{
  "type": "URL",
  "indicator": "https://nutzerreaktion.de",
  "general": {
    "sections": [
      "general",
      "url_list",
      "http_scans",
      "screenshot"
    ],
    "indicator": "https://nutzerreaktion.de",
    "type": "url",
    "type_title": "URL",
    "validation": [],
    "base_indicator": {
      "id": 3255779796,
      "indicator": "https://nutzerreaktion.de",
      "type": "URL",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 21,
      "pulses": [
        {
          "id": "69a9cd444aa144401d0c4988",
          "name": "Pools Open",
          "description": "",
          "modified": "2026-04-15T19:21:28.851000",
          "created": "2026-03-05T18:36:52.014000",
          "tags": [
            "Timothy Pool",
            "Christopher Pool",
            "Pool's Closed"
          ],
          "references": [
            "Pool Closed",
            "Pool's Closed"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1546",
              "name": "Event Triggered Execution",
              "display_name": "T1546 - Event Triggered Execution"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            }
          ],
          "industries": [
            "Media",
            "ad fraud"
          ],
          "TLP": "white",
          "cloned_from": "5fa57698ac0f6638b7b9a8ba",
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 8098,
            "URL": 23428,
            "hostname": 9592,
            "domain": 4727,
            "SSLCertFingerprint": 22,
            "FileHash-MD5": 696,
            "FileHash-SHA1": 457,
            "CIDR": 78,
            "email": 3,
            "CVE": 2
          },
          "indicator_count": 47103,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 50,
          "modified_text": "4 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "5fa57698ac0f6638b7b9a8ba",
          "name": "Pool's Closed",
          "description": "Two paupers from the meadow spring forth an upheaval of nasty sites on the world wide web.",
          "modified": "2025-12-27T05:02:34.910000",
          "created": "2020-11-06T16:15:20.139000",
          "tags": [
            "Timothy Pool",
            "Christopher Pool",
            "Pool's Closed"
          ],
          "references": [
            "Pool Closed",
            "Pool's Closed"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1546",
              "name": "Event Triggered Execution",
              "display_name": "T1546 - Event Triggered Execution"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            }
          ],
          "industries": [
            "Media",
            "ad fraud"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 61,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 4,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scnrscnr",
            "id": "126475",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_126475/resized/80/avatar_67ca5b7bae.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 8098,
            "URL": 23426,
            "hostname": 9590,
            "domain": 4727,
            "SSLCertFingerprint": 22,
            "FileHash-MD5": 696,
            "FileHash-SHA1": 457,
            "CIDR": 78,
            "email": 3,
            "CVE": 2
          },
          "indicator_count": 47099,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 133,
          "modified_text": "113 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "65a48b6ea16eeb6b54dfad7c",
          "name": "https://neca.omeclk.com/portal/wts/uc^cn^ejkaejsaBeyk7-^Oa | Brian Sabey dangerous obsession with Tsara Brashears",
          "description": "",
          "modified": "2024-01-15T01:33:34.790000",
          "created": "2024-01-15T01:33:34.790000",
          "tags": [
            "cisco umbrella",
            "site",
            "alexa top",
            "emotet",
            "telefonica co",
            "million",
            "malware",
            "detection list",
            "blacklist",
            "alexa",
            "installcore",
            "heur",
            "cyber threat",
            "united",
            "phishing",
            "engineering",
            "phishing site",
            "team phishing",
            "spammer",
            "malicious site",
            "team",
            "download",
            "cobalt strike",
            "facebook",
            "artemis",
            "pony",
            "binder",
            "suppobox",
            "virut",
            "ramnit",
            "dropper",
            "formbook",
            "azorult",
            "simda",
            "downloader",
            "service",
            "bank",
            "zbot",
            "trojanspy",
            "heodo",
            "hostname",
            "hostnames",
            "whois record",
            "kgs0",
            "kls0",
            "apple ios",
            "tsara brashears",
            "ssl certificate",
            "elf collection",
            "cyberstalking",
            "spyware",
            "hackers",
            "installer",
            "open",
            "banker",
            "keylogger",
            "malicious",
            "hacktool",
            "core",
            "noname057",
            "generic malware",
            "safe site",
            "malware site",
            "iframe",
            "riskware",
            "exploit",
            "fakealert",
            "unsafe",
            "acint",
            "win64",
            "nircmd",
            "agent",
            "opencandy",
            "conduit",
            "swrort",
            "crack",
            "installpack",
            "xtrat",
            "psexec",
            "occamy",
            "brontok",
            "zpevdo",
            "startpage",
            "nanocore",
            "keygen",
            "fareit",
            "secrisk",
            "unruy",
            "filetour",
            "floxif",
            "cleaner",
            "patcher",
            "adload",
            "presenoker",
            "wacatac",
            "fusioncore",
            "genkryptik",
            "webtoolbar",
            "maltiverse",
            "smokeloader",
            "download json",
            "urls",
            "blacklist http",
            "kyriazhs1975",
            "vidar",
            "strike",
            "china cobalt",
            "meterpreter",
            "nanocore rat",
            "njrat",
            "redline stealer",
            "stealer",
            "nymaim",
            "mirai",
            "ghost rat",
            "runescape",
            "bradesco",
            "msil",
            "bladabindi",
            "orkut",
            "cutwail",
            "bandoo",
            "matsnu",
            "inmortal",
            "domains",
            "redline",
            "control server",
            "services",
            "generic",
            "br",
            "threat report",
            "ip summary",
            "url summary",
            "summary",
            "sample",
            "samples",
            "squirrelwaffle",
            "soc http",
            "soc https",
            "back",
            "download csv",
            "json sample",
            "injector",
            "malicious url",
            "downldr",
            "covid19 scam",
            "historical ssl",
            "referrer",
            "contacted",
            "whois whois",
            "contacted urls",
            "whois sslcert",
            "threat roundup",
            "copy",
            "august",
            "execution",
            "ransomware",
            "gopher",
            "remcos",
            "attack",
            "radar ineractive",
            "paypal",
            "covid19",
            "phishing chase",
            "phishing google",
            "tracker malware",
            "chase personal",
            "banking",
            "javascript",
            "please",
            "cnc server",
            "tracker",
            "cnc feodo",
            "phishtank",
            "threats et",
            "name verdict",
            "falcon sandbox",
            "pattern match",
            "file",
            "ascii text",
            "indicator",
            "windows nt",
            "jpeg image",
            "appdata",
            "jfif standard",
            "script",
            "show",
            "date",
            "span",
            "unknown",
            "general",
            "hybrid",
            "local",
            "click",
            "strings",
            "class",
            "generator",
            "critical",
            "error",
            "path",
            "http header",
            "tcp traffic",
            "mitre att",
            "ck id",
            "show technique",
            "ck matrix",
            "accept",
            "adware",
            "ip address",
            "hsbc",
            "outbreak",
            "downer",
            "shell",
            "mediamagnet",
            "sality",
            "adaptivebee",
            "iobit",
            "trojanx",
            "webshell",
            "systweak",
            "behav",
            "tiggre",
            "runtime process",
            "sha256",
            "sha1",
            "mark brian sabey",
            "brian sabey",
            "sabey",
            "apple",
            "114.114.114.114",
            "attorney",
            "law",
            "spammer",
            "fraud service",
            "hallrender",
            "malvertizing",
            "cybercrime",
            "social engineering",
            "malware hosting",
            "cyber threat",
            "iphone unlocker",
            "malicious",
            "attacker",
            "tulach",
            "tulach.cc",
            "adult content",
            "child pornographer",
            "sabey data centers",
            "hall render denver",
            "monitoring",
            "stalker",
            "dev",
            "developer",
            "cyber harassment",
            "defacement",
            "death threats",
            "miner",
            "agenttesla",
            "trojan",
            "detplock",
            "networm",
            "rms",
            "sneaky server",
            "replacement",
            "unauthorized",
            "steam route",
            "tool",
            "probe",
            "safebae.org",
            "safebae",
            "daisy",
            "daisy coleman",
            "benjamin",
            "colorado",
            "missouri",
            "telefonica",
            "boost mobile",
            "blackievirus.com",
            "TrojanX",
            "metro t-mobile",
            "t-mobile",
            "mile high media",
            "CNC",
            "C2",
            "malware host",
            "yixun"
          ],
          "references": [
            "https://hybrid-analysis.com/sample/a1b9247b6ad18f1cda0304e406333459d4000fced5753f91e5c046f6577c388a",
            "https://www.hallrender.com/attorney/brian-sabey",
            "safebae.org",
            "poemhunter.com",
            "http://www.hallrender.com/resources/blog/",
            "http://benjamin.xww.de/",
            "http://alohatube.xyz/search/tsara-brashears",
            "https://www.anyxxxtube.net/search-porn/tsara-brashears/",
            "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian",
            "Hybrid Analysis",
            "wTools",
            "Research"
          ],
          "public": 1,
          "adversary": "Tulach | Mark Brian Sabey | Hall Render Law Firm",
          "targeted_countries": [
            "United States of America",
            "Japan"
          ],
          "malware_families": [
            {
              "id": "TrojanSpy",
              "display_name": "TrojanSpy",
              "target": null
            },
            {
              "id": "WebToolbar",
              "display_name": "WebToolbar",
              "target": null
            },
            {
              "id": "Maltiverse",
              "display_name": "Maltiverse",
              "target": null
            },
            {
              "id": "Inmortal",
              "display_name": "Inmortal",
              "target": null
            },
            {
              "id": "Domains",
              "display_name": "Domains",
              "target": null
            },
            {
              "id": "RedLine",
              "display_name": "RedLine",
              "target": null
            },
            {
              "id": "BR",
              "display_name": "BR",
              "target": null
            },
            {
              "id": "Radar Ineractive",
              "display_name": "Radar Ineractive",
              "target": null
            },
            {
              "id": "HSBC",
              "display_name": "HSBC",
              "target": null
            },
            {
              "id": "RMS",
              "display_name": "RMS",
              "target": null
            },
            {
              "id": "Feodo Tracker",
              "display_name": "Feodo Tracker",
              "target": null
            },
            {
              "id": "Wacatac",
              "display_name": "Wacatac",
              "target": null
            },
            {
              "id": "Zpevdo",
              "display_name": "Zpevdo",
              "target": null
            },
            {
              "id": "Zbot",
              "display_name": "Zbot",
              "target": null
            },
            {
              "id": "OpenCandy",
              "display_name": "OpenCandy",
              "target": null
            },
            {
              "id": "xRAT",
              "display_name": "xRAT",
              "target": null
            },
            {
              "id": "Vidar",
              "display_name": "Vidar",
              "target": null
            },
            {
              "id": "Agent Tesla",
              "display_name": "Agent Tesla",
              "target": null
            },
            {
              "id": "noname057",
              "display_name": "noname057",
              "target": null
            },
            {
              "id": "TrojanSpy",
              "display_name": "TrojanSpy",
              "target": null
            },
            {
              "id": "DarkSide .Beware",
              "display_name": "DarkSide .Beware",
              "target": null
            },
            {
              "id": "Nymaim",
              "display_name": "Nymaim",
              "target": null
            },
            {
              "id": "SLFPER:BrowserModifier:Win32/MediaMagnet",
              "display_name": "SLFPER:BrowserModifier:Win32/MediaMagnet",
              "target": null
            },
            {
              "id": "Virut",
              "display_name": "Virut",
              "target": null
            },
            {
              "id": "Cutwail",
              "display_name": "Cutwail",
              "target": null
            },
            {
              "id": "Nanocore RAT",
              "display_name": "Nanocore RAT",
              "target": null
            },
            {
              "id": "Tulach Malware",
              "display_name": "Tulach Malware",
              "target": null
            },
            {
              "id": "SuppoBox",
              "display_name": "SuppoBox",
              "target": null
            },
            {
              "id": "Systweak",
              "display_name": "Systweak",
              "target": null
            },
            {
              "id": "Occamy",
              "display_name": "Occamy",
              "target": null
            },
            {
              "id": "Tiggre",
              "display_name": "Tiggre",
              "target": null
            },
            {
              "id": "IObit",
              "display_name": "IObit",
              "target": null
            },
            {
              "id": "Sality",
              "display_name": "Sality",
              "target": null
            },
            {
              "id": "FORMBOOK",
              "display_name": "FORMBOOK",
              "target": null
            },
            {
              "id": "Emotet",
              "display_name": "Emotet",
              "target": null
            },
            {
              "id": "Yixun",
              "display_name": "Yixun",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1496",
              "name": "Resource Hijacking",
              "display_name": "T1496 - Resource Hijacking"
            },
            {
              "id": "T1176",
              "name": "Browser Extensions",
              "display_name": "T1176 - Browser Extensions"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1041",
              "name": "Exfiltration Over C2 Channel",
              "display_name": "T1041 - Exfiltration Over C2 Channel"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1114",
              "name": "Email Collection",
              "display_name": "T1114 - Email Collection"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1012",
              "name": "Query Registry",
              "display_name": "T1012 - Query Registry"
            },
            {
              "id": "T1043",
              "name": "Commonly Used Port",
              "display_name": "T1043 - Commonly Used Port"
            },
            {
              "id": "T1112",
              "name": "Modify Registry",
              "display_name": "T1112 - Modify Registry"
            },
            {
              "id": "T1179",
              "name": "Hooking",
              "display_name": "T1179 - Hooking"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1583.005",
              "name": "Botnet",
              "display_name": "T1583.005 - Botnet"
            },
            {
              "id": "T1449",
              "name": "Exploit SS7 to Redirect Phone Calls/SMS",
              "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
            },
            {
              "id": "T1071.004",
              "name": "DNS",
              "display_name": "T1071.004 - DNS"
            },
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1068",
              "name": "Exploitation for Privilege Escalation",
              "display_name": "T1068 - Exploitation for Privilege Escalation"
            },
            {
              "id": "T1056.001",
              "name": "Keylogging",
              "display_name": "T1056.001 - Keylogging"
            }
          ],
          "industries": [
            "Health"
          ],
          "TLP": "green",
          "cloned_from": "6590f9b6b1fe0330c655c25f",
          "export_count": 36,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 1643,
            "hostname": 1438,
            "CVE": 30,
            "FileHash-MD5": 2853,
            "FileHash-SHA1": 1584,
            "FileHash-SHA256": 3001,
            "URL": 2904,
            "email": 1
          },
          "indicator_count": 13454,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 228,
          "modified_text": "825 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6590f9b6b1fe0330c655c25f",
          "name": "https://neca.omeclk.com/portal/wts/uc^cn^ejkaejsaBeyk7-^Oa | Brian Sabey dangerous obsession with Tsara Brashears ",
          "description": "",
          "modified": "2023-12-31T05:18:46.519000",
          "created": "2023-12-31T05:18:46.519000",
          "tags": [
            "cisco umbrella",
            "site",
            "alexa top",
            "emotet",
            "telefonica co",
            "million",
            "malware",
            "detection list",
            "blacklist",
            "alexa",
            "installcore",
            "heur",
            "cyber threat",
            "united",
            "phishing",
            "engineering",
            "phishing site",
            "team phishing",
            "spammer",
            "malicious site",
            "team",
            "download",
            "cobalt strike",
            "facebook",
            "artemis",
            "pony",
            "binder",
            "suppobox",
            "virut",
            "ramnit",
            "dropper",
            "formbook",
            "azorult",
            "simda",
            "downloader",
            "service",
            "bank",
            "zbot",
            "trojanspy",
            "heodo",
            "hostname",
            "hostnames",
            "whois record",
            "kgs0",
            "kls0",
            "apple ios",
            "tsara brashears",
            "ssl certificate",
            "elf collection",
            "cyberstalking",
            "spyware",
            "hackers",
            "installer",
            "open",
            "banker",
            "keylogger",
            "malicious",
            "hacktool",
            "core",
            "noname057",
            "generic malware",
            "safe site",
            "malware site",
            "iframe",
            "riskware",
            "exploit",
            "fakealert",
            "unsafe",
            "acint",
            "win64",
            "nircmd",
            "agent",
            "opencandy",
            "conduit",
            "swrort",
            "crack",
            "installpack",
            "xtrat",
            "psexec",
            "occamy",
            "brontok",
            "zpevdo",
            "startpage",
            "nanocore",
            "keygen",
            "fareit",
            "secrisk",
            "unruy",
            "filetour",
            "floxif",
            "cleaner",
            "patcher",
            "adload",
            "presenoker",
            "wacatac",
            "fusioncore",
            "genkryptik",
            "webtoolbar",
            "maltiverse",
            "smokeloader",
            "download json",
            "urls",
            "blacklist http",
            "kyriazhs1975",
            "vidar",
            "strike",
            "china cobalt",
            "meterpreter",
            "nanocore rat",
            "njrat",
            "redline stealer",
            "stealer",
            "nymaim",
            "mirai",
            "ghost rat",
            "runescape",
            "bradesco",
            "msil",
            "bladabindi",
            "orkut",
            "cutwail",
            "bandoo",
            "matsnu",
            "inmortal",
            "domains",
            "redline",
            "control server",
            "services",
            "generic",
            "br",
            "threat report",
            "ip summary",
            "url summary",
            "summary",
            "sample",
            "samples",
            "squirrelwaffle",
            "soc http",
            "soc https",
            "back",
            "download csv",
            "json sample",
            "injector",
            "malicious url",
            "downldr",
            "covid19 scam",
            "historical ssl",
            "referrer",
            "contacted",
            "whois whois",
            "contacted urls",
            "whois sslcert",
            "threat roundup",
            "copy",
            "august",
            "execution",
            "ransomware",
            "gopher",
            "remcos",
            "attack",
            "radar ineractive",
            "paypal",
            "covid19",
            "phishing chase",
            "phishing google",
            "tracker malware",
            "chase personal",
            "banking",
            "javascript",
            "please",
            "cnc server",
            "tracker",
            "cnc feodo",
            "phishtank",
            "threats et",
            "name verdict",
            "falcon sandbox",
            "pattern match",
            "file",
            "ascii text",
            "indicator",
            "windows nt",
            "jpeg image",
            "appdata",
            "jfif standard",
            "script",
            "show",
            "date",
            "span",
            "unknown",
            "general",
            "hybrid",
            "local",
            "click",
            "strings",
            "class",
            "generator",
            "critical",
            "error",
            "path",
            "http header",
            "tcp traffic",
            "mitre att",
            "ck id",
            "show technique",
            "ck matrix",
            "accept",
            "adware",
            "ip address",
            "hsbc",
            "outbreak",
            "downer",
            "shell",
            "mediamagnet",
            "sality",
            "adaptivebee",
            "iobit",
            "trojanx",
            "webshell",
            "systweak",
            "behav",
            "tiggre",
            "runtime process",
            "sha256",
            "sha1",
            "mark brian sabey",
            "brian sabey",
            "sabey",
            "apple",
            "114.114.114.114",
            "attorney",
            "law",
            "spammer",
            "fraud service",
            "hallrender",
            "malvertizing",
            "cybercrime",
            "social engineering",
            "malware hosting",
            "cyber threat",
            "iphone unlocker",
            "malicious",
            "attacker",
            "tulach",
            "tulach.cc",
            "adult content",
            "child pornographer",
            "sabey data centers",
            "hall render denver",
            "monitoring",
            "stalker",
            "dev",
            "developer",
            "cyber harassment",
            "defacement",
            "death threats",
            "miner",
            "agenttesla",
            "trojan",
            "detplock",
            "networm",
            "rms",
            "sneaky server",
            "replacement",
            "unauthorized",
            "steam route",
            "tool",
            "probe",
            "safebae.org",
            "safebae",
            "daisy",
            "daisy coleman",
            "benjamin",
            "colorado",
            "missouri",
            "telefonica",
            "boost mobile",
            "blackievirus.com",
            "TrojanX",
            "metro t-mobile",
            "t-mobile",
            "mile high media",
            "CNC",
            "C2",
            "malware host",
            "yixun"
          ],
          "references": [
            "https://hybrid-analysis.com/sample/a1b9247b6ad18f1cda0304e406333459d4000fced5753f91e5c046f6577c388a",
            "https://www.hallrender.com/attorney/brian-sabey",
            "safebae.org",
            "poemhunter.com",
            "http://www.hallrender.com/resources/blog/",
            "http://benjamin.xww.de/",
            "http://alohatube.xyz/search/tsara-brashears",
            "https://www.anyxxxtube.net/search-porn/tsara-brashears/",
            "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian",
            "Hybrid Analysis",
            "wTools",
            "Research"
          ],
          "public": 1,
          "adversary": "Tulach | Mark Brian Sabey | Hall Render Law Firm",
          "targeted_countries": [
            "United States of America",
            "Japan"
          ],
          "malware_families": [
            {
              "id": "TrojanSpy",
              "display_name": "TrojanSpy",
              "target": null
            },
            {
              "id": "WebToolbar",
              "display_name": "WebToolbar",
              "target": null
            },
            {
              "id": "Maltiverse",
              "display_name": "Maltiverse",
              "target": null
            },
            {
              "id": "Inmortal",
              "display_name": "Inmortal",
              "target": null
            },
            {
              "id": "Domains",
              "display_name": "Domains",
              "target": null
            },
            {
              "id": "RedLine",
              "display_name": "RedLine",
              "target": null
            },
            {
              "id": "BR",
              "display_name": "BR",
              "target": null
            },
            {
              "id": "Radar Ineractive",
              "display_name": "Radar Ineractive",
              "target": null
            },
            {
              "id": "HSBC",
              "display_name": "HSBC",
              "target": null
            },
            {
              "id": "RMS",
              "display_name": "RMS",
              "target": null
            },
            {
              "id": "Feodo Tracker",
              "display_name": "Feodo Tracker",
              "target": null
            },
            {
              "id": "Wacatac",
              "display_name": "Wacatac",
              "target": null
            },
            {
              "id": "Zpevdo",
              "display_name": "Zpevdo",
              "target": null
            },
            {
              "id": "Zbot",
              "display_name": "Zbot",
              "target": null
            },
            {
              "id": "OpenCandy",
              "display_name": "OpenCandy",
              "target": null
            },
            {
              "id": "xRAT",
              "display_name": "xRAT",
              "target": null
            },
            {
              "id": "Vidar",
              "display_name": "Vidar",
              "target": null
            },
            {
              "id": "Agent Tesla",
              "display_name": "Agent Tesla",
              "target": null
            },
            {
              "id": "noname057",
              "display_name": "noname057",
              "target": null
            },
            {
              "id": "TrojanSpy",
              "display_name": "TrojanSpy",
              "target": null
            },
            {
              "id": "DarkSide .Beware",
              "display_name": "DarkSide .Beware",
              "target": null
            },
            {
              "id": "Nymaim",
              "display_name": "Nymaim",
              "target": null
            },
            {
              "id": "SLFPER:BrowserModifier:Win32/MediaMagnet",
              "display_name": "SLFPER:BrowserModifier:Win32/MediaMagnet",
              "target": null
            },
            {
              "id": "Virut",
              "display_name": "Virut",
              "target": null
            },
            {
              "id": "Cutwail",
              "display_name": "Cutwail",
              "target": null
            },
            {
              "id": "Nanocore RAT",
              "display_name": "Nanocore RAT",
              "target": null
            },
            {
              "id": "Tulach Malware",
              "display_name": "Tulach Malware",
              "target": null
            },
            {
              "id": "SuppoBox",
              "display_name": "SuppoBox",
              "target": null
            },
            {
              "id": "Systweak",
              "display_name": "Systweak",
              "target": null
            },
            {
              "id": "Occamy",
              "display_name": "Occamy",
              "target": null
            },
            {
              "id": "Tiggre",
              "display_name": "Tiggre",
              "target": null
            },
            {
              "id": "IObit",
              "display_name": "IObit",
              "target": null
            },
            {
              "id": "Sality",
              "display_name": "Sality",
              "target": null
            },
            {
              "id": "FORMBOOK",
              "display_name": "FORMBOOK",
              "target": null
            },
            {
              "id": "Emotet",
              "display_name": "Emotet",
              "target": null
            },
            {
              "id": "Yixun",
              "display_name": "Yixun",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1496",
              "name": "Resource Hijacking",
              "display_name": "T1496 - Resource Hijacking"
            },
            {
              "id": "T1176",
              "name": "Browser Extensions",
              "display_name": "T1176 - Browser Extensions"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1041",
              "name": "Exfiltration Over C2 Channel",
              "display_name": "T1041 - Exfiltration Over C2 Channel"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1114",
              "name": "Email Collection",
              "display_name": "T1114 - Email Collection"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1012",
              "name": "Query Registry",
              "display_name": "T1012 - Query Registry"
            },
            {
              "id": "T1043",
              "name": "Commonly Used Port",
              "display_name": "T1043 - Commonly Used Port"
            },
            {
              "id": "T1112",
              "name": "Modify Registry",
              "display_name": "T1112 - Modify Registry"
            },
            {
              "id": "T1179",
              "name": "Hooking",
              "display_name": "T1179 - Hooking"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1583.005",
              "name": "Botnet",
              "display_name": "T1583.005 - Botnet"
            },
            {
              "id": "T1449",
              "name": "Exploit SS7 to Redirect Phone Calls/SMS",
              "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
            },
            {
              "id": "T1071.004",
              "name": "DNS",
              "display_name": "T1071.004 - DNS"
            },
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1068",
              "name": "Exploitation for Privilege Escalation",
              "display_name": "T1068 - Exploitation for Privilege Escalation"
            },
            {
              "id": "T1056.001",
              "name": "Keylogging",
              "display_name": "T1056.001 - Keylogging"
            }
          ],
          "industries": [
            "Health"
          ],
          "TLP": "green",
          "cloned_from": "658741502e029e25c7152cc0",
          "export_count": 45,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 1643,
            "hostname": 1438,
            "CVE": 30,
            "FileHash-MD5": 2853,
            "FileHash-SHA1": 1584,
            "FileHash-SHA256": 3001,
            "URL": 2904,
            "email": 1
          },
          "indicator_count": 13454,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 221,
          "modified_text": "840 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "658741502e029e25c7152cc0",
          "name": "busted hijacking",
          "description": "",
          "modified": "2023-12-23T20:21:36.641000",
          "created": "2023-12-23T20:21:36.641000",
          "tags": [
            "cisco umbrella",
            "site",
            "alexa top",
            "emotet",
            "telefonica co",
            "million",
            "malware",
            "detection list",
            "blacklist",
            "alexa",
            "installcore",
            "heur",
            "cyber threat",
            "united",
            "phishing",
            "engineering",
            "phishing site",
            "team phishing",
            "spammer",
            "malicious site",
            "team",
            "download",
            "cobalt strike",
            "facebook",
            "artemis",
            "pony",
            "binder",
            "suppobox",
            "virut",
            "ramnit",
            "dropper",
            "formbook",
            "azorult",
            "simda",
            "downloader",
            "service",
            "bank",
            "zbot",
            "trojanspy",
            "heodo",
            "hostname",
            "hostnames",
            "whois record",
            "kgs0",
            "kls0",
            "apple ios",
            "tsara brashears",
            "ssl certificate",
            "elf collection",
            "cyberstalking",
            "spyware",
            "hackers",
            "installer",
            "open",
            "banker",
            "keylogger",
            "malicious",
            "hacktool",
            "core",
