{
  "type": "URL",
  "indicator": "https://ns1.raid.ru/",
  "general": {
    "sections": [
      "general",
      "url_list",
      "http_scans",
      "screenshot"
    ],
    "indicator": "https://ns1.raid.ru/",
    "type": "url",
    "type_title": "URL",
    "validation": [],
    "base_indicator": {
      "id": 4181912568,
      "indicator": "https://ns1.raid.ru/",
      "type": "URL",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 4,
      "pulses": [
        {
          "id": "69bf261cc4e399447d78776c",
          "name": "Cyber Bully Attackers | Revenge Attacks | Remote attackers | Malware Packed |",
          "description": "Several government entities, attorneys have sought porn revenge including physical violence, attempted crimes, malicious prosecution case , harassment when a female patient of man formerly known as Jeffrey Scott Reimer of Chester Springs, PA, violently, critically injured patient in a sexually charged assault [URL\thttp://foundry2-lbl.dvr.dn2.n-helix.com\t\t\t\nhttps://foundry2-lbl.dvr.dn2.n-helix.com\t\tfoundry2-lbl.dvr.dn2.n-helix.com\t\t\t\t\thttps://www.palantir.io/docs/foundry/ontologies/test-changes-in-ontology/\t\t\nhttp://datafoundry.com\t\t\t\nhttp://foundry2sdbl.dvr.dn2.n-helix.com\t\t\thttps://209-99-40-223.fwd.datafoundry.com\t\t\t\ndatafoundry.com",
          "modified": "2026-04-20T18:43:51.664000",
          "created": "2026-03-21T23:13:32.760000",
          "tags": [
            "sc data",
            "data upload",
            "please sub",
            "include data",
            "extraction",
            "failed",
            "sc pulse",
            "idron anv",
            "extr please",
            "include review",
            "exclude sugges",
            "stop show",
            "typ domain",
            "united",
            "virtool",
            "name servers",
            "cryp",
            "emails",
            "win32",
            "ip address",
            "worm",
            "trojan",
            "learn",
            "suspicious",
            "informative",
            "ck id",
            "name tactics",
            "command",
            "adversaries",
            "spawns",
            "ssl certificate",
            "initial access",
            "link initial",
            "prefetch8",
            "mitre att",
            "ck matrix",
            "flag",
            "windows nt",
            "win64",
            "accept",
            "encrypt",
            "form",
            "hybrid",
            "bypass",
            "general",
            "path",
            "iframe",
            "click",
            "strings",
            "anchor https",
            "anchor",
            "liberal",
            "sabey",
            "liberal friends",
            "meta",
            "html internet",
            "html document",
            "unicode text",
            "utf8 text",
            "info initial",
            "access ta0001",
            "compromise",
            "t1189 network",
            "communication",
            "get http",
            "artifacts v",
            "full reports",
            "v get",
            "help dns",
            "resolutions",
            "ip traffic",
            "extr data",
            "enter sc",
            "extra data",
            "referen",
            "broth",
            "passive dns",
            "urls",
            "http",
            "hostname",
            "files domain",
            "files related",
            "related tags",
            "none google",
            "safe browsing",
            "inquest labs",
            "lucas acha",
            "code integrity",
            "checks creation",
            "otx logo",
            "all hostname",
            "files",
            "domain",
            "protect",
            "date",
            "title",
            "exchange",
            "se http",
            "present jan",
            "present feb",
            "present dec",
            "backdoor",
            "certificate",
            "all domain",
            "alibaba cloud",
            "hichina",
            "porkbun llc",
            "cloudflare",
            "namecheap inc",
            "namecheap",
            "domains",
            "dynadot llc",
            "ascio",
            "denmark",
            "url https",
            "filehashsha256",
            "url http",
            "dopple ai",
            "snit",
            "iocs",
            "otx description",
            "information",
            "report spam",
            "delete service",
            "poem",
            "hunter",
            "malicious",
            "porn revenge",
            "brian sabeys",
            "all report",
            "spam delete",
            "rl http",
            "https",
            "expiration http",
            "spam brian",
            "swipper",
            "type indicator",
            "role title",
            "added active",
            "related pulses",
            "filehashmd5",
            "filehashsha1",
            "sha256",
            "scan",
            "learn more",
            "indicators show",
            "tbmvid",
            "sourcelnms",
            "zx1724209326040",
            "xxx videos",
            "xxxvideohd",
            "adversary",
            "packing",
            "palantir.com",
            "discovery",
            "victim won case",
            "doin it",
            "palantirian abuse",
            "apple",
            "sabey data centers",
            "insurance",
            "quasi government",
            "the brother sabey",
            "reimer",
            "law enforcement",
            "vessel state",
            "sabey porn",
            "hall evans",
            "christopher ahmann",
            "defamation",
            "google"
          ],
          "references": [
            "The Brothers Sabey \u2013 Conservatives with Liberal Friends \u2022 https://thebrotherssabey.com/",
            "http://watchhers.net/index.php",
            "http://212.33.237.86/images/1/report.php",
            "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian",
            "https://webmail.police.govmm.org/owa/",
            "https://pks.wroclaw.sa.gov.pl:1443/ \u2022 portal.bialystok.sa.gov.pl",
            "https://tulach.cc/ phishing \u2022 45.32.112.220 scanning_host \u2022 45.76.79.215",
            "Mark Brian Sabey",
            "Melvin Sabey",
            "Christopher P \u2018Buzz\u2019 Ahmann",
            "Ronda Cordova",
            "Unknown Persons impersonating Private Investigators (plural)",
            "Quasi Government Case",
            "Victim silenced. Struck by Car Driven by male police let walk",
            "Denver Police let this attempted murder walk. Cited him as a ghost driver",
            "Make driver stuck victim with large vehicle after PT unknowingly reported original assault Jeffrey Reiner to Dora",
            "Sexual and Physical Assaulter - Jeffrey Scott Reimer",
            "Reimer was a PT. Unknown whereabouts , name or job description",
            "Denver Police Department Major Crimes closed investigation",
            "Investigation closed when Brian Sabey initiated a malicious prosecution case against Victim",
            "I bring up the personal nature of the crime because a delete service has been used",
            "More than 1000 IoC\u2019s including pulses have been ILLEGALLY removed",
            "All IoC\u2019s originate from sources named. There are some unknown attackers",
            "This is a serious crime. I\u2019m certain God WILL pay them.",
            "https://palantirwww.sweetheartvideo.com\t\t\tMar 21, 2026, 2:06:10 PM\t\t3\t  domain\tpalantir.io\t\t\tMar 21, 2026, 2:06:10 PM\t\t34\t  URL\thttps://www.palantir.io/docs/foundry/ontologies/test-changes-in-ontology/ \u2022 www.palantir.com",
            "http://palantirwww.sweetheartvideo.com/ (weirdness)",
            "http://foundry2-lbl.dvr.dn2.n-helix.com \u2022 https://foundry2-lbl.dvr.dn2.n-helix.com",
            "foundry2-lbl.dvr.dn2.n-helix.com\t\t\tMar 21, 2026, 2:06:10 PM\t\t29\t  URL\thttps://www.palantir.io/docs/foundry/ontologies/test-changes-in-ontology/\t\t\tMar 21, 2026, 2:06:10 PM\t\t8\t  URL\thttp://datafoundry.com\t\t\tMar 21, 2026, 2:06:10 PM\t\t9\t  URL\thttp://foundry2sdbl.dvr.dn2.n-helix.com\t\t\tMar 21, 2026, 2:06:10 PM\t\t17\t  URL\thttps://209-99-40-223.fwd.datafoundry.com\t\t\tMar 21, 2026, 2:06:10 PM\t\t27\t  domain\tdatafoundry.com\t\t\tMar 21, 2026, 2:06:10 PM\t\t40\t  hostname\t209-99-40-223.fwd.datafoundry.com\t\t\tMar 21, 2026, 2:06:1",
            "foundry2-lbl.dvr.dn2.n-helix.com\t\t\tMar 21, 2026, 2:06:10 PM\t\t29\t  URL\thttps://www.palantir.io/docs/foundry/ontologies/test-changes-in-ontology/\t\t\tMar 21, 2026, 2:06:10 PM\t\t8\t  URL\thttp://datafoundry.com\t\t\tMar 21, 2026, 2:06:10 PM\t\t9\t  URL\thttp://foundry2sdbl.dvr.dn2.n-helix.com\t\t\tMar 21, 2026, 2:06:10 PM\t\t17\t  URL\thttps://209-99-40-223.fwd.datafoundry.com\t\t\tMar 21, 2026, 2:06:10 PM\t\t27\t  domain\tdatafoundry.com\t\t\tMar 21, 2026, 2:06:10 PM\t\t40\t  hostname\t209-99-40-223.fwd.datafoundry.com\t\t\tMar 21, 2026, 2:06:1",
            "https://rdweb.datafoundry.com/RDWeb/Pages/en-US/login.aspx",
            "https://www.datafoundry.com/data-center-contamination-control/",
            "https://www.datafoundry.com/data-center-contamination-control/",
            "https://www.palantir.io/docs/foundry/ontologies/test-changes-in-ontology/",
            "http://foundry2-lbl.dvr.dn2.n-helix.com/",
            "https://207-207-25-201.fwd.datafoundry.com/",
            "http://datafoundry.com \u2022 http://foundry2sdbl.dvr.dn2.n-helix.com \u2022 https://209-99-40-223.fwd.datafoundry.com \u2022 datafoundry.com \u2022 209-99-40-223.fwd.datafoundry.com \u2022 beabetta.ifoundry.co.uk.s7b2.psmtp.com \u2022 foundry2sdbl.dvr.dn2.n-helix.com \u2022 fwd.datafoundry.com \u2022 207-207-25-154.fwd.datafoundry.com \u2022 207-207-25-156.fwd.datafoundry.com\t\t\t207-207-25-160.fwd.datafoundry.com \u2022 207-207-25-163.fwd.datafoundry.com  \u2022\t207-207-25-164.fwd.datafoundry.com \u2022 207-207-25-165.fwd.datafoundry.com\t\t\tMar 21, 207-207-25-166.fwd",
            "http://datafoundry.com \u2022 https://209-99-40-223.fwd.datafoundry.com\tdatafoundry.com \u2022 209-99-40-223.fwd.datafoundry.com\t\t\tMar 21, 2026, 2:06:10 PM\t\t13\t  hostname\tbeabetta.ifoundry.co.uk.s7b2.psmtp.com\t\t\tMar 21, 2026, 2:06:10 PM\t\t12\t  hostname\tfoundry2sdbl.dvr.dn2.n-helix.com\t\t\tMar 21, 2026, 2:06:10 PM\t\t18\t  hostname\tfwd.datafoundry.com\t\t\tMar 21, 2026, 2:06:10 PM\t\t8\t  hostname\t207-207-25-154.fwd.datafoundry.com\t\t\tMar 21, 2026, 2:06:10 PM\t\t19\t  hostname\t207-207-25-156.fwd.datafoundry.com\t\t\tMar 21, 2026, 2:06:1",
            "https://rdweb.datafoundry.com/",
            "https://www.palantir.io/docs/foundry/ontologies/test-changes-in-ontology/",
            "http://foundry2sdbl.dvr.dn2.n-helix.com/",
            "Updated | What\u2019s left after theft",
            "207-207-25-167.fwd.datafoundry.com \u2022 207-207-25-168.fwd.datafoundry.com \u2022 207-207-25-169.fwd.datafoundry.com",
            "207-207-25-170.fwd.datafoundry.com \u2022 207-207-25-171.fwd.datafoundry.com \u2022 207-207-25-201.fwd.datafoundry.com",
            "https://www.datafoundry.com/category/news/press-releases/ (Fake Press) abuse",
            "https://www.datafoundry.com/category/news/press-releases/",
            "207-207-25-209.fwd.datafoundry.com \u2022\t207-207-25-212.fwd.datafoundry.com \u2022 207-207-25-213.fwd.datafoundry.com \u2022 209-99-64-53.fwd.datafoundry.com",
            "209-99-69-91.fwd.datafoundry.com \u2022 dns1.datafoundry.com \u2022 dns2.datafoundry.com \u2022 rdweb.datafoundry.com",
            "www.go.datafoundry.com \u2022 http://207-207-25-209.fwd.datafoundry.com",
            "http://209-99-64-53.fwd.datafoundry.com \u2022 http://dns2.datafoundry.com \u2022 http://fwd.datafoundry.com",
            "http://pdns1.datafoundry.com/ \u2022\thttp://rdweb.datafoundry.com \u2022 http://rdweb.datafoundry.com/",
            "https://rdweb.datafoundry.com/ \u2022 http://www.datafoundry.com \u2022 https://207-207-25-163.fwd.datafoundry.com \u2022",
            "https://207-207-25-209.fwd.datafoundry.com \u2022 https://209-99-40-224.fwd.datafoundry.com/",
            "https://209-99-64-53.fwd.datafoundry.com \u2022 https://dns1.datafoundry.com \u2022 https://dns2.datafoundry.com \u2022 https://fwd.datafoundry.com",
            "Some may may find this content is very disturbing and offensive"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Porn Revenge",
              "display_name": "Porn Revenge",
              "target": null
            },
            {
              "id": "Tons of Malware",
              "display_name": "Tons of Malware",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1041",
              "name": "Exfiltration Over C2 Channel",
              "display_name": "T1041 - Exfiltration Over C2 Channel"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1132",
              "name": "Data Encoding",
              "display_name": "T1132 - Data Encoding"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1189",
              "name": "Drive-by Compromise",
