{
  "type": "URL",
  "indicator": "https://onsapay.com/loaderSe",
  "general": {
    "sections": [
      "general",
      "url_list",
      "http_scans",
      "screenshot"
    ],
    "indicator": "https://onsapay.com/loaderSe",
    "type": "url",
    "type_title": "URL",
    "validation": [],
    "base_indicator": {
      "id": 3766851045,
      "indicator": "https://onsapay.com/loaderSe",
      "type": "URL",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 6,
      "pulses": [
        {
          "id": "6570a823f8dbade2ab32ee77",
          "name": "Remote Access |Trick Clicks | C2 | False evidence appearing real. Content reputation.",
          "description": "",
          "modified": "2023-12-06T16:58:11.569000",
          "created": "2023-12-06T16:58:11.569000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 14,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "CVE": 7,
            "FileHash-SHA256": 598,
            "hostname": 403,
            "domain": 583,
            "URL": 1814,
            "FileHash-MD5": 175,
            "FileHash-SHA1": 95
          },
          "indicator_count": 3675,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 110,
          "modified_text": "865 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6570a819664c2499fc2adc79",
          "name": "BLOG | cloak-and-dagger | Page 4 of 8",
          "description": "",
          "modified": "2023-12-06T16:58:01.198000",
          "created": "2023-12-06T16:58:01.198000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 8,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "CVE": 4,
            "FileHash-SHA256": 1664,
            "FileHash-MD5": 367,
            "FileHash-SHA1": 237,
            "domain": 1950,
            "URL": 6466,
            "hostname": 2346,
            "email": 1
          },
          "indicator_count": 13035,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 112,
          "modified_text": "865 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6522804c01930c8d2f1ad71f",
          "name": "Remote Access |Trick Clicks | C2 | False evidence appearing real. Content reputation.",
          "description": "Unrelated websites successfully flood , and dismantle reputations, marketing efforts of targets who has and lost 100% online visibility. Cyber criminals set up malicious websites, that drive down reputation, relevant media of target. The domains are traps popular w/some hackers or malicious red team groups typically hired by attorneys.  Clicks, revenue flow to cyber criminals through malicious redirects, AGGRESSIVE social engineering, intellectual property abuse and obnoxious distraction. Contact is often made to trick target into believing their is interested in their product, body of work. Legal docs or funds may be exchange, giving cyber criminal access, email, clouds, Dropbox, forced login abuse, cloud share, phone number, C2,  payment methods, banking,  privilege to distribute, falsify ad campaigns of target. It's complicated but practices to frustrate , impoverish, profit, track, silence target. Malicious intent. Heavy tracking, core communication service swap.",
          "modified": "2023-11-07T08:04:06.581000",
          "created": "2023-10-08T10:11:22.600000",
          "tags": [
            "heur",
            "cyber threat",
            "engineering",
            "covid19",
            "united",
            "phishing site",
            "telefonica peru",
            "malicious site",
            "control server",
            "phishing",
            "suppobox",
            "malware",
            "team",
            "ransomware",
            "download",
            "facebook",
            "daum",
            "cobalt strike",
            "pony",
            "artemis",
            "simda",
            "sodinokibi",
            "zbot",
            "bank",
            "feodo",
            "laplasclipper",
            "squirrelwaffle",
            "binder",
            "virut",
            "ramnit",
            "dropper",
            "formbook",
            "azorult",
            "revil",
            "matsnu",
            "service",
            "generic",
            "malicious",
            "emotet",
            "br",
            "trojanspy",
            "cisco umbrella",
            "site",
            "safe site",
            "alexa top",
            "million",
            "malware site",
            "blacklist",
            "alexa",
            "malicious url",
            "detection list",
            "INDICATOR ROLE TITLE DESCRIPTION EXPIRATION RELATED PULSES  URL ",
            "C2",
            "command_and_control",
            "nr-data",
            "cyber crime",
            "impersonation",
            "fraud",
            "intellectual property",
            "targets",
            "kedence",
            "song culture",
            "tsara lynn",
            "k\u00e9dence",
            "tsara",
            "tsara brashears",
