{
  "type": "URL",
  "indicator": "https://nextron.com",
  "general": {
    "sections": [
      "general",
      "url_list",
      "http_scans",
      "screenshot"
    ],
    "indicator": "https://nextron.com",
    "type": "url",
    "type_title": "URL",
    "validation": [],
    "base_indicator": {
      "id": 4345533468,
      "indicator": "https://nextron.com",
      "type": "URL",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 2,
      "pulses": [
        {
          "id": "69faf0e7e922f6018d039d15",
          "name": "CAPE Sandbox - Aurora like Flo.",
          "description": "[This research pulse identifies a file exhibiting high-frequency network activity with minimal local file system impact. The sample bypasses common detection signatures, relying on encrypted communications and rapid DNS resolution to establish external connections.Technical Analysis & MITRE ATT&CKCommand and Control (T1071.001): The sample utilizes standard Web Protocols (HTTP/DNS) for external communication.Reconnaissance (T1589): High volume of unique IP connections (17) and DNS queries (6) suggests automated environmental scanning or identity gathering.Protocol Obfuscation: The presence of 11 unique JA3 fingerprints indicates a sophisticated rotating encryption strategy for SSL/TLS traffic to evade traditional network inspection.Indicators of Compromise (IoCs)File Hash (SHA-256): df8f1674d7034cb48fcd0651304833febfcaf1814c8294839246e9db1d269b1dNetwork Activity with Nextron:HTTP Requests: 5DNS Queries: 6Unique IP Connections: 17Encrypted Traffic: 11 JA3 SSL/TLS fingerprints observed.",
          "modified": "2026-05-06T10:50:46.591000",
          "created": "2026-05-06T07:42:31.304000",
          "tags": [
            "html internet",
            "html document",
            "ascii text",
            "code",
            "date",
            "icann whois",
            "server",
            "registrar abuse",
            "whois status",
            "notice",
            "dnssec",
            "registrant name",
            "tech email",
            "form",
            "tech",
            "handle",
            "address range",
            "cidr",
            "network name",
            "allocation type",
            "allocated pa",
            "status",
            "whois server",
            "entity scipmnt",
            "nextron",
            "show",
            "read",
            "t series",
            "textron",
            "europe",
            "nextron product",
            "brands",
            "transportation",
            "taiwan"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1095",
              "name": "Non-Application Layer Protocol",
              "display_name": "T1095 - Non-Application Layer Protocol"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 3,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 2,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 151,
            "hostname": 232,
            "domain": 98,
            "FileHash-MD5": 50,
            "FileHash-SHA1": 6,
            "FileHash-SHA256": 32,
            "IPv4": 44,
            "email": 1,
            "CIDR": 2,
            "CVE": 1
          },
          "indicator_count": 617,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 69,
          "modified_text": "27 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "69faf0e688402e4e3ab85930",
          "name": "CAPE Sandbox - Aurora like Flo.",
          "description": "[This research pulse identifies a file exhibiting high-frequency network activity with minimal local file system impact. The sample bypasses common detection signatures, relying on encrypted communications and rapid DNS resolution to establish external connections.Technical Analysis & MITRE ATT&CKCommand and Control (T1071.001): The sample utilizes standard Web Protocols (HTTP/DNS) for external communication.Reconnaissance (T1589): High volume of unique IP connections (17) and DNS queries (6) suggests automated environmental scanning or identity gathering.Protocol Obfuscation: The presence of 11 unique JA3 fingerprints indicates a sophisticated rotating encryption strategy for SSL/TLS traffic to evade traditional network inspection.Indicators of Compromise (IoCs)File Hash (SHA-256): df8f1674d7034cb48fcd0651304833febfcaf1814c8294839246e9db1d269b1dNetwork Activity with Nextron:HTTP Requests: 5DNS Queries: 6Unique IP Connections: 17Encrypted Traffic: 11 JA3 SSL/TLS fingerprints observed.",
          "modified": "2026-05-06T10:50:46.337000",
          "created": "2026-05-06T07:42:30.565000",
          "tags": [
            "html internet",
            "html document",
            "ascii text",
            "code",
            "date",
            "icann whois",
            "server",
            "registrar abuse",
            "whois status",
            "notice",
            "dnssec",
            "registrant name",
            "tech email",
            "form",
            "tech",
            "handle",
            "address range",
            "cidr",
            "network name",
            "allocation type",
            "allocated pa",
            "status",
            "whois server",
            "entity scipmnt",
            "nextron",
            "show",
            "read",
            "t series",
            "textron",
            "europe",
            "nextron product",
            "brands",
            "transportation",
            "taiwan"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1095",
              "name": "Non-Application Layer Protocol",
              "display_name": "T1095 - Non-Application Layer Protocol"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 88,
            "hostname": 185,
            "domain": 62,
            "FileHash-MD5": 16,
            "FileHash-SHA1": 4,
            "FileHash-SHA256": 17,
            "IPv4": 32,
            "email": 1,
            "CIDR": 2,
            "CVE": 1
          },
          "indicator_count": 408,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 69,
          "modified_text": "27 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        }
      ],
