{
  "type": "URL",
  "indicator": "https://occasionallyhumans.com",
  "general": {
    "sections": [
      "general",
      "url_list",
      "http_scans",
      "screenshot"
    ],
    "indicator": "https://occasionallyhumans.com",
    "type": "url",
    "type_title": "URL",
    "validation": [],
    "base_indicator": {
      "id": 4063855008,
      "indicator": "https://occasionallyhumans.com",
      "type": "URL",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 5,
      "pulses": [
        {
          "id": "69fee87278bb07a0d0b5a92f",
          "name": "Most all from April 28,2025 - New Spam Email Dump - 2024 edition CREATED 2 YEARS AGO MODIFIED 2 WEEKS AGO by Silius_Soddus clone",
          "description": "",
          "modified": "2026-05-09T07:55:30.061000",
          "created": "2026-05-09T07:55:30.061000",
          "tags": [
            "Spam",
            "Fake delivery notification"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": "65bd484c6d37209568778727",
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 249,
            "domain": 118,
            "hostname": 49,
            "FileHash-MD5": 18,
            "FileHash-SHA1": 18,
            "URL": 111,
            "email": 1
          },
          "indicator_count": 564,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 67,
          "modified_text": "23 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "69fee86d0a3fb70b06212cc9",
          "name": "Most all from April 28,2025 - New Spam Email Dump - 2024 edition CREATED 2 YEARS AGO MODIFIED 2 WEEKS AGO by Silius_Soddus clone",
          "description": "",
          "modified": "2026-05-09T07:55:25.485000",
          "created": "2026-05-09T07:55:25.485000",
          "tags": [
            "Spam",
            "Fake delivery notification"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": "65bd484c6d37209568778727",
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 249,
            "domain": 118,
            "hostname": 49,
            "FileHash-MD5": 18,
            "FileHash-SHA1": 18,
            "URL": 111,
            "email": 1
          },
          "indicator_count": 564,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 67,
          "modified_text": "23 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "65bd484c6d37209568778727",
          "name": "New Spam Email Dump - 2024 edition",
          "description": "New place for me to dump IOCs for the year ahead",
          "modified": "2026-04-24T23:04:40.568000",
          "created": "2024-02-02T19:53:48.419000",
          "tags": [
            "Spam",
            "Fake delivery notification"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 5,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Silius_Soddus",
            "id": "67731",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_67731/resized/80/avatar_51e2b48419.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 249,
            "domain": 118,
            "hostname": 49,
            "FileHash-MD5": 18,
            "FileHash-SHA1": 18,
            "URL": 111,
            "email": 1
          },
          "indicator_count": 564,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 77,
          "modified_text": "37 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "692f23547b713b128b9c8156",
          "name": "Indicator Deletion Attack | Chris P. Ahmann Esq  still utilizes parking crews to execute cyber attacks",
          "description": "Unable to open malware indicators at this time. These attackers use Parking Crews for their exploits, leasing parked  domains for the amount of time needed to execute an attack. The attack last predate me ever using Level Blue. I have to review  indicators reports more closely but, I do see a the multitude of attacks against target TLB and an intersection of attacks concerning Disable_Duck (Alberta) Chris Ahmann , Colorado government indicated. \n\n[OTX auto populated - Adversaries may use techniques to evade detection in their malware or tools, as well as using techniques such as code signing, encryption, and other techniques for avoiding detection and monitoring of their activities.]",
          "modified": "2026-01-01T17:01:48.163000",
          "created": "2025-12-02T17:35:15.203000",
          "tags": [
            "data upload",
            "extraction",
            "failed",
            "learn",
            "ck id",
            "name tactics",
            "suspicious",
            "informative",
            "adversaries",
            "command",
            "defense evasion",
            "spawns",
            "development att",
            "united",