            "social engineering",
            "interface exchange",
            "abuse",
            "privilege",
            "indicator",
            "file",
            "pattern match",
            "ascii text",
            "appdata",
            "windows nt",
            "script",
            "mitre att",
            "ck id",
            "show technique",
            "hybrid",
            "general",
            "local",
            "forced login",
            "content reputation",
            "reputation",
            "scheme",
            "crime",
            "cyber criminals",
            "arizona",
            "colorado",
            "newyork",
            "british",
            "misc attack",
            "et tor",
            "known tor",
            "relayrouter",
            "exit",
            "node traffic",
            "suricata alerts",
            "event category",
            "description sid",
            "suricata",
            "suricata",
            "cloud",
            "device remotwd",
            "remote attack",
            "remote controlled devices",
            "tracking",
            "spyware",
            "florida",
            "united states",
            "canada",
            "estonia",
            "cyber criminal",
            "alert"
          ],
          "references": [
            "smartwishlist_1_.js",
            "https://www.hybrid-analysis.com/sample/ef02a04e1487fd373923ef2aa42b3d9af8d5fd600e5198150283b31aa7ed7558",
            "CVE-2012-1856",
            "CVE-2013-1331",
            "CVE-2017-8570",
            "CVE-2017-0147",
            "CVE-2017-11882",
            "CVE-2017-0199",
            "CVE-2018-8453",
            "https://the.sciencebehindecommerce.com/d9core",
            "https://pixel.tapad.com/idsync/ex/push static-tracking.klaviyo.com u002dtracking.klaviyo.com",
            "https://www.miraclebrand.co/apps/wonderment/tracking",
            "remote-access.net",
            "dev.remote-access.net",
            "hubspot.remote-access.net",
            "http://avient.remote-access.net/",
            "qa.remote-access.net",
            "http://www.remote-access.net",
            "https://avient.remote-access.net",
            "bam.nr-data.net",
            "appleaccessory.online",
            "init.ess.apple.com",
            "tv.apple.com",
            "http://icloud.ypcdce.com",
            "dr4qe3ddw9y32.cloudfront.net",
            "http://45.159.189.105/bot/regex",
            "http://clipper.guru/bot/regex",
            "http://45.159.189.105/bot/regex?key=afc950a4a18fd71c9d7be4c460e4cb77d0bcf29a49d097e4e739c17c332c3a34",
            "cloud.smartwishlist.webmarked.net",
            "http://dialacake.com/mumbai/yellow-pineapple-cake-2770.html",
            "https://hubspot.remote-access.net",
            "icloud.ypcdce.com",
            "Research and Data analysis"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "BR",
              "display_name": "BR",
              "target": null
            },
            {
              "id": "TrojanSpy",
              "display_name": "TrojanSpy",
              "target": null
            },
            {
              "id": "Maltiverse",
              "display_name": "Maltiverse",
              "target": null
            },
            {
              "id": "Ramnit",
              "display_name": "Ramnit",
              "target": null
            },
            {
              "id": "Emotet - S0367",
              "display_name": "Emotet - S0367",
              "target": null
            },
            {
              "id": "Squirrelwaffle",
              "display_name": "Squirrelwaffle",
              "target": null
            },
            {
              "id": "LaplasClipper",
              "display_name": "LaplasClipper",
              "target": null
            },
            {
              "id": "SuppoBox",
              "display_name": "SuppoBox",
              "target": null
            },
            {
              "id": "Virus:Win32/Daum",
              "display_name": "Virus:Win32/Daum",
              "target": "/malware/Virus:Win32/Daum"
            },
            {
              "id": "Cobalt Strike",
              "display_name": "Cobalt Strike",
              "target": null
            },
            {
              "id": "Backdoor:PHP/Artemis",
              "display_name": "Backdoor:PHP/Artemis",
              "target": "/malware/Backdoor:PHP/Artemis"
            },
            {
              "id": "TEL:HackTool:Win32/ArtemisUser",
              "display_name": "TEL:HackTool:Win32/ArtemisUser",
              "target": null
            },
            {
              "id": "Azorult - S0344",
              "display_name": "Azorult - S0344",
              "target": null
            },
            {
              "id": "Feodo",
              "display_name": "Feodo",
              "target": null
            },
            {
