyber",
      "modified": "2026-05-31T15:12:27.524000",
      "created": "2026-05-31T15:12:27.524000",
      "tags": [
        "phishing"
      ],
      "references": [
        "https://ltna.com.au/cyber"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "LTNA-Australia",
        "id": "380633",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 1998
      },
      "indicator_count": 1998,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 93,
      "modified_text": "1 day ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6a1aff769b6669f939b4b1c8",
      "name": "Phishing | May 31, 2026 | Part 395/566",
      "description": "Phishing indicators. Date: May 31, 2026. Part 395/566. For more threat intelligence visit https://ltna.com.au/cyber",
      "modified": "2026-05-30T15:17:10.272000",
      "created": "2026-05-30T15:17:10.272000",
      "tags": [
        "phishing"
      ],
      "references": [
        "https://ltna.com.au/cyber"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "LTNA-Australia",
        "id": "380633",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 1998
      },
      "indicator_count": 1998,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 93,
      "modified_text": "2 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6a19ad4e9b2839fb97dc556d",
      "name": "Phishing | May 30, 2026 | Part 395/566",
      "description": "Phishing indicators. Date: May 30, 2026. Part 395/566. For more threat intelligence visit https://ltna.com.au/cyber",
      "modified": "2026-05-29T15:14:22.246000",
      "created": "2026-05-29T15:14:22.246000",
      "tags": [
        "phishing"
      ],
      "references": [
        "https://ltna.com.au/cyber"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "LTNA-Australia",
        "id": "380633",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 1998
      },
      "indicator_count": 1998,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 93,
      "modified_text": "3 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6a1864f468f5deec400fd46e",
      "name": "Phishing | May 29, 2026 | Part 395/566",
      "description": "Phishing indicators. Date: May 29, 2026. Part 395/566. For more threat intelligence visit https://ltna.com.au/cyber",
      "modified": "2026-05-28T15:53:24.146000",
      "created": "2026-05-28T15:53:24.146000",
      "tags": [
        "phishing"
      ],
      "references": [
        "https://ltna.com.au/cyber"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "LTNA-Australia",
        "id": "380633",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 1998
      },
      "indicator_count": 1998,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 93,
      "modified_text": "4 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6a170cf13e2fd9b71d1f2b8b",
      "name": "Phishing | May 28, 2026 | Part 395/566",
      "description": "Phishing indicators. Date: May 28, 2026. Part 395/566. For more threat intelligence visit https://ltna.com.au/cyber",
      "modified": "2026-05-27T15:25:37.026000",
      "created": "2026-05-27T15:25:37.026000",
      "tags": [
        "phishing"
      ],
      "references": [
        "https://ltna.com.au/cyber"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "LTNA-Australia",
        "id": "380633",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 1998
      },
      "indicator_count": 1998,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 93,
      "modified_text": "5 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6a15b9b01ca27a2bdbc5b653",
      "name": "Phishing | May 27, 2026 | Part 395/566",
      "description": "Phishing indicators. Date: May 27, 2026. Part 395/566. For more threat intelligence visit https://ltna.com.au/cyber",
      "modified": "2026-05-26T15:18:08.338000",
      "created": "2026-05-26T15:18:08.338000",
      "tags": [
        "phishing"
      ],
      "references": [
        "https://ltna.com.au/cyber"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "LTNA-Australia",
        "id": "380633",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 1998
      },
      "indicator_count": 1998,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 93,
      "modified_text": "6 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6a1466db90fe091f094f7c2f",
      "name": "Phishing | May 26, 2026 | Part 395/566",
      "description": "Phishing indicators. Date: May 26, 2026. Part 395/566. For more threat intelligence visit https://ltna.com.au/cyber",
      "modified": "2026-05-25T15:12:27.586000",
      "created": "2026-05-25T15:12:27.586000",
      "tags": [
        "phishing"
      ],
      "references": [
        "https://ltna.com.au/cyber"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "LTNA-Australia",
        "id": "380633",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 1998
      },
      "indicator_count": 1998,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 93,
      "modified_text": "7 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6a13155a3eee46df14670b44",
      "name": "Phishing | May 25, 2026 | Part 395/566",
      "description": "Phishing indicators. Date: May 25, 2026. Part 395/566. For more threat intelligence visit https://ltna.com.au/cyber",
      "modified": "2026-05-24T15:12:26.222000",
      "created": "2026-05-24T15:12:26.222000",
      "tags": [
        "phishing"
      ],
      "references": [
        "https://ltna.com.au/cyber"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "LTNA-Australia",
        "id": "380633",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 1998
      },
      "indicator_count": 1998,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 93,
      "modified_text": "8 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6a11c365d31ea17c5d4e174e",
      "name": "Phishing | May 24, 2026 | Part 395/566",
      "description": "Phishing indicators. Date: May 24, 2026. Part 395/566. For more threat intelligence visit https://ltna.com.au/cyber",
      "modified": "2026-05-23T15:10:29.888000",
      "created": "2026-05-23T15:10:29.888000",
      "tags": [
        "phishing"
      ],
      "references": [
        "https://ltna.com.au/cyber"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "LTNA-Australia",
        "id": "380633",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_380633/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 1998
      },
      "indicator_count": 1998,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 92,
      "modified_text": "9 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "https://news.eventkrafton.com",
    "type": "URL"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "https://news.eventkrafton.com",
    "type": "URL",
    "found": false,
    "verdict": "clean",
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780335980.705392
}