            "flag",
            "poland poland",
            "windir",
            "openurl c",
            "prefetch2",
            "analysis",
            "tor analysis",
            "dns requests",
            "domain address",
            "mitre att",
            "ck matrix",
            "pattern match",
            "ascii text",
            "show process",
            "network traffic",
            "t1057",
            "general",
            "local",
            "path",
            "encrypt",
            "hosts ip",
            "details",
            "ssl certificate",
            "sha256",
            "sha1",
            "size",
            "unicode text",
            "crlf",
            "utf8",
            "lf line",
            "server",
            "command decode",
            "markmonitor",
            "amazon",
            "ltd dba",
            "com laude",
            "organization",
            "click",
            "show technique",
            "brand",
            "microsoft edge",
            "windows nt",
            "win64",
            "khtml",
            "gecko",
            "submitted",
            "prefetch1",
            "name server",
            "misc attack",
            "et tor",
            "known tor",
            "relayrouter",
            "contacted hosts",
            "google",
            "pornhub",
            "ip address",
            "t1480 execution",
            "file defense",
            "passive dns",
            "related nids",
            "urls",
            "files location",
            "flag united"
          ],
          "references": [
            "deploy-delete-app-us-east-2-1.deploy-delete-test-us-east-2-1mtsufd.us-east-2.gamma.forgeapps.ec2.aws.dev",
            "Amazon.com \u2022 Google.com \u2022YouTube.com, Apple.com ,  etc Exploited",
            "cloudendpointsapis.com \u2022 https://www.vgt.pl/style/style.css \u2022 ceidg.gov.pl",
            "pl.wikipedia.org \u2022  fontawesome.io \u2022  opensource.org \u2022 videojet.com",
            "https://discoverreceiver.gurus.vmicrosoft.com/ \u2022 account.live.com \u2022 acctcdn.msauth.net",
            "https://www.milehighmedia.com/legal/2257",
            "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian",
            "https://twitter.com/PORNO_SEXYBABES",
            "http://www.anyxxxtube.net/search-porn/tsara-brashears",
            "https://wallpapers-nature.com/tsara-brashears/urlscan-io",
            "http://www.anyxxxtube.net/search-porn/tsara-brashears-denies-jeffrey-scott-reimer-sex",
            "http://www.anyxxxtube.net/search-porn/tsara-brashears/",
            "https://wallpapers-nature.com/tsara-brashears/tse1-mm-bing-net \u2022 wallpapers-nature.com",
            "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian \u2022",
            "https://wallpapers-nature.com/ tsara-brashears/urlscan-io",
            "https://wallpapers-nature.com/%20tsara-brashears/urlscan-io",
            "http://aplikacja.ceidg.gov.pl/CEIDG/CEIDG.Public.UI/EntryChangeHistory.Id=7a025cc6",
            "(Delete app that removed YoiTube views) www.youtube.com/watch?v=GyuMozsVyYs",
            "http://watchhers.net/index.php",
            "everesttech.net \u2022 aws.amazon.com \u2022  cm.everesttech.net \u2022 dpm.demdex.net \u2022 s3.amazonaws.com"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "CVE-2023-22518",
              "display_name": "CVE-2023-22518",
              "target": null
            },
            {
              "id": "Other Malware",
              "display_name": "Other Malware",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1069",
              "name": "Permission Groups Discovery",
              "display_name": "T1069 - Permission Groups Discovery"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1480",
              "name": "Execution Guardrails",
              "display_name": "T1480 - Execution Guardrails"
            },
            {
              "id": "T1539",
              "name": "Steal Web Session Cookie",
              "display_name": "T1539 - Steal Web Session Cookie"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1562",
              "name": "Impair Defenses",
              "display_name": "T1562 - Impair Defenses"
            },
            {
              "id": "T1568",
              "name": "Dynamic Resolution",
              "display_name": "T1568 - Dynamic Resolution"
            },
            {
              "id": "T1583",
              "name": "Acquire Infrastructure",
              "display_name": "T1583 - Acquire Infrastructure"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1518",