            "noname057",
            "generic malware",
            "safe site",
            "malware site",
            "iframe",
            "riskware",
            "exploit",
            "fakealert",
            "unsafe",
            "acint",
            "win64",
            "nircmd",
            "agent",
            "opencandy",
            "conduit",
            "swrort",
            "crack",
            "installpack",
            "xtrat",
            "psexec",
            "occamy",
            "brontok",
            "zpevdo",
            "startpage",
            "nanocore",
            "keygen",
            "fareit",
            "secrisk",
            "unruy",
            "filetour",
            "floxif",
            "cleaner",
            "patcher",
            "adload",
            "presenoker",
            "wacatac",
            "fusioncore",
            "genkryptik",
            "webtoolbar",
            "maltiverse",
            "smokeloader",
            "download json",
            "urls",
            "blacklist http",
            "kyriazhs1975",
            "vidar",
            "strike",
            "china cobalt",
            "meterpreter",
            "nanocore rat",
            "njrat",
            "redline stealer",
            "stealer",
            "nymaim",
            "mirai",
            "ghost rat",
            "runescape",
            "bradesco",
            "msil",
            "bladabindi",
            "orkut",
            "cutwail",
            "bandoo",
            "matsnu",
            "inmortal",
            "domains",
            "redline",
            "control server",
            "services",
            "generic",
            "br",
            "threat report",
            "ip summary",
            "url summary",
            "summary",
            "sample",
            "samples",
            "squirrelwaffle",
            "soc http",
            "soc https",
            "back",
            "download csv",
            "json sample",
            "injector",
            "malicious url",
            "downldr",
            "covid19 scam",
            "historical ssl",
            "referrer",
            "contacted",
            "whois whois",
            "contacted urls",
            "whois sslcert",
            "threat roundup",
            "copy",
            "august",
            "execution",
            "ransomware",
            "gopher",
            "remcos",
            "attack",
            "radar ineractive",
            "paypal",
            "covid19",
            "phishing chase",
            "phishing google",
            "tracker malware",
            "chase personal",
            "banking",
            "javascript",
            "please",
            "cnc server",
            "tracker",
            "cnc feodo",
            "phishtank",
            "threats et",
            "name verdict",
            "falcon sandbox",
            "pattern match",
            "file",
            "ascii text",
            "indicator",
            "windows nt",
            "jpeg image",
            "appdata",
            "jfif standard",
            "script",
            "show",
            "date",
            "span",
            "unknown",
            "general",
            "hybrid",
            "local",
            "click",
            "strings",
            "class",
            "generator",
            "critical",
            "error",
            "path",
            "http header",
            "tcp traffic",
            "mitre att",
            "ck id",
            "show technique",
            "ck matrix",
            "accept",
            "adware",
            "ip address",
            "hsbc",
            "outbreak",
            "downer",
            "shell",
            "mediamagnet",
            "sality",
            "adaptivebee",
            "iobit",
            "trojanx",
            "webshell",
            "systweak",
            "behav",
            "tiggre",
            "runtime process",
            "sha256",
            "sha1",
            "mark brian sabey",
            "brian sabey",
            "sabey",
            "apple",
            "114.114.114.114",
            "attorney",
            "law",
            "spammer",
            "fraud service",
            "hallrender",
            "malvertizing",
            "cybercrime",
            "social engineering",
            "malware hosting",
            "cyber threat",
            "iphone unlocker",
            "malicious",
            "attacker",
            "tulach",
            "tulach.cc",
            "adult content",
            "child pornographer",
            "sabey data centers",
            "hall render denver",
            "monitoring",
            "stalker",
            "dev",
            "developer",
            "cyber harassment",
            "defacement",
            "death threats",
            "miner",
            "agenttesla",
            "trojan",
            "detplock",
            "networm",
            "rms",
            "sneaky server",
            "replacement",
            "unauthorized",
            "steam route",
            "tool",
            "probe",
            "safebae.org",
            "safebae",
            "daisy",
            "daisy coleman",
            "benjamin",
            "colorado",
            "missouri",
            "telefonica",
            "boost mobile",
            "blackievirus.com",
            "TrojanX",
            "metro t-mobile",
            "t-mobile",
            "mile high media",
            "CNC",
            "C2",
            "malware host",
            "yixun"
          ],
          "references": [
            "https://hybrid-analysis.com/sample/a1b9247b6ad18f1cda0304e406333459d4000fced5753f91e5c046f6577c388a",
            "https://www.hallrender.com/attorney/brian-sabey",
            "safebae.org",
            "poemhunter.com",
            "http://www.hallrender.com/resources/blog/",
            "http://benjamin.xww.de/",
            "http://alohatube.xyz/search/tsara-brashears",
            "https://www.anyxxxtube.net/search-porn/tsara-brashears/",
            "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian",
            "Hybrid Analysis",
            "wTools",
            "Research"
          ],
          "public": 1,
          "adversary": "Tulach | Mark Brian Sabey | Hall Render Law Firm",
          "targeted_countries": [
            "United States of America",
            "Japan"
          ],
          "malware_families": [
            {
              "id": "TrojanSpy",
              "display_name": "TrojanSpy",
              "target": null
            },
            {
              "id": "WebToolbar",
              "display_name": "WebToolbar",
              "target": null
            },
            {
              "id": "Maltiverse",
              "display_name": "Maltiverse",
              "target": null
            },
            {
              "id": "Inmortal",
              "display_name": "Inmortal",
              "target": null
            },
            {
              "id": "Domains",
              "display_name": "Domains",
              "target": null
            },
            {
              "id": "RedLine",
              "display_name": "RedLine",
              "target": null
            },
            {
              "id": "BR",
              "display_name": "BR",
              "target": null
            },
            {
              "id": "Radar Ineractive",
              "display_name": "Radar Ineractive",
              "target": null
            },
            {
              "id": "HSBC",
              "display_name": "HSBC",
              "target": null
            },
            {
              "id": "RMS",
              "display_name": "RMS",
              "target": null
            },
            {
              "id": "Feodo Tracker",
              "display_name": "Feodo Tracker",
              "target": null
            },
            {
              "id": "Wacatac",
              "display_name": "Wacatac",
              "target": null
            },
            {
              "id": "Zpevdo",
              "display_name": "Zpevdo",
              "target": null
            },
            {
              "id": "Zbot",
              "display_name": "Zbot",
              "target": null
            },
            {
              "id": "OpenCandy",
              "display_name": "OpenCandy",
              "target": null
            },
            {
              "id": "xRAT",
              "display_name": "xRAT",
              "target": null
            },
            {
              "id": "Vidar",
              "display_name": "Vidar",
              "target": null
            },
            {
              "id": "Agent Tesla",
              "display_name": "Agent Tesla",
              "target": null
            },
            {
              "id": "noname057",
              "display_name": "noname057",
              "target": null
            },
            {
              "id": "TrojanSpy",
              "display_name": "TrojanSpy",
              "target": null
            },
            {
              "id": "DarkSide .Beware",
              "display_name": "DarkSide .Beware",
              "target": null
            },
            {
              "id": "Nymaim",
              "display_name": "Nymaim",
              "target": null
            },
            {
              "id": "SLFPER:BrowserModifier:Win32/MediaMagnet",
              "display_name": "SLFPER:BrowserModifier:Win32/MediaMagnet",
              "target": null
            },
            {
              "id": "Virut",
              "display_name": "Virut",
              "target": null
            },
            {
              "id": "Cutwail",
              "display_name": "Cutwail",
              "target": null
            },
            {
              "id": "Nanocore RAT",
              "display_name": "Nanocore RAT",
              "target": null
            },
            {
              "id": "Tulach Malware",
              "display_name": "Tulach Malware",
              "target": null
            },
            {
              "id": "SuppoBox",
              "display_name": "SuppoBox",
              "target": null
            },
            {
              "id": "Systweak",
              "display_name": "Systweak",
              "target": null
            },
            {
              "id": "Occamy",
              "display_name": "Occamy",
              "target": null
            },
            {
              "id": "Tiggre",
              "display_name": "Tiggre",
              "target": null
            },
            {
              "id": "IObit",
              "display_name": "IObit",
              "target": null
            },
            {
              "id": "Sality",
              "display_name": "Sality",
              "target": null
            },
            {
              "id": "FORMBOOK",
              "display_name": "FORMBOOK",
              "target": null
            },
            {
              "id": "Emotet",
              "display_name": "Emotet",
              "target": null
            },
            {
              "id": "Yixun",
              "display_name": "Yixun",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1496",
              "name": "Resource Hijacking",
              "display_name": "T1496 - Resource Hijacking"
            },
            {
              "id": "T1176",
              "name": "Browser Extensions",
              "display_name": "T1176 - Browser Extensions"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1041",
              "name": "Exfiltration Over C2 Channel",
              "display_name": "T1041 - Exfiltration Over C2 Channel"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1114",
              "name": "Email Collection",
              "display_name": "T1114 - Email Collection"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1012",
              "name": "Query Registry",
              "display_name": "T1012 - Query Registry"
            },
            {
              "id": "T1043",
              "name": "Commonly Used Port",
              "display_name": "T1043 - Commonly Used Port"
            },
            {
              "id": "T1112",
              "name": "Modify Registry",
              "display_name": "T1112 - Modify Registry"
            },
            {
              "id": "T1179",
              "name": "Hooking",
              "display_name": "T1179 - Hooking"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1583.005",
              "name": "Botnet",
              "display_name": "T1583.005 - Botnet"
            },
            {
              "id": "T1449",
              "name": "Exploit SS7 to Redirect Phone Calls/SMS",
              "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
            },
            {
              "id": "T1071.004",
              "name": "DNS",
              "display_name": "T1071.004 - DNS"
            },
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1068",
              "name": "Exploitation for Privilege Escalation",
              "display_name": "T1068 - Exploitation for Privilege Escalation"
            },
            {
              "id": "T1056.001",
              "name": "Keylogging",
              "display_name": "T1056.001 - Keylogging"
            }
          ],
          "industries": [
            "Health"
          ],
          "TLP": "green",
          "cloned_from": "6544c99af21a2fde7bd6927e",
          "export_count": 33,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Machidian45",
            "id": "262704",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 1643,
            "hostname": 1438,
            "CVE": 30,
            "FileHash-MD5": 2853,
            "FileHash-SHA1": 1584,
            "FileHash-SHA256": 3001,
            "URL": 2904,
            "email": 1
          },
          "indicator_count": 13454,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 32,
          "modified_text": "848 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6587414f2e029e25c7152cbf",
          "name": "busted hijacking",
          "description": "",
          "modified": "2023-12-23T20:21:35.725000",
          "created": "2023-12-23T20:21:35.725000",
          "tags": [
            "cisco umbrella",
            "site",
            "alexa top",
            "emotet",
            "telefonica co",
            "million",
            "malware",
            "detection list",
            "blacklist",
            "alexa",
            "installcore",
            "heur",
            "cyber threat",
            "united",
            "phishing",
            "engineering",
            "phishing site",
            "team phishing",
            "spammer",
            "malicious site",
            "team",
            "download",
            "cobalt strike",
            "facebook",
            "artemis",
            "pony",
            "binder",
            "suppobox",
            "virut",
            "ramnit",
            "dropper",
            "formbook",
            "azorult",
            "simda",
            "downloader",
            "service",
            "bank",
            "zbot",
            "trojanspy",
            "heodo",
            "hostname",
            "hostnames",
            "whois record",
            "kgs0",
            "kls0",
            "apple ios",
            "tsara brashears",
            "ssl certificate",
            "elf collection",
            "cyberstalking",
            "spyware",
            "hackers",
            "installer",
            "open",
            "banker",
            "keylogger",
            "malicious",
            "hacktool",
            "core",
            "noname057",
            "generic malware",
            "safe site",
            "malware site",
            "iframe",
            "riskware",
            "exploit",
            "fakealert",
            "unsafe",
            "acint",
            "win64",
            "nircmd",
            "agent",
            "opencandy",
            "conduit",
            "swrort",
            "crack",
            "installpack",
            "xtrat",
            "psexec",
            "occamy",
            "brontok",
            "zpevdo",
            "startpage",
            "nanocore",
            "keygen",
            "fareit",
            "secrisk",
            "unruy",
            "filetour",
            "floxif",
            "cleaner",
            "patcher",
            "adload",
            "presenoker",
            "wacatac",
            "fusioncore",
            "genkryptik",
            "webtoolbar",
            "maltiverse",
            "smokeloader",
            "download json",
            "urls",
            "blacklist http",
            "kyriazhs1975",
            "vidar",
            "strike",
            "china cobalt",
            "meterpreter",
            "nanocore rat",
            "njrat",
            "redline stealer",
            "stealer",
            "nymaim",
            "mirai",
            "ghost rat",
            "runescape",
            "bradesco",
            "msil",
            "bladabindi",
            "orkut",
            "cutwail",
            "bandoo",
            "matsnu",
            "inmortal",
            "domains",
            "redline",
            "control server",
            "services",
            "generic",
            "br",
            "threat report",
            "ip summary",
            "url summary",
            "summary",
            "sample",
            "samples",
            "squirrelwaffle",
            "soc http",
            "soc https",
            "back",
            "download csv",
            "json sample",
            "injector",
            "malicious url",
            "downldr",
            "covid19 scam",
            "historical ssl",
            "referrer",
            "contacted",
            "whois whois",
            "contacted urls",
            "whois sslcert",
            "threat roundup",
            "copy",
            "august",
            "execution",
            "ransomware",
            "gopher",
            "remcos",
            "attack",
            "radar ineractive",
            "paypal",
            "covid19",
            "phishing chase",
            "phishing google",
            "tracker malware",
            "chase personal",
            "banking",
            "javascript",
            "please",
            "cnc server",
            "tracker",
            "cnc feodo",
            "phishtank",
            "threats et",
            "name verdict",
            "falcon sandbox",
            "pattern match",
            "file",
            "ascii text",
            "indicator",
            "windows nt",
            "jpeg image",
            "appdata",
            "jfif standard",
            "script",
            "show",
            "date",
            "span",
            "unknown",
            "general",
            "hybrid",
            "local",
            "click",
            "strings",
            "class",
            "generator",
            "critical",
            "error",
            "path",
            "http header",
            "tcp traffic",
            "mitre att",
            "ck id",
            "show technique",
            "ck matrix",
            "accept",
            "adware",
            "ip address",
            "hsbc",
            "outbreak",
            "downer",
            "shell",
            "mediamagnet",
            "sality",
            "adaptivebee",
            "iobit",
            "trojanx",
            "webshell",
            "systweak",
            "behav",
            "tiggre",
            "runtime process",
            "sha256",
            "sha1",
            "mark brian sabey",
            "brian sabey",
            "sabey",
            "apple",
            "114.114.114.114",
            "attorney",
            "law",
            "spammer",
            "fraud service",
            "hallrender",
            "malvertizing",
            "cybercrime",
            "social engineering",
            "malware hosting",
            "cyber threat",
            "iphone unlocker",
            "malicious",
            "attacker",
            "tulach",
            "tulach.cc",
            "adult content",
            "child pornographer",
            "sabey data centers",
            "hall render denver",
            "monitoring",
            "stalker",
            "dev",
            "developer",
            "cyber harassment",
            "defacement",
            "death threats",
            "miner",
            "agenttesla",
            "trojan",
            "detplock",
            "networm",
            "rms",
            "sneaky server",
            "replacement",
            "unauthorized",
            "steam route",
            "tool",
            "probe",
            "safebae.org",
            "safebae",
            "daisy",
            "daisy coleman",
            "benjamin",
            "colorado",
            "missouri",
            "telefonica",
            "boost mobile",
            "blackievirus.com",
            "TrojanX",
            "metro t-mobile",
            "t-mobile",
            "mile high media",
            "CNC",
            "C2",
            "malware host",
            "yixun"
          ],
          "references": [
            "https://hybrid-analysis.com/sample/a1b9247b6ad18f1cda0304e406333459d4000fced5753f91e5c046f6577c388a",
            "https://www.hallrender.com/attorney/brian-sabey",
            "safebae.org",
            "poemhunter.com",
            "http://www.hallrender.com/resources/blog/",
            "http://benjamin.xww.de/",
            "http://alohatube.xyz/search/tsara-brashears",
            "https://www.anyxxxtube.net/search-porn/tsara-brashears/",
            "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian",
            "Hybrid Analysis",
            "wTools",
            "Research"
          ],
          "public": 1,
          "adversary": "Tulach | Mark Brian Sabey | Hall Render Law Firm",
          "targeted_countries": [
            "United States of America",
            "Japan"
          ],
          "malware_families": [
            {
              "id": "TrojanSpy",
              "display_name": "TrojanSpy",
              "target": null
            },
            {
              "id": "WebToolbar",
              "display_name": "WebToolbar",
              "target": null
            },
            {
              "id": "Maltiverse",
              "display_name": "Maltiverse",
              "target": null
            },
            {
              "id": "Inmortal",
              "display_name": "Inmortal",
              "target": null
            },
            {
              "id": "Domains",
              "display_name": "Domains",
              "target": null
            },
            {
              "id": "RedLine",
              "display_name": "RedLine",
              "target": null
            },
            {
              "id": "BR",
              "display_name": "BR",
              "target": null
            },
            {
              "id": "Radar Ineractive",
              "display_name": "Radar Ineractive",
              "target": null
            },
            {
              "id": "HSBC",
              "display_name": "HSBC",
              "target": null
            },
            {
              "id": "RMS",
              "display_name": "RMS",
              "target": null
            },
            {
              "id": "Feodo Tracker",
              "display_name": "Feodo Tracker",
              "target": null
            },
            {
              "id": "Wacatac",
              "display_name": "Wacatac",
              "target": null
            },
            {
              "id": "Zpevdo",
              "display_name": "Zpevdo",
              "target": null
            },
            {
              "id": "Zbot",
              "display_name": "Zbot",
              "target": null
            },
            {
              "id": "OpenCandy",
              "display_name": "OpenCandy",
              "target": null
            },
            {
              "id": "xRAT",
              "display_name": "xRAT",
              "target": null
            },
            {
              "id": "Vidar",
              "display_name": "Vidar",
              "target": null
            },
            {
              "id": "Agent Tesla",
              "display_name": "Agent Tesla",
              "target": null
            },
            {
              "id": "noname057",
              "display_name": "noname057",
              "target": null
            },
            {
              "id": "TrojanSpy",
              "display_name": "TrojanSpy",
              "target": null
            },
            {
              "id": "DarkSide .Beware",
              "display_name": "DarkSide .Beware",
              "target": null
            },
            {
              "id": "Nymaim",
              "display_name": "Nymaim",
              "target": null
            },
            {
              "id": "SLFPER:BrowserModifier:Win32/MediaMagnet",
              "display_name": "SLFPER:BrowserModifier:Win32/MediaMagnet",
              "target": null
            },
            {
              "id": "Virut",
              "display_name": "Virut",
              "target": null
            },
            {
              "id": "Cutwail",
              "display_name": "Cutwail",
              "target": null
            },
            {
              "id": "Nanocore RAT",
              "display_name": "Nanocore RAT",
              "target": null
            },
            {
              "id": "Tulach Malware",
              "display_name": "Tulach Malware",
              "target": null
            },
            {
              "id": "SuppoBox",
              "display_name": "SuppoBox",
              "target": null
            },
            {
              "id": "Systweak",
              "display_name": "Systweak",
              "target": null
            },
            {
              "id": "Occamy",
              "display_name": "Occamy",
              "target": null
            },
            {
              "id": "Tiggre",
              "display_name": "Tiggre",
              "target": null
            },
            {
              "id": "IObit",
              "display_name": "IObit",
              "target": null
            },
            {
              "id": "Sality",
              "display_name": "Sality",
              "target": null
            },
            {
              "id": "FORMBOOK",
              "display_name": "FORMBOOK",
              "target": null
            },
            {
              "id": "Emotet",
              "display_name": "Emotet",
              "target": null
            },
            {
              "id": "Yixun",
              "display_name": "Yixun",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1496",
              "name": "Resource Hijacking",
              "display_name": "T1496 - Resource Hijacking"
            },
            {
              "id": "T1176",
              "name": "Browser Extensions",
              "display_name": "T1176 - Browser Extensions"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1041",
              "name": "Exfiltration Over C2 Channel",
              "display_name": "T1041 - Exfiltration Over C2 Channel"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1114",
              "name": "Email Collection",
              "display_name": "T1114 - Email Collection"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1012",
              "name": "Query Registry",
              "display_name": "T1012 - Query Registry"
            },
            {
              "id": "T1043",
              "name": "Commonly Used Port",
              "display_name": "T1043 - Commonly Used Port"
            },
            {
              "id": "T1112",
              "name": "Modify Registry",
              "display_name": "T1112 - Modify Registry"
            },
            {
              "id": "T1179",
              "name": "Hooking",
              "display_name": "T1179 - Hooking"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1583.005",
              "name": "Botnet",
              "display_name": "T1583.005 - Botnet"
            },
            {
              "id": "T1449",
              "name": "Exploit SS7 to Redirect Phone Calls/SMS",
              "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
            },
            {
              "id": "T1071.004",
              "name": "DNS",
              "display_name": "T1071.004 - DNS"
            },
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1068",
              "name": "Exploitation for Privilege Escalation",
              "display_name": "T1068 - Exploitation for Privilege Escalation"
            },
            {
              "id": "T1056.001",
              "name": "Keylogging",
              "display_name": "T1056.001 - Keylogging"
            }
          ],
          "industries": [
            "Health"
          ],
          "TLP": "green",
          "cloned_from": "6544c99af21a2fde7bd6927e",
          "export_count": 34,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Machidian45",
            "id": "262704",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 1643,
            "hostname": 1438,
            "CVE": 30,
            "FileHash-MD5": 2853,
            "FileHash-SHA1": 1584,
            "FileHash-SHA256": 3001,
            "URL": 2904,
            "email": 1
          },
          "indicator_count": 13454,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 34,
          "modified_text": "848 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6544c7a11d7541bdb3bfe5ff",
          "name": "Radar Ineractive. Law Firm responsible for cyber crime.",
          "description": "Is this legal.  Attorney from Hall Render law firm cyber stalking  and malvertizing targets in adult content, dungeons, death scenarios, suicide threats? Pulse auto populates targets: Tsara Brashears 'alleged'  SA victim. This may not be the forum for my , death threats should always be investigated as should allegations of assault. Malware, BotNet, car and phone tracking, monitoring, injection,   .gov is found throughout. Monitoring of Safebae.org; online movement began by now deceased 'alleged' SA victim, Daisy Coleman of Audrey & Daisy.  High Risk surviving target. Crazy cover up? Each target seems to have a state government power 'implicated' in attack. \n\nEd Said",
          "modified": "2023-12-16T19:40:11.047000",
          "created": "2023-11-03T10:12:49.539000",
          "tags": [
            "cisco umbrella",
            "site",
            "alexa top",
            "emotet",
            "telefonica co",
            "million",
            "malware",
            "detection list",
            "blacklist",
            "alexa",
            "installcore",
            "heur",
            "cyber threat",
            "united",
            "phishing",
            "engineering",
            "phishing site",
            "team phishing",
            "spammer",
            "malicious site",
            "team",
            "download",
            "cobalt strike",
            "facebook",
            "artemis",
            "pony",
            "binder",
            "suppobox",
            "virut",
            "ramnit",
            "dropper",
            "formbook",
            "azorult",
            "simda",
            "downloader",
            "service",
            "bank",
            "zbot",
            "trojanspy",
            "heodo",
            "hostname",
            "hostnames",
            "whois record",
            "kgs0",
            "kls0",
            "apple ios",
            "tsara brashears",
            "ssl certificate",
            "elf collection",
            "cyberstalking",
            "spyware",
            "hackers",
            "installer",
            "open",
            "banker",
            "keylogger",
            "malicious",
            "hacktool",
            "core",
            "noname057",
            "generic malware",
            "safe site",
            "malware site",
            "iframe",
            "riskware",
            "exploit",
            "fakealert",
            "unsafe",
            "acint",
            "win64",
            "nircmd",
            "agent",
            "opencandy",
            "conduit",
            "swrort",
            "crack",
            "installpack",
            "xtrat",
            "psexec",
            "occamy",
            "brontok",
            "zpevdo",
            "startpage",
            "nanocore",
            "keygen",
            "fareit",
            "secrisk",
            "unruy",
            "filetour",
            "floxif",
            "cleaner",
            "patcher",
            "adload",
            "presenoker",
            "wacatac",
            "fusioncore",
            "genkryptik",
            "webtoolbar",
            "maltiverse",
            "smokeloader",
            "download json",
            "urls",
            "blacklist http",
            "kyriazhs1975",
            "vidar",
            "strike",
            "china cobalt",
            "meterpreter",
            "nanocore rat",
            "njrat",
            "redline stealer",
            "stealer",
            "nymaim",
            "mirai",
            "ghost rat",
            "runescape",
            "bradesco",
            "msil",
            "bladabindi",
            "orkut",
            "cutwail",
            "bandoo",
            "matsnu",
            "inmortal",
            "domains",
            "redline",
            "control server",
            "services",
            "generic",
            "br",
            "threat report",
            "ip summary",
            "url summary",
            "summary",
            "sample",
            "samples",
            "squirrelwaffle",
            "soc http",
            "soc https",
            "back",
            "download csv",
            "json sample",
            "injector",
            "malicious url",
            "downldr",
            "covid19 scam",
            "historical ssl",
            "referrer",
            "contacted",
            "whois whois",
            "contacted urls",
            "whois sslcert",
            "threat roundup",
            "copy",
            "august",
            "execution",
            "ransomware",
            "gopher",
            "remcos",
            "attack",
            "radar ineractive",
            "paypal",
            "covid19",
            "phishing chase",
            "phishing google",
            "tracker malware",
            "chase personal",
            "banking",
            "javascript",
            "please",
            "cnc server",
            "tracker",
            "cnc feodo",
            "phishtank",
            "threats et",
            "name verdict",
            "falcon sandbox",
            "pattern match",
            "file",
            "ascii text",
            "indicator",
            "windows nt",
            "jpeg image",
            "appdata",
            "jfif standard",
            "script",
            "show",
            "date",
            "span",
            "unknown",
            "general",
            "hybrid",
            "local",
            "click",
            "strings",
            "class",
            "generator",
            "critical",
            "error",
            "path",
            "http header",
            "tcp traffic",
            "mitre att",
            "ck id",
            "show technique",
            "ck matrix",
            "accept",
            "adware",
            "ip address",
            "hsbc",
            "outbreak",
            "downer",
            "shell",
            "mediamagnet",
            "sality",
            "adaptivebee",
            "iobit",
            "trojanx",
            "webshell",
            "systweak",
            "behav",
            "tiggre",
            "runtime process",
            "sha256",
            "sha1",
            "mark brian sabey",
            "brian sabey",
            "sabey",
            "apple",
            "114.114.114.114",
            "attorney",
            "law",
            "spammer",
            "fraud service",
            "hallrender",
            "malvertizing",
            "cybercrime",
            "social engineering",