      "references": [],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 0
        },
        "other": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 517
        }
      }
    },
    "false_positive": [],
    "alexa": "http://www.alexa.com/siteinfo/nextron.com",
    "whois": "http://whois.domaintools.com/nextron.com",
    "domain": "nextron.com",
    "hostname": "Unavailable"
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 2,
  "pulses": [
    {
      "id": "69faf0e7e922f6018d039d15",
      "name": "CAPE Sandbox - Aurora like Flo.",
      "description": "[This research pulse identifies a file exhibiting high-frequency network activity with minimal local file system impact. The sample bypasses common detection signatures, relying on encrypted communications and rapid DNS resolution to establish external connections.Technical Analysis & MITRE ATT&CKCommand and Control (T1071.001): The sample utilizes standard Web Protocols (HTTP/DNS) for external communication.Reconnaissance (T1589): High volume of unique IP connections (17) and DNS queries (6) suggests automated environmental scanning or identity gathering.Protocol Obfuscation: The presence of 11 unique JA3 fingerprints indicates a sophisticated rotating encryption strategy for SSL/TLS traffic to evade traditional network inspection.Indicators of Compromise (IoCs)File Hash (SHA-256): df8f1674d7034cb48fcd0651304833febfcaf1814c8294839246e9db1d269b1dNetwork Activity with Nextron:HTTP Requests: 5DNS Queries: 6Unique IP Connections: 17Encrypted Traffic: 11 JA3 SSL/TLS fingerprints observed.",
      "modified": "2026-05-06T10:50:46.591000",
      "created": "2026-05-06T07:42:31.304000",
      "tags": [
        "html internet",
        "html document",
        "ascii text",
        "code",
        "date",
        "icann whois",
        "server",
        "registrar abuse",
        "whois status",
        "notice",
        "dnssec",
        "registrant name",
        "tech email",
        "form",
        "tech",
        "handle",
        "address range",
        "cidr",
        "network name",
        "allocation type",
        "allocated pa",
        "status",
        "whois server",
        "entity scipmnt",
        "nextron",
        "show",
        "read",
        "t series",
        "textron",
        "europe",
        "nextron product",
        "brands",
        "transportation",
        "taiwan"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1095",
          "name": "Non-Application Layer Protocol",
          "display_name": "T1095 - Non-Application Layer Protocol"
        },
        {
          "id": "T1573",
          "name": "Encrypted Channel",
          "display_name": "T1573 - Encrypted Channel"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 3,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 2,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 151,
        "hostname": 232,
        "domain": 98,
        "FileHash-MD5": 50,
        "FileHash-SHA1": 6,
        "FileHash-SHA256": 32,
        "IPv4": 44,
        "email": 1,
        "CIDR": 2,
        "CVE": 1
      },
      "indicator_count": 617,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 69,
      "modified_text": "27 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "69faf0e688402e4e3ab85930",
      "name": "CAPE Sandbox - Aurora like Flo.",
      "description": "[This research pulse identifies a file exhibiting high-frequency network activity with minimal local file system impact. The sample bypasses common detection signatures, relying on encrypted communications and rapid DNS resolution to establish external connections.Technical Analysis & MITRE ATT&CKCommand and Control (T1071.001): The sample utilizes standard Web Protocols (HTTP/DNS) for external communication.Reconnaissance (T1589): High volume of unique IP connections (17) and DNS queries (6) suggests automated environmental scanning or identity gathering.Protocol Obfuscation: The presence of 11 unique JA3 fingerprints indicates a sophisticated rotating encryption strategy for SSL/TLS traffic to evade traditional network inspection.Indicators of Compromise (IoCs)File Hash (SHA-256): df8f1674d7034cb48fcd0651304833febfcaf1814c8294839246e9db1d269b1dNetwork Activity with Nextron:HTTP Requests: 5DNS Queries: 6Unique IP Connections: 17Encrypted Traffic: 11 JA3 SSL/TLS fingerprints observed.",
      "modified": "2026-05-06T10:50:46.337000",
      "created": "2026-05-06T07:42:30.565000",
      "tags": [
        "html internet",
        "html document",
        "ascii text",
        "code",
        "date",
        "icann whois",
        "server",
        "registrar abuse",
        "whois status",
        "notice",
        "dnssec",
        "registrant name",
        "tech email",
        "form",
        "tech",
        "handle",
        "address range",
        "cidr",
        "network name",
        "allocation type",
        "allocated pa",
        "status",
        "whois server",
        "entity scipmnt",
        "nextron",
        "show",
        "read",
        "t series",
        "textron",
        "europe",
        "nextron product",
        "brands",
        "transportation",
        "taiwan"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1095",
          "name": "Non-Application Layer Protocol",
          "display_name": "T1095 - Non-Application Layer Protocol"
        },
        {
          "id": "T1573",
          "name": "Encrypted Channel",
          "display_name": "T1573 - Encrypted Channel"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 88,
        "hostname": 185,
        "domain": 62,
        "FileHash-MD5": 16,
        "FileHash-SHA1": 4,
        "FileHash-SHA256": 17,
        "IPv4": 32,
        "email": 1,
        "CIDR": 2,
        "CVE": 1
      },
      "indicator_count": 408,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 69,
      "modified_text": "27 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "https://nextron.com",
    "type": "URL"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "https://nextron.com",
    "type": "URL",
    "found": false,
    "verdict": "clean",
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780430898.5157795
}