              "name": "Software Discovery",
              "display_name": "T1518 - Software Discovery"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Q.Vashti",
            "id": "337942",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 1358,
            "FileHash-MD5": 100,
            "FileHash-SHA1": 102,
            "FileHash-SHA256": 1682,
            "URL": 2497,
            "CVE": 2,
            "domain": 400,
            "SSLCertFingerprint": 6,
            "email": 3
          },
          "indicator_count": 6150,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 142,
          "modified_text": "150 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "68e32dd0c55bf224eb99dd58",
          "name": "Appspot.com - Google account fraud & infostealing",
          "description": "Fake Google email accounts. I\u2019ve reviewed a handful of targets with this issue. If starting with a new device, signed up for a new google account,\nthe users are automatically logged out, forced to sign in again, checked security features where you can see an unauthorized autonomous general\nphone, or iPhone or MacBook was also signed in in a different location. Even if you delete the device or email account, I\u2019ve seen the intruder handle CnC of all backups of photos and clouds. \n\n\n\n[OTX auto populated - The full list of domain names: APPSPot.COM.com, which was created on the same day as the Google search engine, has been published by the internet regulator, the IANA.]",
          "modified": "2025-11-05T01:01:26.928000",
          "created": "2025-10-06T02:47:44.098000",
          "tags": [
            "aaaa",
            "susp",
            "trojan",
            "google",
            "server",
            "domain status",
            "registrar abuse",
            "domain name",
            "us registrant",
            "email",
            "contact email",
            "rdap database",
            "google app",
            "google hosted",
            "please",
            "vulnerabilities",
            "join",
            "bring",
            "api explorer",
            "engine",
            "admin sdk",
            "info",
            "learn",
            "ck id",
            "name tactics",
            "suspicious",
            "informative",
            "adversaries",
            "command",
            "defense evasion",
            "ssl certificate",
            "ascii text",
            "united",
            "pattern match",
            "mitre att",
            "general",
            "local",
            "path",
            "click",
            "strings",
            "porn",
            "phishing",
            "fraud",
            "sandbox",
            "malware",
            "analysis",
            "online",
            "submit",
            "vxstream",
            "download",
            "apt",
            "ansi",
            "dumps",
            "file string",
            "seen",
            "disabled hash",
            "close",
            "hosts",
            "contact",
            "tellwise",
            "passive dns",
            "urls",
            "pulse pulses",
            "files",
            "verdict",
            "domain",
            "files ip",
            "address",
            "location united",
            "asn as15169",
            "extraction",
            "data upload",
            "extra",
            "referen http",
            "changed data",
            "failed",
            "include review",
            "t07 exclude",
            "extri data",
            "changed",
            "exclude",
            "find s",
            "tvnes data",
            "status",
            "present nov",
            "name servers",
            "entries",
            "geoid no",
            "present dec",
            "date",
            "error",
            "title",
            "sugges",
            "typ no",
            "no entrieotound",
            "scam",
            "foundry",
            "sabey type",
            "denver",
            "quasi",
            "phoenix",
            "australia"
          ],
          "references": [
            "appspot.com  \u2022 hyper7install.appspot.com",
            "https://hybrid-analysis.com/sample/c61237fcb798f05e6af32a6aa13f8e795aac47559d601eb7f93ad65bcf58b418/68e30c476b91a8000b0dd786",
            "http://acounts.google.com/v/signin/identifier?continue=hts%253%252F2Fconsole.cloud.google.com2Fapengine&dsh=5-1106814258%2539876543210",
            "Changed last several digits of gmail account # In example",
            "http://console.cloud.google.com/appengine",
            "https://310940000.android.com.twitter.android.adsenseformobileapps.com/",