            "malware hosting",
            "cyber threat",
            "iphone unlocker",
            "malicious",
            "attacker",
            "tulach",
            "tulach.cc",
            "adult content",
            "child pornographer",
            "sabey data centers",
            "hall render denver",
            "monitoring",
            "stalker",
            "dev",
            "developer",
            "cyber harassment",
            "defacement",
            "death threats",
            "miner",
            "agenttesla",
            "trojan",
            "detplock",
            "networm",
            "rms",
            "sneaky server",
            "replacement",
            "unauthorized",
            "steam route",
            "tool",
            "probe",
            "safebae.org",
            "safebae",
            "daisy",
            "daisy coleman",
            "benjamin",
            "colorado",
            "missouri",
            "telefonica",
            "boost mobile",
            "blackievirus.com",
            "TrojanX",
            "metro t-mobile",
            "t-mobile",
            "mile high media",
            "CNC",
            "C2",
            "malware host",
            "yixun"
          ],
          "references": [
            "https://hybrid-analysis.com/sample/a1b9247b6ad18f1cda0304e406333459d4000fced5753f91e5c046f6577c388a",
            "https://www.hallrender.com/attorney/brian-sabey",
            "safebae.org",
            "poemhunter.com",
            "http://www.hallrender.com/resources/blog/",
            "http://benjamin.xww.de/",
            "http://alohatube.xyz/search/tsara-brashears",
            "https://www.anyxxxtube.net/search-porn/tsara-brashears/",
            "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian",
            "Hybrid Analysis",
            "wTools",
            "Research"
          ],
          "public": 1,
          "adversary": "Tulach | Mark Brian Sabey | Hall Render Law Firm",
          "targeted_countries": [
            "United States of America",
            "Japan"
          ],
          "malware_families": [
            {
              "id": "TrojanSpy",
              "display_name": "TrojanSpy",
              "target": null
            },
            {
              "id": "WebToolbar",
              "display_name": "WebToolbar",
              "target": null
            },
            {
              "id": "Maltiverse",
              "display_name": "Maltiverse",
              "target": null
            },
            {
              "id": "Inmortal",
              "display_name": "Inmortal",
              "target": null
            },
            {
              "id": "Domains",
              "display_name": "Domains",
              "target": null
            },
            {
              "id": "RedLine",
              "display_name": "RedLine",
              "target": null
            },
            {
              "id": "BR",
              "display_name": "BR",
              "target": null
            },
            {
              "id": "Radar Ineractive",
              "display_name": "Radar Ineractive",
              "target": null
            },
            {
              "id": "HSBC",
              "display_name": "HSBC",
              "target": null
            },
            {
              "id": "RMS",
              "display_name": "RMS",
              "target": null
            },
            {
              "id": "Feodo Tracker",
              "display_name": "Feodo Tracker",
              "target": null
            },
            {
              "id": "Wacatac",
              "display_name": "Wacatac",
              "target": null
            },
            {
              "id": "Zpevdo",
              "display_name": "Zpevdo",
              "target": null
            },
            {
              "id": "Zbot",
              "display_name": "Zbot",
              "target": null
            },
            {
              "id": "OpenCandy",
              "display_name": "OpenCandy",
              "target": null
            },
            {
              "id": "xRAT",
              "display_name": "xRAT",
              "target": null
            },
            {
              "id": "Vidar",
              "display_name": "Vidar",
              "target": null
            },
            {
              "id": "Agent Tesla",
              "display_name": "Agent Tesla",
              "target": null
            },
            {
              "id": "noname057",
              "display_name": "noname057",
              "target": null
            },
            {
              "id": "TrojanSpy",
              "display_name": "TrojanSpy",
              "target": null
            },
            {
              "id": "DarkSide .Beware",
              "display_name": "DarkSide .Beware",
              "target": null
            },
            {
              "id": "Nymaim",
              "display_name": "Nymaim",
              "target": null
            },
            {
              "id": "SLFPER:BrowserModifier:Win32/MediaMagnet",
              "display_name": "SLFPER:BrowserModifier:Win32/MediaMagnet",
              "target": null
            },
            {
              "id": "Virut",
              "display_name": "Virut",
              "target": null
            },
            {
              "id": "Cutwail",
              "display_name": "Cutwail",
              "target": null
            },
            {
              "id": "Nanocore RAT",
              "display_name": "Nanocore RAT",
              "target": null
            },
            {
              "id": "Tulach Malware",
              "display_name": "Tulach Malware",
              "target": null
            },
            {
              "id": "SuppoBox",
              "display_name": "SuppoBox",
              "target": null
            },
            {
              "id": "Systweak",
              "display_name": "Systweak",
              "target": null
            },
            {
              "id": "Occamy",
              "display_name": "Occamy",
              "target": null
            },
            {
              "id": "Tiggre",
              "display_name": "Tiggre",
              "target": null
            },
            {
              "id": "IObit",
              "display_name": "IObit",
              "target": null
            },
            {
              "id": "Sality",
              "display_name": "Sality",
              "target": null
            },
            {
              "id": "FORMBOOK",
              "display_name": "FORMBOOK",
              "target": null
            },
            {
              "id": "Emotet",
              "display_name": "Emotet",
              "target": null
            },
            {
              "id": "Yixun",
              "display_name": "Yixun",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1496",
              "name": "Resource Hijacking",
              "display_name": "T1496 - Resource Hijacking"
            },
            {
              "id": "T1176",
              "name": "Browser Extensions",
              "display_name": "T1176 - Browser Extensions"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1041",
              "name": "Exfiltration Over C2 Channel",
              "display_name": "T1041 - Exfiltration Over C2 Channel"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1114",
              "name": "Email Collection",
              "display_name": "T1114 - Email Collection"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1012",
              "name": "Query Registry",
              "display_name": "T1012 - Query Registry"
            },
            {
              "id": "T1043",
              "name": "Commonly Used Port",
              "display_name": "T1043 - Commonly Used Port"
            },
            {
              "id": "T1112",
              "name": "Modify Registry",
              "display_name": "T1112 - Modify Registry"
            },
            {
              "id": "T1179",
              "name": "Hooking",
              "display_name": "T1179 - Hooking"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1583.005",
              "name": "Botnet",
              "display_name": "T1583.005 - Botnet"
            },
            {
              "id": "T1449",
              "name": "Exploit SS7 to Redirect Phone Calls/SMS",
              "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
            },
            {
              "id": "T1071.004",
              "name": "DNS",
              "display_name": "T1071.004 - DNS"
            },
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1068",
              "name": "Exploitation for Privilege Escalation",
              "display_name": "T1068 - Exploitation for Privilege Escalation"
            },
            {
              "id": "T1056.001",
              "name": "Keylogging",
              "display_name": "T1056.001 - Keylogging"
            }
          ],
          "industries": [
            "Health"
          ],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 82,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 1,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 1644,
            "hostname": 1438,
            "CVE": 30,
            "FileHash-MD5": 2853,
            "FileHash-SHA1": 1584,
            "FileHash-SHA256": 3001,
            "URL": 2904,
            "email": 1
          },
          "indicator_count": 13455,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 222,
          "modified_text": "855 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6570a161f0681f4ff3d67feb",
          "name": "Pool's Closed (by @scnrscnr)",
          "description": "",
          "modified": "2023-12-06T16:29:21.844000",
          "created": "2023-12-06T16:29:21.844000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 10,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 7844,
            "FileHash-MD5": 562,
            "FileHash-SHA1": 429,
            "URL": 22749,
            "hostname": 9461,
            "domain": 4578,
            "SSLCertFingerprint": 20,
            "CIDR": 32,
            "email": 3,
            "CVE": 2
          },
          "indicator_count": 45680,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 111,
          "modified_text": "865 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6570a145926a5676de0e2a1a",
          "name": "Pool's Closed (by @scnrscnr)",
          "description": "",
          "modified": "2023-12-06T16:28:53.979000",
          "created": "2023-12-06T16:28:53.979000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 9,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 7844,
            "FileHash-MD5": 562,
            "FileHash-SHA1": 429,
            "URL": 22749,
            "hostname": 9461,
            "domain": 4578,
            "SSLCertFingerprint": 20,
            "CIDR": 32,
            "email": 3,
            "CVE": 2
          },
          "indicator_count": 45680,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 111,
          "modified_text": "865 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "65707b9630308cb99a817277",
          "name": "Pool's Closed",
          "description": "",
          "modified": "2023-12-06T13:48:06.514000",
          "created": "2023-12-06T13:48:06.514000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 3,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 7844,
            "FileHash-MD5": 562,
            "FileHash-SHA1": 429,
            "URL": 22749,
            "hostname": 9461,
            "domain": 4578,
            "SSLCertFingerprint": 20,
            "CIDR": 32,
            "email": 3,
            "CVE": 2
          },
          "indicator_count": 45680,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 111,
          "modified_text": "865 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6546d0120a7e479fecffe2b1",
          "name": "Browser Malware Attack",
          "description": "Attacking  browser to identify researcher.\nCommand for critical failure/destruction:    https://search.app.goo.gl/?ofl=https://lens.google&al=googleapp://lens?lens_data=KAw&apn=com.google.android.googlequicksearchbox&amv=301204913&isi=284815942&ius=googleapp&ibi=com.goog",
          "modified": "2023-12-04T22:00:43.514000",
          "created": "2023-11-04T23:13:21.883000",
          "tags": [
            "united",
            "facebook",
            "phishtank",
            "detection list",
            "ip address",
            "blacklist",
            "paypal",
            "cisco umbrella",
            "site",
            "alexa top",
            "safe site",
            "million",
            "malicious url",
            "malware site",
            "malicious site",
            "malware",
            "name verdict",
            "falcon sandbox",
            "reports no",
            "speci",
            "efr1",
            "pattern match",
            "file",
            "web open",
            "font format",
            "truetype",
            "indicator",
            "windows nt",
            "et tor",
            "known tor",
            "relayrouter",
            "date",
            "unknown",
            "general",
            "hybrid",
            "local",
            "stream",
            "click",
            "strings",
            "class",
            "generator",
            "critical",
            "error",
            "self",
            "http response",
            "final url",
            "serving ip",
            "address",
            "status code",
            "body length",
            "kb body",
            "sha256",
            "phishing site",
            "heur",
            "cyber threat",
            "unsafe",
            "riskware",
            "phishing",
            "bank",
            "service",
            "artemis",
            "team",
            "xtrat",
            "agent",
            "xrat",
            "filetour",
            "exploit",
            "conduit",
            "opencandy",
            "fusioncore",
            "orkut",
            "steam",
            "genkryptik",
            "runescape",
            "presenoker",
            "ramnit",
            "msil",
            "crack",
            "tofsee",
            "suppobox",
            "malicious",
            "simda",
            "vawtrak",
            "hotmail",
            "generic",
            "webtoolbar",
            "hsbc",
            "maltiverse",
            "ip summary",
            "url summary",
            "summary",
            "sample",
            "samples",
            "count blacklist",
            "tag count",
            "downldr",
            "cleaner",
            "iframe",
            "wacatac",
            "alexa",
            "win64",
            "swrort",
            "installcore",
            "azorult",
            "download",
            "blacknet rat",
            "stealer",
            "softcnapp",
            "nircmd",
            "unruy",
            "patcher",
            "adload",
            "dropper",
            "installpack",
            "tiggre",
            "gamehack",
            "trojanspy",
            "germany http",
            "attacker",
            "static engine",
            "internet storm",
            "center",
            "passive dns",
            "urls",
            "scan endpoints",
            "all search",
            "otx scoreblue",
            "url http",
            "pulse pulses",
            "http",
            "related nids"
          ],
          "references": [
            "https://search.app.goo.gl/?ofl=https://lens.google&al=googleapp://lens?lens_data=KAw&apn=com.google.android.googlequicksearchbox&amv=301204913&isi=284815942&ius=googleapp&ibi=com.goog",
            "object.prototype.hasownproperty.call",
            "hasownproperty.call",
            "a.default.meta.applestore.id",
            "applestore.id",
            "http://decafsmob.this.id",
            "id.google.com",
            "http://critical-system-failure7250.21ny35098453.com-bm3y-v806d9gk.cricket/",
            "http://git.io/yBU2rg",
            "critical-failure-alert2286.40ek97931491.com-4nj1ze3ivfwy.website",
            "https://fairspin.io/?track_id=44698569&pid=1&geo=6252001&utm_source=bonafides&utm_medium=&utm_campaign=smarttds&utm_term=incorrect_param",
            "http://tracking.3061331.corn10wuk.club",
            "http://information.7174932.cakcuk.az/tracking/tracking.php?id=8459701&page=904",
            "apps.apple.com/us/app/id$",
            "t.name",
            "http://e.id?e.id:e.id.getAttribute",
            "location.search",
            "https://dnsorangetel.dn2.n-helix.com",
            "1080p-torrent.ml",
            "states.app",
            "dev-2.ernestatech.com",
            "https://hybrid-analysis.com/sample/d26000dfe1137f05f9187996dc752a703000402fe9e35a8ea216e9215a34560d",
            "209.85.145.113 [malware]",
            "cdn.fuckporntube.com",
            "www.search.app.goo.gl",
            "apps.apple.com",
            "http://www.youtube.com/gen_204?cplatform=tablet&c=android&cver=5.6.36&cos=Android&cosver=4.4.2&cbr=com.google.android.youtube&cbrv",
            "https://coloradosprings.americanlisted.com/pets-animals/beautiful-ragdoll-kittens_31591993.html",
            "globalworker1.sol.us",
            "worker-m-tlcus1.sol.us"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America",
            "Germany",
            "Ireland",
            "Singapore"
          ],
          "malware_families": [
            {
              "id": "WebToolbar",
              "display_name": "WebToolbar",
              "target": null
            },
            {
              "id": "HSBC",
              "display_name": "HSBC",
              "target": null
            },
            {
              "id": "Maltiverse",
              "display_name": "Maltiverse",
              "target": null
            },
            {
              "id": "GameHack",
              "display_name": "GameHack",
              "target": null
            },
            {
              "id": "TrojanSpy",
              "display_name": "TrojanSpy",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1041",
              "name": "Exfiltration Over C2 Channel",
              "display_name": "T1041 - Exfiltration Over C2 Channel"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1114",
              "name": "Email Collection",
              "display_name": "T1114 - Email Collection"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1059.007",
              "name": "JavaScript",
              "display_name": "T1059.007 - JavaScript"
            },
            {
              "id": "TA0004",
              "name": "Privilege Escalation",
              "display_name": "TA0004 - Privilege Escalation"
            },
            {
              "id": "T1210",
              "name": "Exploitation of Remote Services",
              "display_name": "T1210 - Exploitation of Remote Services"
            },
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1071.004",
              "name": "DNS",
              "display_name": "T1071.004 - DNS"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1496",
              "name": "Resource Hijacking",
              "display_name": "T1496 - Resource Hijacking"
            },
            {
              "id": "T1176",
              "name": "Browser Extensions",
              "display_name": "T1176 - Browser Extensions"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 33,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 1015,
            "hostname": 1309,
            "FileHash-MD5": 466,
            "FileHash-SHA1": 255,
            "FileHash-SHA256": 3783,
            "URL": 4001,
            "CVE": 9,
            "email": 3
          },
          "indicator_count": 10841,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 229,
          "modified_text": "867 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6546cf78627adef6562a97aa",
          "name": "Browser Malware Attack",
          "description": "Attacking my browser to identify.\nCommand for critical failure/destruction:    https://search.app.goo.gl/?ofl=https://lens.google&al=googleapp://lens?lens_data=KAw&apn=com.google.android.googlequicksearchbox&amv=301204913&isi=284815942&ius=googleapp&ibi=com.goog",
          "modified": "2023-12-04T22:00:43.514000",
          "created": "2023-11-04T23:10:48.676000",
          "tags": [
            "united",
            "facebook",
            "phishtank",
            "detection list",
            "ip address",
            "blacklist",
            "paypal",
            "cisco umbrella",
            "site",
            "alexa top",
            "safe site",
            "million",
            "malicious url",
            "malware site",
            "malicious site",
            "malware",
            "name verdict",
            "falcon sandbox",
            "reports no",
            "speci",
            "efr1",
            "pattern match",
            "file",
            "web open",
            "font format",
            "truetype",
            "indicator",
            "windows nt",
            "et tor",
            "known tor",
            "relayrouter",
            "date",
            "unknown",
            "general",
            "hybrid",
            "local",
            "stream",
            "click",
            "strings",
            "class",
            "generator",
            "critical",
            "error",
            "self",
            "http response",
            "final url",
            "serving ip",
            "address",
            "status code",
            "body length",
            "kb body",
            "sha256",
            "phishing site",
            "heur",
            "cyber threat",
            "unsafe",
            "riskware",
            "phishing",
            "bank",
            "service",
            "artemis",
            "team",
            "xtrat",
            "agent",
            "xrat",
            "filetour",
            "exploit",
            "conduit",
            "opencandy",
            "fusioncore",
            "orkut",
            "steam",
            "genkryptik",
            "runescape",
            "presenoker",
            "ramnit",
            "msil",
            "crack",
            "tofsee",
            "suppobox",
            "malicious",
            "simda",
            "vawtrak",
            "hotmail",
            "generic",
            "webtoolbar",
            "hsbc",
            "maltiverse",
            "ip summary",
            "url summary",
            "summary",
            "sample",
            "samples",
            "count blacklist",
            "tag count",
            "downldr",
            "cleaner",
            "iframe",
            "wacatac",
            "alexa",
            "win64",
            "swrort",
            "installcore",
            "azorult",
            "download",
            "blacknet rat",
            "stealer",
            "softcnapp",
            "nircmd",
            "unruy",
            "patcher",
            "adload",
            "dropper",
            "installpack",
            "tiggre",
            "gamehack",
            "trojanspy",
            "germany http",
            "attacker",
            "static engine",
            "internet storm",
            "center",
            "passive dns",
            "urls",
            "scan endpoints",
            "all search",
            "otx scoreblue",
            "url http",
            "pulse pulses",
            "http",
            "related nids"
          ],
          "references": [
            "https://search.app.goo.gl/?ofl=https://lens.google&al=googleapp://lens?lens_data=KAw&apn=com.google.android.googlequicksearchbox&amv=301204913&isi=284815942&ius=googleapp&ibi=com.goog",
            "object.prototype.hasownproperty.call",
            "hasownproperty.call",
            "a.default.meta.applestore.id",
            "applestore.id",
            "http://decafsmob.this.id",
            "id.google.com",
            "http://critical-system-failure7250.21ny35098453.com-bm3y-v806d9gk.cricket/",
            "http://git.io/yBU2rg",
            "critical-failure-alert2286.40ek97931491.com-4nj1ze3ivfwy.website",
            "https://fairspin.io/?track_id=44698569&pid=1&geo=6252001&utm_source=bonafides&utm_medium=&utm_campaign=smarttds&utm_term=incorrect_param",
            "http://tracking.3061331.corn10wuk.club",
            "http://information.7174932.cakcuk.az/tracking/tracking.php?id=8459701&page=904",
            "apps.apple.com/us/app/id$",
            "t.name",
            "http://e.id?e.id:e.id.getAttribute",
            "location.search",
            "https://dnsorangetel.dn2.n-helix.com",
            "1080p-torrent.ml",
            "states.app",
            "dev-2.ernestatech.com",
            "https://hybrid-analysis.com/sample/d26000dfe1137f05f9187996dc752a703000402fe9e35a8ea216e9215a34560d",
            "209.85.145.113 [malware]",
            "cdn.fuckporntube.com",
            "www.search.app.goo.gl",
            "apps.apple.com",
            "http://www.youtube.com/gen_204?cplatform=tablet&c=android&cver=5.6.36&cos=Android&cosver=4.4.2&cbr=com.google.android.youtube&cbrv",
            "https://coloradosprings.americanlisted.com/pets-animals/beautiful-ragdoll-kittens_31591993.html",
            "globalworker1.sol.us",
            "worker-m-tlcus1.sol.us"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America",
            "Germany",
            "Ireland",
            "Singapore"
          ],
          "malware_families": [
            {
              "id": "WebToolbar",
              "display_name": "WebToolbar",
              "target": null
            },
            {
              "id": "HSBC",
              "display_name": "HSBC",
              "target": null
            },
            {
              "id": "Maltiverse",
              "display_name": "Maltiverse",
              "target": null
            },
            {
              "id": "GameHack",
              "display_name": "GameHack",
              "target": null
            },
            {
              "id": "TrojanSpy",
              "display_name": "TrojanSpy",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1041",
              "name": "Exfiltration Over C2 Channel",
              "display_name": "T1041 - Exfiltration Over C2 Channel"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1114",
              "name": "Email Collection",
              "display_name": "T1114 - Email Collection"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1059.007",
              "name": "JavaScript",
              "display_name": "T1059.007 - JavaScript"
            },
            {
              "id": "TA0004",
              "name": "Privilege Escalation",
              "display_name": "TA0004 - Privilege Escalation"
            },
            {
              "id": "T1210",
              "name": "Exploitation of Remote Services",
              "display_name": "T1210 - Exploitation of Remote Services"
            },
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1071.004",
              "name": "DNS",
              "display_name": "T1071.004 - DNS"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1496",
              "name": "Resource Hijacking",
              "display_name": "T1496 - Resource Hijacking"
            },
            {
              "id": "T1176",
              "name": "Browser Extensions",
              "display_name": "T1176 - Browser Extensions"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 25,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 1015,
            "hostname": 1309,
            "FileHash-MD5": 466,
            "FileHash-SHA1": 255,
            "FileHash-SHA256": 3783,
            "URL": 4001,
            "CVE": 9,
            "email": 3
          },
          "indicator_count": 10841,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 225,
          "modified_text": "867 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6546d206936ee17a0828d9c9",
          "name": "Deptlock Browser Compromise attack initiated by malicious (SOC) Partner ",
          "description": "",
          "modified": "2023-12-03T06:04:06.473000",
          "created": "2023-11-04T23:21:42.110000",
          "tags": [
            "cisco umbrella",
            "site",
            "alexa top",
            "emotet",
            "telefonica co",
            "million",
            "malware",
            "detection list",
            "blacklist",
            "alexa",
            "installcore",
            "heur",
            "cyber threat",
            "united",
            "phishing",
            "engineering",
            "phishing site",
            "team phishing",
            "spammer",
            "malicious site",
            "team",
            "download",
            "cobalt strike",
            "facebook",
            "artemis",
            "pony",
            "binder",
            "suppobox",
            "virut",
            "ramnit",
            "dropper",
            "formbook",
            "azorult",
            "simda",
            "downloader",
            "service",
            "bank",
            "zbot",
            "trojanspy",
            "heodo",
            "hostname",
            "hostnames",
            "whois record",
            "kgs0",
            "kls0",
            "apple ios",
            "tsara brashears",
            "ssl certificate",
            "elf collection",
            "cyberstalking",
            "spyware",
            "hackers",
            "installer",
            "open",
            "banker",
            "keylogger",
            "malicious",
            "hacktool",
            "core",
            "noname057",
            "generic malware",
            "safe site",
            "malware site",
            "iframe",
            "riskware",
            "exploit",
            "fakealert",
            "unsafe",
            "acint",
            "win64",
            "nircmd",
            "agent",
            "opencandy",
            "conduit",
            "swrort",
            "crack",
            "installpack",
            "xtrat",
            "psexec",
            "occamy",
            "brontok",
            "zpevdo",
            "startpage",
            "nanocore",
            "keygen",
            "fareit",
            "secrisk",
            "unruy",
            "filetour",
            "floxif",
            "cleaner",
            "patcher",
            "adload",
            "presenoker",
            "wacatac",
            "fusioncore",
            "genkryptik",
            "webtoolbar",
            "maltiverse",
            "smokeloader",
            "download json",
            "urls",
            "blacklist http",
            "kyriazhs1975",
            "vidar",
            "strike",
            "china cobalt",
            "meterpreter",
            "nanocore rat",
            "njrat",
            "redline stealer",
            "stealer",
            "nymaim",
            "mirai",
            "ghost rat",
            "runescape",
            "bradesco",
            "msil",
            "bladabindi",
            "orkut",
            "cutwail",
            "bandoo",
            "matsnu",
            "inmortal",
            "domains",
            "redline",
            "control server",
            "services",
            "generic",
            "br",
            "threat report",
            "ip summary",
            "url summary",
            "summary",
            "sample",
            "samples",
            "squirrelwaffle",
            "soc http",
            "soc https",
            "back",
            "download csv",
            "json sample",
            "injector",
            "malicious url",
            "downldr",
            "covid19 scam",
            "historical ssl",
            "referrer",
            "contacted",
            "whois whois",
            "contacted urls",
            "whois sslcert",
            "threat roundup",
            "copy",
            "august",
            "execution",
            "ransomware",
            "gopher",
            "remcos",
            "attack",
            "radar ineractive",
            "paypal",
            "covid19",
            "phishing chase",
            "phishing google",
            "tracker malware",
            "chase personal",
            "banking",
            "javascript",
            "please",
            "cnc server",
            "tracker",
            "cnc feodo",
            "phishtank",
            "threats et",
            "name verdict",
            "falcon sandbox",
            "pattern match",
            "file",
            "ascii text",
            "indicator",
            "windows nt",
            "jpeg image",
            "appdata",
            "jfif standard",
            "script",
            "show",
            "date",
            "span",
            "unknown",
            "general",
            "hybrid",
            "local",
            "click",
            "strings",
            "class",
            "generator",
            "critical",
            "error",
            "path",
            "http header",
            "tcp traffic",
            "mitre att",
            "ck id",
            "show technique",
            "ck matrix",
            "accept",
            "adware",
            "ip address",
            "hsbc",
            "outbreak",
            "downer",
            "shell",
            "mediamagnet",
            "sality",
            "adaptivebee",
            "iobit",
            "trojanx",
            "webshell",
            "systweak",
            "behav",
            "tiggre",
            "runtime process",
            "sha256",
            "sha1",
            "mark brian sabey",
            "brian sabey",
            "sabey",
            "apple",
            "114.114.114.114",
            "attorney",
            "law",
            "spammer",
            "fraud service",
            "hallrender",
            "malvertizing",
            "cybercrime",
            "social engineering",
            "malware hosting",
            "cyber threat",
            "iphone unlocker",
            "malicious",
            "attacker",
            "tulach",
            "tulach.cc",
            "adult content",
            "child pornographer",
            "sabey data centers",
            "hall render denver",
            "monitoring",
            "stalker",
            "dev",
            "developer",
            "cyber harassment",
            "defacement",
            "death threats",
            "miner",
            "agenttesla",
            "trojan",
            "detplock",
            "networm",
            "rms",
            "sneaky server",
            "replacement",
            "unauthorized",
            "steam route",
            "tool",
            "probe",
            "safebae.org",
            "safebae",
            "daisy",
            "daisy coleman",
            "benjamin",
            "colorado",
            "missouri",
            "telefonica",
            "boost mobile",
            "blackievirus.com",
            "TrojanX",
            "metro t-mobile",
            "t-mobile",
            "mile high media",
            "CNC",
            "C2",
            "malware host",
            "yixun"
          ],
          "references": [
            "https://hybrid-analysis.com/sample/a1b9247b6ad18f1cda0304e406333459d4000fced5753f91e5c046f6577c388a",
            "https://www.hallrender.com/attorney/brian-sabey",
            "safebae.org",
            "poemhunter.com",
            "http://www.hallrender.com/resources/blog/",
            "http://benjamin.xww.de/",
            "http://alohatube.xyz/search/tsara-brashears",
            "https://www.anyxxxtube.net/search-porn/tsara-brashears/",
            "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian",
            "Hybrid Analysis",
            "wTools",
            "Research"
          ],
          "public": 1,
          "adversary": "Tulach | Mark Brian Sabey | Hall Render Law Firm",
          "targeted_countries": [
            "United States of America",
            "Japan"
          ],
          "malware_families": [
            {
              "id": "TrojanSpy",
              "display_name": "TrojanSpy",
              "target": null
            },
            {
              "id": "WebToolbar",
              "display_name": "WebToolbar",