              "display_name": "T1189 - Drive-by Compromise"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1568",
              "name": "Dynamic Resolution",
              "display_name": "T1568 - Dynamic Resolution"
            },
            {
              "id": "T1583",
              "name": "Acquire Infrastructure",
              "display_name": "T1583 - Acquire Infrastructure"
            },
            {
              "id": "T1583.001",
              "name": "Domains",
              "display_name": "T1583.001 - Domains"
            },
            {
              "id": "T1553.002",
              "name": "Code Signing",
              "display_name": "T1553.002 - Code Signing"
            },
            {
              "id": "T1132.001",
              "name": "Standard Encoding",
              "display_name": "T1132.001 - Standard Encoding"
            },
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1568.002",
              "name": "Domain Generation Algorithms",
              "display_name": "T1568.002 - Domain Generation Algorithms"
            },
            {
              "id": "T1071.004",
              "name": "DNS",
              "display_name": "T1071.004 - DNS"
            },
            {
              "id": "T1113",
              "name": "Screen Capture",
              "display_name": "T1113 - Screen Capture"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1045",
              "name": "Software Packing",
              "display_name": "T1045 - Software Packing"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1060",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1060 - Registry Run Keys / Startup Folder"
            },
            {
              "id": "T1070",
              "name": "Indicator Removal on Host",
              "display_name": "T1070 - Indicator Removal on Host"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1125",
              "name": "Video Capture",
              "display_name": "T1125 - Video Capture"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1143",
              "name": "Hidden Window",
              "display_name": "T1143 - Hidden Window"
            },
            {
              "id": "T1176",
              "name": "Browser Extensions",
              "display_name": "T1176 - Browser Extensions"
            },
            {
              "id": "T1449",
              "name": "Exploit SS7 to Redirect Phone Calls/SMS",
              "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
            },
            {
              "id": "T1495",
              "name": "Firmware Corruption",
              "display_name": "T1495 - Firmware Corruption"
            },
            {
              "id": "T1546",
              "name": "Event Triggered Execution",
              "display_name": "T1546 - Event Triggered Execution"
            },
            {
              "id": "T1587.001",
              "name": "Malware",
              "display_name": "T1587.001 - Malware"
            },
            {
              "id": "T1608.001",
              "name": "Upload Malware",
              "display_name": "T1608.001 - Upload Malware"
            },
            {
              "id": "T1457",
              "name": "Malicious Media Content",
              "display_name": "T1457 - Malicious Media Content"
            },
            {
              "id": "T1586.001",
              "name": "Social Media Accounts",
              "display_name": "T1586.001 - Social Media Accounts"
            },
            {
              "id": "T1593.001",
              "name": "Social Media",
              "display_name": "T1593.001 - Social Media"
            },
            {
              "id": "T1068",
              "name": "Exploitation for Privilege Escalation",
              "display_name": "T1068 - Exploitation for Privilege Escalation"
            },
            {
              "id": "T1080",
              "name": "Taint Shared Content",
              "display_name": "T1080 - Taint Shared Content"
            },
            {
              "id": "T1190",
              "name": "Exploit Public-Facing Application",
              "display_name": "T1190 - Exploit Public-Facing Application"
            },
            {
              "id": "T1472",
              "name": "Generate Fraudulent Advertising Revenue",
              "display_name": "T1472 - Generate Fraudulent Advertising Revenue"
            },
            {
              "id": "T1586",
              "name": "Compromise Accounts",
              "display_name": "T1586 - Compromise Accounts"
            },
            {
              "id": "T1059.002",
              "name": "AppleScript",
              "display_name": "T1059.002 - AppleScript"
            },
            {
              "id": "T1456",
              "name": "Drive-by Compromise",
              "display_name": "T1456 - Drive-by Compromise"
            },
            {
              "id": "T1210",
              "name": "Exploitation of Remote Services",
              "display_name": "T1210 - Exploitation of Remote Services"
            },
            {
              "id": "T1583.005",
              "name": "Botnet",
              "display_name": "T1583.005 - Botnet"
            },
            {
              "id": "T1584",
              "name": "Compromise Infrastructure",
              "display_name": "T1584 - Compromise Infrastructure"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 5,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Q.Vashti",
            "id": "337942",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 6034,
            "domain": 1422,
            "IPv4": 397,
            "FileHash-MD5": 274,
            "FileHash-SHA1": 252,
            "FileHash-SHA256": 3378,
            "email": 11,
            "hostname": 2753,
            "CVE": 1,
            "SSLCertFingerprint": 9,
            "IPv6": 32
          },
          "indicator_count": 14563,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 140,
          "modified_text": "19 minutes ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "69ded8198b25581a09b90824",
          "name": "BearShare \u2022 Solarwinds? \u2022 SearchSuite \u2022 Healthcare Administration",
          "description": "",
          "modified": "2026-04-15T00:13:13.981000",
          "created": "2026-04-15T00:13:13.981000",
          "tags": [
            "Win32/SearchSuite",
            "pe32",
            "intel",
            "ms windows",
            "ms visual",
            "win32 dynamic",
            "link library",
            "win16 ne",
            "pe32 installer",
            "install system",
            "compiler",
            "NSIS",
            "code signing",
            "serial number",
            "db d2",
            "de d3",
            "f3 e1",
            "issuer thawte",
            "primary root",
            "ca valid",
            "valid",
            "valid usage",
            "client auth",
            "algorithm",
            "rticon english",
            "type type",
            "chi2",
            "ico rtgroupicon",
            "english us",
            "capa",
            "c2 antianalysis",
            "executable",
            "sample appears",
            "installer",
            "installers well",
            "results may",
            "be misleading",
            "or incomplete",
            "analyze created",
            "techniques",
            "info modify",
            "files",
            "modify registry",
            "directory permi",
            "techniques none",
            "info",
            "scripting inte",
            "shared modules",
            "Bear Share",
            "urls",
            "ip address",
            "asn as8075",
            "united",
            "flag united",
            "name servers",
            "name domain",
            "org apple",
            "infinite loop",
            "city cupertino",
            "country us",
            "dnssec",
            "urlmailto",
            "urlhttps",
            "search",
            "urlhttp",
            "moved",
            "title",
            "encrypt",
            "certificate",
            "segoe ui",
            "otx logo",
            "url analysis",
            "tokyo",
            "msie",
            "chrome",
            "gmt content",
            "all ipv4",
            "zeppelin",
            "trojandropper",
            "cookie",
            "backdoor",
            "hash avast",
            "avg clamav",
            "msdefender feb",
            "k oct",
            "k may",
            "mtb feb",
            "mtb jan",
            "k aug",
            "windows nt",
            "dynamicloader",
            "unknown",
            "medium",
            "default",
            "as16509",
            "show",
            "powershell",
            "write",
            "xserver",
            "bearshar data",
            "passive dns",
            "pulse submit",
            "port",
            "destination",
            "high",
            "displayname",
            "windows",
            "win64",
            "tofsee",
            "stream",
            "malware",
            "push",
            "next",
            "asnone",
            "germany as8560",
            "russia as198610",
            "strings",
            "is__elf",
            "systembc_linux_variant",
            "khtml",
            "gecko",
            "acceptencoding",
            "get na",
            "macintosh",
            "intel mac",
            "accept",
            "france as16276",
            "yara detections",
            "contacted",
            "all filehash",
            "sha256",
            "pulse pulses",
            "av detections",
            "ids detections",
            "alerts",
            "analysis date",
            "tls sni",
            "less see",
            "all ip",
            "Apple",
            "xordata",
            "United States"
          ],
          "references": [
            "b9e4e47c3f96846c30581c08acf5bc56.virus",
            "BearShare Install File Version 12.0.0.135802",
            "Musiclab, LLC",
            "msoid.applemanic.com \u2022 msoid.giftcardapple.shop \u2022 msoid.appleportconsulting.com",
            "gateway.fe.apple-dns.net \u2022 apple-dns.net",
            "africa.konnect.com",
            "http://scratch-mit-edu.027.cloudns.asia/users/alessandrito123",
            "euw-serp-dev-testing19.duck.ai",
            "account-apple.com",
            "Win.Trojan.Tofsee-7102058-0 ,  Backdoor:Win32/Tofsee.T",
            "IDS Detections Win32/Tofsee.AX google.com connectivity check Observed Telegram Domain (t .me in TLS SNI)",
            "Yara Detections: Tofsee",
            "Alerts: behavior_tofsee creates_largekey injection_write_exe_process network_bind",
            "Alerts: persistence_autorun persistence_autorun_tasks procmem_yara static_pe_anomaly",
            "Alerts: suricata_alert antivm_generic_services physical_drive_access deletes_executed_files",
            "Alerts: deletes_self injection_runpe persistence_ads suspicious_command_tools",
            "Alerts: anomalous_deletefile antisandbox_sleep dead_connect dynamic_function_loading",
            "IP\u2019s Contacted: 47.43.26.4  195.35.13.119  149.154.167.99  185.138.56.214  142.250.147.26  81.88.48.101",
            "IP\u2019s Contacted: 104.21.72.117  172.66.156.195  157.240.200.174  141.193.213.20",
            "Domains Contacted: microsoft.com microsoft-com.mail.protection.outlook.com vanaheim.cn yahoo.com mta6.am0.yahoodns.net 13.205.167.198.dnsbl.sorbs.net 13.205.167.198.bl.spamcop.net 13.205.167.198.zen.spamhaus.org 13.205.167.198.sbl-xbl.spamhaus.org 13.205.167.198.cbl.abuseat.org",
            "https://perigon-one.au.itglue.com/password_shared_links/52f082d3-d889-4db5-ae03-c7bfcbe5aa21",
            "https://identity.prd-cdc.jemena.com.au/pages/jemena-reset-password",
            "https://in2it.itglue.com/password_shared_links/9b0e2a1d-b554-4f0c-a333-390e41defe8e",
            "https://oauth2.admin.p4d-1.p4d.aks.lightops.cloud.slb-ds.com/lightops-auth/callback&response_type=code&scope=openid+email+profile&state=uJZE80MW6TdJQjbI0RWXhnF3SpYZXckLkfafnEHgr_I:",
            "https://oauth2.admin.p4d-1.p4d.aks.lightops.cloud.slb-ds.com/lightops-auth/callback",
            "ids-apple.com \u2022 itunes.org",
            "xn--cloud-4sa.com",
            "http://cab.applemarketingtools.com",
            "http://console.applemarketingtools.com/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America",
            "Spain",
            "France",
            "United Kingdom of Great Britain and Northern Ireland",
            "Netherlands",
            "Japan",
            "Switzerland",
            "Madagascar",
            "Finland",
            "Germany",
            "Russian Federation"
          ],
          "malware_families": [
            {
              "id": "Win32/SearchSuite",
              "display_name": "Win32/SearchSuite",
              "target": null
            },
            {
              "id": "Win32.Application.BearShare.A",
              "display_name": "Win32.Application.BearShare.A",
              "target": null
            },
            {