            "https://www.netify.ai/resources/domains \u2022 192-168-0-21.3pt3m9ng2hf.ddns.manage.alta.inc",
            "device-local-de06e551-6b23-4aa3-bb67-6972ae6d30b5.remotewd.com 192.168.0.21",
            "116e33e0-8832-11ec-aef5-99a1d044639a-local.solinkcloud.com",
            "jaycobundaberg.eclipseaurahub.com.au 192.168.0.21",
            "grafana.ledocloud.com\u2022 192.168.0.21",
            "192-168-0-21.siliconevalley1.direct.quickconnect.to"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Win32/Madang",
              "display_name": "Win32/Madang",
              "target": null
            },
            {
              "id": "Win.Downloader.Small-1966",
              "display_name": "Win.Downloader.Small-1966",
              "target": null
            },
            {
              "id": "Win32:SaliCode",
              "display_name": "Win32:SaliCode",
              "target": null
            },
            {
              "id": "Virtool:Win32/Vbinder.CO",
              "display_name": "Virtool:Win32/Vbinder.CO",
              "target": "/malware/Virtool:Win32/Vbinder.CO"
            },
            {
              "id": "!Themida",
              "display_name": "!Themida",
              "target": null
            },
            {
              "id": "Virus:Win32/Sality.AT",
              "display_name": "Virus:Win32/Sality.AT",
              "target": "/malware/Virus:Win32/Sality.AT"
            },
            {
              "id": "Win32/Scrarev.C",
              "display_name": "Win32/Scrarev.C",
              "target": null
            },
            {
              "id": "Trojan:MSIL/RapidStealer.A",
              "display_name": "Trojan:MSIL/RapidStealer.A",
              "target": "/malware/Trojan:MSIL/RapidStealer.A"
            }
          ],
          "attack_ids": [
            {
              "id": "T1204",
              "name": "User Execution",
              "display_name": "T1204 - User Execution"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1069",
              "name": "Permission Groups Discovery",
              "display_name": "T1069 - Permission Groups Discovery"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1480",
              "name": "Execution Guardrails",
              "display_name": "T1480 - Execution Guardrails"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1562",
              "name": "Impair Defenses",
              "display_name": "T1562 - Impair Defenses"
            },
            {
              "id": "T1583",
              "name": "Acquire Infrastructure",
              "display_name": "T1583 - Acquire Infrastructure"
            },
            {
              "id": "T1113",
              "name": "Screen Capture",
              "display_name": "T1113 - Screen Capture"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1598",
              "name": "Phishing for Information",
              "display_name": "T1598 - Phishing for Information"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 9,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Q.Vashti",
            "id": "337942",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 222,
            "FileHash-MD5": 146,
            "FileHash-SHA1": 317,
            "FileHash-SHA256": 1120,
            "email": 3,
            "hostname": 881,
            "URL": 1338,
            "SSLCertFingerprint": 7
          },
          "indicator_count": 4034,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 143,
          "modified_text": "208 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "http://watchhers.net/index.php",
        "https://hybrid-analysis.com/sample/c61237fcb798f05e6af32a6aa13f8e795aac47559d601eb7f93ad65bcf58b418/68e30c476b91a8000b0dd786",
        "cloudendpointsapis.com \u2022 https://www.vgt.pl/style/style.css \u2022 ceidg.gov.pl",
        "https://wallpapers-nature.com/tsara-brashears/urlscan-io",
        "https://www.netify.ai/resources/domains \u2022 192-168-0-21.3pt3m9ng2hf.ddns.manage.alta.inc",
        "(Delete app that removed YoiTube views) www.youtube.com/watch?v=GyuMozsVyYs",
        "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian \u2022",
        "Changed last several digits of gmail account # In example",
        "device-local-de06e551-6b23-4aa3-bb67-6972ae6d30b5.remotewd.com 192.168.0.21",
        "deploy-delete-app-us-east-2-1.deploy-delete-test-us-east-2-1mtsufd.us-east-2.gamma.forgeapps.ec2.aws.dev",
        "http://www.anyxxxtube.net/search-porn/tsara-brashears",
        "https://wallpapers-nature.com/ tsara-brashears/urlscan-io",
        "https://wallpapers-nature.com/%20tsara-brashears/urlscan-io",