              "target": null
            },
            {
              "id": "Maltiverse",
              "display_name": "Maltiverse",
              "target": null
            },
            {
              "id": "Inmortal",
              "display_name": "Inmortal",
              "target": null
            },
            {
              "id": "Domains",
              "display_name": "Domains",
              "target": null
            },
            {
              "id": "RedLine",
              "display_name": "RedLine",
              "target": null
            },
            {
              "id": "BR",
              "display_name": "BR",
              "target": null
            },
            {
              "id": "Radar Ineractive",
              "display_name": "Radar Ineractive",
              "target": null
            },
            {
              "id": "HSBC",
              "display_name": "HSBC",
              "target": null
            },
            {
              "id": "RMS",
              "display_name": "RMS",
              "target": null
            },
            {
              "id": "Feodo Tracker",
              "display_name": "Feodo Tracker",
              "target": null
            },
            {
              "id": "Wacatac",
              "display_name": "Wacatac",
              "target": null
            },
            {
              "id": "Zpevdo",
              "display_name": "Zpevdo",
              "target": null
            },
            {
              "id": "Zbot",
              "display_name": "Zbot",
              "target": null
            },
            {
              "id": "OpenCandy",
              "display_name": "OpenCandy",
              "target": null
            },
            {
              "id": "xRAT",
              "display_name": "xRAT",
              "target": null
            },
            {
              "id": "Vidar",
              "display_name": "Vidar",
              "target": null
            },
            {
              "id": "Agent Tesla",
              "display_name": "Agent Tesla",
              "target": null
            },
            {
              "id": "noname057",
              "display_name": "noname057",
              "target": null
            },
            {
              "id": "TrojanSpy",
              "display_name": "TrojanSpy",
              "target": null
            },
            {
              "id": "DarkSide .Beware",
              "display_name": "DarkSide .Beware",
              "target": null
            },
            {
              "id": "Nymaim",
              "display_name": "Nymaim",
              "target": null
            },
            {
              "id": "SLFPER:BrowserModifier:Win32/MediaMagnet",
              "display_name": "SLFPER:BrowserModifier:Win32/MediaMagnet",
              "target": null
            },
            {
              "id": "Virut",
              "display_name": "Virut",
              "target": null
            },
            {
              "id": "Cutwail",
              "display_name": "Cutwail",
              "target": null
            },
            {
              "id": "Nanocore RAT",
              "display_name": "Nanocore RAT",
              "target": null
            },
            {
              "id": "Tulach Malware",
              "display_name": "Tulach Malware",
              "target": null
            },
            {
              "id": "SuppoBox",
              "display_name": "SuppoBox",
              "target": null
            },
            {
              "id": "Systweak",
              "display_name": "Systweak",
              "target": null
            },
            {
              "id": "Occamy",
              "display_name": "Occamy",
              "target": null
            },
            {
              "id": "Tiggre",
              "display_name": "Tiggre",
              "target": null
            },
            {
              "id": "IObit",
              "display_name": "IObit",
              "target": null
            },
            {
              "id": "Sality",
              "display_name": "Sality",
              "target": null
            },
            {
              "id": "FORMBOOK",
              "display_name": "FORMBOOK",
              "target": null
            },
            {
              "id": "Emotet",
              "display_name": "Emotet",
              "target": null
            },
            {
              "id": "Yixun",
              "display_name": "Yixun",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1496",
              "name": "Resource Hijacking",
              "display_name": "T1496 - Resource Hijacking"
            },
            {
              "id": "T1176",
              "name": "Browser Extensions",
              "display_name": "T1176 - Browser Extensions"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1041",
              "name": "Exfiltration Over C2 Channel",
              "display_name": "T1041 - Exfiltration Over C2 Channel"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1114",
              "name": "Email Collection",
              "display_name": "T1114 - Email Collection"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1012",
              "name": "Query Registry",
              "display_name": "T1012 - Query Registry"
            },
            {
              "id": "T1043",
              "name": "Commonly Used Port",
              "display_name": "T1043 - Commonly Used Port"
            },
            {
              "id": "T1112",
              "name": "Modify Registry",
              "display_name": "T1112 - Modify Registry"
            },
            {
              "id": "T1179",
              "name": "Hooking",
              "display_name": "T1179 - Hooking"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1583.005",
              "name": "Botnet",
              "display_name": "T1583.005 - Botnet"
            },
            {
              "id": "T1449",
              "name": "Exploit SS7 to Redirect Phone Calls/SMS",
              "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
            },
            {
              "id": "T1071.004",
              "name": "DNS",
              "display_name": "T1071.004 - DNS"
            },
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1068",
              "name": "Exploitation for Privilege Escalation",
              "display_name": "T1068 - Exploitation for Privilege Escalation"
            },
            {
              "id": "T1056.001",
              "name": "Keylogging",
              "display_name": "T1056.001 - Keylogging"
            }
          ],
          "industries": [
            "Health"
          ],
          "TLP": "green",
          "cloned_from": "6544c7a11d7541bdb3bfe5ff",
          "export_count": 60,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 1643,
            "hostname": 1438,
            "CVE": 30,
            "FileHash-MD5": 2853,
            "FileHash-SHA1": 1584,
            "FileHash-SHA256": 3001,
            "URL": 2904,
            "email": 1
          },
          "indicator_count": 13454,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 225,
          "modified_text": "868 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "656a94d1bdedd646afda170d",
          "name": "Resources Hijacking by Attorney 11_03_2023",
          "description": "",
          "modified": "2023-12-03T06:04:06.473000",
          "created": "2023-12-02T02:22:09.814000",
          "tags": [
            "cisco umbrella",
            "site",
            "alexa top",
            "emotet",
            "telefonica co",
            "million",
            "malware",
            "detection list",
            "blacklist",
            "alexa",
            "installcore",
            "heur",
            "cyber threat",
            "united",
            "phishing",
            "engineering",
            "phishing site",
            "team phishing",
            "spammer",
            "malicious site",
            "team",
            "download",
            "cobalt strike",
            "facebook",
            "artemis",
            "pony",
            "binder",
            "suppobox",
            "virut",
            "ramnit",
            "dropper",
            "formbook",
            "azorult",
            "simda",
            "downloader",
            "service",
            "bank",
            "zbot",
            "trojanspy",
            "heodo",
            "hostname",
            "hostnames",
            "whois record",
            "kgs0",
            "kls0",
            "apple ios",
            "tsara brashears",
            "ssl certificate",
            "elf collection",
            "cyberstalking",
            "spyware",
            "hackers",
            "installer",
            "open",
            "banker",
            "keylogger",
            "malicious",
            "hacktool",
            "core",
            "noname057",
            "generic malware",
            "safe site",
            "malware site",
            "iframe",
            "riskware",
            "exploit",
            "fakealert",
            "unsafe",
            "acint",
            "win64",
            "nircmd",
            "agent",
            "opencandy",
            "conduit",
            "swrort",
            "crack",
            "installpack",
            "xtrat",
            "psexec",
            "occamy",
            "brontok",
            "zpevdo",
            "startpage",
            "nanocore",
            "keygen",
            "fareit",
            "secrisk",
            "unruy",
            "filetour",
            "floxif",
            "cleaner",
            "patcher",
            "adload",
            "presenoker",
            "wacatac",
            "fusioncore",
            "genkryptik",
            "webtoolbar",
            "maltiverse",
            "smokeloader",
            "download json",
            "urls",
            "blacklist http",
            "kyriazhs1975",
            "vidar",
            "strike",
            "china cobalt",
            "meterpreter",
            "nanocore rat",
            "njrat",
            "redline stealer",
            "stealer",
            "nymaim",
            "mirai",
            "ghost rat",
            "runescape",
            "bradesco",
            "msil",
            "bladabindi",
            "orkut",
            "cutwail",
            "bandoo",
            "matsnu",
            "inmortal",
            "domains",
            "redline",
            "control server",
            "services",
            "generic",
            "br",
            "threat report",
            "ip summary",
            "url summary",
            "summary",
            "sample",
            "samples",
            "squirrelwaffle",
            "soc http",
            "soc https",
            "back",
            "download csv",
            "json sample",
            "injector",
            "malicious url",
            "downldr",
            "covid19 scam",
            "historical ssl",
            "referrer",
            "contacted",
            "whois whois",
            "contacted urls",
            "whois sslcert",
            "threat roundup",
            "copy",
            "august",
            "execution",
            "ransomware",
            "gopher",
            "remcos",
            "attack",
            "radar ineractive",
            "paypal",
            "covid19",
            "phishing chase",
            "phishing google",
            "tracker malware",
            "chase personal",
            "banking",
            "javascript",
            "please",
            "cnc server",
            "tracker",
            "cnc feodo",
            "phishtank",
            "threats et",
            "name verdict",
            "falcon sandbox",
            "pattern match",
            "file",
            "ascii text",
            "indicator",
            "windows nt",
            "jpeg image",
            "appdata",
            "jfif standard",
            "script",
            "show",
            "date",
            "span",
            "unknown",
            "general",
            "hybrid",
            "local",
            "click",
            "strings",
            "class",
            "generator",
            "critical",
            "error",
            "path",
            "http header",
            "tcp traffic",
            "mitre att",
            "ck id",
            "show technique",
            "ck matrix",
            "accept",
            "adware",
            "ip address",
            "hsbc",
            "outbreak",
            "downer",
            "shell",
            "mediamagnet",
            "sality",
            "adaptivebee",
            "iobit",
            "trojanx",
            "webshell",
            "systweak",
            "behav",
            "tiggre",
            "runtime process",
            "sha256",
            "sha1",
            "mark brian sabey",
            "brian sabey",
            "sabey",
            "apple",
            "114.114.114.114",
            "attorney",
            "law",
            "spammer",
            "fraud service",
            "hallrender",
            "malvertizing",
            "cybercrime",
            "social engineering",
            "malware hosting",
            "cyber threat",
            "iphone unlocker",
            "malicious",
            "attacker",
            "tulach",
            "tulach.cc",
            "adult content",
            "child pornographer",
            "sabey data centers",
            "hall render denver",
            "monitoring",
            "stalker",
            "dev",
            "developer",
            "cyber harassment",
            "defacement",
            "death threats",
            "miner",
            "agenttesla",
            "trojan",
            "detplock",
            "networm",
            "rms",
            "sneaky server",
            "replacement",
            "unauthorized",
            "steam route",
            "tool",
            "probe",
            "safebae.org",
            "safebae",
            "daisy",
            "daisy coleman",
            "benjamin",
            "colorado",
            "missouri",
            "telefonica",
            "boost mobile",
            "blackievirus.com",
            "TrojanX",
            "metro t-mobile",
            "t-mobile",
            "mile high media",
            "CNC",
            "C2",
            "malware host",
            "yixun"
          ],
          "references": [
            "https://hybrid-analysis.com/sample/a1b9247b6ad18f1cda0304e406333459d4000fced5753f91e5c046f6577c388a",
            "https://www.hallrender.com/attorney/brian-sabey",
            "safebae.org",
            "poemhunter.com",
            "http://www.hallrender.com/resources/blog/",
            "http://benjamin.xww.de/",
            "http://alohatube.xyz/search/tsara-brashears",
            "https://www.anyxxxtube.net/search-porn/tsara-brashears/",
            "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian",
            "Hybrid Analysis",
            "wTools",
            "Research"
          ],
          "public": 1,
          "adversary": "Tulach | Mark Brian Sabey | Hall Render Law Firm",
          "targeted_countries": [
            "United States of America",
            "Japan"
          ],
          "malware_families": [
            {
              "id": "TrojanSpy",
              "display_name": "TrojanSpy",
              "target": null
            },
            {
              "id": "WebToolbar",
              "display_name": "WebToolbar",
              "target": null
            },
            {
              "id": "Maltiverse",
              "display_name": "Maltiverse",
              "target": null
            },
            {
              "id": "Inmortal",
              "display_name": "Inmortal",
              "target": null
            },
            {
              "id": "Domains",
              "display_name": "Domains",
              "target": null
            },
            {
              "id": "RedLine",
              "display_name": "RedLine",
              "target": null
            },
            {
              "id": "BR",
              "display_name": "BR",
              "target": null
            },
            {
              "id": "Radar Ineractive",
              "display_name": "Radar Ineractive",
              "target": null
            },
            {
              "id": "HSBC",
              "display_name": "HSBC",
              "target": null
            },
            {
              "id": "RMS",
              "display_name": "RMS",
              "target": null
            },
            {
              "id": "Feodo Tracker",
              "display_name": "Feodo Tracker",
              "target": null
            },
            {
              "id": "Wacatac",
              "display_name": "Wacatac",
              "target": null
            },
            {
              "id": "Zpevdo",
              "display_name": "Zpevdo",
              "target": null
            },
            {
              "id": "Zbot",
              "display_name": "Zbot",
              "target": null
            },
            {
              "id": "OpenCandy",
              "display_name": "OpenCandy",
              "target": null
            },
            {
              "id": "xRAT",
              "display_name": "xRAT",
              "target": null
            },
            {
              "id": "Vidar",
              "display_name": "Vidar",
              "target": null
            },
            {
              "id": "Agent Tesla",
              "display_name": "Agent Tesla",
              "target": null
            },
            {
              "id": "noname057",
              "display_name": "noname057",
              "target": null
            },
            {
              "id": "TrojanSpy",
              "display_name": "TrojanSpy",
              "target": null
            },
            {
              "id": "DarkSide .Beware",
              "display_name": "DarkSide .Beware",
              "target": null
            },
            {
              "id": "Nymaim",
              "display_name": "Nymaim",
              "target": null
            },
            {
              "id": "SLFPER:BrowserModifier:Win32/MediaMagnet",
              "display_name": "SLFPER:BrowserModifier:Win32/MediaMagnet",
              "target": null
            },
            {
              "id": "Virut",
              "display_name": "Virut",
              "target": null
            },
            {
              "id": "Cutwail",
              "display_name": "Cutwail",
              "target": null
            },
            {
              "id": "Nanocore RAT",
              "display_name": "Nanocore RAT",
              "target": null
            },
            {
              "id": "Tulach Malware",
              "display_name": "Tulach Malware",
              "target": null
            },
            {
              "id": "SuppoBox",
              "display_name": "SuppoBox",
              "target": null
            },
            {
              "id": "Systweak",
              "display_name": "Systweak",
              "target": null
            },
            {
              "id": "Occamy",
              "display_name": "Occamy",
              "target": null
            },
            {
              "id": "Tiggre",
              "display_name": "Tiggre",
              "target": null
            },
            {
              "id": "IObit",
              "display_name": "IObit",
              "target": null
            },
            {
              "id": "Sality",
              "display_name": "Sality",
              "target": null
            },
            {
              "id": "FORMBOOK",
              "display_name": "FORMBOOK",
              "target": null
            },
            {
              "id": "Emotet",
              "display_name": "Emotet",
              "target": null
            },
            {
              "id": "Yixun",
              "display_name": "Yixun",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1496",
              "name": "Resource Hijacking",
              "display_name": "T1496 - Resource Hijacking"
            },
            {
              "id": "T1176",
              "name": "Browser Extensions",
              "display_name": "T1176 - Browser Extensions"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1041",
              "name": "Exfiltration Over C2 Channel",
              "display_name": "T1041 - Exfiltration Over C2 Channel"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1114",
              "name": "Email Collection",
              "display_name": "T1114 - Email Collection"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1012",
              "name": "Query Registry",
              "display_name": "T1012 - Query Registry"
            },
            {
              "id": "T1043",
              "name": "Commonly Used Port",
              "display_name": "T1043 - Commonly Used Port"
            },
            {
              "id": "T1112",
              "name": "Modify Registry",
              "display_name": "T1112 - Modify Registry"
            },
            {
              "id": "T1179",
              "name": "Hooking",
              "display_name": "T1179 - Hooking"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1583.005",
              "name": "Botnet",
              "display_name": "T1583.005 - Botnet"
            },
            {
              "id": "T1449",
              "name": "Exploit SS7 to Redirect Phone Calls/SMS",
              "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
            },
            {
              "id": "T1071.004",
              "name": "DNS",
              "display_name": "T1071.004 - DNS"
            },
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1068",
              "name": "Exploitation for Privilege Escalation",
              "display_name": "T1068 - Exploitation for Privilege Escalation"
            },
            {
              "id": "T1056.001",
              "name": "Keylogging",
              "display_name": "T1056.001 - Keylogging"
            }
          ],
          "industries": [
            "Health"
          ],
          "TLP": "green",
          "cloned_from": "6544d9b0f9b23205eb355210",
          "export_count": 34,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 1643,
            "hostname": 1438,
            "CVE": 30,
            "FileHash-MD5": 2853,
            "FileHash-SHA1": 1584,
            "FileHash-SHA256": 3001,
            "URL": 2904,
            "email": 1
          },
          "indicator_count": 13454,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 224,
          "modified_text": "868 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6545bda27bd3a147ebac71a8",
          "name": "CNC Feodo Tracker | Resources Hijacking by Attorney ",
          "description": "",
          "modified": "2023-12-03T06:04:06.473000",
          "created": "2023-11-04T03:42:26.978000",
          "tags": [
            "cisco umbrella",
            "site",
            "alexa top",
            "emotet",
            "telefonica co",
            "million",
            "malware",
            "detection list",
            "blacklist",
            "alexa",
            "installcore",
            "heur",
            "cyber threat",
            "united",
            "phishing",
            "engineering",
            "phishing site",
            "team phishing",
            "spammer",
            "malicious site",
            "team",
            "download",
            "cobalt strike",
            "facebook",
            "artemis",
            "pony",
            "binder",
            "suppobox",
            "virut",
            "ramnit",
            "dropper",
            "formbook",
            "azorult",
            "simda",
            "downloader",
            "service",
            "bank",
            "zbot",
            "trojanspy",
            "heodo",
            "hostname",
            "hostnames",
            "whois record",
            "kgs0",
            "kls0",
            "apple ios",
            "tsara brashears",
            "ssl certificate",
            "elf collection",
            "cyberstalking",
            "spyware",
            "hackers",
            "installer",
            "open",
            "banker",
            "keylogger",
            "malicious",
            "hacktool",
            "core",
            "noname057",
            "generic malware",
            "safe site",
            "malware site",
            "iframe",
            "riskware",
            "exploit",
            "fakealert",
            "unsafe",
            "acint",
            "win64",
            "nircmd",
            "agent",
            "opencandy",
            "conduit",
            "swrort",
            "crack",
            "installpack",
            "xtrat",
            "psexec",
            "occamy",
            "brontok",
            "zpevdo",
            "startpage",
            "nanocore",
            "keygen",
            "fareit",
            "secrisk",
            "unruy",
            "filetour",
            "floxif",
            "cleaner",
            "patcher",
            "adload",
            "presenoker",
            "wacatac",
            "fusioncore",
            "genkryptik",
            "webtoolbar",
            "maltiverse",
            "smokeloader",
            "download json",
            "urls",
            "blacklist http",
            "kyriazhs1975",
            "vidar",
            "strike",
            "china cobalt",
            "meterpreter",
            "nanocore rat",
            "njrat",
            "redline stealer",
            "stealer",
            "nymaim",
            "mirai",
            "ghost rat",
            "runescape",
            "bradesco",
            "msil",
            "bladabindi",
            "orkut",
            "cutwail",
            "bandoo",
            "matsnu",
            "inmortal",
            "domains",
            "redline",
            "control server",
            "services",
            "generic",
            "br",
            "threat report",
            "ip summary",
            "url summary",
            "summary",
            "sample",
            "samples",
            "squirrelwaffle",
            "soc http",
            "soc https",
            "back",
            "download csv",
            "json sample",
            "injector",
            "malicious url",
            "downldr",
            "covid19 scam",
            "historical ssl",
            "referrer",
            "contacted",
            "whois whois",
            "contacted urls",
            "whois sslcert",
            "threat roundup",
            "copy",
            "august",
            "execution",
            "ransomware",
            "gopher",
            "remcos",
            "attack",
            "radar ineractive",
            "paypal",
            "covid19",
            "phishing chase",
            "phishing google",
            "tracker malware",
            "chase personal",
            "banking",
            "javascript",
            "please",
            "cnc server",
            "tracker",
            "cnc feodo",
            "phishtank",
            "threats et",
            "name verdict",
            "falcon sandbox",
            "pattern match",
            "file",
            "ascii text",
            "indicator",
            "windows nt",
            "jpeg image",
            "appdata",
            "jfif standard",
            "script",
            "show",
            "date",
            "span",
            "unknown",
            "general",
            "hybrid",
            "local",
            "click",
            "strings",
            "class",
            "generator",
            "critical",
            "error",
            "path",
            "http header",
            "tcp traffic",
            "mitre att",
            "ck id",
            "show technique",
            "ck matrix",
            "accept",
            "adware",
            "ip address",
            "hsbc",
            "outbreak",
            "downer",
            "shell",
            "mediamagnet",
            "sality",
            "adaptivebee",
            "iobit",
            "trojanx",
            "webshell",
            "systweak",
            "behav",
            "tiggre",
            "runtime process",
            "sha256",
            "sha1",
            "mark brian sabey",
            "brian sabey",
            "sabey",
            "apple",
            "114.114.114.114",
            "attorney",
            "law",
            "spammer",
            "fraud service",
            "hallrender",
            "malvertizing",
            "cybercrime",
            "social engineering",
            "malware hosting",
            "cyber threat",
            "iphone unlocker",
            "malicious",
            "attacker",
            "tulach",
            "tulach.cc",
            "adult content",
            "child pornographer",
            "sabey data centers",
            "hall render denver",
            "monitoring",
            "stalker",
            "dev",
            "developer",
            "cyber harassment",
            "defacement",
            "death threats",
            "miner",
            "agenttesla",
            "trojan",
            "detplock",
            "networm",
            "rms",
            "sneaky server",
            "replacement",
            "unauthorized",
            "steam route",
            "tool",
            "probe",
            "safebae.org",
            "safebae",
            "daisy",
            "daisy coleman",
            "benjamin",
            "colorado",
            "missouri",
            "telefonica",
            "boost mobile",
            "blackievirus.com",
            "TrojanX",
            "metro t-mobile",
            "t-mobile",
            "mile high media",
            "CNC",
            "C2",
            "malware host",
            "yixun"
          ],
          "references": [
            "https://hybrid-analysis.com/sample/a1b9247b6ad18f1cda0304e406333459d4000fced5753f91e5c046f6577c388a",
            "https://www.hallrender.com/attorney/brian-sabey",
            "safebae.org",
            "poemhunter.com",
            "http://www.hallrender.com/resources/blog/",
            "http://benjamin.xww.de/",
            "http://alohatube.xyz/search/tsara-brashears",
            "https://www.anyxxxtube.net/search-porn/tsara-brashears/",
            "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian",
            "Hybrid Analysis",
            "wTools",
            "Research"
          ],
          "public": 1,
          "adversary": "Tulach | Mark Brian Sabey | Hall Render Law Firm",
          "targeted_countries": [
            "United States of America",
            "Japan"
          ],
          "malware_families": [
            {
              "id": "TrojanSpy",
              "display_name": "TrojanSpy",
              "target": null
            },
            {
              "id": "WebToolbar",
              "display_name": "WebToolbar",
              "target": null
            },
            {
              "id": "Maltiverse",
              "display_name": "Maltiverse",
              "target": null
            },
            {
              "id": "Inmortal",
              "display_name": "Inmortal",
              "target": null
            },
            {
              "id": "Domains",
              "display_name": "Domains",
              "target": null
            },
            {
              "id": "RedLine",
              "display_name": "RedLine",
              "target": null
            },
            {
              "id": "BR",
              "display_name": "BR",
              "target": null
            },
            {
              "id": "Radar Ineractive",
              "display_name": "Radar Ineractive",
              "target": null
            },
            {
              "id": "HSBC",
              "display_name": "HSBC",
              "target": null
            },
            {
              "id": "RMS",
              "display_name": "RMS",
              "target": null
            },
            {
              "id": "Feodo Tracker",
              "display_name": "Feodo Tracker",
              "target": null
            },
            {
              "id": "Wacatac",
              "display_name": "Wacatac",
              "target": null
            },
            {
              "id": "Zpevdo",
              "display_name": "Zpevdo",
              "target": null
            },
            {
              "id": "Zbot",
              "display_name": "Zbot",
              "target": null
            },
            {
              "id": "OpenCandy",
              "display_name": "OpenCandy",
              "target": null
            },
            {
              "id": "xRAT",
              "display_name": "xRAT",
              "target": null
            },
            {
              "id": "Vidar",
              "display_name": "Vidar",
              "target": null
            },
            {
              "id": "Agent Tesla",
              "display_name": "Agent Tesla",
              "target": null
            },
            {
              "id": "noname057",
              "display_name": "noname057",
              "target": null
            },
            {
              "id": "TrojanSpy",
              "display_name": "TrojanSpy",
              "target": null
            },
            {
              "id": "DarkSide .Beware",
              "display_name": "DarkSide .Beware",
              "target": null
            },
            {
              "id": "Nymaim",
              "display_name": "Nymaim",
              "target": null
            },
            {
              "id": "SLFPER:BrowserModifier:Win32/MediaMagnet",
              "display_name": "SLFPER:BrowserModifier:Win32/MediaMagnet",
              "target": null
            },
            {
              "id": "Virut",
              "display_name": "Virut",
              "target": null
            },
            {
              "id": "Cutwail",
              "display_name": "Cutwail",
              "target": null
            },
            {
              "id": "Nanocore RAT",
              "display_name": "Nanocore RAT",
              "target": null
            },
            {
              "id": "Tulach Malware",
              "display_name": "Tulach Malware",
              "target": null
            },
            {
              "id": "SuppoBox",
              "display_name": "SuppoBox",
              "target": null
            },
            {
              "id": "Systweak",
              "display_name": "Systweak",
              "target": null
            },
            {
              "id": "Occamy",
              "display_name": "Occamy",
              "target": null
            },
            {
              "id": "Tiggre",
              "display_name": "Tiggre",
              "target": null
            },
            {
              "id": "IObit",
              "display_name": "IObit",
              "target": null
            },
            {
              "id": "Sality",
              "display_name": "Sality",
              "target": null
            },
            {
              "id": "FORMBOOK",
              "display_name": "FORMBOOK",
              "target": null
            },
            {
              "id": "Emotet",
              "display_name": "Emotet",
              "target": null
            },
            {
              "id": "Yixun",
              "display_name": "Yixun",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1496",
              "name": "Resource Hijacking",
              "display_name": "T1496 - Resource Hijacking"
            },
            {
              "id": "T1176",
              "name": "Browser Extensions",
              "display_name": "T1176 - Browser Extensions"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1041",
              "name": "Exfiltration Over C2 Channel",
              "display_name": "T1041 - Exfiltration Over C2 Channel"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1114",
              "name": "Email Collection",
              "display_name": "T1114 - Email Collection"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1012",