              "id": "Exploit:Win32/CVE-2017-0147",
              "display_name": "Exploit:Win32/CVE-2017-0147",
              "target": "/malware/Exploit:Win32/CVE-2017-0147"
            },
            {
              "id": "CVE-2023-22518",
              "display_name": "CVE-2023-22518",
              "target": null
            },
            {
              "id": "Win.Packed.Bandook-9882274-1",
              "display_name": "Win.Packed.Bandook-9882274-1",
              "target": null
            },
            {
              "id": "Win.Trojan.Tofsee-7102058-0",
              "display_name": "Win.Trojan.Tofsee-7102058-0",
              "target": null
            },
            {
              "id": "Backdoor:Win32/Tofsee.T",
              "display_name": "Backdoor:Win32/Tofsee.T",
              "target": "/malware/Backdoor:Win32/Tofsee.T"
            },
            {
              "id": "TrojanDownloader:Win32/Cutwail",
              "display_name": "TrojanDownloader:Win32/Cutwail",
              "target": "/malware/TrojanDownloader:Win32/Cutwail"
            }
          ],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1112",
              "name": "Modify Registry",
              "display_name": "T1112 - Modify Registry"
            },
            {
              "id": "T1222",
              "name": "File and Directory Permissions Modification",
              "display_name": "T1222 - File and Directory Permissions Modification"
            },
            {
              "id": "TA0003",
              "name": "Persistence",
              "display_name": "TA0003 - Persistence"
            },
            {
              "id": "TA0005",
              "name": "Defense Evasion",
              "display_name": "TA0005 - Defense Evasion"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "TA0002",
              "name": "Execution",
              "display_name": "TA0002 - Execution"
            },
            {
              "id": "T1155",
              "name": "AppleScript",
              "display_name": "T1155 - AppleScript"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1060",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1060 - Registry Run Keys / Startup Folder"
            }
          ],
          "industries": [
            "Government",
            "Healthcare",
            "Technology"
          ],
          "TLP": "green",
          "cloned_from": "69dab27a0493e0e80a0f35cd",
          "export_count": 4,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Q.Vashti",
            "id": "337942",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 138,
            "FileHash-SHA1": 119,
            "FileHash-SHA256": 3553,
            "IPv4": 633,
            "CVE": 2,
            "URL": 6134,
            "domain": 2439,
            "hostname": 2271,
            "email": 9,
            "SSLCertFingerprint": 2
          },
          "indicator_count": 15300,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 137,
          "modified_text": "5 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "69db05f833d3d6d2231fb201",
          "name": "CREDIT: Q.Vashti's research: SearchSuite \u2022 Healthcare Administration CREATED 6 HOURS AGO by Q.Vashti",
          "description": "",
          "modified": "2026-04-12T02:39:52.993000",
          "created": "2026-04-12T02:39:52.993000",
          "tags": [
            "Win32/SearchSuite",
            "pe32",
            "intel",
            "ms windows",
            "ms visual",
            "win32 dynamic",
            "link library",
            "win16 ne",
            "pe32 installer",
            "install system",
            "compiler",
            "NSIS",
            "code signing",
            "serial number",
            "db d2",
            "de d3",
            "f3 e1",
            "issuer thawte",
            "primary root",
            "ca valid",
            "valid",
            "valid usage",
            "client auth",
            "algorithm",
            "rticon english",
            "type type",
            "chi2",
            "ico rtgroupicon",
            "english us",
            "capa",
            "c2 antianalysis",
            "executable",
            "sample appears",
            "installer",
            "installers well",
            "results may",
            "be misleading",
            "or incomplete",
            "analyze created",
            "techniques",
            "info modify",
            "files",
            "modify registry",
            "directory permi",
            "techniques none",
            "info",
            "scripting inte",
            "shared modules",
            "Bear Share",
            "urls",
            "ip address",
            "asn as8075",
            "united",
            "flag united",
            "name servers",
            "name domain",
            "org apple",
            "infinite loop",
            "city cupertino",
            "country us",
            "dnssec",
            "urlmailto",
            "urlhttps",
            "search",
            "urlhttp",
            "moved",
            "title",
            "encrypt",
            "certificate",
            "segoe ui",
            "otx logo",
            "url analysis",
            "tokyo",
            "msie",
            "chrome",
            "gmt content",
            "all ipv4",
            "zeppelin",
            "trojandropper",
            "cookie",
            "backdoor",
            "hash avast",
            "avg clamav",
            "msdefender feb",
            "k oct",
            "k may",
            "mtb feb",
            "mtb jan",
            "k aug",
            "windows nt",
            "dynamicloader",
            "unknown",
            "medium",
            "default",
            "as16509",
            "show",
            "powershell",
            "write",
            "xserver",
            "bearshar data",
            "passive dns",
            "pulse submit",
            "port",
            "destination",
            "high",
            "displayname",
            "windows",
            "win64",
            "tofsee",
            "stream",
            "malware",
            "push",
            "next",
            "asnone",
            "germany as8560",
            "russia as198610",
            "strings",
            "is__elf",
            "systembc_linux_variant",
            "khtml",
            "gecko",
            "acceptencoding",
            "get na",
            "macintosh",
            "intel mac",
            "accept",
            "france as16276",
            "yara detections",
            "contacted",
            "all filehash",
            "sha256",
            "pulse pulses",
            "av detections",
            "ids detections",
            "alerts",
            "analysis date",
            "tls sni",
            "less see",
            "all ip",
            "Apple",
            "xordata",
            "United States"
          ],
          "references": [
            "b9e4e47c3f96846c30581c08acf5bc56.virus",
            "BearShare Install File Version 12.0.0.135802",
            "Musiclab, LLC",
            "msoid.applemanic.com \u2022 msoid.giftcardapple.shop \u2022 msoid.appleportconsulting.com",
            "gateway.fe.apple-dns.net \u2022 apple-dns.net",
            "africa.konnect.com",
            "http://scratch-mit-edu.027.cloudns.asia/users/alessandrito123",
            "euw-serp-dev-testing19.duck.ai",
            "account-apple.com",
            "Win.Trojan.Tofsee-7102058-0 ,  Backdoor:Win32/Tofsee.T",
            "IDS Detections Win32/Tofsee.AX google.com connectivity check Observed Telegram Domain (t .me in TLS SNI)",
            "Yara Detections: Tofsee",
            "Alerts: behavior_tofsee creates_largekey injection_write_exe_process network_bind",
            "Alerts: persistence_autorun persistence_autorun_tasks procmem_yara static_pe_anomaly",
            "Alerts: suricata_alert antivm_generic_services physical_drive_access deletes_executed_files",
            "Alerts: deletes_self injection_runpe persistence_ads suspicious_command_tools",
            "Alerts: anomalous_deletefile antisandbox_sleep dead_connect dynamic_function_loading",
            "IP\u2019s Contacted: 47.43.26.4  195.35.13.119  149.154.167.99  185.138.56.214  142.250.147.26  81.88.48.101",
            "IP\u2019s Contacted: 104.21.72.117  172.66.156.195  157.240.200.174  141.193.213.20",
            "Domains Contacted: microsoft.com microsoft-com.mail.protection.outlook.com vanaheim.cn yahoo.com mta6.am0.yahoodns.net 13.205.167.198.dnsbl.sorbs.net 13.205.167.198.bl.spamcop.net 13.205.167.198.zen.spamhaus.org 13.205.167.198.sbl-xbl.spamhaus.org 13.205.167.198.cbl.abuseat.org",
            "https://perigon-one.au.itglue.com/password_shared_links/52f082d3-d889-4db5-ae03-c7bfcbe5aa21",
            "https://identity.prd-cdc.jemena.com.au/pages/jemena-reset-password",
            "https://in2it.itglue.com/password_shared_links/9b0e2a1d-b554-4f0c-a333-390e41defe8e",
            "https://oauth2.admin.p4d-1.p4d.aks.lightops.cloud.slb-ds.com/lightops-auth/callback&response_type=code&scope=openid+email+profile&state=uJZE80MW6TdJQjbI0RWXhnF3SpYZXckLkfafnEHgr_I:",
            "https://oauth2.admin.p4d-1.p4d.aks.lightops.cloud.slb-ds.com/lightops-auth/callback",
            "ids-apple.com \u2022 itunes.org",
            "xn--cloud-4sa.com",
            "http://cab.applemarketingtools.com",
            "http://console.applemarketingtools.com/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America",
            "Spain",
            "France",
            "United Kingdom of Great Britain and Northern Ireland",
            "Netherlands",
            "Japan",
            "Switzerland",
            "Madagascar",
            "Finland",
            "Germany",
            "Russian Federation"
          ],
          "malware_families": [
            {
              "id": "Win32/SearchSuite",
              "display_name": "Win32/SearchSuite",
              "target": null
            },
            {
              "id": "Win32.Application.BearShare.A",
              "display_name": "Win32.Application.BearShare.A",
              "target": null
            },
            {
              "id": "Exploit:Win32/CVE-2017-0147",
              "display_name": "Exploit:Win32/CVE-2017-0147",
              "target": "/malware/Exploit:Win32/CVE-2017-0147"
            },
            {
              "id": "CVE-2023-22518",
              "display_name": "CVE-2023-22518",
              "target": null
            },
            {
              "id": "Win.Packed.Bandook-9882274-1",
              "display_name": "Win.Packed.Bandook-9882274-1",
              "target": null
            },
            {
              "id": "Win.Trojan.Tofsee-7102058-0",
              "display_name": "Win.Trojan.Tofsee-7102058-0",
              "target": null
            },
            {
              "id": "Backdoor:Win32/Tofsee.T",
              "display_name": "Backdoor:Win32/Tofsee.T",
              "target": "/malware/Backdoor:Win32/Tofsee.T"
            },
            {
              "id": "TrojanDownloader:Win32/Cutwail",
              "display_name": "TrojanDownloader:Win32/Cutwail",
              "target": "/malware/TrojanDownloader:Win32/Cutwail"
            }
          ],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1112",
              "name": "Modify Registry",
              "display_name": "T1112 - Modify Registry"
            },
            {
              "id": "T1222",
              "name": "File and Directory Permissions Modification",
              "display_name": "T1222 - File and Directory Permissions Modification"
            },
            {
              "id": "TA0003",
              "name": "Persistence",
              "display_name": "TA0003 - Persistence"
            },
            {
              "id": "TA0005",
              "name": "Defense Evasion",
              "display_name": "TA0005 - Defense Evasion"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "TA0002",
              "name": "Execution",
              "display_name": "TA0002 - Execution"
            },
            {
              "id": "T1155",
              "name": "AppleScript",
              "display_name": "T1155 - AppleScript"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1060",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1060 - Registry Run Keys / Startup Folder"
            }
          ],
          "industries": [
            "Government",
            "Healthcare",
            "Technology"
          ],
          "TLP": "green",
          "cloned_from": "69dab27a0493e0e80a0f35cd",
          "export_count": 3,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 138,
            "FileHash-SHA1": 119,
            "FileHash-SHA256": 3553,
            "IPv4": 633,
            "CVE": 2,
            "URL": 6134,
            "domain": 2439,
            "hostname": 2271,
            "email": 9,
            "SSLCertFingerprint": 2
          },
          "indicator_count": 15300,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 49,
          "modified_text": "8 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "69dab27a0493e0e80a0f35cd",
          "name": "SearchSuite \u2022 Healthcare Administration",