              "id": "Backdoor:Win32/Simda",
              "display_name": "Backdoor:Win32/Simda",
              "target": "/malware/Backdoor:Win32/Simda"
            },
            {
              "id": "Ransomware",
              "display_name": "Ransomware",
              "target": null
            },
            {
              "id": "Formbook",
              "display_name": "Formbook",
              "target": null
            },
            {
              "id": "REvil (ELF)",
              "display_name": "REvil (ELF)",
              "target": null
            },
            {
              "id": "Trojan:Win32/Matsnu",
              "display_name": "Trojan:Win32/Matsnu",
              "target": "/malware/Trojan:Win32/Matsnu"
            },
            {
              "id": "Virut",
              "display_name": "Virut",
              "target": null
            },
            {
              "id": "Backdoor:Win32/Zbot",
              "display_name": "Backdoor:Win32/Zbot",
              "target": "/malware/Backdoor:Win32/Zbot"
            },
            {
              "id": "ZeuS",
              "display_name": "ZeuS",
              "target": null
            },
            {
              "id": "Pony - S0453",
              "display_name": "Pony - S0453",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1176",
              "name": "Browser Extensions",
              "display_name": "T1176 - Browser Extensions"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1496",
              "name": "Resource Hijacking",
              "display_name": "T1496 - Resource Hijacking"
            },
            {
              "id": "T1041",
              "name": "Exfiltration Over C2 Channel",
              "display_name": "T1041 - Exfiltration Over C2 Channel"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1071.004",
              "name": "DNS",
              "display_name": "T1071.004 - DNS"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 41,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "CVE": 7,
            "hostname": 403,
            "domain": 583,
            "URL": 1814,
            "FileHash-MD5": 175,
            "FileHash-SHA1": 95,
            "FileHash-SHA256": 598
          },
          "indicator_count": 3675,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 227,
          "modified_text": "894 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "653f1b570ce3f6227774113b",
          "name": "Remote Access |Trick Clicks | C2 | False evidence appearing real. ",
          "description": "",
          "modified": "2023-11-07T08:04:06.581000",
          "created": "2023-10-30T02:56:23.462000",
          "tags": [
            "heur",
            "cyber threat",
            "engineering",
            "covid19",
            "united",
            "phishing site",
            "telefonica peru",
            "malicious site",
            "control server",
            "phishing",
            "suppobox",
            "malware",
            "team",
            "ransomware",
            "download",
            "facebook",
            "daum",
            "cobalt strike",
            "pony",
            "artemis",
            "simda",
            "sodinokibi",
            "zbot",
            "bank",
            "feodo",
            "laplasclipper",
            "squirrelwaffle",
            "binder",
            "virut",
            "ramnit",
            "dropper",
            "formbook",
            "azorult",
            "revil",
            "matsnu",
            "service",
            "generic",
            "malicious",
            "emotet",
            "br",
            "trojanspy",
            "cisco umbrella",
            "site",
            "safe site",
            "alexa top",
            "million",
            "malware site",
            "blacklist",
            "alexa",
            "malicious url",
            "detection list",
            "INDICATOR ROLE TITLE DESCRIPTION EXPIRATION RELATED PULSES  URL ",
            "C2",
            "command_and_control",
            "nr-data",
            "cyber crime",
            "impersonation",
            "fraud",
            "intellectual property",
            "targets",
            "kedence",
            "song culture",
            "tsara lynn",
            "k\u00e9dence",
            "tsara",
            "tsara brashears",
            "social engineering",
            "interface exchange",
            "abuse",
            "privilege",
            "indicator",
            "file",
            "pattern match",
            "ascii text",
            "appdata",
            "windows nt",
            "script",
            "mitre att",
            "ck id",
            "show technique",
            "hybrid",
            "general",
            "local",
            "forced login",
            "content reputation",
            "reputation",
            "scheme",
            "crime",
            "cyber criminals",
            "arizona",