              "name": "Query Registry",
              "display_name": "T1012 - Query Registry"
            },
            {
              "id": "T1043",
              "name": "Commonly Used Port",
              "display_name": "T1043 - Commonly Used Port"
            },
            {
              "id": "T1112",
              "name": "Modify Registry",
              "display_name": "T1112 - Modify Registry"
            },
            {
              "id": "T1179",
              "name": "Hooking",
              "display_name": "T1179 - Hooking"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1583.005",
              "name": "Botnet",
              "display_name": "T1583.005 - Botnet"
            },
            {
              "id": "T1449",
              "name": "Exploit SS7 to Redirect Phone Calls/SMS",
              "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
            },
            {
              "id": "T1071.004",
              "name": "DNS",
              "display_name": "T1071.004 - DNS"
            },
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1068",
              "name": "Exploitation for Privilege Escalation",
              "display_name": "T1068 - Exploitation for Privilege Escalation"
            },
            {
              "id": "T1056.001",
              "name": "Keylogging",
              "display_name": "T1056.001 - Keylogging"
            }
          ],
          "industries": [
            "Health"
          ],
          "TLP": "green",
          "cloned_from": "6544d9b0f9b23205eb355210",
          "export_count": 57,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 1,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 1643,
            "hostname": 1438,
            "CVE": 30,
            "FileHash-MD5": 2853,
            "FileHash-SHA1": 1584,
            "FileHash-SHA256": 3001,
            "URL": 2904,
            "email": 1
          },
          "indicator_count": 13454,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 224,
          "modified_text": "868 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6545a303731b2df439eb1a3b",
          "name": "Occamy Remote PC / Device Control",
          "description": "",
          "modified": "2023-12-03T06:04:06.473000",
          "created": "2023-11-04T01:48:51.255000",
          "tags": [
            "cisco umbrella",
            "site",
            "alexa top",
            "emotet",
            "telefonica co",
            "million",
            "malware",
            "detection list",
            "blacklist",
            "alexa",
            "installcore",
            "heur",
            "cyber threat",
            "united",
            "phishing",
            "engineering",
            "phishing site",
            "team phishing",
            "spammer",
            "malicious site",
            "team",
            "download",
            "cobalt strike",
            "facebook",
            "artemis",
            "pony",
            "binder",
            "suppobox",
            "virut",
            "ramnit",
            "dropper",
            "formbook",
            "azorult",
            "simda",
            "downloader",
            "service",
            "bank",
            "zbot",
            "trojanspy",
            "heodo",
            "hostname",
            "hostnames",
            "whois record",
            "kgs0",
            "kls0",
            "apple ios",
            "tsara brashears",
            "ssl certificate",
            "elf collection",
            "cyberstalking",
            "spyware",
            "hackers",
            "installer",
            "open",
            "banker",
            "keylogger",
            "malicious",
            "hacktool",
            "core",
            "noname057",
            "generic malware",
            "safe site",
            "malware site",
            "iframe",
            "riskware",
            "exploit",
            "fakealert",
            "unsafe",
            "acint",
            "win64",
            "nircmd",
            "agent",
            "opencandy",
            "conduit",
            "swrort",
            "crack",
            "installpack",
            "xtrat",
            "psexec",
            "occamy",
            "brontok",
            "zpevdo",
            "startpage",
            "nanocore",
            "keygen",
            "fareit",
            "secrisk",
            "unruy",
            "filetour",
            "floxif",
            "cleaner",
            "patcher",
            "adload",
            "presenoker",
            "wacatac",
            "fusioncore",
            "genkryptik",
            "webtoolbar",
            "maltiverse",
            "smokeloader",
            "download json",
            "urls",
            "blacklist http",
            "kyriazhs1975",
            "vidar",
            "strike",
            "china cobalt",
            "meterpreter",
            "nanocore rat",
            "njrat",
            "redline stealer",
            "stealer",
            "nymaim",
            "mirai",
            "ghost rat",
            "runescape",
            "bradesco",
            "msil",
            "bladabindi",
            "orkut",
            "cutwail",
            "bandoo",
            "matsnu",
            "inmortal",
            "domains",
            "redline",
            "control server",
            "services",
            "generic",
            "br",
            "threat report",
            "ip summary",
            "url summary",
            "summary",
            "sample",
            "samples",
            "squirrelwaffle",
            "soc http",
            "soc https",
            "back",
            "download csv",
            "json sample",
            "injector",
            "malicious url",
            "downldr",
            "covid19 scam",
            "historical ssl",
            "referrer",
            "contacted",
            "whois whois",
            "contacted urls",
            "whois sslcert",
            "threat roundup",
            "copy",
            "august",
            "execution",
            "ransomware",
            "gopher",
            "remcos",
            "attack",
            "radar ineractive",
            "paypal",
            "covid19",
            "phishing chase",
            "phishing google",
            "tracker malware",
            "chase personal",
            "banking",
            "javascript",
            "please",
            "cnc server",
            "tracker",
            "cnc feodo",
            "phishtank",
            "threats et",
            "name verdict",
            "falcon sandbox",
            "pattern match",
            "file",
            "ascii text",
            "indicator",
            "windows nt",
            "jpeg image",
            "appdata",
            "jfif standard",
            "script",
            "show",
            "date",
            "span",
            "unknown",
            "general",
            "hybrid",
            "local",
            "click",
            "strings",
            "class",
            "generator",
            "critical",
            "error",
            "path",
            "http header",
            "tcp traffic",
            "mitre att",
            "ck id",
            "show technique",
            "ck matrix",
            "accept",
            "adware",
            "ip address",
            "hsbc",
            "outbreak",
            "downer",
            "shell",
            "mediamagnet",
            "sality",
            "adaptivebee",
            "iobit",
            "trojanx",
            "webshell",
            "systweak",
            "behav",
            "tiggre",
            "runtime process",
            "sha256",
            "sha1",
            "mark brian sabey",
            "brian sabey",
            "sabey",
            "apple",
            "114.114.114.114",
            "attorney",
            "law",
            "spammer",
            "fraud service",
            "hallrender",
            "malvertizing",
            "cybercrime",
            "social engineering",
            "malware hosting",
            "cyber threat",
            "iphone unlocker",
            "malicious",
            "attacker",
            "tulach",
            "tulach.cc",
            "adult content",
            "child pornographer",
            "sabey data centers",
            "hall render denver",
            "monitoring",
            "stalker",
            "dev",
            "developer",
            "cyber harassment",
            "defacement",
            "death threats",
            "miner",
            "agenttesla",
            "trojan",
            "detplock",
            "networm",
            "rms",
            "sneaky server",
            "replacement",
            "unauthorized",
            "steam route",
            "tool",
            "probe",
            "safebae.org",
            "safebae",
            "daisy",
            "daisy coleman",
            "benjamin",
            "colorado",
            "missouri",
            "telefonica",
            "boost mobile",
            "blackievirus.com",
            "TrojanX",
            "metro t-mobile",
            "t-mobile",
            "mile high media",
            "CNC",
            "C2",
            "malware host",
            "yixun"
          ],
          "references": [
            "https://hybrid-analysis.com/sample/a1b9247b6ad18f1cda0304e406333459d4000fced5753f91e5c046f6577c388a",
            "https://www.hallrender.com/attorney/brian-sabey",
            "safebae.org",
            "poemhunter.com",
            "http://www.hallrender.com/resources/blog/",
            "http://benjamin.xww.de/",
            "http://alohatube.xyz/search/tsara-brashears",
            "https://www.anyxxxtube.net/search-porn/tsara-brashears/",
            "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian",
            "Hybrid Analysis",
            "wTools",
            "Research"
          ],
          "public": 1,
          "adversary": "Tulach | Mark Brian Sabey | Hall Render Law Firm",
          "targeted_countries": [
            "United States of America",
            "Japan"
          ],
          "malware_families": [
            {
              "id": "TrojanSpy",
              "display_name": "TrojanSpy",
              "target": null
            },
            {
              "id": "WebToolbar",
              "display_name": "WebToolbar",
              "target": null
            },
            {
              "id": "Maltiverse",
              "display_name": "Maltiverse",
              "target": null
            },
            {
              "id": "Inmortal",
              "display_name": "Inmortal",
              "target": null
            },
            {
              "id": "Domains",
              "display_name": "Domains",
              "target": null
            },
            {
              "id": "RedLine",
              "display_name": "RedLine",
              "target": null
            },
            {
              "id": "BR",
              "display_name": "BR",
              "target": null
            },
            {
              "id": "Radar Ineractive",
              "display_name": "Radar Ineractive",
              "target": null
            },
            {
              "id": "HSBC",
              "display_name": "HSBC",
              "target": null
            },
            {
              "id": "RMS",
              "display_name": "RMS",
              "target": null
            },
            {
              "id": "Feodo Tracker",
              "display_name": "Feodo Tracker",
              "target": null
            },
            {
              "id": "Wacatac",
              "display_name": "Wacatac",
              "target": null
            },
            {
              "id": "Zpevdo",
              "display_name": "Zpevdo",
              "target": null
            },
            {
              "id": "Zbot",
              "display_name": "Zbot",
              "target": null
            },
            {
              "id": "OpenCandy",
              "display_name": "OpenCandy",
              "target": null
            },
            {
              "id": "xRAT",
              "display_name": "xRAT",
              "target": null
            },
            {
              "id": "Vidar",
              "display_name": "Vidar",
              "target": null
            },
            {
              "id": "Agent Tesla",
              "display_name": "Agent Tesla",
              "target": null
            },
            {
              "id": "noname057",
              "display_name": "noname057",
              "target": null
            },
            {
              "id": "TrojanSpy",
              "display_name": "TrojanSpy",
              "target": null
            },
            {
              "id": "DarkSide .Beware",
              "display_name": "DarkSide .Beware",
              "target": null
            },
            {
              "id": "Nymaim",
              "display_name": "Nymaim",
              "target": null
            },
            {
              "id": "SLFPER:BrowserModifier:Win32/MediaMagnet",
              "display_name": "SLFPER:BrowserModifier:Win32/MediaMagnet",
              "target": null
            },
            {
              "id": "Virut",
              "display_name": "Virut",
              "target": null
            },
            {
              "id": "Cutwail",
              "display_name": "Cutwail",
              "target": null
            },
            {
              "id": "Nanocore RAT",
              "display_name": "Nanocore RAT",
              "target": null
            },
            {
              "id": "Tulach Malware",
              "display_name": "Tulach Malware",
              "target": null
            },
            {
              "id": "SuppoBox",
              "display_name": "SuppoBox",
              "target": null
            },
            {
              "id": "Systweak",
              "display_name": "Systweak",
              "target": null
            },
            {
              "id": "Occamy",
              "display_name": "Occamy",
              "target": null
            },
            {
              "id": "Tiggre",
              "display_name": "Tiggre",
              "target": null
            },
            {
              "id": "IObit",
              "display_name": "IObit",
              "target": null
            },
            {
              "id": "Sality",
              "display_name": "Sality",
              "target": null
            },
            {
              "id": "FORMBOOK",
              "display_name": "FORMBOOK",
              "target": null
            },
            {
              "id": "Emotet",
              "display_name": "Emotet",
              "target": null
            },
            {
              "id": "Yixun",
              "display_name": "Yixun",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1496",
              "name": "Resource Hijacking",
              "display_name": "T1496 - Resource Hijacking"
            },
            {
              "id": "T1176",
              "name": "Browser Extensions",
              "display_name": "T1176 - Browser Extensions"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1041",
              "name": "Exfiltration Over C2 Channel",
              "display_name": "T1041 - Exfiltration Over C2 Channel"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1114",
              "name": "Email Collection",
              "display_name": "T1114 - Email Collection"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1012",
              "name": "Query Registry",
              "display_name": "T1012 - Query Registry"
            },
            {
              "id": "T1043",
              "name": "Commonly Used Port",
              "display_name": "T1043 - Commonly Used Port"
            },
            {
              "id": "T1112",
              "name": "Modify Registry",
              "display_name": "T1112 - Modify Registry"
            },
            {
              "id": "T1179",
              "name": "Hooking",
              "display_name": "T1179 - Hooking"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1583.005",
              "name": "Botnet",
              "display_name": "T1583.005 - Botnet"
            },
            {
              "id": "T1449",
              "name": "Exploit SS7 to Redirect Phone Calls/SMS",
              "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
            },
            {
              "id": "T1071.004",
              "name": "DNS",
              "display_name": "T1071.004 - DNS"
            },
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1068",
              "name": "Exploitation for Privilege Escalation",
              "display_name": "T1068 - Exploitation for Privilege Escalation"
            },
            {
              "id": "T1056.001",
              "name": "Keylogging",
              "display_name": "T1056.001 - Keylogging"
            }
          ],
          "industries": [
            "Health"
          ],
          "TLP": "green",
          "cloned_from": "6544c99af21a2fde7bd6927e",
          "export_count": 56,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 2,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 1643,
            "hostname": 1438,
            "CVE": 30,
            "FileHash-MD5": 2853,
            "FileHash-SHA1": 1584,
            "FileHash-SHA256": 3001,
            "URL": 2904,
            "email": 1
          },
          "indicator_count": 13454,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 227,
          "modified_text": "868 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "65459cbd3069e99e327642b6",
          "name": "Resources Hijacking ",
          "description": "",
          "modified": "2023-12-03T06:04:06.473000",
          "created": "2023-11-04T01:22:05.691000",
          "tags": [
            "cisco umbrella",
            "site",
            "alexa top",
            "emotet",
            "telefonica co",
            "million",
            "malware",
            "detection list",
            "blacklist",
            "alexa",
            "installcore",
            "heur",
            "cyber threat",
            "united",
            "phishing",
            "engineering",
            "phishing site",
            "team phishing",
            "spammer",
            "malicious site",
            "team",
            "download",
            "cobalt strike",
            "facebook",
            "artemis",
            "pony",
            "binder",
            "suppobox",
            "virut",
            "ramnit",
            "dropper",
            "formbook",
            "azorult",
            "simda",
            "downloader",
            "service",
            "bank",
            "zbot",
            "trojanspy",
            "heodo",
            "hostname",
            "hostnames",
            "whois record",
            "kgs0",
            "kls0",
            "apple ios",
            "tsara brashears",
            "ssl certificate",
            "elf collection",
            "cyberstalking",
            "spyware",
            "hackers",
            "installer",
            "open",
            "banker",
            "keylogger",
            "malicious",
            "hacktool",
            "core",
            "noname057",
            "generic malware",
            "safe site",
            "malware site",
            "iframe",
            "riskware",
            "exploit",
            "fakealert",
            "unsafe",
            "acint",
            "win64",
            "nircmd",
            "agent",
            "opencandy",
            "conduit",
            "swrort",
            "crack",
            "installpack",
            "xtrat",
            "psexec",
            "occamy",
            "brontok",
            "zpevdo",
            "startpage",
            "nanocore",
            "keygen",
            "fareit",
            "secrisk",
            "unruy",
            "filetour",
            "floxif",
            "cleaner",
            "patcher",
            "adload",
            "presenoker",
            "wacatac",
            "fusioncore",
            "genkryptik",
            "webtoolbar",
            "maltiverse",
            "smokeloader",
            "download json",
            "urls",
            "blacklist http",
            "kyriazhs1975",
            "vidar",
            "strike",
            "china cobalt",
            "meterpreter",
            "nanocore rat",
            "njrat",
            "redline stealer",
            "stealer",
            "nymaim",
            "mirai",
            "ghost rat",
            "runescape",
            "bradesco",
            "msil",
            "bladabindi",
            "orkut",
            "cutwail",
            "bandoo",
            "matsnu",
            "inmortal",
            "domains",
            "redline",
            "control server",
            "services",
            "generic",
            "br",
            "threat report",
            "ip summary",
            "url summary",
            "summary",
            "sample",
            "samples",
            "squirrelwaffle",
            "soc http",
            "soc https",
            "back",
            "download csv",
            "json sample",
            "injector",
            "malicious url",
            "downldr",
            "covid19 scam",
            "historical ssl",
            "referrer",
            "contacted",
            "whois whois",
            "contacted urls",
            "whois sslcert",
            "threat roundup",
            "copy",
            "august",
            "execution",
            "ransomware",
            "gopher",
            "remcos",
            "attack",
            "radar ineractive",
            "paypal",
            "covid19",
            "phishing chase",
            "phishing google",
            "tracker malware",
            "chase personal",
            "banking",
            "javascript",
            "please",
            "cnc server",
            "tracker",
            "cnc feodo",
            "phishtank",
            "threats et",
            "name verdict",
            "falcon sandbox",
            "pattern match",
            "file",
            "ascii text",
            "indicator",
            "windows nt",
            "jpeg image",
            "appdata",
            "jfif standard",
            "script",
            "show",
            "date",
            "span",
            "unknown",
            "general",
            "hybrid",
            "local",
            "click",
            "strings",
            "class",
            "generator",
            "critical",
            "error",
            "path",
            "http header",
            "tcp traffic",
            "mitre att",
            "ck id",
            "show technique",
            "ck matrix",
            "accept",
            "adware",
            "ip address",
            "hsbc",
            "outbreak",
            "downer",
            "shell",
            "mediamagnet",
            "sality",
            "adaptivebee",
            "iobit",
            "trojanx",
            "webshell",
            "systweak",
            "behav",
            "tiggre",
            "runtime process",
            "sha256",
            "sha1",
            "mark brian sabey",
            "brian sabey",
            "sabey",
            "apple",
            "114.114.114.114",
            "attorney",
            "law",
            "spammer",
            "fraud service",
            "hallrender",
            "malvertizing",
            "cybercrime",
            "social engineering",
            "malware hosting",
            "cyber threat",
            "iphone unlocker",
            "malicious",
            "attacker",
            "tulach",
            "tulach.cc",
            "adult content",
            "child pornographer",
            "sabey data centers",
            "hall render denver",
            "monitoring",
            "stalker",
            "dev",
            "developer",
            "cyber harassment",
            "defacement",
            "death threats",
            "miner",
            "agenttesla",
            "trojan",
            "detplock",
            "networm",
            "rms",
            "sneaky server",
            "replacement",
            "unauthorized",
            "steam route",
            "tool",
            "probe",
            "safebae.org",
            "safebae",
            "daisy",
            "daisy coleman",
            "benjamin",
            "colorado",
            "missouri",
            "telefonica",
            "boost mobile",
            "blackievirus.com",
            "TrojanX",
            "metro t-mobile",
            "t-mobile",
            "mile high media",
            "CNC",
            "C2",
            "malware host",
            "yixun"
          ],
          "references": [
            "https://hybrid-analysis.com/sample/a1b9247b6ad18f1cda0304e406333459d4000fced5753f91e5c046f6577c388a",
            "https://www.hallrender.com/attorney/brian-sabey",
            "safebae.org",
            "poemhunter.com",
            "http://www.hallrender.com/resources/blog/",
            "http://benjamin.xww.de/",
            "http://alohatube.xyz/search/tsara-brashears",
            "https://www.anyxxxtube.net/search-porn/tsara-brashears/",
            "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian",
            "Hybrid Analysis",
            "wTools",
            "Research"
          ],
          "public": 1,
          "adversary": "Tulach | Mark Brian Sabey | Hall Render Law Firm",
          "targeted_countries": [
            "United States of America",
            "Japan"
          ],
          "malware_families": [
            {
              "id": "TrojanSpy",
              "display_name": "TrojanSpy",
              "target": null
            },
            {
              "id": "WebToolbar",
              "display_name": "WebToolbar",
              "target": null
            },
            {
              "id": "Maltiverse",
              "display_name": "Maltiverse",
              "target": null
            },
            {
              "id": "Inmortal",
              "display_name": "Inmortal",
              "target": null
            },
            {
              "id": "Domains",
              "display_name": "Domains",
              "target": null
            },
            {
              "id": "RedLine",
              "display_name": "RedLine",
              "target": null
            },
            {
              "id": "BR",
              "display_name": "BR",
              "target": null
            },
            {
              "id": "Radar Ineractive",
              "display_name": "Radar Ineractive",
              "target": null
            },
            {
              "id": "HSBC",
              "display_name": "HSBC",
              "target": null
            },
            {
              "id": "RMS",
              "display_name": "RMS",
              "target": null
            },
            {
              "id": "Feodo Tracker",
              "display_name": "Feodo Tracker",
              "target": null
            },
            {
              "id": "Wacatac",
              "display_name": "Wacatac",
              "target": null
            },
            {
              "id": "Zpevdo",
              "display_name": "Zpevdo",
              "target": null
            },
            {
              "id": "Zbot",
              "display_name": "Zbot",
              "target": null
            },
            {
              "id": "OpenCandy",
              "display_name": "OpenCandy",
              "target": null
            },
            {
              "id": "xRAT",
              "display_name": "xRAT",
              "target": null
            },
            {
              "id": "Vidar",
              "display_name": "Vidar",
              "target": null
            },
            {
              "id": "Agent Tesla",
              "display_name": "Agent Tesla",
              "target": null
            },
            {
              "id": "noname057",
              "display_name": "noname057",
              "target": null
            },
            {
              "id": "TrojanSpy",
              "display_name": "TrojanSpy",
              "target": null
            },
            {
              "id": "DarkSide .Beware",
              "display_name": "DarkSide .Beware",
              "target": null
            },
            {
              "id": "Nymaim",
              "display_name": "Nymaim",
              "target": null
            },
            {
              "id": "SLFPER:BrowserModifier:Win32/MediaMagnet",
              "display_name": "SLFPER:BrowserModifier:Win32/MediaMagnet",
              "target": null
            },
            {
              "id": "Virut",
              "display_name": "Virut",
              "target": null
            },
            {
              "id": "Cutwail",
              "display_name": "Cutwail",
              "target": null
            },
            {
              "id": "Nanocore RAT",
              "display_name": "Nanocore RAT",
              "target": null
            },
            {
              "id": "Tulach Malware",
              "display_name": "Tulach Malware",
              "target": null
            },
            {
              "id": "SuppoBox",
              "display_name": "SuppoBox",
              "target": null
            },
            {
              "id": "Systweak",
              "display_name": "Systweak",
              "target": null
            },
            {
              "id": "Occamy",
              "display_name": "Occamy",
              "target": null
            },
            {
              "id": "Tiggre",
              "display_name": "Tiggre",
              "target": null
            },
            {
              "id": "IObit",
              "display_name": "IObit",
              "target": null
            },
            {
              "id": "Sality",
              "display_name": "Sality",
              "target": null
            },
            {
              "id": "FORMBOOK",
              "display_name": "FORMBOOK",
              "target": null
            },
            {
              "id": "Emotet",
              "display_name": "Emotet",
              "target": null
            },
            {
              "id": "Yixun",
              "display_name": "Yixun",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1496",
              "name": "Resource Hijacking",
              "display_name": "T1496 - Resource Hijacking"
            },
            {
              "id": "T1176",
              "name": "Browser Extensions",
              "display_name": "T1176 - Browser Extensions"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1041",
              "name": "Exfiltration Over C2 Channel",
              "display_name": "T1041 - Exfiltration Over C2 Channel"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1114",
              "name": "Email Collection",
              "display_name": "T1114 - Email Collection"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1012",
              "name": "Query Registry",
              "display_name": "T1012 - Query Registry"
            },
            {
              "id": "T1043",
              "name": "Commonly Used Port",
              "display_name": "T1043 - Commonly Used Port"
            },
            {
              "id": "T1112",
              "name": "Modify Registry",
              "display_name": "T1112 - Modify Registry"
            },
            {
              "id": "T1179",
              "name": "Hooking",
              "display_name": "T1179 - Hooking"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1583.005",
              "name": "Botnet",
              "display_name": "T1583.005 - Botnet"
            },
            {
              "id": "T1449",
              "name": "Exploit SS7 to Redirect Phone Calls/SMS",
              "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
            },
            {
              "id": "T1071.004",
              "name": "DNS",
              "display_name": "T1071.004 - DNS"
            },
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1068",
              "name": "Exploitation for Privilege Escalation",
              "display_name": "T1068 - Exploitation for Privilege Escalation"
            },
            {
              "id": "T1056.001",
              "name": "Keylogging",
              "display_name": "T1056.001 - Keylogging"
            }
          ],
          "industries": [
            "Health"
          ],
          "TLP": "green",
          "cloned_from": "6544d9b0f9b23205eb355210",
          "export_count": 56,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 1643,
            "hostname": 1438,
            "CVE": 30,
            "FileHash-MD5": 2853,
            "FileHash-SHA1": 1584,
            "FileHash-SHA256": 3001,
            "URL": 2904,
            "email": 1
          },
          "indicator_count": 13454,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 226,
          "modified_text": "868 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6544d9b0f9b23205eb355210",
          "name": "Resources Hijacking by Attorney  11_03_2023",
          "description": "",
          "modified": "2023-12-03T06:04:06.473000",
          "created": "2023-11-03T11:29:52.652000",
          "tags": [
            "cisco umbrella",
            "site",
            "alexa top",
            "emotet",
            "telefonica co",
            "million",
            "malware",
            "detection list",
            "blacklist",
            "alexa",
            "installcore",
            "heur",
            "cyber threat",
            "united",
            "phishing",
            "engineering",
            "phishing site",
            "team phishing",
            "spammer",
            "malicious site",
            "team",
            "download",
            "cobalt strike",
            "facebook",
            "artemis",
            "pony",
            "binder",
            "suppobox",
            "virut",
            "ramnit",
            "dropper",
            "formbook",
            "azorult",
            "simda",
            "downloader",
            "service",
            "bank",
            "zbot",
            "trojanspy",
            "heodo",
            "hostname",
            "hostnames",
            "whois record",
            "kgs0",
            "kls0",
            "apple ios",
            "tsara brashears",
            "ssl certificate",
            "elf collection",
            "cyberstalking",
            "spyware",
            "hackers",
            "installer",
            "open",
            "banker",
            "keylogger",
            "malicious",
            "hacktool",
            "core",
            "noname057",
            "generic malware",
            "safe site",
            "malware site",
            "iframe",
            "riskware",
            "exploit",
            "fakealert",
            "unsafe",
            "acint",
            "win64",
            "nircmd",
            "agent",
            "opencandy",
            "conduit",
            "swrort",
            "crack",
            "installpack",
            "xtrat",
            "psexec",
            "occamy",
            "brontok",
            "zpevdo",
            "startpage",
            "nanocore",
            "keygen",
            "fareit",
            "secrisk",
            "unruy",
            "filetour",
            "floxif",
            "cleaner",
            "patcher",
            "adload",
            "presenoker",
            "wacatac",
            "fusioncore",
            "genkryptik",
            "webtoolbar",
            "maltiverse",
            "smokeloader",
            "download json",
            "urls",
            "blacklist http",
            "kyriazhs1975",
            "vidar",
            "strike",
            "china cobalt",
            "meterpreter",
            "nanocore rat",
            "njrat",
            "redline stealer",
            "stealer",
            "nymaim",
            "mirai",
            "ghost rat",
            "runescape",
            "bradesco",