          "description": "Embedded in communication between a healthcare system and a client. \n\nThis is just one of countless internal issues causing a gap in communication, malicious adware, spyware, system sweeps, injection, system modification, downloads , call failures.",
          "modified": "2026-04-11T20:43:38.695000",
          "created": "2026-04-11T20:43:38.695000",
          "tags": [
            "Win32/SearchSuite",
            "pe32",
            "intel",
            "ms windows",
            "ms visual",
            "win32 dynamic",
            "link library",
            "win16 ne",
            "pe32 installer",
            "install system",
            "compiler",
            "NSIS",
            "code signing",
            "serial number",
            "db d2",
            "de d3",
            "f3 e1",
            "issuer thawte",
            "primary root",
            "ca valid",
            "valid",
            "valid usage",
            "client auth",
            "algorithm",
            "rticon english",
            "type type",
            "chi2",
            "ico rtgroupicon",
            "english us",
            "capa",
            "c2 antianalysis",
            "executable",
            "sample appears",
            "installer",
            "installers well",
            "results may",
            "be misleading",
            "or incomplete",
            "analyze created",
            "techniques",
            "info modify",
            "files",
            "modify registry",
            "directory permi",
            "techniques none",
            "info",
            "scripting inte",
            "shared modules",
            "Bear Share",
            "urls",
            "ip address",
            "asn as8075",
            "united",
            "flag united",
            "name servers",
            "name domain",
            "org apple",
            "infinite loop",
            "city cupertino",
            "country us",
            "dnssec",
            "urlmailto",
            "urlhttps",
            "search",
            "urlhttp",
            "moved",
            "title",
            "encrypt",
            "certificate",
            "segoe ui",
            "otx logo",
            "url analysis",
            "tokyo",
            "msie",
            "chrome",
            "gmt content",
            "all ipv4",
            "zeppelin",
            "trojandropper",
            "cookie",
            "backdoor",
            "hash avast",
            "avg clamav",
            "msdefender feb",
            "k oct",
            "k may",
            "mtb feb",
            "mtb jan",
            "k aug",
            "windows nt",
            "dynamicloader",
            "unknown",
            "medium",
            "default",
            "as16509",
            "show",
            "powershell",
            "write",
            "xserver",
            "bearshar data",
            "passive dns",
            "pulse submit",
            "port",
            "destination",
            "high",
            "displayname",
            "windows",
            "win64",
            "tofsee",
            "stream",
            "malware",
            "push",
            "next",
            "asnone",
            "germany as8560",
            "russia as198610",
            "strings",
            "is__elf",
            "systembc_linux_variant",
            "khtml",
            "gecko",
            "acceptencoding",
            "get na",
            "macintosh",
            "intel mac",
            "accept",
            "france as16276",
            "yara detections",
            "contacted",
            "all filehash",
            "sha256",
            "pulse pulses",
            "av detections",
            "ids detections",
            "alerts",
            "analysis date",
            "tls sni",
            "less see",
            "all ip",
            "Apple",
            "xordata",
            "United States"
          ],
          "references": [
            "b9e4e47c3f96846c30581c08acf5bc56.virus",
            "BearShare Install File Version 12.0.0.135802",
            "Musiclab, LLC",
            "msoid.applemanic.com \u2022 msoid.giftcardapple.shop \u2022 msoid.appleportconsulting.com",
            "gateway.fe.apple-dns.net \u2022 apple-dns.net",
            "africa.konnect.com",
            "http://scratch-mit-edu.027.cloudns.asia/users/alessandrito123",
            "euw-serp-dev-testing19.duck.ai",
            "account-apple.com",
            "Win.Trojan.Tofsee-7102058-0 ,  Backdoor:Win32/Tofsee.T",
            "IDS Detections Win32/Tofsee.AX google.com connectivity check Observed Telegram Domain (t .me in TLS SNI)",
            "Yara Detections: Tofsee",
            "Alerts: behavior_tofsee creates_largekey injection_write_exe_process network_bind",
            "Alerts: persistence_autorun persistence_autorun_tasks procmem_yara static_pe_anomaly",
            "Alerts: suricata_alert antivm_generic_services physical_drive_access deletes_executed_files",
            "Alerts: deletes_self injection_runpe persistence_ads suspicious_command_tools",
            "Alerts: anomalous_deletefile antisandbox_sleep dead_connect dynamic_function_loading",
            "IP\u2019s Contacted: 47.43.26.4  195.35.13.119  149.154.167.99  185.138.56.214  142.250.147.26  81.88.48.101",
            "IP\u2019s Contacted: 104.21.72.117  172.66.156.195  157.240.200.174  141.193.213.20",
            "Domains Contacted: microsoft.com microsoft-com.mail.protection.outlook.com vanaheim.cn yahoo.com mta6.am0.yahoodns.net 13.205.167.198.dnsbl.sorbs.net 13.205.167.198.bl.spamcop.net 13.205.167.198.zen.spamhaus.org 13.205.167.198.sbl-xbl.spamhaus.org 13.205.167.198.cbl.abuseat.org",
            "https://perigon-one.au.itglue.com/password_shared_links/52f082d3-d889-4db5-ae03-c7bfcbe5aa21",
            "https://identity.prd-cdc.jemena.com.au/pages/jemena-reset-password",
            "https://in2it.itglue.com/password_shared_links/9b0e2a1d-b554-4f0c-a333-390e41defe8e",
            "https://oauth2.admin.p4d-1.p4d.aks.lightops.cloud.slb-ds.com/lightops-auth/callback&response_type=code&scope=openid+email+profile&state=uJZE80MW6TdJQjbI0RWXhnF3SpYZXckLkfafnEHgr_I:",
            "https://oauth2.admin.p4d-1.p4d.aks.lightops.cloud.slb-ds.com/lightops-auth/callback",
            "ids-apple.com \u2022 itunes.org",
            "xn--cloud-4sa.com",
            "http://cab.applemarketingtools.com",
            "http://console.applemarketingtools.com/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America",
            "Spain",
            "France",
            "United Kingdom of Great Britain and Northern Ireland",
            "Netherlands",
            "Japan",
            "Switzerland",
            "Madagascar",
            "Finland",
            "Germany",
            "Russian Federation"
          ],
          "malware_families": [
            {
              "id": "Win32/SearchSuite",
              "display_name": "Win32/SearchSuite",
              "target": null
            },
            {
              "id": "Win32.Application.BearShare.A",
              "display_name": "Win32.Application.BearShare.A",
              "target": null
            },
            {
              "id": "Exploit:Win32/CVE-2017-0147",
              "display_name": "Exploit:Win32/CVE-2017-0147",
              "target": "/malware/Exploit:Win32/CVE-2017-0147"
            },
            {
              "id": "CVE-2023-22518",
              "display_name": "CVE-2023-22518",
              "target": null
            },
            {
              "id": "Win.Packed.Bandook-9882274-1",
              "display_name": "Win.Packed.Bandook-9882274-1",
              "target": null
            },
            {
              "id": "Win.Trojan.Tofsee-7102058-0",
              "display_name": "Win.Trojan.Tofsee-7102058-0",
              "target": null
            },
            {
              "id": "Backdoor:Win32/Tofsee.T",
              "display_name": "Backdoor:Win32/Tofsee.T",
              "target": "/malware/Backdoor:Win32/Tofsee.T"
            },
            {
              "id": "TrojanDownloader:Win32/Cutwail",
              "display_name": "TrojanDownloader:Win32/Cutwail",
              "target": "/malware/TrojanDownloader:Win32/Cutwail"
            }
          ],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1112",
              "name": "Modify Registry",
              "display_name": "T1112 - Modify Registry"
            },
            {
              "id": "T1222",
              "name": "File and Directory Permissions Modification",
              "display_name": "T1222 - File and Directory Permissions Modification"
            },
            {
              "id": "TA0003",
              "name": "Persistence",
              "display_name": "TA0003 - Persistence"
            },
            {
              "id": "TA0005",
              "name": "Defense Evasion",
              "display_name": "TA0005 - Defense Evasion"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "TA0002",
              "name": "Execution",
              "display_name": "TA0002 - Execution"
            },
            {
              "id": "T1155",
              "name": "AppleScript",
              "display_name": "T1155 - AppleScript"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1060",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1060 - Registry Run Keys / Startup Folder"
            }
          ],
          "industries": [
            "Government",
            "Healthcare",
            "Technology"
          ],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 7,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Q.Vashti",
            "id": "337942",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 138,
            "FileHash-SHA1": 119,
            "FileHash-SHA256": 3553,
            "IPv4": 633,
            "CVE": 2,
            "URL": 6134,
            "domain": 2439,
            "hostname": 2271,
            "email": 9,
            "SSLCertFingerprint": 2
          },
          "indicator_count": 15300,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 140,
          "modified_text": "8 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "IP\u2019s Contacted: 104.21.72.117  172.66.156.195  157.240.200.174  141.193.213.20",
        "https://207-207-25-209.fwd.datafoundry.com \u2022 https://209-99-40-224.fwd.datafoundry.com/",
        "http://pdns1.datafoundry.com/ \u2022\thttp://rdweb.datafoundry.com \u2022 http://rdweb.datafoundry.com/",
        "https://identity.prd-cdc.jemena.com.au/pages/jemena-reset-password",
        "http://console.applemarketingtools.com/",
        "africa.konnect.com",
        "https://rdweb.datafoundry.com/",
        "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian",
        "Updated | What\u2019s left after theft",
        "More than 1000 IoC\u2019s including pulses have been ILLEGALLY removed",
        "http://foundry2-lbl.dvr.dn2.n-helix.com/",
        "Melvin Sabey",
        "account-apple.com",
        "The Brothers Sabey \u2013 Conservatives with Liberal Friends \u2022 https://thebrotherssabey.com/",
        "Sexual and Physical Assaulter - Jeffrey Scott Reimer",
        "https://rdweb.datafoundry.com/RDWeb/Pages/en-US/login.aspx",
        "All IoC\u2019s originate from sources named. There are some unknown attackers",
        "Alerts: behavior_tofsee creates_largekey injection_write_exe_process network_bind",
        "Make driver stuck victim with large vehicle after PT unknowingly reported original assault Jeffrey Reiner to Dora",
        "https://www.palantir.io/docs/foundry/ontologies/test-changes-in-ontology/",
        "https://perigon-one.au.itglue.com/password_shared_links/52f082d3-d889-4db5-ae03-c7bfcbe5aa21",
        "Quasi Government Case",
        "Alerts: suricata_alert antivm_generic_services physical_drive_access deletes_executed_files",
        "https://www.datafoundry.com/data-center-contamination-control/",
        "https://palantirwww.sweetheartvideo.com\t\t\tMar 21, 2026, 2:06:10 PM\t\t3\t  domain\tpalantir.io\t\t\tMar 21, 2026, 2:06:10 PM\t\t34\t  URL\thttps://www.palantir.io/docs/foundry/ontologies/test-changes-in-ontology/ \u2022 www.palantir.com",
        "http://209-99-64-53.fwd.datafoundry.com \u2022 http://dns2.datafoundry.com \u2022 http://fwd.datafoundry.com",
        "This is a serious crime. I\u2019m certain God WILL pay them.",
        "https://207-207-25-201.fwd.datafoundry.com/",
        "http://cab.applemarketingtools.com",
        "https://tulach.cc/ phishing \u2022 45.32.112.220 scanning_host \u2022 45.76.79.215",
        "Yara Detections: Tofsee",
        "https://209-99-64-53.fwd.datafoundry.com \u2022 https://dns1.datafoundry.com \u2022 https://dns2.datafoundry.com \u2022 https://fwd.datafoundry.com",
        "Musiclab, LLC",
        "IP\u2019s Contacted: 47.43.26.4  195.35.13.119  149.154.167.99  185.138.56.214  142.250.147.26  81.88.48.101",
        "http://palantirwww.sweetheartvideo.com/ (weirdness)",
        "Alerts: deletes_self injection_runpe persistence_ads suspicious_command_tools",
        "https://pks.wroclaw.sa.gov.pl:1443/ \u2022 portal.bialystok.sa.gov.pl",