        "116e33e0-8832-11ec-aef5-99a1d044639a-local.solinkcloud.com",
        "https://www.milehighmedia.com/legal/2257",
        "grafana.ledocloud.com\u2022 192.168.0.21",
        "https://discoverreceiver.gurus.vmicrosoft.com/ \u2022 account.live.com \u2022 acctcdn.msauth.net",
        "http://www.anyxxxtube.net/search-porn/tsara-brashears-denies-jeffrey-scott-reimer-sex",
        "Amazon.com \u2022 Google.com \u2022YouTube.com, Apple.com ,  etc Exploited",
        "everesttech.net \u2022 aws.amazon.com \u2022  cm.everesttech.net \u2022 dpm.demdex.net \u2022 s3.amazonaws.com",
        "192-168-0-21.siliconevalley1.direct.quickconnect.to",
        "http://acounts.google.com/v/signin/identifier?continue=hts%253%252F2Fconsole.cloud.google.com2Fapengine&dsh=5-1106814258%2539876543210",
        "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian",
        "http://console.cloud.google.com/appengine",
        "pl.wikipedia.org \u2022  fontawesome.io \u2022  opensource.org \u2022 videojet.com",
        "http://aplikacja.ceidg.gov.pl/CEIDG/CEIDG.Public.UI/EntryChangeHistory.Id=7a025cc6",
        "https://twitter.com/PORNO_SEXYBABES",
        "https://310940000.android.com.twitter.android.adsenseformobileapps.com/",
        "http://www.anyxxxtube.net/search-porn/tsara-brashears/",
        "jaycobundaberg.eclipseaurahub.com.au 192.168.0.21",
        "appspot.com  \u2022 hyper7install.appspot.com",
        "https://wallpapers-nature.com/tsara-brashears/tse1-mm-bing-net \u2022 wallpapers-nature.com"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 0
        },
        "other": {
          "adversary": [],
          "malware_families": [
            "Virtool:win32/vbinder.co",
            "Win32/madang",
            "Trojan:msil/rapidstealer.a",
            "!themida",
            "Win32:salicode",
            "Win.downloader.small-1966",
            "Virus:win32/sality.at",
            "Win32/scrarev.c",
            "Other malware",
            "Cve-2023-22518"
          ],
          "industries": [],
          "unique_indicators": 10704
        }
      }
    },
    "false_positive": [],
    "alexa": "http://www.alexa.com/siteinfo/occasionallyhumans.com",
    "whois": "http://whois.domaintools.com/occasionallyhumans.com",
    "domain": "occasionallyhumans.com",
    "hostname": "Unavailable"
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 5,
  "pulses": [
    {
      "id": "69fee87278bb07a0d0b5a92f",
      "name": "Most all from April 28,2025 - New Spam Email Dump - 2024 edition CREATED 2 YEARS AGO MODIFIED 2 WEEKS AGO by Silius_Soddus clone",
      "description": "",
      "modified": "2026-05-09T07:55:30.061000",
      "created": "2026-05-09T07:55:30.061000",
      "tags": [
        "Spam",
        "Fake delivery notification"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": "65bd484c6d37209568778727",
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 249,
        "domain": 118,
        "hostname": 49,
        "FileHash-MD5": 18,
        "FileHash-SHA1": 18,
        "URL": 111,
        "email": 1
      },
      "indicator_count": 564,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 67,
      "modified_text": "23 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "69fee86d0a3fb70b06212cc9",
      "name": "Most all from April 28,2025 - New Spam Email Dump - 2024 edition CREATED 2 YEARS AGO MODIFIED 2 WEEKS AGO by Silius_Soddus clone",
      "description": "",
      "modified": "2026-05-09T07:55:25.485000",
      "created": "2026-05-09T07:55:25.485000",
      "tags": [
        "Spam",
        "Fake delivery notification"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": "65bd484c6d37209568778727",
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 249,
        "domain": 118,
        "hostname": 49,
        "FileHash-MD5": 18,
        "FileHash-SHA1": 18,
        "URL": 111,
        "email": 1
      },
      "indicator_count": 564,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 67,
      "modified_text": "23 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "65bd484c6d37209568778727",
      "name": "New Spam Email Dump - 2024 edition",
      "description": "New place for me to dump IOCs for the year ahead",
      "modified": "2026-04-24T23:04:40.568000",
      "created": "2024-02-02T19:53:48.419000",
      "tags": [
        "Spam",
        "Fake delivery notification"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 5,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Silius_Soddus",
        "id": "67731",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_67731/resized/80/avatar_51e2b48419.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 249,