            "msil",
            "bladabindi",
            "orkut",
            "cutwail",
            "bandoo",
            "matsnu",
            "inmortal",
            "domains",
            "redline",
            "control server",
            "services",
            "generic",
            "br",
            "threat report",
            "ip summary",
            "url summary",
            "summary",
            "sample",
            "samples",
            "squirrelwaffle",
            "soc http",
            "soc https",
            "back",
            "download csv",
            "json sample",
            "injector",
            "malicious url",
            "downldr",
            "covid19 scam",
            "historical ssl",
            "referrer",
            "contacted",
            "whois whois",
            "contacted urls",
            "whois sslcert",
            "threat roundup",
            "copy",
            "august",
            "execution",
            "ransomware",
            "gopher",
            "remcos",
            "attack",
            "radar ineractive",
            "paypal",
            "covid19",
            "phishing chase",
            "phishing google",
            "tracker malware",
            "chase personal",
            "banking",
            "javascript",
            "please",
            "cnc server",
            "tracker",
            "cnc feodo",
            "phishtank",
            "threats et",
            "name verdict",
            "falcon sandbox",
            "pattern match",
            "file",
            "ascii text",
            "indicator",
            "windows nt",
            "jpeg image",
            "appdata",
            "jfif standard",
            "script",
            "show",
            "date",
            "span",
            "unknown",
            "general",
            "hybrid",
            "local",
            "click",
            "strings",
            "class",
            "generator",
            "critical",
            "error",
            "path",
            "http header",
            "tcp traffic",
            "mitre att",
            "ck id",
            "show technique",
            "ck matrix",
            "accept",
            "adware",
            "ip address",
            "hsbc",
            "outbreak",
            "downer",
            "shell",
            "mediamagnet",
            "sality",
            "adaptivebee",
            "iobit",
            "trojanx",
            "webshell",
            "systweak",
            "behav",
            "tiggre",
            "runtime process",
            "sha256",
            "sha1",
            "mark brian sabey",
            "brian sabey",
            "sabey",
            "apple",
            "114.114.114.114",
            "attorney",
            "law",
            "spammer",
            "fraud service",
            "hallrender",
            "malvertizing",
            "cybercrime",
            "social engineering",
            "malware hosting",
            "cyber threat",
            "iphone unlocker",
            "malicious",
            "attacker",
            "tulach",
            "tulach.cc",
            "adult content",
            "child pornographer",
            "sabey data centers",
            "hall render denver",
            "monitoring",
            "stalker",
            "dev",
            "developer",
            "cyber harassment",
            "defacement",
            "death threats",
            "miner",
            "agenttesla",
            "trojan",
            "detplock",
            "networm",
            "rms",
            "sneaky server",
            "replacement",
            "unauthorized",
            "steam route",
            "tool",
            "probe",
            "safebae.org",
            "safebae",
            "daisy",
            "daisy coleman",
            "benjamin",
            "colorado",
            "missouri",
            "telefonica",
            "boost mobile",
            "blackievirus.com",
            "TrojanX",
            "metro t-mobile",
            "t-mobile",
            "mile high media",
            "CNC",
            "C2",
            "malware host",
            "yixun"
          ],
          "references": [
            "https://hybrid-analysis.com/sample/a1b9247b6ad18f1cda0304e406333459d4000fced5753f91e5c046f6577c388a",
            "https://www.hallrender.com/attorney/brian-sabey",
            "safebae.org",
            "poemhunter.com",
            "http://www.hallrender.com/resources/blog/",
            "http://benjamin.xww.de/",
            "http://alohatube.xyz/search/tsara-brashears",
            "https://www.anyxxxtube.net/search-porn/tsara-brashears/",
            "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian",
            "Hybrid Analysis",
            "wTools",
            "Research"
          ],
          "public": 1,
          "adversary": "Tulach | Mark Brian Sabey | Hall Render Law Firm",
          "targeted_countries": [
            "United States of America",
            "Japan"
          ],
          "malware_families": [
            {
              "id": "TrojanSpy",
              "display_name": "TrojanSpy",
              "target": null
            },
            {
              "id": "WebToolbar",
              "display_name": "WebToolbar",
              "target": null
            },
            {
              "id": "Maltiverse",
              "display_name": "Maltiverse",
              "target": null
            },
            {
              "id": "Inmortal",
              "display_name": "Inmortal",
              "target": null
            },
            {
              "id": "Domains",
              "display_name": "Domains",
              "target": null
            },
            {
              "id": "RedLine",
              "display_name": "RedLine",
              "target": null
            },
            {
              "id": "BR",
              "display_name": "BR",
              "target": null
            },
            {
              "id": "Radar Ineractive",
              "display_name": "Radar Ineractive",
              "target": null
            },
            {
              "id": "HSBC",
              "display_name": "HSBC",
              "target": null
            },
            {
              "id": "RMS",
              "display_name": "RMS",
              "target": null
            },
            {
              "id": "Feodo Tracker",
              "display_name": "Feodo Tracker",
              "target": null
            },
            {
              "id": "Wacatac",
              "display_name": "Wacatac",
              "target": null
            },
            {
              "id": "Zpevdo",
              "display_name": "Zpevdo",
              "target": null
            },
            {
              "id": "Zbot",
              "display_name": "Zbot",
              "target": null
            },
            {
              "id": "OpenCandy",
              "display_name": "OpenCandy",
              "target": null
            },
            {
              "id": "xRAT",
              "display_name": "xRAT",
              "target": null
            },
            {
              "id": "Vidar",
              "display_name": "Vidar",
              "target": null
            },
            {
              "id": "Agent Tesla",
              "display_name": "Agent Tesla",
              "target": null
            },
            {
              "id": "noname057",
              "display_name": "noname057",
              "target": null
            },
            {
              "id": "TrojanSpy",
              "display_name": "TrojanSpy",
              "target": null
            },
            {
              "id": "DarkSide .Beware",
              "display_name": "DarkSide .Beware",
              "target": null
            },
            {
              "id": "Nymaim",
              "display_name": "Nymaim",
              "target": null
            },
            {
              "id": "SLFPER:BrowserModifier:Win32/MediaMagnet",
              "display_name": "SLFPER:BrowserModifier:Win32/MediaMagnet",
              "target": null
            },
            {
              "id": "Virut",
              "display_name": "Virut",
              "target": null
            },
            {
              "id": "Cutwail",
              "display_name": "Cutwail",
              "target": null
            },
            {
              "id": "Nanocore RAT",
              "display_name": "Nanocore RAT",
              "target": null
            },
            {
              "id": "Tulach Malware",
              "display_name": "Tulach Malware",
              "target": null
            },
            {
              "id": "SuppoBox",
              "display_name": "SuppoBox",
              "target": null
            },
            {
              "id": "Systweak",
              "display_name": "Systweak",
              "target": null
            },
            {
              "id": "Occamy",
              "display_name": "Occamy",
              "target": null
            },
            {
              "id": "Tiggre",
              "display_name": "Tiggre",
              "target": null
            },
            {
              "id": "IObit",
              "display_name": "IObit",
              "target": null
            },
            {
              "id": "Sality",
              "display_name": "Sality",
              "target": null
            },
            {
              "id": "FORMBOOK",
              "display_name": "FORMBOOK",
              "target": null
            },
            {
              "id": "Emotet",
              "display_name": "Emotet",
              "target": null
            },
            {
              "id": "Yixun",
              "display_name": "Yixun",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1496",
              "name": "Resource Hijacking",
              "display_name": "T1496 - Resource Hijacking"
            },
            {
              "id": "T1176",
              "name": "Browser Extensions",
              "display_name": "T1176 - Browser Extensions"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1041",
              "name": "Exfiltration Over C2 Channel",
              "display_name": "T1041 - Exfiltration Over C2 Channel"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1114",
              "name": "Email Collection",
              "display_name": "T1114 - Email Collection"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1012",
              "name": "Query Registry",
              "display_name": "T1012 - Query Registry"
            },
            {
              "id": "T1043",
              "name": "Commonly Used Port",
              "display_name": "T1043 - Commonly Used Port"
            },
            {
              "id": "T1112",
              "name": "Modify Registry",
              "display_name": "T1112 - Modify Registry"
            },
            {
              "id": "T1179",
              "name": "Hooking",
              "display_name": "T1179 - Hooking"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1583.005",
              "name": "Botnet",
              "display_name": "T1583.005 - Botnet"
            },
            {
              "id": "T1449",
              "name": "Exploit SS7 to Redirect Phone Calls/SMS",
              "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
            },
            {
              "id": "T1071.004",
              "name": "DNS",
              "display_name": "T1071.004 - DNS"
            },
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1068",
              "name": "Exploitation for Privilege Escalation",
              "display_name": "T1068 - Exploitation for Privilege Escalation"
            },
            {
              "id": "T1056.001",
              "name": "Keylogging",
              "display_name": "T1056.001 - Keylogging"
            }
          ],
          "industries": [
            "Health"
          ],
          "TLP": "green",
          "cloned_from": "6544c7a11d7541bdb3bfe5ff",
          "export_count": 60,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 1,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 1643,
            "hostname": 1438,
            "CVE": 30,
            "FileHash-MD5": 2853,
            "FileHash-SHA1": 1584,
            "FileHash-SHA256": 3001,
            "URL": 2904,
            "email": 1
          },
          "indicator_count": 13454,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 219,
          "modified_text": "868 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6544c99af21a2fde7bd6927e",
          "name": "Occamy Remote PC / Device Control ",
          "description": "",
          "modified": "2023-12-03T06:04:06.473000",
          "created": "2023-11-03T10:21:14.428000",
          "tags": [
            "cisco umbrella",
            "site",
            "alexa top",
            "emotet",
            "telefonica co",
            "million",
            "malware",
            "detection list",
            "blacklist",
            "alexa",
            "installcore",
            "heur",
            "cyber threat",
            "united",
            "phishing",
            "engineering",
            "phishing site",
            "team phishing",
            "spammer",
            "malicious site",
            "team",
            "download",
            "cobalt strike",
            "facebook",
            "artemis",
            "pony",
            "binder",
            "suppobox",
            "virut",
            "ramnit",
            "dropper",
            "formbook",
            "azorult",
            "simda",
            "downloader",
            "service",
            "bank",
            "zbot",
            "trojanspy",
            "heodo",
            "hostname",
            "hostnames",
            "whois record",
            "kgs0",
            "kls0",
            "apple ios",
            "tsara brashears",
            "ssl certificate",
            "elf collection",
            "cyberstalking",
            "spyware",
            "hackers",
            "installer",
            "open",
            "banker",
            "keylogger",
            "malicious",
            "hacktool",
            "core",
            "noname057",
            "generic malware",
            "safe site",
            "malware site",
            "iframe",
            "riskware",
            "exploit",
            "fakealert",
            "unsafe",
            "acint",
            "win64",
            "nircmd",
            "agent",
            "opencandy",
            "conduit",
            "swrort",
            "crack",
            "installpack",
            "xtrat",
            "psexec",
            "occamy",
            "brontok",
            "zpevdo",
            "startpage",
            "nanocore",
            "keygen",
            "fareit",
            "secrisk",
            "unruy",
            "filetour",
            "floxif",
            "cleaner",
            "patcher",
            "adload",
            "presenoker",
            "wacatac",
            "fusioncore",
            "genkryptik",
            "webtoolbar",
            "maltiverse",
            "smokeloader",
            "download json",
            "urls",
            "blacklist http",
            "kyriazhs1975",
            "vidar",
            "strike",
            "china cobalt",
            "meterpreter",
            "nanocore rat",
            "njrat",
            "redline stealer",
            "stealer",
            "nymaim",
            "mirai",
            "ghost rat",
            "runescape",
            "bradesco",
            "msil",
            "bladabindi",
            "orkut",
            "cutwail",
            "bandoo",
            "matsnu",
            "inmortal",
            "domains",
            "redline",
            "control server",
            "services",
            "generic",
            "br",
            "threat report",
            "ip summary",
            "url summary",
            "summary",
            "sample",
            "samples",
            "squirrelwaffle",
            "soc http",
            "soc https",
            "back",
            "download csv",
            "json sample",
            "injector",
            "malicious url",
            "downldr",
            "covid19 scam",
            "historical ssl",
            "referrer",
            "contacted",
            "whois whois",
            "contacted urls",
            "whois sslcert",
            "threat roundup",
            "copy",
            "august",
            "execution",
            "ransomware",
            "gopher",
            "remcos",
            "attack",
            "radar ineractive",
            "paypal",
            "covid19",
            "phishing chase",
            "phishing google",
            "tracker malware",
            "chase personal",
            "banking",
            "javascript",
            "please",
            "cnc server",
            "tracker",
            "cnc feodo",
            "phishtank",
            "threats et",
            "name verdict",
            "falcon sandbox",
            "pattern match",
            "file",
            "ascii text",
            "indicator",
            "windows nt",
            "jpeg image",
            "appdata",
            "jfif standard",
            "script",
            "show",
            "date",
            "span",
            "unknown",
            "general",
            "hybrid",
            "local",
            "click",
            "strings",
            "class",
            "generator",
            "critical",
            "error",
            "path",
            "http header",
            "tcp traffic",
            "mitre att",
            "ck id",
            "show technique",
            "ck matrix",
            "accept",
            "adware",
            "ip address",
            "hsbc",
            "outbreak",
            "downer",
            "shell",
            "mediamagnet",
            "sality",
            "adaptivebee",
            "iobit",
            "trojanx",
            "webshell",
            "systweak",
            "behav",
            "tiggre",
            "runtime process",
            "sha256",
            "sha1",
            "mark brian sabey",
            "brian sabey",
            "sabey",
            "apple",
            "114.114.114.114",
            "attorney",
            "law",
            "spammer",
            "fraud service",
            "hallrender",
            "malvertizing",
            "cybercrime",
            "social engineering",
            "malware hosting",
            "cyber threat",
            "iphone unlocker",
            "malicious",
            "attacker",
            "tulach",
            "tulach.cc",
            "adult content",
            "child pornographer",
            "sabey data centers",
            "hall render denver",
            "monitoring",
            "stalker",
            "dev",
            "developer",
            "cyber harassment",
            "defacement",
            "death threats",
            "miner",
            "agenttesla",
            "trojan",
            "detplock",
            "networm",
            "rms",
            "sneaky server",
            "replacement",
            "unauthorized",
            "steam route",
            "tool",
            "probe",
            "safebae.org",
            "safebae",
            "daisy",
            "daisy coleman",
            "benjamin",
            "colorado",
            "missouri",
            "telefonica",
            "boost mobile",
            "blackievirus.com",
            "TrojanX",
            "metro t-mobile",
            "t-mobile",
            "mile high media",
            "CNC",
            "C2",
            "malware host",
            "yixun"
          ],
          "references": [
            "https://hybrid-analysis.com/sample/a1b9247b6ad18f1cda0304e406333459d4000fced5753f91e5c046f6577c388a",
            "https://www.hallrender.com/attorney/brian-sabey",
            "safebae.org",
            "poemhunter.com",
            "http://www.hallrender.com/resources/blog/",
            "http://benjamin.xww.de/",
            "http://alohatube.xyz/search/tsara-brashears",
            "https://www.anyxxxtube.net/search-porn/tsara-brashears/",
            "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian",
            "Hybrid Analysis",
            "wTools",
            "Research"
          ],
          "public": 1,
          "adversary": "Tulach | Mark Brian Sabey | Hall Render Law Firm",
          "targeted_countries": [
            "United States of America",
            "Japan"
          ],
          "malware_families": [
            {
              "id": "TrojanSpy",
              "display_name": "TrojanSpy",
              "target": null
            },
            {
              "id": "WebToolbar",
              "display_name": "WebToolbar",
              "target": null
            },
            {
              "id": "Maltiverse",
              "display_name": "Maltiverse",
              "target": null
            },
            {
              "id": "Inmortal",
              "display_name": "Inmortal",
              "target": null
            },
            {
              "id": "Domains",
              "display_name": "Domains",
              "target": null
            },
            {
              "id": "RedLine",
              "display_name": "RedLine",
              "target": null
            },
            {
              "id": "BR",
              "display_name": "BR",
              "target": null
            },
            {
              "id": "Radar Ineractive",
              "display_name": "Radar Ineractive",
              "target": null
            },
            {
              "id": "HSBC",
              "display_name": "HSBC",
              "target": null
            },
            {
              "id": "RMS",
              "display_name": "RMS",
              "target": null
            },
            {
              "id": "Feodo Tracker",
              "display_name": "Feodo Tracker",
              "target": null
            },
            {
              "id": "Wacatac",
              "display_name": "Wacatac",
              "target": null
            },
            {
              "id": "Zpevdo",
              "display_name": "Zpevdo",
              "target": null
            },
            {
              "id": "Zbot",
              "display_name": "Zbot",
              "target": null
            },
            {
              "id": "OpenCandy",
              "display_name": "OpenCandy",
              "target": null
            },
            {
              "id": "xRAT",
              "display_name": "xRAT",
              "target": null
            },
            {
              "id": "Vidar",
              "display_name": "Vidar",
              "target": null
            },
            {
              "id": "Agent Tesla",
              "display_name": "Agent Tesla",
              "target": null
            },
            {
              "id": "noname057",
              "display_name": "noname057",
              "target": null
            },
            {
              "id": "TrojanSpy",
              "display_name": "TrojanSpy",
              "target": null
            },
            {
              "id": "DarkSide .Beware",
              "display_name": "DarkSide .Beware",
              "target": null
            },
            {
              "id": "Nymaim",
              "display_name": "Nymaim",
              "target": null
            },
            {
              "id": "SLFPER:BrowserModifier:Win32/MediaMagnet",
              "display_name": "SLFPER:BrowserModifier:Win32/MediaMagnet",
              "target": null
            },
            {
              "id": "Virut",
              "display_name": "Virut",
              "target": null
            },
            {
              "id": "Cutwail",
              "display_name": "Cutwail",
              "target": null
            },
            {
              "id": "Nanocore RAT",
              "display_name": "Nanocore RAT",
              "target": null
            },
            {
              "id": "Tulach Malware",
              "display_name": "Tulach Malware",
              "target": null
            },
            {
              "id": "SuppoBox",
              "display_name": "SuppoBox",
              "target": null
            },
            {
              "id": "Systweak",
              "display_name": "Systweak",
              "target": null
            },
            {
              "id": "Occamy",
              "display_name": "Occamy",
              "target": null
            },
            {
              "id": "Tiggre",
              "display_name": "Tiggre",
              "target": null
            },
            {
              "id": "IObit",
              "display_name": "IObit",
              "target": null
            },
            {
              "id": "Sality",
              "display_name": "Sality",
              "target": null
            },
            {
              "id": "FORMBOOK",
              "display_name": "FORMBOOK",
              "target": null
            },
            {
              "id": "Emotet",
              "display_name": "Emotet",
              "target": null
            },
            {
              "id": "Yixun",
              "display_name": "Yixun",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1496",
              "name": "Resource Hijacking",
              "display_name": "T1496 - Resource Hijacking"
            },
            {
              "id": "T1176",
              "name": "Browser Extensions",
              "display_name": "T1176 - Browser Extensions"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1041",
              "name": "Exfiltration Over C2 Channel",
              "display_name": "T1041 - Exfiltration Over C2 Channel"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1114",
              "name": "Email Collection",
              "display_name": "T1114 - Email Collection"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1012",
              "name": "Query Registry",
              "display_name": "T1012 - Query Registry"
            },
            {
              "id": "T1043",
              "name": "Commonly Used Port",
              "display_name": "T1043 - Commonly Used Port"
            },
            {
              "id": "T1112",
              "name": "Modify Registry",
              "display_name": "T1112 - Modify Registry"
            },
            {
              "id": "T1179",
              "name": "Hooking",
              "display_name": "T1179 - Hooking"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1583.005",
              "name": "Botnet",
              "display_name": "T1583.005 - Botnet"
            },
            {
              "id": "T1449",
              "name": "Exploit SS7 to Redirect Phone Calls/SMS",
              "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
            },
            {
              "id": "T1071.004",
              "name": "DNS",
              "display_name": "T1071.004 - DNS"
            },
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1068",
              "name": "Exploitation for Privilege Escalation",
              "display_name": "T1068 - Exploitation for Privilege Escalation"
            },
            {
              "id": "T1056.001",
              "name": "Keylogging",
              "display_name": "T1056.001 - Keylogging"
            }
          ],
          "industries": [
            "Health"
          ],
          "TLP": "green",
          "cloned_from": "6544c7a11d7541bdb3bfe5ff",
          "export_count": 59,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 1,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 1643,
            "hostname": 1438,
            "CVE": 30,
            "FileHash-MD5": 2853,
            "FileHash-SHA1": 1584,
            "FileHash-SHA256": 3001,
            "URL": 2904,
            "email": 1
          },
          "indicator_count": 13454,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 221,
          "modified_text": "868 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "64f37719db054ccde25aa9df",
          "name": "Pool's Closed (by @scnrscnr)",
          "description": "",
          "modified": "2023-09-02T17:55:37.269000",
          "created": "2023-09-02T17:55:37.269000",
          "tags": [
            "Timothy Pool",
            "Christopher Pool",
            "Pool's Closed"
          ],
          "references": [
            "Pool Closed",
            "Pool's Closed"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1546",
              "name": "Event Triggered Execution",
              "display_name": "T1546 - Event Triggered Execution"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            }
          ],
          "industries": [
            "Media",
            "ad fraud"
          ],
          "TLP": "white",
          "cloned_from": "5fa57698ac0f6638b7b9a8ba",
          "export_count": 16,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 7851,
            "URL": 23098,
            "hostname": 9521,
            "domain": 4595,
            "SSLCertFingerprint": 22,
            "FileHash-MD5": 564,
            "FileHash-SHA1": 432,
            "CIDR": 32,
            "email": 3,
            "CVE": 2
          },
          "indicator_count": 46120,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 221,
          "modified_text": "960 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "64f3771616d9a9891947e4df",
          "name": "Pool's Closed (by @scnrscnr)",
          "description": "",
          "modified": "2023-09-02T17:55:34.095000",
          "created": "2023-09-02T17:55:34.095000",
          "tags": [
            "Timothy Pool",
            "Christopher Pool",
            "Pool's Closed"
          ],
          "references": [
            "Pool Closed",
            "Pool's Closed"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1546",
              "name": "Event Triggered Execution",
              "display_name": "T1546 - Event Triggered Execution"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            }
          ],
          "industries": [
            "Media",
            "ad fraud"
          ],
          "TLP": "white",
          "cloned_from": "5fa57698ac0f6638b7b9a8ba",
          "export_count": 15,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 7851,
            "URL": 23098,
            "hostname": 9521,
            "domain": 4595,
            "SSLCertFingerprint": 22,
            "FileHash-MD5": 564,
            "FileHash-SHA1": 432,
            "CIDR": 32,
            "email": 3,
            "CVE": 2
          },
          "indicator_count": 46120,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 220,
          "modified_text": "960 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "https://search.app.goo.gl/?ofl=https://lens.google&al=googleapp://lens?lens_data=KAw&apn=com.google.android.googlequicksearchbox&amv=301204913&isi=284815942&ius=googleapp&ibi=com.goog",
        "www.search.app.goo.gl",
        "https://hybrid-analysis.com/sample/a1b9247b6ad18f1cda0304e406333459d4000fced5753f91e5c046f6577c388a",
        "globalworker1.sol.us",
        "Research",
        "http://decafsmob.this.id",
        "id.google.com",
        "http://e.id?e.id:e.id.getAttribute",
        "poemhunter.com",
        "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian",
        "http://critical-system-failure7250.21ny35098453.com-bm3y-v806d9gk.cricket/",
        "apps.apple.com",
        "209.85.145.113 [malware]",
        "states.app",
        "applestore.id",
        "http://benjamin.xww.de/",
        "https://hybrid-analysis.com/sample/d26000dfe1137f05f9187996dc752a703000402fe9e35a8ea216e9215a34560d",
        "http://information.7174932.cakcuk.az/tracking/tracking.php?id=8459701&page=904",
        "https://www.anyxxxtube.net/search-porn/tsara-brashears/",
        "cdn.fuckporntube.com",
        "http://alohatube.xyz/search/tsara-brashears",
        "wTools",
        "http://www.youtube.com/gen_204?cplatform=tablet&c=android&cver=5.6.36&cos=Android&cosver=4.4.2&cbr=com.google.android.youtube&cbrv",
        "apps.apple.com/us/app/id$",
        "location.search",
        "Pool's Closed",
        "dev-2.ernestatech.com",
        "critical-failure-alert2286.40ek97931491.com-4nj1ze3ivfwy.website",
        "Pool Closed",
        "http://www.hallrender.com/resources/blog/",
        "1080p-torrent.ml",
        "t.name",
        "object.prototype.hasownproperty.call",
        "http://git.io/yBU2rg",
        "safebae.org",
        "https://fairspin.io/?track_id=44698569&pid=1&geo=6252001&utm_source=bonafides&utm_medium=&utm_campaign=smarttds&utm_term=incorrect_param",
        "https://coloradosprings.americanlisted.com/pets-animals/beautiful-ragdoll-kittens_31591993.html",
        "https://dnsorangetel.dn2.n-helix.com",
        "worker-m-tlcus1.sol.us",
        "a.default.meta.applestore.id",
        "hasownproperty.call",
        "https://www.hallrender.com/attorney/brian-sabey",
        "http://tracking.3061331.corn10wuk.club",
        "Hybrid Analysis"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 0
        },
        "other": {
          "adversary": [
            "Tulach | Mark Brian Sabey | Hall Render Law Firm"
          ],
          "malware_families": [
            "Feodo tracker",
            "Tiggre",
            "Occamy",
            "Redline",
            "Noname057",
            "Hsbc",
            "Radar ineractive",
            "Vidar",
            "Slfper:browsermodifier:win32/mediamagnet",
            "Cutwail",
            "Zbot",
            "Gamehack",
            "Zpevdo",
            "Rms",
            "Emotet",
            "Yixun",
            "Sality",
            "Br",
            "Agent tesla",
            "Virut",
            "Suppobox",
            "Formbook",
            "Nanocore rat",
            "Nymaim",
            "Inmortal",
            "Maltiverse",
            "Domains",
            "Tulach malware",
            "Darkside .beware",
            "Systweak",
            "Wacatac",
            "Opencandy",
            "Xrat",
            "Iobit",
            "Webtoolbar",
            "Trojanspy"
          ],
          "industries": [
            "Media",
            "Ad fraud",
            "Health"
          ],
          "unique_indicators": 71977
        }
      }
    },
    "false_positive": [],
    "alexa": "http://www.alexa.com/siteinfo/nutzerreaktion.de",
    "whois": "http://whois.domaintools.com/nutzerreaktion.de",
    "domain": "nutzerreaktion.de",
    "hostname": "Unavailable"
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 21,
  "pulses": [
    {
      "id": "69a9cd444aa144401d0c4988",
      "name": "Pools Open",
      "description": "",
      "modified": "2026-04-15T19:21:28.851000",
      "created": "2026-03-05T18:36:52.014000",
      "tags": [
        "Timothy Pool",
        "Christopher Pool",
        "Pool's Closed"
      ],
      "references": [
        "Pool Closed",
        "Pool's Closed"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1546",
          "name": "Event Triggered Execution",
          "display_name": "T1546 - Event Triggered Execution"
        },
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        }
      ],
      "industries": [
        "Media",
        "ad fraud"
      ],
      "TLP": "white",
      "cloned_from": "5fa57698ac0f6638b7b9a8ba",
      "export_count": 1,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 8098,
        "URL": 23428,
        "hostname": 9592,
        "domain": 4727,
        "SSLCertFingerprint": 22,
        "FileHash-MD5": 696,
        "FileHash-SHA1": 457,
        "CIDR": 78,
        "email": 3,
        "CVE": 2
      },
      "indicator_count": 47103,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 50,
      "modified_text": "4 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "5fa57698ac0f6638b7b9a8ba",
      "name": "Pool's Closed",
      "description": "Two paupers from the meadow spring forth an upheaval of nasty sites on the world wide web.",
      "modified": "2025-12-27T05:02:34.910000",
      "created": "2020-11-06T16:15:20.139000",
      "tags": [
        "Timothy Pool",
        "Christopher Pool",
        "Pool's Closed"
      ],