        "Alerts: anomalous_deletefile antisandbox_sleep dead_connect dynamic_function_loading",
        "https://in2it.itglue.com/password_shared_links/9b0e2a1d-b554-4f0c-a333-390e41defe8e",
        "xn--cloud-4sa.com",
        "ids-apple.com \u2022 itunes.org",
        "Unknown Persons impersonating Private Investigators (plural)",
        "https://rdweb.datafoundry.com/ \u2022 http://www.datafoundry.com \u2022 https://207-207-25-163.fwd.datafoundry.com \u2022",
        "https://www.datafoundry.com/category/news/press-releases/ (Fake Press) abuse",
        "BearShare Install File Version 12.0.0.135802",
        "209-99-69-91.fwd.datafoundry.com \u2022 dns1.datafoundry.com \u2022 dns2.datafoundry.com \u2022 rdweb.datafoundry.com",
        "http://datafoundry.com \u2022 https://209-99-40-223.fwd.datafoundry.com\tdatafoundry.com \u2022 209-99-40-223.fwd.datafoundry.com\t\t\tMar 21, 2026, 2:06:10 PM\t\t13\t  hostname\tbeabetta.ifoundry.co.uk.s7b2.psmtp.com\t\t\tMar 21, 2026, 2:06:10 PM\t\t12\t  hostname\tfoundry2sdbl.dvr.dn2.n-helix.com\t\t\tMar 21, 2026, 2:06:10 PM\t\t18\t  hostname\tfwd.datafoundry.com\t\t\tMar 21, 2026, 2:06:10 PM\t\t8\t  hostname\t207-207-25-154.fwd.datafoundry.com\t\t\tMar 21, 2026, 2:06:10 PM\t\t19\t  hostname\t207-207-25-156.fwd.datafoundry.com\t\t\tMar 21, 2026, 2:06:1",
        "http://datafoundry.com \u2022 http://foundry2sdbl.dvr.dn2.n-helix.com \u2022 https://209-99-40-223.fwd.datafoundry.com \u2022 datafoundry.com \u2022 209-99-40-223.fwd.datafoundry.com \u2022 beabetta.ifoundry.co.uk.s7b2.psmtp.com \u2022 foundry2sdbl.dvr.dn2.n-helix.com \u2022 fwd.datafoundry.com \u2022 207-207-25-154.fwd.datafoundry.com \u2022 207-207-25-156.fwd.datafoundry.com\t\t\t207-207-25-160.fwd.datafoundry.com \u2022 207-207-25-163.fwd.datafoundry.com  \u2022\t207-207-25-164.fwd.datafoundry.com \u2022 207-207-25-165.fwd.datafoundry.com\t\t\tMar 21, 207-207-25-166.fwd",
        "Mark Brian Sabey",
        "foundry2-lbl.dvr.dn2.n-helix.com\t\t\tMar 21, 2026, 2:06:10 PM\t\t29\t  URL\thttps://www.palantir.io/docs/foundry/ontologies/test-changes-in-ontology/\t\t\tMar 21, 2026, 2:06:10 PM\t\t8\t  URL\thttp://datafoundry.com\t\t\tMar 21, 2026, 2:06:10 PM\t\t9\t  URL\thttp://foundry2sdbl.dvr.dn2.n-helix.com\t\t\tMar 21, 2026, 2:06:10 PM\t\t17\t  URL\thttps://209-99-40-223.fwd.datafoundry.com\t\t\tMar 21, 2026, 2:06:10 PM\t\t27\t  domain\tdatafoundry.com\t\t\tMar 21, 2026, 2:06:10 PM\t\t40\t  hostname\t209-99-40-223.fwd.datafoundry.com\t\t\tMar 21, 2026, 2:06:1",
        "https://www.datafoundry.com/category/news/press-releases/",
        "http://watchhers.net/index.php",
        "Some may may find this content is very disturbing and offensive",
        "http://scratch-mit-edu.027.cloudns.asia/users/alessandrito123",
        "https://oauth2.admin.p4d-1.p4d.aks.lightops.cloud.slb-ds.com/lightops-auth/callback",
        "207-207-25-209.fwd.datafoundry.com \u2022\t207-207-25-212.fwd.datafoundry.com \u2022 207-207-25-213.fwd.datafoundry.com \u2022 209-99-64-53.fwd.datafoundry.com",
        "https://oauth2.admin.p4d-1.p4d.aks.lightops.cloud.slb-ds.com/lightops-auth/callback&response_type=code&scope=openid+email+profile&state=uJZE80MW6TdJQjbI0RWXhnF3SpYZXckLkfafnEHgr_I:",
        "https://webmail.police.govmm.org/owa/",
        "Denver Police let this attempted murder walk. Cited him as a ghost driver",
        "Denver Police Department Major Crimes closed investigation",
        "Ronda Cordova",
        "IDS Detections Win32/Tofsee.AX google.com connectivity check Observed Telegram Domain (t .me in TLS SNI)",
        "Domains Contacted: microsoft.com microsoft-com.mail.protection.outlook.com vanaheim.cn yahoo.com mta6.am0.yahoodns.net 13.205.167.198.dnsbl.sorbs.net 13.205.167.198.bl.spamcop.net 13.205.167.198.zen.spamhaus.org 13.205.167.198.sbl-xbl.spamhaus.org 13.205.167.198.cbl.abuseat.org",
        "Victim silenced. Struck by Car Driven by male police let walk",
        "Reimer was a PT. Unknown whereabouts , name or job description",
        "Win.Trojan.Tofsee-7102058-0 ,  Backdoor:Win32/Tofsee.T",
        "Alerts: persistence_autorun persistence_autorun_tasks procmem_yara static_pe_anomaly",
        "msoid.applemanic.com \u2022 msoid.giftcardapple.shop \u2022 msoid.appleportconsulting.com",
        "207-207-25-167.fwd.datafoundry.com \u2022 207-207-25-168.fwd.datafoundry.com \u2022 207-207-25-169.fwd.datafoundry.com",
        "Christopher P \u2018Buzz\u2019 Ahmann",
        "b9e4e47c3f96846c30581c08acf5bc56.virus",
        "euw-serp-dev-testing19.duck.ai",
        "Investigation closed when Brian Sabey initiated a malicious prosecution case against Victim",
        "207-207-25-170.fwd.datafoundry.com \u2022 207-207-25-171.fwd.datafoundry.com \u2022 207-207-25-201.fwd.datafoundry.com",
        "www.go.datafoundry.com \u2022 http://207-207-25-209.fwd.datafoundry.com",
        "I bring up the personal nature of the crime because a delete service has been used",
        "gateway.fe.apple-dns.net \u2022 apple-dns.net",
        "http://foundry2-lbl.dvr.dn2.n-helix.com \u2022 https://foundry2-lbl.dvr.dn2.n-helix.com",
        "http://212.33.237.86/images/1/report.php",
        "http://foundry2sdbl.dvr.dn2.n-helix.com/"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 0
        },
        "other": {
          "adversary": [],
          "malware_families": [
            "Tons of malware",
            "Win32.application.bearshare.a",
            "Trojandownloader:win32/cutwail",
            "Backdoor:win32/tofsee.t",
            "Win.trojan.tofsee-7102058-0",
            "Win.packed.bandook-9882274-1",
            "Exploit:win32/cve-2017-0147",
            "Win32/searchsuite",
            "Porn revenge",
            "Cve-2023-22518"
          ],
          "industries": [
            "Healthcare",
            "Government",
            "Technology"
          ],
          "unique_indicators": 29866
        }
      }
    },
    "false_positive": [],
    "alexa": "http://www.alexa.com/siteinfo/raid.ru",
    "whois": "http://whois.domaintools.com/raid.ru",
    "domain": "raid.ru",
    "hostname": "ns1.raid.ru"
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 4,
  "pulses": [
    {
      "id": "69bf261cc4e399447d78776c",
      "name": "Cyber Bully Attackers | Revenge Attacks | Remote attackers | Malware Packed |",
      "description": "Several government entities, attorneys have sought porn revenge including physical violence, attempted crimes, malicious prosecution case , harassment when a female patient of man formerly known as Jeffrey Scott Reimer of Chester Springs, PA, violently, critically injured patient in a sexually charged assault [URL\thttp://foundry2-lbl.dvr.dn2.n-helix.com\t\t\t\nhttps://foundry2-lbl.dvr.dn2.n-helix.com\t\tfoundry2-lbl.dvr.dn2.n-helix.com\t\t\t\t\thttps://www.palantir.io/docs/foundry/ontologies/test-changes-in-ontology/\t\t\nhttp://datafoundry.com\t\t\t\nhttp://foundry2sdbl.dvr.dn2.n-helix.com\t\t\thttps://209-99-40-223.fwd.datafoundry.com\t\t\t\ndatafoundry.com",
      "modified": "2026-04-20T18:43:51.664000",
      "created": "2026-03-21T23:13:32.760000",
      "tags": [
        "sc data",
        "data upload",
        "please sub",
        "include data",
        "extraction",
        "failed",
        "sc pulse",
        "idron anv",
        "extr please",
        "include review",
        "exclude sugges",
        "stop show",
        "typ domain",
        "united",
        "virtool",
        "name servers",
        "cryp",
        "emails",
        "win32",
        "ip address",
        "worm",
        "trojan",
        "learn",
        "suspicious",
        "informative",
        "ck id",
        "name tactics",
        "command",
        "adversaries",
        "spawns",
        "ssl certificate",
        "initial access",
        "link initial",
        "prefetch8",
        "mitre att",
        "ck matrix",
        "flag",
        "windows nt",
        "win64",
        "accept",
        "encrypt",
        "form",
        "hybrid",
        "bypass",
        "general",
        "path",
        "iframe",
        "click",
        "strings",
        "anchor https",
        "anchor",
        "liberal",
        "sabey",
        "liberal friends",
        "meta",
        "html internet",
        "html document",
        "unicode text",
        "utf8 text",
        "info initial",
        "access ta0001",
        "compromise",
        "t1189 network",
        "communication",
        "get http",
        "artifacts v",
        "full reports",
        "v get",
        "help dns",
        "resolutions",
        "ip traffic",
        "extr data",
        "enter sc",
        "extra data",
        "referen",
        "broth",
        "passive dns",
        "urls",
        "http",
        "hostname",
        "files domain",
        "files related",
        "related tags",
        "none google",
        "safe browsing",
        "inquest labs",
        "lucas acha",
        "code integrity",
        "checks creation",
        "otx logo",
        "all hostname",
        "files",
        "domain",
        "protect",
        "date",
        "title",
        "exchange",
        "se http",
        "present jan",
        "present feb",
        "present dec",
        "backdoor",
        "certificate",
        "all domain",
        "alibaba cloud",
        "hichina",
        "porkbun llc",
        "cloudflare",
        "namecheap inc",
        "namecheap",
        "domains",
        "dynadot llc",
        "ascio",
        "denmark",
        "url https",
        "filehashsha256",
        "url http",
        "dopple ai",
        "snit",
        "iocs",
        "otx description",
        "information",
        "report spam",
        "delete service",
        "poem",
        "hunter",
        "malicious",
        "porn revenge",
        "brian sabeys",
        "all report",
        "spam delete",
        "rl http",
        "https",
        "expiration http",
        "spam brian",
        "swipper",
        "type indicator",
        "role title",
        "added active",
        "related pulses",
        "filehashmd5",
        "filehashsha1",
        "sha256",
        "scan",
        "learn more",
        "indicators show",
        "tbmvid",
        "sourcelnms",
        "zx1724209326040",
        "xxx videos",
        "xxxvideohd",
        "adversary",
        "packing",
        "palantir.com",
        "discovery",
        "victim won case",
        "doin it",
        "palantirian abuse",
        "apple",
        "sabey data centers",
        "insurance",
        "quasi government",
        "the brother sabey",
        "reimer",
        "law enforcement",
        "vessel state",
        "sabey porn",
        "hall evans",
        "christopher ahmann",
        "defamation",
        "google"
      ],
      "references": [
        "The Brothers Sabey \u2013 Conservatives with Liberal Friends \u2022 https://thebrotherssabey.com/",
        "http://watchhers.net/index.php",
        "http://212.33.237.86/images/1/report.php",
        "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian",
        "https://webmail.police.govmm.org/owa/",
        "https://pks.wroclaw.sa.gov.pl:1443/ \u2022 portal.bialystok.sa.gov.pl",
        "https://tulach.cc/ phishing \u2022 45.32.112.220 scanning_host \u2022 45.76.79.215",
        "Mark Brian Sabey",
        "Melvin Sabey",
        "Christopher P \u2018Buzz\u2019 Ahmann",
        "Ronda Cordova",
        "Unknown Persons impersonating Private Investigators (plural)",
        "Quasi Government Case",
        "Victim silenced. Struck by Car Driven by male police let walk",
        "Denver Police let this attempted murder walk. Cited him as a ghost driver",
        "Make driver stuck victim with large vehicle after PT unknowingly reported original assault Jeffrey Reiner to Dora",
        "Sexual and Physical Assaulter - Jeffrey Scott Reimer",
        "Reimer was a PT. Unknown whereabouts , name or job description",
        "Denver Police Department Major Crimes closed investigation",
        "Investigation closed when Brian Sabey initiated a malicious prosecution case against Victim",
        "I bring up the personal nature of the crime because a delete service has been used",
        "More than 1000 IoC\u2019s including pulses have been ILLEGALLY removed",
        "All IoC\u2019s originate from sources named. There are some unknown attackers",
        "This is a serious crime. I\u2019m certain God WILL pay them.",
        "https://palantirwww.sweetheartvideo.com\t\t\tMar 21, 2026, 2:06:10 PM\t\t3\t  domain\tpalantir.io\t\t\tMar 21, 2026, 2:06:10 PM\t\t34\t  URL\thttps://www.palantir.io/docs/foundry/ontologies/test-changes-in-ontology/ \u2022 www.palantir.com",
        "http://palantirwww.sweetheartvideo.com/ (weirdness)",
        "http://foundry2-lbl.dvr.dn2.n-helix.com \u2022 https://foundry2-lbl.dvr.dn2.n-helix.com",
        "foundry2-lbl.dvr.dn2.n-helix.com\t\t\tMar 21, 2026, 2:06:10 PM\t\t29\t  URL\thttps://www.palantir.io/docs/foundry/ontologies/test-changes-in-ontology/\t\t\tMar 21, 2026, 2:06:10 PM\t\t8\t  URL\thttp://datafoundry.com\t\t\tMar 21, 2026, 2:06:10 PM\t\t9\t  URL\thttp://foundry2sdbl.dvr.dn2.n-helix.com\t\t\tMar 21, 2026, 2:06:10 PM\t\t17\t  URL\thttps://209-99-40-223.fwd.datafoundry.com\t\t\tMar 21, 2026, 2:06:10 PM\t\t27\t  domain\tdatafoundry.com\t\t\tMar 21, 2026, 2:06:10 PM\t\t40\t  hostname\t209-99-40-223.fwd.datafoundry.com\t\t\tMar 21, 2026, 2:06:1",