        "domain": 118,
        "hostname": 49,
        "FileHash-MD5": 18,
        "FileHash-SHA1": 18,
        "URL": 111,
        "email": 1
      },
      "indicator_count": 564,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 77,
      "modified_text": "37 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "692f23547b713b128b9c8156",
      "name": "Indicator Deletion Attack | Chris P. Ahmann Esq  still utilizes parking crews to execute cyber attacks",
      "description": "Unable to open malware indicators at this time. These attackers use Parking Crews for their exploits, leasing parked  domains for the amount of time needed to execute an attack. The attack last predate me ever using Level Blue. I have to review  indicators reports more closely but, I do see a the multitude of attacks against target TLB and an intersection of attacks concerning Disable_Duck (Alberta) Chris Ahmann , Colorado government indicated. \n\n[OTX auto populated - Adversaries may use techniques to evade detection in their malware or tools, as well as using techniques such as code signing, encryption, and other techniques for avoiding detection and monitoring of their activities.]",
      "modified": "2026-01-01T17:01:48.163000",
      "created": "2025-12-02T17:35:15.203000",
      "tags": [
        "data upload",
        "extraction",
        "failed",
        "learn",
        "ck id",
        "name tactics",
        "suspicious",
        "informative",
        "adversaries",
        "command",
        "defense evasion",
        "spawns",
        "development att",
        "united",
        "flag",
        "poland poland",
        "windir",
        "openurl c",
        "prefetch2",
        "analysis",
        "tor analysis",
        "dns requests",
        "domain address",
        "mitre att",
        "ck matrix",
        "pattern match",
        "ascii text",
        "show process",
        "network traffic",
        "t1057",
        "general",
        "local",
        "path",
        "encrypt",
        "hosts ip",
        "details",
        "ssl certificate",
        "sha256",
        "sha1",
        "size",
        "unicode text",
        "crlf",
        "utf8",
        "lf line",
        "server",
        "command decode",
        "markmonitor",
        "amazon",
        "ltd dba",
        "com laude",
        "organization",
        "click",
        "show technique",
        "brand",
        "microsoft edge",
        "windows nt",
        "win64",
        "khtml",
        "gecko",
        "submitted",
        "prefetch1",
        "name server",
        "misc attack",
        "et tor",
        "known tor",
        "relayrouter",
        "contacted hosts",
        "google",
        "pornhub",
        "ip address",
        "t1480 execution",
        "file defense",
        "passive dns",
        "related nids",
        "urls",
        "files location",
        "flag united"
      ],
      "references": [
        "deploy-delete-app-us-east-2-1.deploy-delete-test-us-east-2-1mtsufd.us-east-2.gamma.forgeapps.ec2.aws.dev",
        "Amazon.com \u2022 Google.com \u2022YouTube.com, Apple.com ,  etc Exploited",
        "cloudendpointsapis.com \u2022 https://www.vgt.pl/style/style.css \u2022 ceidg.gov.pl",
        "pl.wikipedia.org \u2022  fontawesome.io \u2022  opensource.org \u2022 videojet.com",
        "https://discoverreceiver.gurus.vmicrosoft.com/ \u2022 account.live.com \u2022 acctcdn.msauth.net",
        "https://www.milehighmedia.com/legal/2257",
        "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian",
        "https://twitter.com/PORNO_SEXYBABES",
        "http://www.anyxxxtube.net/search-porn/tsara-brashears",
        "https://wallpapers-nature.com/tsara-brashears/urlscan-io",
        "http://www.anyxxxtube.net/search-porn/tsara-brashears-denies-jeffrey-scott-reimer-sex",
        "http://www.anyxxxtube.net/search-porn/tsara-brashears/",
        "https://wallpapers-nature.com/tsara-brashears/tse1-mm-bing-net \u2022 wallpapers-nature.com",
        "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian \u2022",
        "https://wallpapers-nature.com/ tsara-brashears/urlscan-io",
        "https://wallpapers-nature.com/%20tsara-brashears/urlscan-io",
        "http://aplikacja.ceidg.gov.pl/CEIDG/CEIDG.Public.UI/EntryChangeHistory.Id=7a025cc6",
        "(Delete app that removed YoiTube views) www.youtube.com/watch?v=GyuMozsVyYs",
        "http://watchhers.net/index.php",
        "everesttech.net \u2022 aws.amazon.com \u2022  cm.everesttech.net \u2022 dpm.demdex.net \u2022 s3.amazonaws.com"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "CVE-2023-22518",