      "references": [
        "Pool Closed",
        "Pool's Closed"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1546",
          "name": "Event Triggered Execution",
          "display_name": "T1546 - Event Triggered Execution"
        },
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        }
      ],
      "industries": [
        "Media",
        "ad fraud"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 61,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 4,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "scnrscnr",
        "id": "126475",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_126475/resized/80/avatar_67ca5b7bae.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 8098,
        "URL": 23426,
        "hostname": 9590,
        "domain": 4727,
        "SSLCertFingerprint": 22,
        "FileHash-MD5": 696,
        "FileHash-SHA1": 457,
        "CIDR": 78,
        "email": 3,
        "CVE": 2
      },
      "indicator_count": 47099,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 133,
      "modified_text": "113 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "65a48b6ea16eeb6b54dfad7c",
      "name": "https://neca.omeclk.com/portal/wts/uc^cn^ejkaejsaBeyk7-^Oa | Brian Sabey dangerous obsession with Tsara Brashears",
      "description": "",
      "modified": "2024-01-15T01:33:34.790000",
      "created": "2024-01-15T01:33:34.790000",
      "tags": [
        "cisco umbrella",
        "site",
        "alexa top",
        "emotet",
        "telefonica co",
        "million",
        "malware",
        "detection list",
        "blacklist",
        "alexa",
        "installcore",
        "heur",
        "cyber threat",
        "united",
        "phishing",
        "engineering",
        "phishing site",
        "team phishing",
        "spammer",
        "malicious site",
        "team",
        "download",
        "cobalt strike",
        "facebook",
        "artemis",
        "pony",
        "binder",
        "suppobox",
        "virut",
        "ramnit",
        "dropper",
        "formbook",
        "azorult",
        "simda",
        "downloader",
        "service",
        "bank",
        "zbot",
        "trojanspy",
        "heodo",
        "hostname",
        "hostnames",
        "whois record",
        "kgs0",
        "kls0",
        "apple ios",
        "tsara brashears",
        "ssl certificate",
        "elf collection",
        "cyberstalking",
        "spyware",
        "hackers",
        "installer",
        "open",
        "banker",
        "keylogger",
        "malicious",
        "hacktool",
        "core",
        "noname057",
        "generic malware",
        "safe site",
        "malware site",
        "iframe",
        "riskware",
        "exploit",
        "fakealert",
        "unsafe",
        "acint",
        "win64",
        "nircmd",
        "agent",
        "opencandy",
        "conduit",
        "swrort",
        "crack",
        "installpack",
        "xtrat",
        "psexec",
        "occamy",
        "brontok",
        "zpevdo",
        "startpage",
        "nanocore",
        "keygen",
        "fareit",
        "secrisk",
        "unruy",
        "filetour",
        "floxif",
        "cleaner",
        "patcher",
        "adload",
        "presenoker",
        "wacatac",
        "fusioncore",
        "genkryptik",
        "webtoolbar",
        "maltiverse",
        "smokeloader",
        "download json",
        "urls",
        "blacklist http",
        "kyriazhs1975",
        "vidar",
        "strike",
        "china cobalt",
        "meterpreter",
        "nanocore rat",
        "njrat",
        "redline stealer",
        "stealer",
        "nymaim",
        "mirai",
        "ghost rat",
        "runescape",
        "bradesco",
        "msil",
        "bladabindi",
        "orkut",
        "cutwail",
        "bandoo",
        "matsnu",
        "inmortal",
        "domains",
        "redline",
        "control server",
        "services",
        "generic",
        "br",
        "threat report",
        "ip summary",
        "url summary",
        "summary",
        "sample",
        "samples",
        "squirrelwaffle",
        "soc http",
        "soc https",
        "back",
        "download csv",
        "json sample",
        "injector",
        "malicious url",
        "downldr",
        "covid19 scam",
        "historical ssl",
        "referrer",
        "contacted",
        "whois whois",
        "contacted urls",
        "whois sslcert",
        "threat roundup",
        "copy",
        "august",
        "execution",
        "ransomware",
        "gopher",
        "remcos",
        "attack",
        "radar ineractive",
        "paypal",
        "covid19",
        "phishing chase",
        "phishing google",
        "tracker malware",
        "chase personal",
        "banking",
        "javascript",
        "please",
        "cnc server",
        "tracker",
        "cnc feodo",
        "phishtank",
        "threats et",
        "name verdict",
        "falcon sandbox",
        "pattern match",
        "file",
        "ascii text",
        "indicator",
        "windows nt",
        "jpeg image",
        "appdata",
        "jfif standard",
        "script",
        "show",
        "date",
        "span",
        "unknown",
        "general",
        "hybrid",
        "local",
        "click",
        "strings",
        "class",
        "generator",
        "critical",
        "error",
        "path",
        "http header",
        "tcp traffic",
        "mitre att",
        "ck id",
        "show technique",
        "ck matrix",
        "accept",
        "adware",
        "ip address",
        "hsbc",
        "outbreak",
        "downer",
        "shell",
        "mediamagnet",
        "sality",
        "adaptivebee",
        "iobit",
        "trojanx",
        "webshell",
        "systweak",
        "behav",
        "tiggre",
        "runtime process",
        "sha256",
        "sha1",
        "mark brian sabey",
        "brian sabey",
        "sabey",
        "apple",
        "114.114.114.114",
        "attorney",
        "law",
        "spammer",
        "fraud service",
        "hallrender",
        "malvertizing",
        "cybercrime",
        "social engineering",
        "malware hosting",
        "cyber threat",
        "iphone unlocker",
        "malicious",
        "attacker",
        "tulach",
        "tulach.cc",
        "adult content",
        "child pornographer",
        "sabey data centers",
        "hall render denver",
        "monitoring",
        "stalker",
        "dev",
        "developer",
        "cyber harassment",
        "defacement",
        "death threats",
        "miner",
        "agenttesla",
        "trojan",
        "detplock",
        "networm",
        "rms",
        "sneaky server",
        "replacement",
        "unauthorized",
        "steam route",
        "tool",
        "probe",
        "safebae.org",
        "safebae",
        "daisy",
        "daisy coleman",
        "benjamin",
        "colorado",
        "missouri",
        "telefonica",
        "boost mobile",
        "blackievirus.com",
        "TrojanX",
        "metro t-mobile",
        "t-mobile",
        "mile high media",
        "CNC",
        "C2",
        "malware host",
        "yixun"
      ],
      "references": [
        "https://hybrid-analysis.com/sample/a1b9247b6ad18f1cda0304e406333459d4000fced5753f91e5c046f6577c388a",
        "https://www.hallrender.com/attorney/brian-sabey",
        "safebae.org",
        "poemhunter.com",
        "http://www.hallrender.com/resources/blog/",
        "http://benjamin.xww.de/",
        "http://alohatube.xyz/search/tsara-brashears",
        "https://www.anyxxxtube.net/search-porn/tsara-brashears/",
        "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian",
        "Hybrid Analysis",
        "wTools",
        "Research"
      ],
      "public": 1,
      "adversary": "Tulach | Mark Brian Sabey | Hall Render Law Firm",
      "targeted_countries": [
        "United States of America",
        "Japan"
      ],
      "malware_families": [
        {
          "id": "TrojanSpy",
          "display_name": "TrojanSpy",
          "target": null
        },
        {
          "id": "WebToolbar",
          "display_name": "WebToolbar",
          "target": null
        },
        {
          "id": "Maltiverse",
          "display_name": "Maltiverse",
          "target": null
        },
        {
          "id": "Inmortal",
          "display_name": "Inmortal",
          "target": null
        },
        {
          "id": "Domains",
          "display_name": "Domains",
          "target": null
        },
        {
          "id": "RedLine",
          "display_name": "RedLine",
          "target": null
        },
        {
          "id": "BR",
          "display_name": "BR",
          "target": null
        },
        {
          "id": "Radar Ineractive",
          "display_name": "Radar Ineractive",
          "target": null
        },
        {
          "id": "HSBC",
          "display_name": "HSBC",
          "target": null
        },
        {
          "id": "RMS",
          "display_name": "RMS",
          "target": null
        },
        {
          "id": "Feodo Tracker",
          "display_name": "Feodo Tracker",
          "target": null
        },
        {
          "id": "Wacatac",
          "display_name": "Wacatac",
          "target": null
        },
        {
          "id": "Zpevdo",
          "display_name": "Zpevdo",
          "target": null
        },
        {
          "id": "Zbot",
          "display_name": "Zbot",
          "target": null
        },
        {
          "id": "OpenCandy",
          "display_name": "OpenCandy",
          "target": null
        },
        {
          "id": "xRAT",
          "display_name": "xRAT",
          "target": null
        },
        {
          "id": "Vidar",
          "display_name": "Vidar",
          "target": null
        },
        {
          "id": "Agent Tesla",
          "display_name": "Agent Tesla",
          "target": null
        },
        {
          "id": "noname057",
          "display_name": "noname057",
          "target": null
        },
        {
          "id": "TrojanSpy",
          "display_name": "TrojanSpy",
          "target": null
        },
        {
          "id": "DarkSide .Beware",
          "display_name": "DarkSide .Beware",
          "target": null
        },
        {
          "id": "Nymaim",
          "display_name": "Nymaim",
          "target": null
        },
        {
          "id": "SLFPER:BrowserModifier:Win32/MediaMagnet",
          "display_name": "SLFPER:BrowserModifier:Win32/MediaMagnet",
          "target": null
        },
        {
          "id": "Virut",
          "display_name": "Virut",
          "target": null
        },
        {
          "id": "Cutwail",
          "display_name": "Cutwail",
          "target": null
        },
        {
          "id": "Nanocore RAT",
          "display_name": "Nanocore RAT",
          "target": null
        },
        {
          "id": "Tulach Malware",
          "display_name": "Tulach Malware",
          "target": null
        },
        {
          "id": "SuppoBox",
          "display_name": "SuppoBox",
          "target": null
        },
        {
          "id": "Systweak",
          "display_name": "Systweak",
          "target": null
        },
        {
          "id": "Occamy",
          "display_name": "Occamy",
          "target": null
        },
        {
          "id": "Tiggre",
          "display_name": "Tiggre",
          "target": null
        },
        {
          "id": "IObit",
          "display_name": "IObit",
          "target": null
        },
        {
          "id": "Sality",
          "display_name": "Sality",
          "target": null
        },
        {
          "id": "FORMBOOK",
          "display_name": "FORMBOOK",
          "target": null
        },
        {
          "id": "Emotet",
          "display_name": "Emotet",
          "target": null
        },
        {
          "id": "Yixun",
          "display_name": "Yixun",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1496",
          "name": "Resource Hijacking",
          "display_name": "T1496 - Resource Hijacking"
        },
        {
          "id": "T1176",
          "name": "Browser Extensions",
          "display_name": "T1176 - Browser Extensions"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1041",
          "name": "Exfiltration Over C2 Channel",
          "display_name": "T1041 - Exfiltration Over C2 Channel"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1114",
          "name": "Email Collection",
          "display_name": "T1114 - Email Collection"
        },
        {
          "id": "T1497",
          "name": "Virtualization/Sandbox Evasion",
          "display_name": "T1497 - Virtualization/Sandbox Evasion"
        },
        {
          "id": "T1012",
          "name": "Query Registry",
          "display_name": "T1012 - Query Registry"
        },
        {
          "id": "T1043",
          "name": "Commonly Used Port",
          "display_name": "T1043 - Commonly Used Port"
        },
        {
          "id": "T1112",
          "name": "Modify Registry",
          "display_name": "T1112 - Modify Registry"
        },
        {
          "id": "T1179",
          "name": "Hooking",
          "display_name": "T1179 - Hooking"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1583.005",
          "name": "Botnet",
          "display_name": "T1583.005 - Botnet"
        },
        {
          "id": "T1449",
          "name": "Exploit SS7 to Redirect Phone Calls/SMS",
          "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
        },
        {
          "id": "T1071.004",
          "name": "DNS",
          "display_name": "T1071.004 - DNS"
        },
        {
          "id": "T1071.001",
          "name": "Web Protocols",
          "display_name": "T1071.001 - Web Protocols"
        },
        {
          "id": "T1068",
          "name": "Exploitation for Privilege Escalation",
          "display_name": "T1068 - Exploitation for Privilege Escalation"
        },
        {
          "id": "T1056.001",
          "name": "Keylogging",
          "display_name": "T1056.001 - Keylogging"
        }
      ],
      "industries": [
        "Health"
      ],
      "TLP": "green",
      "cloned_from": "6590f9b6b1fe0330c655c25f",
      "export_count": 36,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "scoreblue",
        "id": "254100",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 1643,
        "hostname": 1438,
        "CVE": 30,
        "FileHash-MD5": 2853,
        "FileHash-SHA1": 1584,
        "FileHash-SHA256": 3001,
        "URL": 2904,
        "email": 1
      },
      "indicator_count": 13454,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 228,
      "modified_text": "825 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6590f9b6b1fe0330c655c25f",
      "name": "https://neca.omeclk.com/portal/wts/uc^cn^ejkaejsaBeyk7-^Oa | Brian Sabey dangerous obsession with Tsara Brashears ",
      "description": "",
      "modified": "2023-12-31T05:18:46.519000",
      "created": "2023-12-31T05:18:46.519000",
      "tags": [
        "cisco umbrella",
        "site",
        "alexa top",
        "emotet",
        "telefonica co",
        "million",
        "malware",
        "detection list",
        "blacklist",
        "alexa",
        "installcore",
        "heur",
        "cyber threat",
        "united",
        "phishing",
        "engineering",
        "phishing site",
        "team phishing",
        "spammer",
        "malicious site",
        "team",
        "download",
        "cobalt strike",
        "facebook",
        "artemis",
        "pony",
        "binder",
        "suppobox",
        "virut",
        "ramnit",
        "dropper",
        "formbook",
        "azorult",
        "simda",
        "downloader",
        "service",
        "bank",
        "zbot",
        "trojanspy",
        "heodo",
        "hostname",
        "hostnames",
        "whois record",
        "kgs0",
        "kls0",
        "apple ios",
        "tsara brashears",
        "ssl certificate",
        "elf collection",
        "cyberstalking",
        "spyware",
        "hackers",
        "installer",
        "open",
        "banker",
        "keylogger",
        "malicious",
        "hacktool",
        "core",
        "noname057",
        "generic malware",
        "safe site",
        "malware site",
        "iframe",
        "riskware",
        "exploit",
        "fakealert",
        "unsafe",
        "acint",
        "win64",
        "nircmd",
        "agent",
        "opencandy",
        "conduit",
        "swrort",
        "crack",
        "installpack",
        "xtrat",
        "psexec",
        "occamy",
        "brontok",
        "zpevdo",
        "startpage",
        "nanocore",
        "keygen",
        "fareit",
        "secrisk",
        "unruy",
        "filetour",
        "floxif",
        "cleaner",
        "patcher",
        "adload",
        "presenoker",
        "wacatac",
        "fusioncore",
        "genkryptik",
        "webtoolbar",
        "maltiverse",
        "smokeloader",
        "download json",
        "urls",
        "blacklist http",
        "kyriazhs1975",
        "vidar",
        "strike",
        "china cobalt",
        "meterpreter",
        "nanocore rat",
        "njrat",
        "redline stealer",
        "stealer",
        "nymaim",
        "mirai",
        "ghost rat",
        "runescape",
        "bradesco",
        "msil",
        "bladabindi",
        "orkut",
        "cutwail",
        "bandoo",
        "matsnu",
        "inmortal",
        "domains",
        "redline",
        "control server",
        "services",
        "generic",
        "br",
        "threat report",
        "ip summary",
        "url summary",
        "summary",
        "sample",
        "samples",
        "squirrelwaffle",
        "soc http",
        "soc https",
        "back",
        "download csv",
        "json sample",
        "injector",
        "malicious url",
        "downldr",
        "covid19 scam",
        "historical ssl",
        "referrer",
        "contacted",
        "whois whois",
        "contacted urls",
        "whois sslcert",
        "threat roundup",
        "copy",
        "august",
        "execution",
        "ransomware",
        "gopher",
        "remcos",
        "attack",
        "radar ineractive",
        "paypal",
        "covid19",
        "phishing chase",
        "phishing google",
        "tracker malware",
        "chase personal",
        "banking",
        "javascript",
        "please",
        "cnc server",
        "tracker",
        "cnc feodo",
        "phishtank",
        "threats et",
        "name verdict",
        "falcon sandbox",
        "pattern match",
        "file",
        "ascii text",
        "indicator",
        "windows nt",
        "jpeg image",
        "appdata",
        "jfif standard",
        "script",
        "show",
        "date",
        "span",
        "unknown",
        "general",
        "hybrid",
        "local",
        "click",
        "strings",
        "class",
        "generator",
        "critical",
        "error",
        "path",
        "http header",
        "tcp traffic",
        "mitre att",
        "ck id",
        "show technique",
        "ck matrix",
        "accept",
        "adware",
        "ip address",
        "hsbc",
        "outbreak",
        "downer",
        "shell",
        "mediamagnet",
        "sality",
        "adaptivebee",
        "iobit",
        "trojanx",
        "webshell",
        "systweak",
        "behav",
        "tiggre",
        "runtime process",
        "sha256",
        "sha1",
        "mark brian sabey",
        "brian sabey",
        "sabey",
        "apple",
        "114.114.114.114",
        "attorney",
        "law",
        "spammer",
        "fraud service",
        "hallrender",
        "malvertizing",
        "cybercrime",
        "social engineering",
        "malware hosting",
        "cyber threat",
        "iphone unlocker",
        "malicious",
        "attacker",
        "tulach",
        "tulach.cc",
        "adult content",
        "child pornographer",
        "sabey data centers",
        "hall render denver",
        "monitoring",
        "stalker",
        "dev",
        "developer",
        "cyber harassment",
        "defacement",
        "death threats",
        "miner",
        "agenttesla",
        "trojan",
        "detplock",
        "networm",
        "rms",
        "sneaky server",
        "replacement",
        "unauthorized",
        "steam route",
        "tool",
        "probe",
        "safebae.org",
        "safebae",
        "daisy",
        "daisy coleman",
        "benjamin",
        "colorado",
        "missouri",
        "telefonica",
        "boost mobile",
        "blackievirus.com",
        "TrojanX",
        "metro t-mobile",
        "t-mobile",
        "mile high media",
        "CNC",
        "C2",
        "malware host",
        "yixun"
      ],
      "references": [
        "https://hybrid-analysis.com/sample/a1b9247b6ad18f1cda0304e406333459d4000fced5753f91e5c046f6577c388a",
        "https://www.hallrender.com/attorney/brian-sabey",
        "safebae.org",
        "poemhunter.com",
        "http://www.hallrender.com/resources/blog/",
        "http://benjamin.xww.de/",
        "http://alohatube.xyz/search/tsara-brashears",
        "https://www.anyxxxtube.net/search-porn/tsara-brashears/",
        "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian",
        "Hybrid Analysis",
        "wTools",
        "Research"
      ],
      "public": 1,
      "adversary": "Tulach | Mark Brian Sabey | Hall Render Law Firm",
      "targeted_countries": [
        "United States of America",
        "Japan"
      ],
      "malware_families": [
        {
          "id": "TrojanSpy",
          "display_name": "TrojanSpy",
          "target": null
        },
        {
          "id": "WebToolbar",
          "display_name": "WebToolbar",
          "target": null
        },
        {
          "id": "Maltiverse",
          "display_name": "Maltiverse",
          "target": null
        },
        {
          "id": "Inmortal",
          "display_name": "Inmortal",
          "target": null
        },
        {
          "id": "Domains",
          "display_name": "Domains",
          "target": null
        },
        {
          "id": "RedLine",
          "display_name": "RedLine",
          "target": null
        },
        {
          "id": "BR",
          "display_name": "BR",
          "target": null
        },
        {
          "id": "Radar Ineractive",
          "display_name": "Radar Ineractive",
          "target": null
        },
        {
          "id": "HSBC",
          "display_name": "HSBC",
          "target": null
        },
        {
          "id": "RMS",
          "display_name": "RMS",
          "target": null
        },
        {
          "id": "Feodo Tracker",
          "display_name": "Feodo Tracker",
          "target": null
        },
        {
          "id": "Wacatac",
          "display_name": "Wacatac",
          "target": null
        },
        {
          "id": "Zpevdo",
          "display_name": "Zpevdo",
          "target": null
        },
        {
          "id": "Zbot",
          "display_name": "Zbot",
          "target": null
        },
        {
          "id": "OpenCandy",
          "display_name": "OpenCandy",
          "target": null
        },
        {
          "id": "xRAT",
          "display_name": "xRAT",
          "target": null
        },
        {
          "id": "Vidar",
          "display_name": "Vidar",
          "target": null
        },
        {
          "id": "Agent Tesla",
          "display_name": "Agent Tesla",
          "target": null
        },
        {
          "id": "noname057",
          "display_name": "noname057",
          "target": null
        },
        {
          "id": "TrojanSpy",
          "display_name": "TrojanSpy",
          "target": null
        },
        {
          "id": "DarkSide .Beware",
          "display_name": "DarkSide .Beware",
          "target": null
        },
        {
          "id": "Nymaim",
          "display_name": "Nymaim",
          "target": null
        },
        {
          "id": "SLFPER:BrowserModifier:Win32/MediaMagnet",
          "display_name": "SLFPER:BrowserModifier:Win32/MediaMagnet",
          "target": null
        },
        {
          "id": "Virut",
          "display_name": "Virut",
          "target": null
        },
        {
          "id": "Cutwail",
          "display_name": "Cutwail",
          "target": null
        },
        {
          "id": "Nanocore RAT",
          "display_name": "Nanocore RAT",
          "target": null
        },
        {
          "id": "Tulach Malware",
          "display_name": "Tulach Malware",
          "target": null
        },
        {
          "id": "SuppoBox",
          "display_name": "SuppoBox",
          "target": null
        },
        {
          "id": "Systweak",
          "display_name": "Systweak",
          "target": null
        },
        {
          "id": "Occamy",
          "display_name": "Occamy",
          "target": null
        },
        {
          "id": "Tiggre",
          "display_name": "Tiggre",
          "target": null
        },
        {
          "id": "IObit",
          "display_name": "IObit",
          "target": null
        },
        {
          "id": "Sality",
          "display_name": "Sality",
          "target": null
        },
        {
          "id": "FORMBOOK",
          "display_name": "FORMBOOK",
          "target": null
        },
        {
          "id": "Emotet",
          "display_name": "Emotet",
          "target": null
        },
        {
          "id": "Yixun",
          "display_name": "Yixun",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1496",
          "name": "Resource Hijacking",
          "display_name": "T1496 - Resource Hijacking"
        },
        {
          "id": "T1176",
          "name": "Browser Extensions",
          "display_name": "T1176 - Browser Extensions"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1041",
          "name": "Exfiltration Over C2 Channel",
          "display_name": "T1041 - Exfiltration Over C2 Channel"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1114",
          "name": "Email Collection",
          "display_name": "T1114 - Email Collection"
        },
        {
          "id": "T1497",
          "name": "Virtualization/Sandbox Evasion",
          "display_name": "T1497 - Virtualization/Sandbox Evasion"
        },
        {
          "id": "T1012",
          "name": "Query Registry",
          "display_name": "T1012 - Query Registry"
        },
        {
          "id": "T1043",
          "name": "Commonly Used Port",
          "display_name": "T1043 - Commonly Used Port"
        },
        {
          "id": "T1112",
          "name": "Modify Registry",
          "display_name": "T1112 - Modify Registry"
        },
        {
          "id": "T1179",
          "name": "Hooking",
          "display_name": "T1179 - Hooking"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1583.005",
          "name": "Botnet",
          "display_name": "T1583.005 - Botnet"
        },
        {
          "id": "T1449",
          "name": "Exploit SS7 to Redirect Phone Calls/SMS",
          "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
        },
        {
          "id": "T1071.004",
          "name": "DNS",
          "display_name": "T1071.004 - DNS"
        },
        {
          "id": "T1071.001",
          "name": "Web Protocols",
          "display_name": "T1071.001 - Web Protocols"
        },
        {
          "id": "T1068",
          "name": "Exploitation for Privilege Escalation",
          "display_name": "T1068 - Exploitation for Privilege Escalation"
        },
        {
          "id": "T1056.001",
          "name": "Keylogging",
          "display_name": "T1056.001 - Keylogging"
        }
      ],
      "industries": [
        "Health"
      ],
      "TLP": "green",
      "cloned_from": "658741502e029e25c7152cc0",
      "export_count": 45,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 1643,
        "hostname": 1438,
        "CVE": 30,
        "FileHash-MD5": 2853,
        "FileHash-SHA1": 1584,
        "FileHash-SHA256": 3001,
        "URL": 2904,
        "email": 1
      },
      "indicator_count": 13454,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 221,
      "modified_text": "840 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "658741502e029e25c7152cc0",
      "name": "busted hijacking",
      "description": "",
      "modified": "2023-12-23T20:21:36.641000",
      "created": "2023-12-23T20:21:36.641000",
      "tags": [
        "cisco umbrella",
        "site",
        "alexa top",
        "emotet",
        "telefonica co",
        "million",
        "malware",
        "detection list",
        "blacklist",
        "alexa",
        "installcore",
        "heur",
        "cyber threat",
        "united",
        "phishing",
        "engineering",
        "phishing site",
        "team phishing",
        "spammer",
        "malicious site",
        "team",
        "download",
        "cobalt strike",
        "facebook",
        "artemis",
        "pony",
        "binder",
        "suppobox",
        "virut",
        "ramnit",
        "dropper",
        "formbook",
        "azorult",
        "simda",
        "downloader",
        "service",
        "bank",
        "zbot",
        "trojanspy",
        "heodo",
        "hostname",
        "hostnames",
        "whois record",
        "kgs0",
        "kls0",
        "apple ios",
        "tsara brashears",
        "ssl certificate",
        "elf collection",
        "cyberstalking",
        "spyware",
        "hackers",
        "installer",
        "open",
        "banker",
        "keylogger",
        "malicious",
        "hacktool",
        "core",
        "noname057",
        "generic malware",
        "safe site",
        "malware site",
        "iframe",
        "riskware",
        "exploit",
        "fakealert",
        "unsafe",
        "acint",
        "win64",
        "nircmd",
        "agent",
        "opencandy",
        "conduit",
        "swrort",
        "crack",
        "installpack",
        "xtrat",
        "psexec",
        "occamy",
        "brontok",
        "zpevdo",
        "startpage",
        "nanocore",
        "keygen",
        "fareit",
        "secrisk",
        "unruy",
        "filetour",
        "floxif",
        "cleaner",
        "patcher",
        "adload",
        "presenoker",
        "wacatac",
        "fusioncore",
        "genkryptik",
        "webtoolbar",
        "maltiverse",
        "smokeloader",
        "download json",
        "urls",
        "blacklist http",
        "kyriazhs1975",
        "vidar",
        "strike",
        "china cobalt",
        "meterpreter",
        "nanocore rat",
        "njrat",
        "redline stealer",
        "stealer",
        "nymaim",
        "mirai",
        "ghost rat",
        "runescape",
        "bradesco",
        "msil",
        "bladabindi",
        "orkut",
        "cutwail",
        "bandoo",
        "matsnu",
        "inmortal",
        "domains",
        "redline",
        "control server",
        "services",
        "generic",
        "br",
        "threat report",
        "ip summary",
        "url summary",
        "summary",
        "sample",
        "samples",
        "squirrelwaffle",
        "soc http",
        "soc https",
        "back",
        "download csv",
        "json sample",
        "injector",
        "malicious url",
        "downldr",
        "covid19 scam",
        "historical ssl",
        "referrer",
        "contacted",
        "whois whois",
        "contacted urls",
        "whois sslcert",
        "threat roundup",
        "copy",
        "august",
        "execution",
        "ransomware",
        "gopher",
        "remcos",
        "attack",
        "radar ineractive",
        "paypal",
        "covid19",
        "phishing chase",
        "phishing google",
        "tracker malware",
        "chase personal",
        "banking",
        "javascript",
        "please",
        "cnc server",
        "tracker",
        "cnc feodo",
        "phishtank",
        "threats et",
        "name verdict",
        "falcon sandbox",
        "pattern match",
        "file",
        "ascii text",
        "indicator",
        "windows nt",
        "jpeg image",
        "appdata",
        "jfif standard",
        "script",
        "show",
        "date",
        "span",
        "unknown",
        "general",
        "hybrid",
        "local",
        "click",
        "strings",
        "class",
        "generator",
        "critical",
        "error",
        "path",
        "http header",
        "tcp traffic",
        "mitre att",
        "ck id",
        "show technique",
        "ck matrix",
        "accept",
        "adware",
        "ip address",
        "hsbc",
        "outbreak",
        "downer",
        "shell",
        "mediamagnet",
        "sality",
        "adaptivebee",
        "iobit",
        "trojanx",
        "webshell",
        "systweak",
        "behav",
        "tiggre",
        "runtime process",
        "sha256",
        "sha1",
        "mark brian sabey",
        "brian sabey",
        "sabey",
        "apple",
        "114.114.114.114",
        "attorney",
        "law",
        "spammer",
        "fraud service",
        "hallrender",
        "malvertizing",
        "cybercrime",
        "social engineering",
        "malware hosting",
        "cyber threat",
        "iphone unlocker",
        "malicious",
        "attacker",
        "tulach",
        "tulach.cc",
        "adult content",
        "child pornographer",
        "sabey data centers",
        "hall render denver",
        "monitoring",
        "stalker",
        "dev",
        "developer",
        "cyber harassment",
        "defacement",
        "death threats",
        "miner",
        "agenttesla",
        "trojan",
        "detplock",
        "networm",
        "rms",
        "sneaky server",
        "replacement",
        "unauthorized",
        "steam route",
        "tool",
        "probe",
        "safebae.org",
        "safebae",
        "daisy",
        "daisy coleman",
        "benjamin",
        "colorado",
        "missouri",
        "telefonica",
        "boost mobile",
        "blackievirus.com",
        "TrojanX",
        "metro t-mobile",
        "t-mobile",
        "mile high media",
        "CNC",
        "C2",
        "malware host",
        "yixun"
      ],
      "references": [
        "https://hybrid-analysis.com/sample/a1b9247b6ad18f1cda0304e406333459d4000fced5753f91e5c046f6577c388a",
        "https://www.hallrender.com/attorney/brian-sabey",
        "safebae.org",
        "poemhunter.com",
        "http://www.hallrender.com/resources/blog/",
        "http://benjamin.xww.de/",
        "http://alohatube.xyz/search/tsara-brashears",
        "https://www.anyxxxtube.net/search-porn/tsara-brashears/",
        "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian",
        "Hybrid Analysis",
        "wTools",
        "Research"
      ],
      "public": 1,
      "adversary": "Tulach | Mark Brian Sabey | Hall Render Law Firm",
      "targeted_countries": [
        "United States of America",
        "Japan"
      ],
      "malware_families": [
        {
          "id": "TrojanSpy",
          "display_name": "TrojanSpy",
          "target": null
        },
        {
          "id": "WebToolbar",
          "display_name": "WebToolbar",
          "target": null
        },
        {
          "id": "Maltiverse",
          "display_name": "Maltiverse",
          "target": null
        },
        {
          "id": "Inmortal",
          "display_name": "Inmortal",
          "target": null
        },
        {
          "id": "Domains",
          "display_name": "Domains",
          "target": null
        },
        {
          "id": "RedLine",
          "display_name": "RedLine",
          "target": null
        },
        {
          "id": "BR",
          "display_name": "BR",
          "target": null
        },
        {
          "id": "Radar Ineractive",
          "display_name": "Radar Ineractive",
          "target": null