            "colorado",
            "newyork",
            "british",
            "misc attack",
            "et tor",
            "known tor",
            "relayrouter",
            "exit",
            "node traffic",
            "suricata alerts",
            "event category",
            "description sid",
            "suricata",
            "suricata",
            "cloud",
            "device remotwd",
            "remote attack",
            "remote controlled devices",
            "tracking",
            "spyware",
            "florida",
            "united states",
            "canada",
            "estonia",
            "cyber criminal",
            "alert"
          ],
          "references": [
            "smartwishlist_1_.js",
            "https://www.hybrid-analysis.com/sample/ef02a04e1487fd373923ef2aa42b3d9af8d5fd600e5198150283b31aa7ed7558",
            "CVE-2012-1856",
            "CVE-2013-1331",
            "CVE-2017-8570",
            "CVE-2017-0147",
            "CVE-2017-11882",
            "CVE-2017-0199",
            "CVE-2018-8453",
            "https://the.sciencebehindecommerce.com/d9core",
            "https://pixel.tapad.com/idsync/ex/push static-tracking.klaviyo.com u002dtracking.klaviyo.com",
            "https://www.miraclebrand.co/apps/wonderment/tracking",
            "remote-access.net",
            "dev.remote-access.net",
            "hubspot.remote-access.net",
            "http://avient.remote-access.net/",
            "qa.remote-access.net",
            "http://www.remote-access.net",
            "https://avient.remote-access.net",
            "bam.nr-data.net",
            "appleaccessory.online",
            "init.ess.apple.com",
            "tv.apple.com",
            "http://icloud.ypcdce.com",
            "dr4qe3ddw9y32.cloudfront.net",
            "http://45.159.189.105/bot/regex",
            "http://clipper.guru/bot/regex",
            "http://45.159.189.105/bot/regex?key=afc950a4a18fd71c9d7be4c460e4cb77d0bcf29a49d097e4e739c17c332c3a34",
            "cloud.smartwishlist.webmarked.net",
            "http://dialacake.com/mumbai/yellow-pineapple-cake-2770.html",
            "https://hubspot.remote-access.net",
            "icloud.ypcdce.com",
            "Research and Data analysis"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "BR",
              "display_name": "BR",
              "target": null
            },
            {
              "id": "TrojanSpy",
              "display_name": "TrojanSpy",
              "target": null
            },
            {
              "id": "Maltiverse",
              "display_name": "Maltiverse",
              "target": null
            },
            {
              "id": "Ramnit",
              "display_name": "Ramnit",
              "target": null
            },
            {
              "id": "Emotet - S0367",
              "display_name": "Emotet - S0367",
              "target": null
            },
            {
              "id": "Squirrelwaffle",
              "display_name": "Squirrelwaffle",
              "target": null
            },
            {
              "id": "LaplasClipper",
              "display_name": "LaplasClipper",
              "target": null
            },
            {
              "id": "SuppoBox",
              "display_name": "SuppoBox",
              "target": null
            },
            {
              "id": "Virus:Win32/Daum",
              "display_name": "Virus:Win32/Daum",
              "target": "/malware/Virus:Win32/Daum"
            },
            {
              "id": "Cobalt Strike",
              "display_name": "Cobalt Strike",
              "target": null
            },
            {
              "id": "Backdoor:PHP/Artemis",
              "display_name": "Backdoor:PHP/Artemis",
              "target": "/malware/Backdoor:PHP/Artemis"
            },
            {
              "id": "TEL:HackTool:Win32/ArtemisUser",
              "display_name": "TEL:HackTool:Win32/ArtemisUser",
              "target": null
            },
            {
              "id": "Azorult - S0344",
              "display_name": "Azorult - S0344",
              "target": null
            },
            {
              "id": "Feodo",
              "display_name": "Feodo",
              "target": null
            },
            {
              "id": "Backdoor:Win32/Simda",
              "display_name": "Backdoor:Win32/Simda",
              "target": "/malware/Backdoor:Win32/Simda"
            },
            {
              "id": "Ransomware",
              "display_name": "Ransomware",
              "target": null
            },
            {
              "id": "Formbook",
              "display_name": "Formbook",
              "target": null
            },
            {
              "id": "REvil (ELF)",
              "display_name": "REvil (ELF)",
              "target": null
            },
            {
              "id": "Trojan:Win32/Matsnu",