        "foundry2-lbl.dvr.dn2.n-helix.com\t\t\tMar 21, 2026, 2:06:10 PM\t\t29\t  URL\thttps://www.palantir.io/docs/foundry/ontologies/test-changes-in-ontology/\t\t\tMar 21, 2026, 2:06:10 PM\t\t8\t  URL\thttp://datafoundry.com\t\t\tMar 21, 2026, 2:06:10 PM\t\t9\t  URL\thttp://foundry2sdbl.dvr.dn2.n-helix.com\t\t\tMar 21, 2026, 2:06:10 PM\t\t17\t  URL\thttps://209-99-40-223.fwd.datafoundry.com\t\t\tMar 21, 2026, 2:06:10 PM\t\t27\t  domain\tdatafoundry.com\t\t\tMar 21, 2026, 2:06:10 PM\t\t40\t  hostname\t209-99-40-223.fwd.datafoundry.com\t\t\tMar 21, 2026, 2:06:1",
        "https://rdweb.datafoundry.com/RDWeb/Pages/en-US/login.aspx",
        "https://www.datafoundry.com/data-center-contamination-control/",
        "https://www.datafoundry.com/data-center-contamination-control/",
        "https://www.palantir.io/docs/foundry/ontologies/test-changes-in-ontology/",
        "http://foundry2-lbl.dvr.dn2.n-helix.com/",
        "https://207-207-25-201.fwd.datafoundry.com/",
        "http://datafoundry.com \u2022 http://foundry2sdbl.dvr.dn2.n-helix.com \u2022 https://209-99-40-223.fwd.datafoundry.com \u2022 datafoundry.com \u2022 209-99-40-223.fwd.datafoundry.com \u2022 beabetta.ifoundry.co.uk.s7b2.psmtp.com \u2022 foundry2sdbl.dvr.dn2.n-helix.com \u2022 fwd.datafoundry.com \u2022 207-207-25-154.fwd.datafoundry.com \u2022 207-207-25-156.fwd.datafoundry.com\t\t\t207-207-25-160.fwd.datafoundry.com \u2022 207-207-25-163.fwd.datafoundry.com  \u2022\t207-207-25-164.fwd.datafoundry.com \u2022 207-207-25-165.fwd.datafoundry.com\t\t\tMar 21, 207-207-25-166.fwd",
        "http://datafoundry.com \u2022 https://209-99-40-223.fwd.datafoundry.com\tdatafoundry.com \u2022 209-99-40-223.fwd.datafoundry.com\t\t\tMar 21, 2026, 2:06:10 PM\t\t13\t  hostname\tbeabetta.ifoundry.co.uk.s7b2.psmtp.com\t\t\tMar 21, 2026, 2:06:10 PM\t\t12\t  hostname\tfoundry2sdbl.dvr.dn2.n-helix.com\t\t\tMar 21, 2026, 2:06:10 PM\t\t18\t  hostname\tfwd.datafoundry.com\t\t\tMar 21, 2026, 2:06:10 PM\t\t8\t  hostname\t207-207-25-154.fwd.datafoundry.com\t\t\tMar 21, 2026, 2:06:10 PM\t\t19\t  hostname\t207-207-25-156.fwd.datafoundry.com\t\t\tMar 21, 2026, 2:06:1",
        "https://rdweb.datafoundry.com/",
        "https://www.palantir.io/docs/foundry/ontologies/test-changes-in-ontology/",
        "http://foundry2sdbl.dvr.dn2.n-helix.com/",
        "Updated | What\u2019s left after theft",
        "207-207-25-167.fwd.datafoundry.com \u2022 207-207-25-168.fwd.datafoundry.com \u2022 207-207-25-169.fwd.datafoundry.com",
        "207-207-25-170.fwd.datafoundry.com \u2022 207-207-25-171.fwd.datafoundry.com \u2022 207-207-25-201.fwd.datafoundry.com",
        "https://www.datafoundry.com/category/news/press-releases/ (Fake Press) abuse",
        "https://www.datafoundry.com/category/news/press-releases/",
        "207-207-25-209.fwd.datafoundry.com \u2022\t207-207-25-212.fwd.datafoundry.com \u2022 207-207-25-213.fwd.datafoundry.com \u2022 209-99-64-53.fwd.datafoundry.com",
        "209-99-69-91.fwd.datafoundry.com \u2022 dns1.datafoundry.com \u2022 dns2.datafoundry.com \u2022 rdweb.datafoundry.com",
        "www.go.datafoundry.com \u2022 http://207-207-25-209.fwd.datafoundry.com",
        "http://209-99-64-53.fwd.datafoundry.com \u2022 http://dns2.datafoundry.com \u2022 http://fwd.datafoundry.com",
        "http://pdns1.datafoundry.com/ \u2022\thttp://rdweb.datafoundry.com \u2022 http://rdweb.datafoundry.com/",
        "https://rdweb.datafoundry.com/ \u2022 http://www.datafoundry.com \u2022 https://207-207-25-163.fwd.datafoundry.com \u2022",
        "https://207-207-25-209.fwd.datafoundry.com \u2022 https://209-99-40-224.fwd.datafoundry.com/",
        "https://209-99-64-53.fwd.datafoundry.com \u2022 https://dns1.datafoundry.com \u2022 https://dns2.datafoundry.com \u2022 https://fwd.datafoundry.com",
        "Some may may find this content is very disturbing and offensive"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Porn Revenge",
          "display_name": "Porn Revenge",
          "target": null
        },
        {
          "id": "Tons of Malware",
          "display_name": "Tons of Malware",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1041",
          "name": "Exfiltration Over C2 Channel",
          "display_name": "T1041 - Exfiltration Over C2 Channel"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1132",
          "name": "Data Encoding",
          "display_name": "T1132 - Data Encoding"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1189",
          "name": "Drive-by Compromise",
          "display_name": "T1189 - Drive-by Compromise"
        },
        {
          "id": "T1553",
          "name": "Subvert Trust Controls",
          "display_name": "T1553 - Subvert Trust Controls"
        },
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        },
        {
          "id": "T1568",
          "name": "Dynamic Resolution",
          "display_name": "T1568 - Dynamic Resolution"
        },
        {
          "id": "T1583",
          "name": "Acquire Infrastructure",
          "display_name": "T1583 - Acquire Infrastructure"
        },
        {
          "id": "T1583.001",
          "name": "Domains",
          "display_name": "T1583.001 - Domains"
        },
        {
          "id": "T1553.002",
          "name": "Code Signing",
          "display_name": "T1553.002 - Code Signing"
        },
        {
          "id": "T1132.001",
          "name": "Standard Encoding",
          "display_name": "T1132.001 - Standard Encoding"
        },
        {
          "id": "T1071.001",
          "name": "Web Protocols",
          "display_name": "T1071.001 - Web Protocols"
        },
        {
          "id": "T1568.002",
          "name": "Domain Generation Algorithms",
          "display_name": "T1568.002 - Domain Generation Algorithms"
        },
        {
          "id": "T1071.004",
          "name": "DNS",
          "display_name": "T1071.004 - DNS"
        },
        {
          "id": "T1113",
          "name": "Screen Capture",
          "display_name": "T1113 - Screen Capture"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1036",
          "name": "Masquerading",
          "display_name": "T1036 - Masquerading"
        },
        {
          "id": "T1045",
          "name": "Software Packing",
          "display_name": "T1045 - Software Packing"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1060",
          "name": "Registry Run Keys / Startup Folder",
          "display_name": "T1060 - Registry Run Keys / Startup Folder"
        },
        {
          "id": "T1070",
          "name": "Indicator Removal on Host",
          "display_name": "T1070 - Indicator Removal on Host"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1083",
          "name": "File and Directory Discovery",
          "display_name": "T1083 - File and Directory Discovery"
        },
        {
          "id": "T1106",
          "name": "Native API",
          "display_name": "T1106 - Native API"
        },
        {
          "id": "T1125",
          "name": "Video Capture",
          "display_name": "T1125 - Video Capture"
        },
        {
          "id": "T1129",
          "name": "Shared Modules",
          "display_name": "T1129 - Shared Modules"
        },
        {
          "id": "T1143",
          "name": "Hidden Window",
          "display_name": "T1143 - Hidden Window"
        },
        {
          "id": "T1176",
          "name": "Browser Extensions",
          "display_name": "T1176 - Browser Extensions"
        },
        {
          "id": "T1449",
          "name": "Exploit SS7 to Redirect Phone Calls/SMS",
          "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
        },
        {
          "id": "T1495",
          "name": "Firmware Corruption",
          "display_name": "T1495 - Firmware Corruption"
        },
        {
          "id": "T1546",
          "name": "Event Triggered Execution",
          "display_name": "T1546 - Event Triggered Execution"
        },
        {
          "id": "T1587.001",
          "name": "Malware",
          "display_name": "T1587.001 - Malware"
        },
        {
          "id": "T1608.001",
          "name": "Upload Malware",
          "display_name": "T1608.001 - Upload Malware"
        },
        {
          "id": "T1457",
          "name": "Malicious Media Content",
          "display_name": "T1457 - Malicious Media Content"
        },
        {
          "id": "T1586.001",
          "name": "Social Media Accounts",
          "display_name": "T1586.001 - Social Media Accounts"
        },
        {
          "id": "T1593.001",
          "name": "Social Media",
          "display_name": "T1593.001 - Social Media"
        },
        {
          "id": "T1068",
          "name": "Exploitation for Privilege Escalation",
          "display_name": "T1068 - Exploitation for Privilege Escalation"
        },
        {
          "id": "T1080",
          "name": "Taint Shared Content",
          "display_name": "T1080 - Taint Shared Content"
        },
        {
          "id": "T1190",
          "name": "Exploit Public-Facing Application",
          "display_name": "T1190 - Exploit Public-Facing Application"
        },
        {
          "id": "T1472",
          "name": "Generate Fraudulent Advertising Revenue",
          "display_name": "T1472 - Generate Fraudulent Advertising Revenue"
        },
        {
          "id": "T1586",
          "name": "Compromise Accounts",
          "display_name": "T1586 - Compromise Accounts"
        },
        {
          "id": "T1059.002",
          "name": "AppleScript",
          "display_name": "T1059.002 - AppleScript"
        },
        {
          "id": "T1456",
          "name": "Drive-by Compromise",
          "display_name": "T1456 - Drive-by Compromise"
        },
        {
          "id": "T1210",
          "name": "Exploitation of Remote Services",
          "display_name": "T1210 - Exploitation of Remote Services"
        },
        {
          "id": "T1583.005",
          "name": "Botnet",
          "display_name": "T1583.005 - Botnet"
        },
        {
          "id": "T1584",
          "name": "Compromise Infrastructure",
          "display_name": "T1584 - Compromise Infrastructure"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 5,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Q.Vashti",
        "id": "337942",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 6034,
        "domain": 1422,
        "IPv4": 397,
        "FileHash-MD5": 274,
        "FileHash-SHA1": 252,
        "FileHash-SHA256": 3378,
        "email": 11,
        "hostname": 2753,
        "CVE": 1,
        "SSLCertFingerprint": 9,
        "IPv6": 32
      },
      "indicator_count": 14563,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 140,
      "modified_text": "19 minutes ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "69ded8198b25581a09b90824",
      "name": "BearShare \u2022 Solarwinds? \u2022 SearchSuite \u2022 Healthcare Administration",
      "description": "",
      "modified": "2026-04-15T00:13:13.981000",
      "created": "2026-04-15T00:13:13.981000",
      "tags": [
        "Win32/SearchSuite",
        "pe32",
        "intel",
        "ms windows",
        "ms visual",
        "win32 dynamic",
        "link library",
        "win16 ne",
        "pe32 installer",
        "install system",
        "compiler",
        "NSIS",
        "code signing",
        "serial number",
        "db d2",
        "de d3",
        "f3 e1",
        "issuer thawte",
        "primary root",
        "ca valid",
        "valid",
        "valid usage",
        "client auth",
        "algorithm",
        "rticon english",
        "type type",
        "chi2",
        "ico rtgroupicon",
        "english us",
        "capa",
        "c2 antianalysis",
        "executable",
        "sample appears",
        "installer",
        "installers well",
        "results may",
        "be misleading",
        "or incomplete",
        "analyze created",
        "techniques",
        "info modify",
        "files",
        "modify registry",
        "directory permi",
        "techniques none",
        "info",
        "scripting inte",
        "shared modules",
        "Bear Share",
        "urls",
        "ip address",
        "asn as8075",
        "united",
        "flag united",
        "name servers",
        "name domain",
        "org apple",
        "infinite loop",
        "city cupertino",
        "country us",
        "dnssec",
        "urlmailto",
        "urlhttps",
        "search",
        "urlhttp",
        "moved",
        "title",
        "encrypt",
        "certificate",
        "segoe ui",
        "otx logo",
        "url analysis",
        "tokyo",
        "msie",
        "chrome",
        "gmt content",
        "all ipv4",
        "zeppelin",
        "trojandropper",
        "cookie",
        "backdoor",
        "hash avast",
        "avg clamav",
        "msdefender feb",
        "k oct",
        "k may",
        "mtb feb",
        "mtb jan",