          "display_name": "CVE-2023-22518",
          "target": null
        },
        {
          "id": "Other Malware",
          "display_name": "Other Malware",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1069",
          "name": "Permission Groups Discovery",
          "display_name": "T1069 - Permission Groups Discovery"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1480",
          "name": "Execution Guardrails",
          "display_name": "T1480 - Execution Guardrails"
        },
        {
          "id": "T1539",
          "name": "Steal Web Session Cookie",
          "display_name": "T1539 - Steal Web Session Cookie"
        },
        {
          "id": "T1553",
          "name": "Subvert Trust Controls",
          "display_name": "T1553 - Subvert Trust Controls"
        },
        {
          "id": "T1562",
          "name": "Impair Defenses",
          "display_name": "T1562 - Impair Defenses"
        },
        {
          "id": "T1568",
          "name": "Dynamic Resolution",
          "display_name": "T1568 - Dynamic Resolution"
        },
        {
          "id": "T1583",
          "name": "Acquire Infrastructure",
          "display_name": "T1583 - Acquire Infrastructure"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1518",
          "name": "Software Discovery",
          "display_name": "T1518 - Software Discovery"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Q.Vashti",
        "id": "337942",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 1358,
        "FileHash-MD5": 100,
        "FileHash-SHA1": 102,
        "FileHash-SHA256": 1682,
        "URL": 2497,
        "CVE": 2,
        "domain": 400,
        "SSLCertFingerprint": 6,
        "email": 3
      },
      "indicator_count": 6150,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 142,
      "modified_text": "150 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "68e32dd0c55bf224eb99dd58",
      "name": "Appspot.com - Google account fraud & infostealing",
      "description": "Fake Google email accounts. I\u2019ve reviewed a handful of targets with this issue. If starting with a new device, signed up for a new google account,\nthe users are automatically logged out, forced to sign in again, checked security features where you can see an unauthorized autonomous general\nphone, or iPhone or MacBook was also signed in in a different location. Even if you delete the device or email account, I\u2019ve seen the intruder handle CnC of all backups of photos and clouds. \n\n\n\n[OTX auto populated - The full list of domain names: APPSPot.COM.com, which was created on the same day as the Google search engine, has been published by the internet regulator, the IANA.]",
      "modified": "2025-11-05T01:01:26.928000",
      "created": "2025-10-06T02:47:44.098000",
      "tags": [
        "aaaa",
        "susp",
        "trojan",
        "google",
        "server",
        "domain status",
        "registrar abuse",
        "domain name",
        "us registrant",
        "email",
        "contact email",
        "rdap database",
        "google app",
        "google hosted",
        "please",
        "vulnerabilities",
        "join",
        "bring",
        "api explorer",
        "engine",
        "admin sdk",
        "info",
        "learn",
        "ck id",
        "name tactics",
        "suspicious",
        "informative",
        "adversaries",
        "command",
        "defense evasion",
        "ssl certificate",
        "ascii text",
        "united",
        "pattern match",
        "mitre att",
        "general",
        "local",
        "path",
        "click",
        "strings",
        "porn",
        "phishing",
        "fraud",
        "sandbox",
        "malware",
        "analysis",
        "online",
        "submit",
        "vxstream",
        "download",
        "apt",
        "ansi",
        "dumps",
        "file string",
        "seen",
        "disabled hash",
        "close",
        "hosts",
        "contact",
        "tellwise",
        "passive dns",
        "urls",
        "pulse pulses",
        "files",
        "verdict",
        "domain",
        "files ip",
        "address",
        "location united",
        "asn as15169",
        "extraction",
        "data upload",
        "extra",
        "referen http",
        "changed data",
        "failed",
        "include review",
        "t07 exclude",
        "extri data",
        "changed",
        "exclude",
        "find s",
        "tvnes data",
        "status",
        "present nov",
        "name servers",
        "entries",