              "display_name": "Trojan:Win32/Matsnu",
              "target": "/malware/Trojan:Win32/Matsnu"
            },
            {
              "id": "Virut",
              "display_name": "Virut",
              "target": null
            },
            {
              "id": "Backdoor:Win32/Zbot",
              "display_name": "Backdoor:Win32/Zbot",
              "target": "/malware/Backdoor:Win32/Zbot"
            },
            {
              "id": "ZeuS",
              "display_name": "ZeuS",
              "target": null
            },
            {
              "id": "Pony - S0453",
              "display_name": "Pony - S0453",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1176",
              "name": "Browser Extensions",
              "display_name": "T1176 - Browser Extensions"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1496",
              "name": "Resource Hijacking",
              "display_name": "T1496 - Resource Hijacking"
            },
            {
              "id": "T1041",
              "name": "Exfiltration Over C2 Channel",
              "display_name": "T1041 - Exfiltration Over C2 Channel"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1071.004",
              "name": "DNS",
              "display_name": "T1071.004 - DNS"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": "6522804c01930c8d2f1ad71f",
          "export_count": 30,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "CVE": 7,
            "hostname": 403,
            "domain": 583,
            "URL": 1814,
            "FileHash-MD5": 175,
            "FileHash-SHA1": 95,
            "FileHash-SHA256": 598
          },
          "indicator_count": 3675,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 218,
          "modified_text": "894 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "652214c652025febf66cde33",
          "name": "BLOG | cloak-and-dagger | Page 4 of 8",
          "description": "C2 | scanning_host | Malicious|",
          "modified": "2023-11-07T01:01:57.592000",
          "created": "2023-10-08T02:32:38.609000",
          "tags": [
            "ssl certificate",
            "whois record",
            "historical ssl",
            "threat roundup",
            "whois whois",
            "october",
            "referrer",
            "resolutions",
            "december",
            "september",
            "hacktool",
            "united",
            "anonymizer",
            "firehol",
            "microsoft",
            "phishing site",
            "malware site",
            "paypal",
            "latam",
            "phishing",
            "malicious site",
            "myetherwallet",
            "heur",
            "malware",
            "zeus",
            "zbot",
            "facebook",
            "artemis",
            "bank",
            "bradesco",
            "riskware",
            "download",
            "telecom",
            "dropper",
            "emotet",
            "formbook",
            "cisco umbrella",
            "site",
            "safe site",
            "blacklist https",
            "generic malware",
            "detection list",
            "blacklist",
            "generic",
            "pe resource",
            "contacted",
            "red team",
            "whois",
            "execution",
            "skynet",
            "u4e0b",
            "falcon sandbox",
            "flag",
            "date",
            "server",
            "name server",
            "markmonitor",
            "domain address",
            "gandi sas",
            "mesh digital",
            "vimeo",
            "static engine",
            "alexa top",
            "million",
            "adwarex",
            "alexa",
            "xrat",
            "downldr",
            "presenoker",
            "maltiverse",
            "ocidmy01rz",
            "runtime process",
            "copy md5",
            "sha1",
            "copy sha1",
            "copy sha256"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Generic",
              "display_name": "Generic",
              "target": null
            },
            {
              "id": "Maltiverse",
              "display_name": "Maltiverse",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1115",
              "name": "Clipboard Data",
              "display_name": "T1115 - Clipboard Data"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 17,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 367,
            "FileHash-SHA1": 237,
            "FileHash-SHA256": 1664,
            "URL": 6466,
            "domain": 1950,
            "hostname": 2346,
            "CVE": 4,
            "email": 1
          },
          "indicator_count": 13035,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 226,
          "modified_text": "894 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "653f15cbb17119f3334c0c57",