        "k aug",
        "windows nt",
        "dynamicloader",
        "unknown",
        "medium",
        "default",
        "as16509",
        "show",
        "powershell",
        "write",
        "xserver",
        "bearshar data",
        "passive dns",
        "pulse submit",
        "port",
        "destination",
        "high",
        "displayname",
        "windows",
        "win64",
        "tofsee",
        "stream",
        "malware",
        "push",
        "next",
        "asnone",
        "germany as8560",
        "russia as198610",
        "strings",
        "is__elf",
        "systembc_linux_variant",
        "khtml",
        "gecko",
        "acceptencoding",
        "get na",
        "macintosh",
        "intel mac",
        "accept",
        "france as16276",
        "yara detections",
        "contacted",
        "all filehash",
        "sha256",
        "pulse pulses",
        "av detections",
        "ids detections",
        "alerts",
        "analysis date",
        "tls sni",
        "less see",
        "all ip",
        "Apple",
        "xordata",
        "United States"
      ],
      "references": [
        "b9e4e47c3f96846c30581c08acf5bc56.virus",
        "BearShare Install File Version 12.0.0.135802",
        "Musiclab, LLC",
        "msoid.applemanic.com \u2022 msoid.giftcardapple.shop \u2022 msoid.appleportconsulting.com",
        "gateway.fe.apple-dns.net \u2022 apple-dns.net",
        "africa.konnect.com",
        "http://scratch-mit-edu.027.cloudns.asia/users/alessandrito123",
        "euw-serp-dev-testing19.duck.ai",
        "account-apple.com",
        "Win.Trojan.Tofsee-7102058-0 ,  Backdoor:Win32/Tofsee.T",
        "IDS Detections Win32/Tofsee.AX google.com connectivity check Observed Telegram Domain (t .me in TLS SNI)",
        "Yara Detections: Tofsee",
        "Alerts: behavior_tofsee creates_largekey injection_write_exe_process network_bind",
        "Alerts: persistence_autorun persistence_autorun_tasks procmem_yara static_pe_anomaly",
        "Alerts: suricata_alert antivm_generic_services physical_drive_access deletes_executed_files",
        "Alerts: deletes_self injection_runpe persistence_ads suspicious_command_tools",
        "Alerts: anomalous_deletefile antisandbox_sleep dead_connect dynamic_function_loading",
        "IP\u2019s Contacted: 47.43.26.4  195.35.13.119  149.154.167.99  185.138.56.214  142.250.147.26  81.88.48.101",
        "IP\u2019s Contacted: 104.21.72.117  172.66.156.195  157.240.200.174  141.193.213.20",
        "Domains Contacted: microsoft.com microsoft-com.mail.protection.outlook.com vanaheim.cn yahoo.com mta6.am0.yahoodns.net 13.205.167.198.dnsbl.sorbs.net 13.205.167.198.bl.spamcop.net 13.205.167.198.zen.spamhaus.org 13.205.167.198.sbl-xbl.spamhaus.org 13.205.167.198.cbl.abuseat.org",
        "https://perigon-one.au.itglue.com/password_shared_links/52f082d3-d889-4db5-ae03-c7bfcbe5aa21",
        "https://identity.prd-cdc.jemena.com.au/pages/jemena-reset-password",
        "https://in2it.itglue.com/password_shared_links/9b0e2a1d-b554-4f0c-a333-390e41defe8e",
        "https://oauth2.admin.p4d-1.p4d.aks.lightops.cloud.slb-ds.com/lightops-auth/callback&response_type=code&scope=openid+email+profile&state=uJZE80MW6TdJQjbI0RWXhnF3SpYZXckLkfafnEHgr_I:",
        "https://oauth2.admin.p4d-1.p4d.aks.lightops.cloud.slb-ds.com/lightops-auth/callback",
        "ids-apple.com \u2022 itunes.org",
        "xn--cloud-4sa.com",
        "http://cab.applemarketingtools.com",
        "http://console.applemarketingtools.com/"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America",
        "Spain",
        "France",
        "United Kingdom of Great Britain and Northern Ireland",
        "Netherlands",
        "Japan",
        "Switzerland",
        "Madagascar",
        "Finland",
        "Germany",
        "Russian Federation"
      ],
      "malware_families": [
        {
          "id": "Win32/SearchSuite",
          "display_name": "Win32/SearchSuite",
          "target": null
        },
        {
          "id": "Win32.Application.BearShare.A",
          "display_name": "Win32.Application.BearShare.A",
          "target": null
        },
        {
          "id": "Exploit:Win32/CVE-2017-0147",
          "display_name": "Exploit:Win32/CVE-2017-0147",
          "target": "/malware/Exploit:Win32/CVE-2017-0147"
        },
        {
          "id": "CVE-2023-22518",
          "display_name": "CVE-2023-22518",
          "target": null
        },
        {
          "id": "Win.Packed.Bandook-9882274-1",
          "display_name": "Win.Packed.Bandook-9882274-1",
          "target": null
        },
        {
          "id": "Win.Trojan.Tofsee-7102058-0",
          "display_name": "Win.Trojan.Tofsee-7102058-0",
          "target": null
        },
        {
          "id": "Backdoor:Win32/Tofsee.T",
          "display_name": "Backdoor:Win32/Tofsee.T",
          "target": "/malware/Backdoor:Win32/Tofsee.T"
        },
        {
          "id": "TrojanDownloader:Win32/Cutwail",
          "display_name": "TrojanDownloader:Win32/Cutwail",
          "target": "/malware/TrojanDownloader:Win32/Cutwail"
        }
      ],
      "attack_ids": [
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1112",
          "name": "Modify Registry",
          "display_name": "T1112 - Modify Registry"
        },
        {
          "id": "T1222",
          "name": "File and Directory Permissions Modification",
          "display_name": "T1222 - File and Directory Permissions Modification"
        },
        {
          "id": "TA0003",
          "name": "Persistence",
          "display_name": "TA0003 - Persistence"
        },
        {
          "id": "TA0005",
          "name": "Defense Evasion",
          "display_name": "TA0005 - Defense Evasion"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1129",
          "name": "Shared Modules",
          "display_name": "T1129 - Shared Modules"
        },
        {
          "id": "TA0002",
          "name": "Execution",
          "display_name": "TA0002 - Execution"
        },
        {
          "id": "T1155",
          "name": "AppleScript",
          "display_name": "T1155 - AppleScript"
        },
        {
          "id": "T1553",
          "name": "Subvert Trust Controls",
          "display_name": "T1553 - Subvert Trust Controls"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1060",
          "name": "Registry Run Keys / Startup Folder",
          "display_name": "T1060 - Registry Run Keys / Startup Folder"
        }
      ],
      "industries": [
        "Government",
        "Healthcare",
        "Technology"
      ],
      "TLP": "green",
      "cloned_from": "69dab27a0493e0e80a0f35cd",
      "export_count": 4,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Q.Vashti",
        "id": "337942",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 138,
        "FileHash-SHA1": 119,
        "FileHash-SHA256": 3553,
        "IPv4": 633,
        "CVE": 2,
        "URL": 6134,
        "domain": 2439,
        "hostname": 2271,
        "email": 9,
        "SSLCertFingerprint": 2
      },
      "indicator_count": 15300,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 137,
      "modified_text": "5 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "69db05f833d3d6d2231fb201",
      "name": "CREDIT: Q.Vashti's research: SearchSuite \u2022 Healthcare Administration CREATED 6 HOURS AGO by Q.Vashti",
      "description": "",
      "modified": "2026-04-12T02:39:52.993000",
      "created": "2026-04-12T02:39:52.993000",
      "tags": [
        "Win32/SearchSuite",
        "pe32",
        "intel",
        "ms windows",
        "ms visual",
        "win32 dynamic",
        "link library",
        "win16 ne",
        "pe32 installer",
        "install system",
        "compiler",
        "NSIS",
        "code signing",
        "serial number",
        "db d2",
        "de d3",
        "f3 e1",
        "issuer thawte",
        "primary root",
        "ca valid",
        "valid",
        "valid usage",
        "client auth",
        "algorithm",
        "rticon english",
        "type type",
        "chi2",
        "ico rtgroupicon",
        "english us",
        "capa",
        "c2 antianalysis",
        "executable",
        "sample appears",
        "installer",
        "installers well",
        "results may",
        "be misleading",
        "or incomplete",
        "analyze created",
        "techniques",
        "info modify",
        "files",
        "modify registry",
        "directory permi",
        "techniques none",
        "info",
        "scripting inte",
        "shared modules",
        "Bear Share",
        "urls",
        "ip address",
        "asn as8075",
        "united",
        "flag united",
        "name servers",
        "name domain",
        "org apple",
        "infinite loop",
        "city cupertino",
        "country us",
        "dnssec",
        "urlmailto",
        "urlhttps",
        "search",
        "urlhttp",
        "moved",
        "title",
        "encrypt",
        "certificate",
        "segoe ui",
        "otx logo",
        "url analysis",
        "tokyo",
        "msie",
        "chrome",
        "gmt content",
        "all ipv4",
        "zeppelin",
        "trojandropper",
        "cookie",
        "backdoor",
        "hash avast",
        "avg clamav",
        "msdefender feb",
        "k oct",
        "k may",
        "mtb feb",
        "mtb jan",
        "k aug",
        "windows nt",
        "dynamicloader",
        "unknown",
        "medium",
        "default",
        "as16509",
        "show",
        "powershell",
        "write",
        "xserver",
        "bearshar data",
        "passive dns",
        "pulse submit",
        "port",
        "destination",
        "high",
        "displayname",
        "windows",
        "win64",
        "tofsee",
        "stream",
        "malware",
        "push",
        "next",
        "asnone",
        "germany as8560",
        "russia as198610",
        "strings",
        "is__elf",
        "systembc_linux_variant",
        "khtml",
        "gecko",
        "acceptencoding",
        "get na",
        "macintosh",
        "intel mac",
        "accept",
        "france as16276",
        "yara detections",
        "contacted",
        "all filehash",
        "sha256",
        "pulse pulses",
        "av detections",
        "ids detections",
        "alerts",
        "analysis date",
        "tls sni",
        "less see",
        "all ip",
        "Apple",
        "xordata",
        "United States"
      ],
      "references": [
        "b9e4e47c3f96846c30581c08acf5bc56.virus",
        "BearShare Install File Version 12.0.0.135802",
        "Musiclab, LLC",
        "msoid.applemanic.com \u2022 msoid.giftcardapple.shop \u2022 msoid.appleportconsulting.com",
        "gateway.fe.apple-dns.net \u2022 apple-dns.net",
        "africa.konnect.com",
        "http://scratch-mit-edu.027.cloudns.asia/users/alessandrito123",
        "euw-serp-dev-testing19.duck.ai",
        "account-apple.com",
        "Win.Trojan.Tofsee-7102058-0 ,  Backdoor:Win32/Tofsee.T",
        "IDS Detections Win32/Tofsee.AX google.com connectivity check Observed Telegram Domain (t .me in TLS SNI)",
        "Yara Detections: Tofsee",
        "Alerts: behavior_tofsee creates_largekey injection_write_exe_process network_bind",
        "Alerts: persistence_autorun persistence_autorun_tasks procmem_yara static_pe_anomaly",
        "Alerts: suricata_alert antivm_generic_services physical_drive_access deletes_executed_files",
        "Alerts: deletes_self injection_runpe persistence_ads suspicious_command_tools",
        "Alerts: anomalous_deletefile antisandbox_sleep dead_connect dynamic_function_loading",
        "IP\u2019s Contacted: 47.43.26.4  195.35.13.119  149.154.167.99  185.138.56.214  142.250.147.26  81.88.48.101",
        "IP\u2019s Contacted: 104.21.72.117  172.66.156.195  157.240.200.174  141.193.213.20",
        "Domains Contacted: microsoft.com microsoft-com.mail.protection.outlook.com vanaheim.cn yahoo.com mta6.am0.yahoodns.net 13.205.167.198.dnsbl.sorbs.net 13.205.167.198.bl.spamcop.net 13.205.167.198.zen.spamhaus.org 13.205.167.198.sbl-xbl.spamhaus.org 13.205.167.198.cbl.abuseat.org",
        "https://perigon-one.au.itglue.com/password_shared_links/52f082d3-d889-4db5-ae03-c7bfcbe5aa21",
        "https://identity.prd-cdc.jemena.com.au/pages/jemena-reset-password",
        "https://in2it.itglue.com/password_shared_links/9b0e2a1d-b554-4f0c-a333-390e41defe8e",
        "https://oauth2.admin.p4d-1.p4d.aks.lightops.cloud.slb-ds.com/lightops-auth/callback&response_type=code&scope=openid+email+profile&state=uJZE80MW6TdJQjbI0RWXhnF3SpYZXckLkfafnEHgr_I:",
        "https://oauth2.admin.p4d-1.p4d.aks.lightops.cloud.slb-ds.com/lightops-auth/callback",
        "ids-apple.com \u2022 itunes.org",
        "xn--cloud-4sa.com",
        "http://cab.applemarketingtools.com",
        "http://console.applemarketingtools.com/"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America",
        "Spain",
        "France",
        "United Kingdom of Great Britain and Northern Ireland",
        "Netherlands",
        "Japan",
        "Switzerland",
        "Madagascar",