        "geoid no",
        "present dec",
        "date",
        "error",
        "title",
        "sugges",
        "typ no",
        "no entrieotound",
        "scam",
        "foundry",
        "sabey type",
        "denver",
        "quasi",
        "phoenix",
        "australia"
      ],
      "references": [
        "appspot.com  \u2022 hyper7install.appspot.com",
        "https://hybrid-analysis.com/sample/c61237fcb798f05e6af32a6aa13f8e795aac47559d601eb7f93ad65bcf58b418/68e30c476b91a8000b0dd786",
        "http://acounts.google.com/v/signin/identifier?continue=hts%253%252F2Fconsole.cloud.google.com2Fapengine&dsh=5-1106814258%2539876543210",
        "Changed last several digits of gmail account # In example",
        "http://console.cloud.google.com/appengine",
        "https://310940000.android.com.twitter.android.adsenseformobileapps.com/",
        "https://www.netify.ai/resources/domains \u2022 192-168-0-21.3pt3m9ng2hf.ddns.manage.alta.inc",
        "device-local-de06e551-6b23-4aa3-bb67-6972ae6d30b5.remotewd.com 192.168.0.21",
        "116e33e0-8832-11ec-aef5-99a1d044639a-local.solinkcloud.com",
        "jaycobundaberg.eclipseaurahub.com.au 192.168.0.21",
        "grafana.ledocloud.com\u2022 192.168.0.21",
        "192-168-0-21.siliconevalley1.direct.quickconnect.to"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Win32/Madang",
          "display_name": "Win32/Madang",
          "target": null
        },
        {
          "id": "Win.Downloader.Small-1966",
          "display_name": "Win.Downloader.Small-1966",
          "target": null
        },
        {
          "id": "Win32:SaliCode",
          "display_name": "Win32:SaliCode",
          "target": null
        },
        {
          "id": "Virtool:Win32/Vbinder.CO",
          "display_name": "Virtool:Win32/Vbinder.CO",
          "target": "/malware/Virtool:Win32/Vbinder.CO"
        },
        {
          "id": "!Themida",
          "display_name": "!Themida",
          "target": null
        },
        {
          "id": "Virus:Win32/Sality.AT",
          "display_name": "Virus:Win32/Sality.AT",
          "target": "/malware/Virus:Win32/Sality.AT"
        },
        {
          "id": "Win32/Scrarev.C",
          "display_name": "Win32/Scrarev.C",
          "target": null
        },
        {
          "id": "Trojan:MSIL/RapidStealer.A",
          "display_name": "Trojan:MSIL/RapidStealer.A",
          "target": "/malware/Trojan:MSIL/RapidStealer.A"
        }
      ],
      "attack_ids": [
        {
          "id": "T1204",
          "name": "User Execution",
          "display_name": "T1204 - User Execution"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1069",
          "name": "Permission Groups Discovery",
          "display_name": "T1069 - Permission Groups Discovery"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1480",
          "name": "Execution Guardrails",
          "display_name": "T1480 - Execution Guardrails"
        },
        {
          "id": "T1553",
          "name": "Subvert Trust Controls",
          "display_name": "T1553 - Subvert Trust Controls"
        },
        {
          "id": "T1562",
          "name": "Impair Defenses",
          "display_name": "T1562 - Impair Defenses"
        },
        {
          "id": "T1583",
          "name": "Acquire Infrastructure",
          "display_name": "T1583 - Acquire Infrastructure"
        },
        {
          "id": "T1113",
          "name": "Screen Capture",
          "display_name": "T1113 - Screen Capture"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1106",
          "name": "Native API",
          "display_name": "T1106 - Native API"
        },
        {
          "id": "T1598",
          "name": "Phishing for Information",
          "display_name": "T1598 - Phishing for Information"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 9,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Q.Vashti",
        "id": "337942",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 222,
        "FileHash-MD5": 146,
        "FileHash-SHA1": 317,
        "FileHash-SHA256": 1120,
        "email": 3,
        "hostname": 881,
        "URL": 1338,
        "SSLCertFingerprint": 7
      },
      "indicator_count": 4034,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 143,
      "modified_text": "208 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "https://occasionallyhumans.com",
    "type": "URL"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "https://occasionallyhumans.com",
    "type": "URL",
    "found": false,
    "verdict": "clean",
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780304500.8213522
}