          "name": "BLOG | cloak-and-dagger | Page 4 of 8",
          "description": "",
          "modified": "2023-11-07T01:01:57.592000",
          "created": "2023-10-30T02:32:43.922000",
          "tags": [
            "ssl certificate",
            "whois record",
            "historical ssl",
            "threat roundup",
            "whois whois",
            "october",
            "referrer",
            "resolutions",
            "december",
            "september",
            "hacktool",
            "united",
            "anonymizer",
            "firehol",
            "microsoft",
            "phishing site",
            "malware site",
            "paypal",
            "latam",
            "phishing",
            "malicious site",
            "myetherwallet",
            "heur",
            "malware",
            "zeus",
            "zbot",
            "facebook",
            "artemis",
            "bank",
            "bradesco",
            "riskware",
            "download",
            "telecom",
            "dropper",
            "emotet",
            "formbook",
            "cisco umbrella",
            "site",
            "safe site",
            "blacklist https",
            "generic malware",
            "detection list",
            "blacklist",
            "generic",
            "pe resource",
            "contacted",
            "red team",
            "whois",
            "execution",
            "skynet",
            "u4e0b",
            "falcon sandbox",
            "flag",
            "date",
            "server",
            "name server",
            "markmonitor",
            "domain address",
            "gandi sas",
            "mesh digital",
            "vimeo",
            "static engine",
            "alexa top",
            "million",
            "adwarex",
            "alexa",
            "xrat",
            "downldr",
            "presenoker",
            "maltiverse",
            "ocidmy01rz",
            "runtime process",
            "copy md5",
            "sha1",
            "copy sha1",
            "copy sha256"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Generic",
              "display_name": "Generic",
              "target": null
            },
            {
              "id": "Maltiverse",
              "display_name": "Maltiverse",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1115",
              "name": "Clipboard Data",
              "display_name": "T1115 - Clipboard Data"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": "652214c652025febf66cde33",
          "export_count": 12,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 367,
            "FileHash-SHA1": 237,
            "FileHash-SHA256": 1664,
            "URL": 6466,
            "domain": 1950,
            "hostname": 2346,
            "CVE": 4,
            "email": 1
          },
          "indicator_count": 13035,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 218,
          "modified_text": "894 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "http://www.remote-access.net",
        "cloud.smartwishlist.webmarked.net",
        "http://45.159.189.105/bot/regex?key=afc950a4a18fd71c9d7be4c460e4cb77d0bcf29a49d097e4e739c17c332c3a34",
        "CVE-2017-8570",
        "hubspot.remote-access.net",
        "appleaccessory.online",
        "init.ess.apple.com",
        "dr4qe3ddw9y32.cloudfront.net",
        "smartwishlist_1_.js",
        "http://dialacake.com/mumbai/yellow-pineapple-cake-2770.html",
        "CVE-2017-11882",
        "https://hubspot.remote-access.net",
        "https://pixel.tapad.com/idsync/ex/push static-tracking.klaviyo.com u002dtracking.klaviyo.com",
        "CVE-2012-1856",
        "http://clipper.guru/bot/regex",
        "bam.nr-data.net",
        "tv.apple.com",
        "CVE-2013-1331",
        "https://www.hybrid-analysis.com/sample/ef02a04e1487fd373923ef2aa42b3d9af8d5fd600e5198150283b31aa7ed7558",
        "http://avient.remote-access.net/",
        "CVE-2017-0147",
        "Research and Data analysis",
        "icloud.ypcdce.com",
        "http://icloud.ypcdce.com",
        "CVE-2017-0199",
        "https://avient.remote-access.net",
        "dev.remote-access.net",
        "https://www.miraclebrand.co/apps/wonderment/tracking",
        "https://the.sciencebehindecommerce.com/d9core",
        "http://45.159.189.105/bot/regex",
        "CVE-2018-8453",
        "remote-access.net",
        "qa.remote-access.net"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 0
        },
        "other": {
          "adversary": [],
          "malware_families": [
            "Cobalt strike",
            "Virut",
            "Backdoor:win32/simda",
            "Pony - s0453",
            "Zeus",
            "Suppobox",
            "Formbook",
            "Ransomware",
            "Generic",
            "Trojanspy",
            "Squirrelwaffle",
            "Backdoor:win32/zbot",
            "Feodo",
            "Laplasclipper",