        },
        {
          "id": "HSBC",
          "display_name": "HSBC",
          "target": null
        },
        {
          "id": "RMS",
          "display_name": "RMS",
          "target": null
        },
        {
          "id": "Feodo Tracker",
          "display_name": "Feodo Tracker",
          "target": null
        },
        {
          "id": "Wacatac",
          "display_name": "Wacatac",
          "target": null
        },
        {
          "id": "Zpevdo",
          "display_name": "Zpevdo",
          "target": null
        },
        {
          "id": "Zbot",
          "display_name": "Zbot",
          "target": null
        },
        {
          "id": "OpenCandy",
          "display_name": "OpenCandy",
          "target": null
        },
        {
          "id": "xRAT",
          "display_name": "xRAT",
          "target": null
        },
        {
          "id": "Vidar",
          "display_name": "Vidar",
          "target": null
        },
        {
          "id": "Agent Tesla",
          "display_name": "Agent Tesla",
          "target": null
        },
        {
          "id": "noname057",
          "display_name": "noname057",
          "target": null
        },
        {
          "id": "TrojanSpy",
          "display_name": "TrojanSpy",
          "target": null
        },
        {
          "id": "DarkSide .Beware",
          "display_name": "DarkSide .Beware",
          "target": null
        },
        {
          "id": "Nymaim",
          "display_name": "Nymaim",
          "target": null
        },
        {
          "id": "SLFPER:BrowserModifier:Win32/MediaMagnet",
          "display_name": "SLFPER:BrowserModifier:Win32/MediaMagnet",
          "target": null
        },
        {
          "id": "Virut",
          "display_name": "Virut",
          "target": null
        },
        {
          "id": "Cutwail",
          "display_name": "Cutwail",
          "target": null
        },
        {
          "id": "Nanocore RAT",
          "display_name": "Nanocore RAT",
          "target": null
        },
        {
          "id": "Tulach Malware",
          "display_name": "Tulach Malware",
          "target": null
        },
        {
          "id": "SuppoBox",
          "display_name": "SuppoBox",
          "target": null
        },
        {
          "id": "Systweak",
          "display_name": "Systweak",
          "target": null
        },
        {
          "id": "Occamy",
          "display_name": "Occamy",
          "target": null
        },
        {
          "id": "Tiggre",
          "display_name": "Tiggre",
          "target": null
        },
        {
          "id": "IObit",
          "display_name": "IObit",
          "target": null
        },
        {
          "id": "Sality",
          "display_name": "Sality",
          "target": null
        },
        {
          "id": "FORMBOOK",
          "display_name": "FORMBOOK",
          "target": null
        },
        {
          "id": "Emotet",
          "display_name": "Emotet",
          "target": null
        },
        {
          "id": "Yixun",
          "display_name": "Yixun",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1496",
          "name": "Resource Hijacking",
          "display_name": "T1496 - Resource Hijacking"
        },
        {
          "id": "T1176",
          "name": "Browser Extensions",
          "display_name": "T1176 - Browser Extensions"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1041",
          "name": "Exfiltration Over C2 Channel",
          "display_name": "T1041 - Exfiltration Over C2 Channel"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1114",
          "name": "Email Collection",
          "display_name": "T1114 - Email Collection"
        },
        {
          "id": "T1497",
          "name": "Virtualization/Sandbox Evasion",
          "display_name": "T1497 - Virtualization/Sandbox Evasion"
        },
        {
          "id": "T1012",
          "name": "Query Registry",
          "display_name": "T1012 - Query Registry"
        },
        {
          "id": "T1043",
          "name": "Commonly Used Port",
          "display_name": "T1043 - Commonly Used Port"
        },
        {
          "id": "T1112",
          "name": "Modify Registry",
          "display_name": "T1112 - Modify Registry"
        },
        {
          "id": "T1179",
          "name": "Hooking",
          "display_name": "T1179 - Hooking"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1583.005",
          "name": "Botnet",
          "display_name": "T1583.005 - Botnet"
        },
        {
          "id": "T1449",
          "name": "Exploit SS7 to Redirect Phone Calls/SMS",
          "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
        },
        {
          "id": "T1071.004",
          "name": "DNS",
          "display_name": "T1071.004 - DNS"
        },
        {
          "id": "T1071.001",
          "name": "Web Protocols",
          "display_name": "T1071.001 - Web Protocols"
        },
        {
          "id": "T1068",
          "name": "Exploitation for Privilege Escalation",
          "display_name": "T1068 - Exploitation for Privilege Escalation"
        },
        {
          "id": "T1056.001",
          "name": "Keylogging",
          "display_name": "T1056.001 - Keylogging"
        }
      ],
      "industries": [
        "Health"
      ],
      "TLP": "green",
      "cloned_from": "6544c99af21a2fde7bd6927e",
      "export_count": 33,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Machidian45",
        "id": "262704",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 1643,
        "hostname": 1438,
        "CVE": 30,
        "FileHash-MD5": 2853,
        "FileHash-SHA1": 1584,
        "FileHash-SHA256": 3001,
        "URL": 2904,
        "email": 1
      },
      "indicator_count": 13454,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 32,
      "modified_text": "848 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6587414f2e029e25c7152cbf",
      "name": "busted hijacking",
      "description": "",
      "modified": "2023-12-23T20:21:35.725000",
      "created": "2023-12-23T20:21:35.725000",
      "tags": [
        "cisco umbrella",
        "site",
        "alexa top",
        "emotet",
        "telefonica co",
        "million",
        "malware",
        "detection list",
        "blacklist",
        "alexa",
        "installcore",
        "heur",
        "cyber threat",
        "united",
        "phishing",
        "engineering",
        "phishing site",
        "team phishing",
        "spammer",
        "malicious site",
        "team",
        "download",
        "cobalt strike",
        "facebook",
        "artemis",
        "pony",
        "binder",
        "suppobox",
        "virut",
        "ramnit",
        "dropper",
        "formbook",
        "azorult",
        "simda",
        "downloader",
        "service",
        "bank",
        "zbot",
        "trojanspy",
        "heodo",
        "hostname",
        "hostnames",
        "whois record",
        "kgs0",
        "kls0",
        "apple ios",
        "tsara brashears",
        "ssl certificate",
        "elf collection",
        "cyberstalking",
        "spyware",
        "hackers",
        "installer",
        "open",
        "banker",
        "keylogger",
        "malicious",
        "hacktool",
        "core",
        "noname057",
        "generic malware",
        "safe site",
        "malware site",
        "iframe",
        "riskware",
        "exploit",
        "fakealert",
        "unsafe",
        "acint",
        "win64",
        "nircmd",
        "agent",
        "opencandy",
        "conduit",
        "swrort",
        "crack",
        "installpack",
        "xtrat",
        "psexec",
        "occamy",
        "brontok",
        "zpevdo",
        "startpage",
        "nanocore",
        "keygen",
        "fareit",
        "secrisk",
        "unruy",
        "filetour",
        "floxif",
        "cleaner",
        "patcher",
        "adload",
        "presenoker",
        "wacatac",
        "fusioncore",
        "genkryptik",
        "webtoolbar",
        "maltiverse",
        "smokeloader",
        "download json",
        "urls",
        "blacklist http",
        "kyriazhs1975",
        "vidar",
        "strike",
        "china cobalt",
        "meterpreter",
        "nanocore rat",
        "njrat",
        "redline stealer",
        "stealer",
        "nymaim",
        "mirai",
        "ghost rat",
        "runescape",
        "bradesco",
        "msil",
        "bladabindi",
        "orkut",
        "cutwail",
        "bandoo",
        "matsnu",
        "inmortal",
        "domains",
        "redline",
        "control server",
        "services",
        "generic",
        "br",
        "threat report",
        "ip summary",
        "url summary",
        "summary",
        "sample",
        "samples",
        "squirrelwaffle",
        "soc http",
        "soc https",
        "back",
        "download csv",
        "json sample",
        "injector",
        "malicious url",
        "downldr",
        "covid19 scam",
        "historical ssl",
        "referrer",
        "contacted",
        "whois whois",
        "contacted urls",
        "whois sslcert",
        "threat roundup",
        "copy",
        "august",
        "execution",
        "ransomware",
        "gopher",
        "remcos",
        "attack",
        "radar ineractive",
        "paypal",
        "covid19",
        "phishing chase",
        "phishing google",
        "tracker malware",
        "chase personal",
        "banking",
        "javascript",
        "please",
        "cnc server",
        "tracker",
        "cnc feodo",
        "phishtank",
        "threats et",
        "name verdict",
        "falcon sandbox",
        "pattern match",
        "file",
        "ascii text",
        "indicator",
        "windows nt",
        "jpeg image",
        "appdata",
        "jfif standard",
        "script",
        "show",
        "date",
        "span",
        "unknown",
        "general",
        "hybrid",
        "local",
        "click",
        "strings",
        "class",
        "generator",
        "critical",
        "error",
        "path",
        "http header",
        "tcp traffic",
        "mitre att",
        "ck id",
        "show technique",
        "ck matrix",
        "accept",
        "adware",
        "ip address",
        "hsbc",
        "outbreak",
        "downer",
        "shell",
        "mediamagnet",
        "sality",
        "adaptivebee",
        "iobit",
        "trojanx",
        "webshell",
        "systweak",
        "behav",
        "tiggre",
        "runtime process",
        "sha256",
        "sha1",
        "mark brian sabey",
        "brian sabey",
        "sabey",
        "apple",
        "114.114.114.114",
        "attorney",
        "law",
        "spammer",
        "fraud service",
        "hallrender",
        "malvertizing",
        "cybercrime",
        "social engineering",
        "malware hosting",
        "cyber threat",
        "iphone unlocker",
        "malicious",
        "attacker",
        "tulach",
        "tulach.cc",
        "adult content",
        "child pornographer",
        "sabey data centers",
        "hall render denver",
        "monitoring",
        "stalker",
        "dev",
        "developer",
        "cyber harassment",
        "defacement",
        "death threats",
        "miner",
        "agenttesla",
        "trojan",
        "detplock",
        "networm",
        "rms",
        "sneaky server",
        "replacement",
        "unauthorized",
        "steam route",
        "tool",
        "probe",
        "safebae.org",
        "safebae",
        "daisy",
        "daisy coleman",
        "benjamin",
        "colorado",
        "missouri",
        "telefonica",
        "boost mobile",
        "blackievirus.com",
        "TrojanX",
        "metro t-mobile",
        "t-mobile",
        "mile high media",
        "CNC",
        "C2",
        "malware host",
        "yixun"
      ],
      "references": [
        "https://hybrid-analysis.com/sample/a1b9247b6ad18f1cda0304e406333459d4000fced5753f91e5c046f6577c388a",
        "https://www.hallrender.com/attorney/brian-sabey",
        "safebae.org",
        "poemhunter.com",
        "http://www.hallrender.com/resources/blog/",
        "http://benjamin.xww.de/",
        "http://alohatube.xyz/search/tsara-brashears",
        "https://www.anyxxxtube.net/search-porn/tsara-brashears/",
        "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian",
        "Hybrid Analysis",
        "wTools",
        "Research"
      ],
      "public": 1,
      "adversary": "Tulach | Mark Brian Sabey | Hall Render Law Firm",
      "targeted_countries": [
        "United States of America",
        "Japan"
      ],
      "malware_families": [
        {
          "id": "TrojanSpy",
          "display_name": "TrojanSpy",
          "target": null
        },
        {
          "id": "WebToolbar",
          "display_name": "WebToolbar",
          "target": null
        },
        {
          "id": "Maltiverse",
          "display_name": "Maltiverse",
          "target": null
        },
        {
          "id": "Inmortal",
          "display_name": "Inmortal",
          "target": null
        },
        {
          "id": "Domains",
          "display_name": "Domains",
          "target": null
        },
        {
          "id": "RedLine",
          "display_name": "RedLine",
          "target": null
        },
        {
          "id": "BR",
          "display_name": "BR",
          "target": null
        },
        {
          "id": "Radar Ineractive",
          "display_name": "Radar Ineractive",
          "target": null
        },
        {
          "id": "HSBC",
          "display_name": "HSBC",
          "target": null
        },
        {
          "id": "RMS",
          "display_name": "RMS",
          "target": null
        },
        {
          "id": "Feodo Tracker",
          "display_name": "Feodo Tracker",
          "target": null
        },
        {
          "id": "Wacatac",
          "display_name": "Wacatac",
          "target": null
        },
        {
          "id": "Zpevdo",
          "display_name": "Zpevdo",
          "target": null
        },
        {
          "id": "Zbot",
          "display_name": "Zbot",
          "target": null
        },
        {
          "id": "OpenCandy",
          "display_name": "OpenCandy",
          "target": null
        },
        {
          "id": "xRAT",
          "display_name": "xRAT",
          "target": null
        },
        {
          "id": "Vidar",
          "display_name": "Vidar",
          "target": null
        },
        {
          "id": "Agent Tesla",
          "display_name": "Agent Tesla",
          "target": null
        },
        {
          "id": "noname057",
          "display_name": "noname057",
          "target": null
        },
        {
          "id": "TrojanSpy",
          "display_name": "TrojanSpy",
          "target": null
        },
        {
          "id": "DarkSide .Beware",
          "display_name": "DarkSide .Beware",
          "target": null
        },
        {
          "id": "Nymaim",
          "display_name": "Nymaim",
          "target": null
        },
        {
          "id": "SLFPER:BrowserModifier:Win32/MediaMagnet",
          "display_name": "SLFPER:BrowserModifier:Win32/MediaMagnet",
          "target": null
        },
        {
          "id": "Virut",
          "display_name": "Virut",
          "target": null
        },
        {
          "id": "Cutwail",
          "display_name": "Cutwail",
          "target": null
        },
        {
          "id": "Nanocore RAT",
          "display_name": "Nanocore RAT",
          "target": null
        },
        {
          "id": "Tulach Malware",
          "display_name": "Tulach Malware",
          "target": null
        },
        {
          "id": "SuppoBox",
          "display_name": "SuppoBox",
          "target": null
        },
        {
          "id": "Systweak",
          "display_name": "Systweak",
          "target": null
        },
        {
          "id": "Occamy",
          "display_name": "Occamy",
          "target": null
        },
        {
          "id": "Tiggre",
          "display_name": "Tiggre",
          "target": null
        },
        {
          "id": "IObit",
          "display_name": "IObit",
          "target": null
        },
        {
          "id": "Sality",
          "display_name": "Sality",
          "target": null
        },
        {
          "id": "FORMBOOK",
          "display_name": "FORMBOOK",
          "target": null
        },
        {
          "id": "Emotet",
          "display_name": "Emotet",
          "target": null
        },
        {
          "id": "Yixun",
          "display_name": "Yixun",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1496",
          "name": "Resource Hijacking",
          "display_name": "T1496 - Resource Hijacking"
        },
        {
          "id": "T1176",
          "name": "Browser Extensions",
          "display_name": "T1176 - Browser Extensions"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1041",
          "name": "Exfiltration Over C2 Channel",
          "display_name": "T1041 - Exfiltration Over C2 Channel"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1114",
          "name": "Email Collection",
          "display_name": "T1114 - Email Collection"
        },
        {
          "id": "T1497",
          "name": "Virtualization/Sandbox Evasion",
          "display_name": "T1497 - Virtualization/Sandbox Evasion"
        },
        {
          "id": "T1012",
          "name": "Query Registry",
          "display_name": "T1012 - Query Registry"
        },
        {
          "id": "T1043",
          "name": "Commonly Used Port",
          "display_name": "T1043 - Commonly Used Port"
        },
        {
          "id": "T1112",
          "name": "Modify Registry",
          "display_name": "T1112 - Modify Registry"
        },
        {
          "id": "T1179",
          "name": "Hooking",
          "display_name": "T1179 - Hooking"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1583.005",
          "name": "Botnet",
          "display_name": "T1583.005 - Botnet"
        },
        {
          "id": "T1449",
          "name": "Exploit SS7 to Redirect Phone Calls/SMS",
          "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
        },
        {
          "id": "T1071.004",
          "name": "DNS",
          "display_name": "T1071.004 - DNS"
        },
        {
          "id": "T1071.001",
          "name": "Web Protocols",
          "display_name": "T1071.001 - Web Protocols"
        },
        {
          "id": "T1068",
          "name": "Exploitation for Privilege Escalation",
          "display_name": "T1068 - Exploitation for Privilege Escalation"
        },
        {
          "id": "T1056.001",
          "name": "Keylogging",
          "display_name": "T1056.001 - Keylogging"
        }
      ],
      "industries": [
        "Health"
      ],
      "TLP": "green",
      "cloned_from": "6544c99af21a2fde7bd6927e",
      "export_count": 34,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Machidian45",
        "id": "262704",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 1643,
        "hostname": 1438,
        "CVE": 30,
        "FileHash-MD5": 2853,
        "FileHash-SHA1": 1584,
        "FileHash-SHA256": 3001,
        "URL": 2904,
        "email": 1
      },
      "indicator_count": 13454,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 34,
      "modified_text": "848 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6544c7a11d7541bdb3bfe5ff",
      "name": "Radar Ineractive. Law Firm responsible for cyber crime.",
      "description": "Is this legal.  Attorney from Hall Render law firm cyber stalking  and malvertizing targets in adult content, dungeons, death scenarios, suicide threats? Pulse auto populates targets: Tsara Brashears 'alleged'  SA victim. This may not be the forum for my , death threats should always be investigated as should allegations of assault. Malware, BotNet, car and phone tracking, monitoring, injection,   .gov is found throughout. Monitoring of Safebae.org; online movement began by now deceased 'alleged' SA victim, Daisy Coleman of Audrey & Daisy.  High Risk surviving target. Crazy cover up? Each target seems to have a state government power 'implicated' in attack. \n\nEd Said",
      "modified": "2023-12-16T19:40:11.047000",
      "created": "2023-11-03T10:12:49.539000",
      "tags": [
        "cisco umbrella",
        "site",
        "alexa top",
        "emotet",
        "telefonica co",
        "million",
        "malware",
        "detection list",
        "blacklist",
        "alexa",
        "installcore",
        "heur",
        "cyber threat",
        "united",
        "phishing",
        "engineering",
        "phishing site",
        "team phishing",
        "spammer",
        "malicious site",
        "team",
        "download",
        "cobalt strike",
        "facebook",
        "artemis",
        "pony",
        "binder",
        "suppobox",
        "virut",
        "ramnit",
        "dropper",
        "formbook",
        "azorult",
        "simda",
        "downloader",
        "service",
        "bank",
        "zbot",
        "trojanspy",
        "heodo",
        "hostname",
        "hostnames",
        "whois record",
        "kgs0",
        "kls0",
        "apple ios",
        "tsara brashears",
        "ssl certificate",
        "elf collection",
        "cyberstalking",
        "spyware",
        "hackers",
        "installer",
        "open",
        "banker",
        "keylogger",
        "malicious",
        "hacktool",
        "core",
        "noname057",
        "generic malware",
        "safe site",
        "malware site",
        "iframe",
        "riskware",
        "exploit",
        "fakealert",
        "unsafe",
        "acint",
        "win64",
        "nircmd",
        "agent",
        "opencandy",
        "conduit",
        "swrort",
        "crack",
        "installpack",
        "xtrat",
        "psexec",
        "occamy",
        "brontok",
        "zpevdo",
        "startpage",
        "nanocore",
        "keygen",
        "fareit",
        "secrisk",
        "unruy",
        "filetour",
        "floxif",
        "cleaner",
        "patcher",
        "adload",
        "presenoker",
        "wacatac",
        "fusioncore",
        "genkryptik",
        "webtoolbar",
        "maltiverse",
        "smokeloader",
        "download json",
        "urls",
        "blacklist http",
        "kyriazhs1975",
        "vidar",
        "strike",
        "china cobalt",
        "meterpreter",
        "nanocore rat",
        "njrat",
        "redline stealer",
        "stealer",
        "nymaim",
        "mirai",
        "ghost rat",
        "runescape",
        "bradesco",
        "msil",
        "bladabindi",
        "orkut",
        "cutwail",
        "bandoo",
        "matsnu",
        "inmortal",
        "domains",
        "redline",
        "control server",
        "services",
        "generic",
        "br",
        "threat report",
        "ip summary",
        "url summary",
        "summary",
        "sample",
        "samples",
        "squirrelwaffle",
        "soc http",
        "soc https",
        "back",
        "download csv",
        "json sample",
        "injector",
        "malicious url",
        "downldr",
        "covid19 scam",
        "historical ssl",
        "referrer",
        "contacted",
        "whois whois",
        "contacted urls",
        "whois sslcert",
        "threat roundup",
        "copy",
        "august",
        "execution",
        "ransomware",
        "gopher",
        "remcos",
        "attack",
        "radar ineractive",
        "paypal",
        "covid19",
        "phishing chase",
        "phishing google",
        "tracker malware",
        "chase personal",
        "banking",
        "javascript",
        "please",
        "cnc server",
        "tracker",
        "cnc feodo",
        "phishtank",
        "threats et",
        "name verdict",
        "falcon sandbox",
        "pattern match",
        "file",
        "ascii text",
        "indicator",
        "windows nt",
        "jpeg image",
        "appdata",
        "jfif standard",
        "script",
        "show",
        "date",
        "span",
        "unknown",
        "general",
        "hybrid",
        "local",
        "click",
        "strings",
        "class",
        "generator",
        "critical",
        "error",
        "path",
        "http header",
        "tcp traffic",
        "mitre att",
        "ck id",
        "show technique",
        "ck matrix",
        "accept",
        "adware",
        "ip address",
        "hsbc",
        "outbreak",
        "downer",
        "shell",
        "mediamagnet",
        "sality",
        "adaptivebee",
        "iobit",
        "trojanx",
        "webshell",
        "systweak",
        "behav",
        "tiggre",
        "runtime process",
        "sha256",
        "sha1",
        "mark brian sabey",
        "brian sabey",
        "sabey",
        "apple",
        "114.114.114.114",
        "attorney",
        "law",
        "spammer",
        "fraud service",
        "hallrender",
        "malvertizing",
        "cybercrime",
        "social engineering",
        "malware hosting",
        "cyber threat",
        "iphone unlocker",
        "malicious",
        "attacker",
        "tulach",
        "tulach.cc",
        "adult content",
        "child pornographer",
        "sabey data centers",
        "hall render denver",
        "monitoring",
        "stalker",
        "dev",
        "developer",
        "cyber harassment",
        "defacement",
        "death threats",
        "miner",
        "agenttesla",
        "trojan",
        "detplock",
        "networm",
        "rms",
        "sneaky server",
        "replacement",
        "unauthorized",
        "steam route",
        "tool",
        "probe",
        "safebae.org",
        "safebae",
        "daisy",
        "daisy coleman",
        "benjamin",
        "colorado",
        "missouri",
        "telefonica",
        "boost mobile",
        "blackievirus.com",
        "TrojanX",
        "metro t-mobile",
        "t-mobile",
        "mile high media",
        "CNC",
        "C2",
        "malware host",
        "yixun"
      ],
      "references": [
        "https://hybrid-analysis.com/sample/a1b9247b6ad18f1cda0304e406333459d4000fced5753f91e5c046f6577c388a",
        "https://www.hallrender.com/attorney/brian-sabey",
        "safebae.org",
        "poemhunter.com",
        "http://www.hallrender.com/resources/blog/",
        "http://benjamin.xww.de/",
        "http://alohatube.xyz/search/tsara-brashears",
        "https://www.anyxxxtube.net/search-porn/tsara-brashears/",
        "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian",
        "Hybrid Analysis",
        "wTools",
        "Research"
      ],
      "public": 1,
      "adversary": "Tulach | Mark Brian Sabey | Hall Render Law Firm",
      "targeted_countries": [
        "United States of America",
        "Japan"
      ],
      "malware_families": [
        {
          "id": "TrojanSpy",
          "display_name": "TrojanSpy",
          "target": null
        },
        {
          "id": "WebToolbar",
          "display_name": "WebToolbar",
          "target": null
        },
        {
          "id": "Maltiverse",
          "display_name": "Maltiverse",
          "target": null
        },
        {
          "id": "Inmortal",
          "display_name": "Inmortal",
          "target": null
        },
        {
          "id": "Domains",
          "display_name": "Domains",
          "target": null
        },
        {
          "id": "RedLine",
          "display_name": "RedLine",
          "target": null
        },
        {
          "id": "BR",
          "display_name": "BR",
          "target": null
        },
        {
          "id": "Radar Ineractive",
          "display_name": "Radar Ineractive",
          "target": null
        },
        {
          "id": "HSBC",
          "display_name": "HSBC",
          "target": null
        },
        {
          "id": "RMS",
          "display_name": "RMS",
          "target": null
        },
        {
          "id": "Feodo Tracker",
          "display_name": "Feodo Tracker",
          "target": null
        },
        {
          "id": "Wacatac",
          "display_name": "Wacatac",
          "target": null
        },
        {
          "id": "Zpevdo",
          "display_name": "Zpevdo",
          "target": null
        },
        {
          "id": "Zbot",
          "display_name": "Zbot",
          "target": null
        },
        {
          "id": "OpenCandy",
          "display_name": "OpenCandy",
          "target": null
        },
        {
          "id": "xRAT",
          "display_name": "xRAT",
          "target": null
        },
        {
          "id": "Vidar",
          "display_name": "Vidar",
          "target": null
        },
        {
          "id": "Agent Tesla",
          "display_name": "Agent Tesla",
          "target": null
        },
        {
          "id": "noname057",
          "display_name": "noname057",
          "target": null
        },
        {
          "id": "TrojanSpy",
          "display_name": "TrojanSpy",
          "target": null
        },
        {
          "id": "DarkSide .Beware",
          "display_name": "DarkSide .Beware",
          "target": null
        },
        {
          "id": "Nymaim",
          "display_name": "Nymaim",
          "target": null
        },
        {
          "id": "SLFPER:BrowserModifier:Win32/MediaMagnet",
          "display_name": "SLFPER:BrowserModifier:Win32/MediaMagnet",
          "target": null
        },
        {
          "id": "Virut",
          "display_name": "Virut",
          "target": null
        },
        {
          "id": "Cutwail",
          "display_name": "Cutwail",
          "target": null
        },
        {
          "id": "Nanocore RAT",
          "display_name": "Nanocore RAT",
          "target": null
        },
        {
          "id": "Tulach Malware",
          "display_name": "Tulach Malware",
          "target": null
        },
        {
          "id": "SuppoBox",
          "display_name": "SuppoBox",
          "target": null
        },
        {
          "id": "Systweak",
          "display_name": "Systweak",
          "target": null
        },
        {
          "id": "Occamy",
          "display_name": "Occamy",
          "target": null
        },
        {
          "id": "Tiggre",
          "display_name": "Tiggre",
          "target": null
        },
        {
          "id": "IObit",
          "display_name": "IObit",
          "target": null
        },
        {
          "id": "Sality",
          "display_name": "Sality",
          "target": null
        },
        {
          "id": "FORMBOOK",
          "display_name": "FORMBOOK",
          "target": null
        },
        {
          "id": "Emotet",
          "display_name": "Emotet",
          "target": null
        },
        {
          "id": "Yixun",
          "display_name": "Yixun",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1496",
          "name": "Resource Hijacking",
          "display_name": "T1496 - Resource Hijacking"
        },
        {
          "id": "T1176",
          "name": "Browser Extensions",
          "display_name": "T1176 - Browser Extensions"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1041",
          "name": "Exfiltration Over C2 Channel",
          "display_name": "T1041 - Exfiltration Over C2 Channel"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1114",
          "name": "Email Collection",
          "display_name": "T1114 - Email Collection"
        },
        {
          "id": "T1497",
          "name": "Virtualization/Sandbox Evasion",
          "display_name": "T1497 - Virtualization/Sandbox Evasion"
        },
        {
          "id": "T1012",
          "name": "Query Registry",
          "display_name": "T1012 - Query Registry"
        },
        {
          "id": "T1043",
          "name": "Commonly Used Port",
          "display_name": "T1043 - Commonly Used Port"
        },
        {
          "id": "T1112",
          "name": "Modify Registry",
          "display_name": "T1112 - Modify Registry"
        },
        {
          "id": "T1179",
          "name": "Hooking",
          "display_name": "T1179 - Hooking"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1583.005",
          "name": "Botnet",
          "display_name": "T1583.005 - Botnet"
        },
        {
          "id": "T1449",
          "name": "Exploit SS7 to Redirect Phone Calls/SMS",
          "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
        },
        {
          "id": "T1071.004",
          "name": "DNS",
          "display_name": "T1071.004 - DNS"
        },
        {
          "id": "T1071.001",
          "name": "Web Protocols",
          "display_name": "T1071.001 - Web Protocols"
        },
        {
          "id": "T1068",
          "name": "Exploitation for Privilege Escalation",
          "display_name": "T1068 - Exploitation for Privilege Escalation"
        },
        {
          "id": "T1056.001",
          "name": "Keylogging",
          "display_name": "T1056.001 - Keylogging"
        }
      ],
      "industries": [
        "Health"
      ],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 82,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 1,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 1644,
        "hostname": 1438,
        "CVE": 30,
        "FileHash-MD5": 2853,
        "FileHash-SHA1": 1584,
        "FileHash-SHA256": 3001,
        "URL": 2904,
        "email": 1
      },
      "indicator_count": 13455,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 222,
      "modified_text": "855 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6570a161f0681f4ff3d67feb",
      "name": "Pool's Closed (by @scnrscnr)",
      "description": "",
      "modified": "2023-12-06T16:29:21.844000",
      "created": "2023-12-06T16:29:21.844000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 10,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 7844,
        "FileHash-MD5": 562,
        "FileHash-SHA1": 429,
        "URL": 22749,
        "hostname": 9461,
        "domain": 4578,
        "SSLCertFingerprint": 20,
        "CIDR": 32,
        "email": 3,
        "CVE": 2
      },
      "indicator_count": 45680,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 111,
      "modified_text": "865 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6570a145926a5676de0e2a1a",
      "name": "Pool's Closed (by @scnrscnr)",
      "description": "",
      "modified": "2023-12-06T16:28:53.979000",
      "created": "2023-12-06T16:28:53.979000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 9,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 7844,
        "FileHash-MD5": 562,
        "FileHash-SHA1": 429,
        "URL": 22749,
        "hostname": 9461,
        "domain": 4578,
        "SSLCertFingerprint": 20,
        "CIDR": 32,
        "email": 3,
        "CVE": 2
      },
      "indicator_count": 45680,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 111,
      "modified_text": "865 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "65707b9630308cb99a817277",
      "name": "Pool's Closed",
      "description": "",
      "modified": "2023-12-06T13:48:06.514000",
      "created": "2023-12-06T13:48:06.514000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 3,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 7844,
        "FileHash-MD5": 562,
        "FileHash-SHA1": 429,
        "URL": 22749,
        "hostname": 9461,
        "domain": 4578,
        "SSLCertFingerprint": 20,
        "CIDR": 32,
        "email": 3,
        "CVE": 2
      },
      "indicator_count": 45680,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 111,
      "modified_text": "865 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "https://nutzerreaktion.de",
    "type": "URL"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "https://nutzerreaktion.de",
    "type": "URL",
    "found": false,
    "verdict": "clean",
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1776641661.6020482
}