        "Finland",
        "Germany",
        "Russian Federation"
      ],
      "malware_families": [
        {
          "id": "Win32/SearchSuite",
          "display_name": "Win32/SearchSuite",
          "target": null
        },
        {
          "id": "Win32.Application.BearShare.A",
          "display_name": "Win32.Application.BearShare.A",
          "target": null
        },
        {
          "id": "Exploit:Win32/CVE-2017-0147",
          "display_name": "Exploit:Win32/CVE-2017-0147",
          "target": "/malware/Exploit:Win32/CVE-2017-0147"
        },
        {
          "id": "CVE-2023-22518",
          "display_name": "CVE-2023-22518",
          "target": null
        },
        {
          "id": "Win.Packed.Bandook-9882274-1",
          "display_name": "Win.Packed.Bandook-9882274-1",
          "target": null
        },
        {
          "id": "Win.Trojan.Tofsee-7102058-0",
          "display_name": "Win.Trojan.Tofsee-7102058-0",
          "target": null
        },
        {
          "id": "Backdoor:Win32/Tofsee.T",
          "display_name": "Backdoor:Win32/Tofsee.T",
          "target": "/malware/Backdoor:Win32/Tofsee.T"
        },
        {
          "id": "TrojanDownloader:Win32/Cutwail",
          "display_name": "TrojanDownloader:Win32/Cutwail",
          "target": "/malware/TrojanDownloader:Win32/Cutwail"
        }
      ],
      "attack_ids": [
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1112",
          "name": "Modify Registry",
          "display_name": "T1112 - Modify Registry"
        },
        {
          "id": "T1222",
          "name": "File and Directory Permissions Modification",
          "display_name": "T1222 - File and Directory Permissions Modification"
        },
        {
          "id": "TA0003",
          "name": "Persistence",
          "display_name": "TA0003 - Persistence"
        },
        {
          "id": "TA0005",
          "name": "Defense Evasion",
          "display_name": "TA0005 - Defense Evasion"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1129",
          "name": "Shared Modules",
          "display_name": "T1129 - Shared Modules"
        },
        {
          "id": "TA0002",
          "name": "Execution",
          "display_name": "TA0002 - Execution"
        },
        {
          "id": "T1155",
          "name": "AppleScript",
          "display_name": "T1155 - AppleScript"
        },
        {
          "id": "T1553",
          "name": "Subvert Trust Controls",
          "display_name": "T1553 - Subvert Trust Controls"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1060",
          "name": "Registry Run Keys / Startup Folder",
          "display_name": "T1060 - Registry Run Keys / Startup Folder"
        }
      ],
      "industries": [
        "Government",
        "Healthcare",
        "Technology"
      ],
      "TLP": "green",
      "cloned_from": "69dab27a0493e0e80a0f35cd",
      "export_count": 3,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 138,
        "FileHash-SHA1": 119,
        "FileHash-SHA256": 3553,
        "IPv4": 633,
        "CVE": 2,
        "URL": 6134,
        "domain": 2439,
        "hostname": 2271,
        "email": 9,
        "SSLCertFingerprint": 2
      },
      "indicator_count": 15300,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 49,
      "modified_text": "8 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "69dab27a0493e0e80a0f35cd",
      "name": "SearchSuite \u2022 Healthcare Administration",
      "description": "Embedded in communication between a healthcare system and a client. \n\nThis is just one of countless internal issues causing a gap in communication, malicious adware, spyware, system sweeps, injection, system modification, downloads , call failures.",
      "modified": "2026-04-11T20:43:38.695000",
      "created": "2026-04-11T20:43:38.695000",
      "tags": [
        "Win32/SearchSuite",
        "pe32",
        "intel",
        "ms windows",
        "ms visual",
        "win32 dynamic",
        "link library",
        "win16 ne",
        "pe32 installer",
        "install system",
        "compiler",
        "NSIS",
        "code signing",
        "serial number",
        "db d2",
        "de d3",
        "f3 e1",
        "issuer thawte",
        "primary root",
        "ca valid",
        "valid",
        "valid usage",
        "client auth",
        "algorithm",
        "rticon english",
        "type type",
        "chi2",
        "ico rtgroupicon",
        "english us",
        "capa",
        "c2 antianalysis",
        "executable",
        "sample appears",
        "installer",
        "installers well",
        "results may",
        "be misleading",
        "or incomplete",
        "analyze created",
        "techniques",
        "info modify",
        "files",
        "modify registry",
        "directory permi",
        "techniques none",
        "info",
        "scripting inte",
        "shared modules",
        "Bear Share",
        "urls",
        "ip address",
        "asn as8075",
        "united",
        "flag united",
        "name servers",
        "name domain",
        "org apple",
        "infinite loop",
        "city cupertino",
        "country us",
        "dnssec",
        "urlmailto",
        "urlhttps",
        "search",
        "urlhttp",
        "moved",
        "title",
        "encrypt",
        "certificate",
        "segoe ui",
        "otx logo",
        "url analysis",
        "tokyo",
        "msie",
        "chrome",
        "gmt content",
        "all ipv4",
        "zeppelin",
        "trojandropper",
        "cookie",
        "backdoor",
        "hash avast",
        "avg clamav",
        "msdefender feb",
        "k oct",
        "k may",
        "mtb feb",
        "mtb jan",
        "k aug",
        "windows nt",
        "dynamicloader",
        "unknown",
        "medium",
        "default",
        "as16509",
        "show",
        "powershell",
        "write",
        "xserver",
        "bearshar data",
        "passive dns",
        "pulse submit",
        "port",
        "destination",
        "high",
        "displayname",
        "windows",
        "win64",
        "tofsee",
        "stream",
        "malware",
        "push",
        "next",
        "asnone",
        "germany as8560",
        "russia as198610",
        "strings",
        "is__elf",
        "systembc_linux_variant",
        "khtml",
        "gecko",
        "acceptencoding",
        "get na",
        "macintosh",
        "intel mac",
        "accept",
        "france as16276",
        "yara detections",
        "contacted",
        "all filehash",
        "sha256",
        "pulse pulses",
        "av detections",
        "ids detections",
        "alerts",
        "analysis date",
        "tls sni",
        "less see",
        "all ip",
        "Apple",
        "xordata",
        "United States"
      ],
      "references": [
        "b9e4e47c3f96846c30581c08acf5bc56.virus",
        "BearShare Install File Version 12.0.0.135802",
        "Musiclab, LLC",
        "msoid.applemanic.com \u2022 msoid.giftcardapple.shop \u2022 msoid.appleportconsulting.com",
        "gateway.fe.apple-dns.net \u2022 apple-dns.net",
        "africa.konnect.com",
        "http://scratch-mit-edu.027.cloudns.asia/users/alessandrito123",
        "euw-serp-dev-testing19.duck.ai",
        "account-apple.com",
        "Win.Trojan.Tofsee-7102058-0 ,  Backdoor:Win32/Tofsee.T",
        "IDS Detections Win32/Tofsee.AX google.com connectivity check Observed Telegram Domain (t .me in TLS SNI)",
        "Yara Detections: Tofsee",
        "Alerts: behavior_tofsee creates_largekey injection_write_exe_process network_bind",
        "Alerts: persistence_autorun persistence_autorun_tasks procmem_yara static_pe_anomaly",
        "Alerts: suricata_alert antivm_generic_services physical_drive_access deletes_executed_files",
        "Alerts: deletes_self injection_runpe persistence_ads suspicious_command_tools",
        "Alerts: anomalous_deletefile antisandbox_sleep dead_connect dynamic_function_loading",
        "IP\u2019s Contacted: 47.43.26.4  195.35.13.119  149.154.167.99  185.138.56.214  142.250.147.26  81.88.48.101",
        "IP\u2019s Contacted: 104.21.72.117  172.66.156.195  157.240.200.174  141.193.213.20",
        "Domains Contacted: microsoft.com microsoft-com.mail.protection.outlook.com vanaheim.cn yahoo.com mta6.am0.yahoodns.net 13.205.167.198.dnsbl.sorbs.net 13.205.167.198.bl.spamcop.net 13.205.167.198.zen.spamhaus.org 13.205.167.198.sbl-xbl.spamhaus.org 13.205.167.198.cbl.abuseat.org",
        "https://perigon-one.au.itglue.com/password_shared_links/52f082d3-d889-4db5-ae03-c7bfcbe5aa21",
        "https://identity.prd-cdc.jemena.com.au/pages/jemena-reset-password",
        "https://in2it.itglue.com/password_shared_links/9b0e2a1d-b554-4f0c-a333-390e41defe8e",
        "https://oauth2.admin.p4d-1.p4d.aks.lightops.cloud.slb-ds.com/lightops-auth/callback&response_type=code&scope=openid+email+profile&state=uJZE80MW6TdJQjbI0RWXhnF3SpYZXckLkfafnEHgr_I:",
        "https://oauth2.admin.p4d-1.p4d.aks.lightops.cloud.slb-ds.com/lightops-auth/callback",
        "ids-apple.com \u2022 itunes.org",
        "xn--cloud-4sa.com",
        "http://cab.applemarketingtools.com",
        "http://console.applemarketingtools.com/"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America",
        "Spain",
        "France",
        "United Kingdom of Great Britain and Northern Ireland",
        "Netherlands",
        "Japan",
        "Switzerland",
        "Madagascar",
        "Finland",
        "Germany",
        "Russian Federation"
      ],
      "malware_families": [
        {
          "id": "Win32/SearchSuite",
          "display_name": "Win32/SearchSuite",
          "target": null
        },
        {
          "id": "Win32.Application.BearShare.A",
          "display_name": "Win32.Application.BearShare.A",
          "target": null
        },
        {
          "id": "Exploit:Win32/CVE-2017-0147",
          "display_name": "Exploit:Win32/CVE-2017-0147",
          "target": "/malware/Exploit:Win32/CVE-2017-0147"
        },
        {
          "id": "CVE-2023-22518",
          "display_name": "CVE-2023-22518",
          "target": null
        },
        {
          "id": "Win.Packed.Bandook-9882274-1",
          "display_name": "Win.Packed.Bandook-9882274-1",
          "target": null
        },
        {
          "id": "Win.Trojan.Tofsee-7102058-0",
          "display_name": "Win.Trojan.Tofsee-7102058-0",
          "target": null
        },
        {
          "id": "Backdoor:Win32/Tofsee.T",
          "display_name": "Backdoor:Win32/Tofsee.T",
          "target": "/malware/Backdoor:Win32/Tofsee.T"
        },
        {
          "id": "TrojanDownloader:Win32/Cutwail",
          "display_name": "TrojanDownloader:Win32/Cutwail",
          "target": "/malware/TrojanDownloader:Win32/Cutwail"
        }
      ],
      "attack_ids": [
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1112",
          "name": "Modify Registry",
          "display_name": "T1112 - Modify Registry"
        },
        {
          "id": "T1222",
          "name": "File and Directory Permissions Modification",
          "display_name": "T1222 - File and Directory Permissions Modification"
        },
        {
          "id": "TA0003",
          "name": "Persistence",
          "display_name": "TA0003 - Persistence"
        },
        {
          "id": "TA0005",
          "name": "Defense Evasion",
          "display_name": "TA0005 - Defense Evasion"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1129",
          "name": "Shared Modules",
          "display_name": "T1129 - Shared Modules"
        },
        {
          "id": "TA0002",
          "name": "Execution",
          "display_name": "TA0002 - Execution"
        },
        {
          "id": "T1155",
          "name": "AppleScript",
          "display_name": "T1155 - AppleScript"
        },
        {
          "id": "T1553",
          "name": "Subvert Trust Controls",
          "display_name": "T1553 - Subvert Trust Controls"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1060",
          "name": "Registry Run Keys / Startup Folder",
          "display_name": "T1060 - Registry Run Keys / Startup Folder"
        }
      ],
      "industries": [
        "Government",
        "Healthcare",
        "Technology"
      ],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 7,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Q.Vashti",
        "id": "337942",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 138,
        "FileHash-SHA1": 119,
        "FileHash-SHA256": 3553,
        "IPv4": 633,
        "CVE": 2,
        "URL": 6134,
        "domain": 2439,
        "hostname": 2271,
        "email": 9,
        "SSLCertFingerprint": 2
      },
      "indicator_count": 15300,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 140,
      "modified_text": "8 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "https://ns1.raid.ru/",
    "type": "URL"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "https://ns1.raid.ru/",
    "type": "URL",
    "found": false,
    "verdict": "clean",
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1776711818.7718475
}