            "Revil (elf)",
            "Emotet - s0367",
            "Ramnit",
            "Tel:hacktool:win32/artemisuser",
            "Virus:win32/daum",
            "Br",
            "Azorult - s0344",
            "Backdoor:php/artemis",
            "Maltiverse",
            "Trojan:win32/matsnu"
          ],
          "industries": [],
          "unique_indicators": 16581
        }
      }
    },
    "false_positive": [],
    "alexa": "http://www.alexa.com/siteinfo/onsapay.com",
    "whois": "http://whois.domaintools.com/onsapay.com",
    "domain": "onsapay.com",
    "hostname": "Unavailable"
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 6,
  "pulses": [
    {
      "id": "6570a823f8dbade2ab32ee77",
      "name": "Remote Access |Trick Clicks | C2 | False evidence appearing real. Content reputation.",
      "description": "",
      "modified": "2023-12-06T16:58:11.569000",
      "created": "2023-12-06T16:58:11.569000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 14,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "CVE": 7,
        "FileHash-SHA256": 598,
        "hostname": 403,
        "domain": 583,
        "URL": 1814,
        "FileHash-MD5": 175,
        "FileHash-SHA1": 95
      },
      "indicator_count": 3675,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 110,
      "modified_text": "865 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6570a819664c2499fc2adc79",
      "name": "BLOG | cloak-and-dagger | Page 4 of 8",
      "description": "",
      "modified": "2023-12-06T16:58:01.198000",
      "created": "2023-12-06T16:58:01.198000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 8,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "CVE": 4,
        "FileHash-SHA256": 1664,
        "FileHash-MD5": 367,
        "FileHash-SHA1": 237,
        "domain": 1950,
        "URL": 6466,
        "hostname": 2346,
        "email": 1
      },
      "indicator_count": 13035,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 112,
      "modified_text": "865 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6522804c01930c8d2f1ad71f",
      "name": "Remote Access |Trick Clicks | C2 | False evidence appearing real. Content reputation.",
      "description": "Unrelated websites successfully flood , and dismantle reputations, marketing efforts of targets who has and lost 100% online visibility. Cyber criminals set up malicious websites, that drive down reputation, relevant media of target. The domains are traps popular w/some hackers or malicious red team groups typically hired by attorneys.  Clicks, revenue flow to cyber criminals through malicious redirects, AGGRESSIVE social engineering, intellectual property abuse and obnoxious distraction. Contact is often made to trick target into believing their is interested in their product, body of work. Legal docs or funds may be exchange, giving cyber criminal access, email, clouds, Dropbox, forced login abuse, cloud share, phone number, C2,  payment methods, banking,  privilege to distribute, falsify ad campaigns of target. It's complicated but practices to frustrate , impoverish, profit, track, silence target. Malicious intent. Heavy tracking, core communication service swap.",
      "modified": "2023-11-07T08:04:06.581000",
      "created": "2023-10-08T10:11:22.600000",
      "tags": [
        "heur",
        "cyber threat",
        "engineering",
        "covid19",
        "united",
        "phishing site",
        "telefonica peru",
        "malicious site",
        "control server",
        "phishing",
        "suppobox",
        "malware",
        "team",
        "ransomware",
        "download",
        "facebook",
        "daum",
        "cobalt strike",
        "pony",
        "artemis",
        "simda",
        "sodinokibi",
        "zbot",
        "bank",
        "feodo",
        "laplasclipper",
        "squirrelwaffle",
        "binder",
        "virut",
        "ramnit",
        "dropper",
        "formbook",
        "azorult",
        "revil",
        "matsnu",
        "service",
        "generic",
        "malicious",
        "emotet",
        "br",
        "trojanspy",
        "cisco umbrella",
        "site",
        "safe site",
        "alexa top",
        "million",
        "malware site",
        "blacklist",
        "alexa",
        "malicious url",
        "detection list",
        "INDICATOR ROLE TITLE DESCRIPTION EXPIRATION RELATED PULSES  URL ",
        "C2",
        "command_and_control",
        "nr-data",
        "cyber crime",
        "impersonation",
        "fraud",
        "intellectual property",
        "targets",
        "kedence",
        "song culture",
        "tsara lynn",
        "k\u00e9dence",
        "tsara",
        "tsara brashears",
        "social engineering",
        "interface exchange",
        "abuse",
        "privilege",
        "indicator",
        "file",
        "pattern match",
        "ascii text",
        "appdata",
        "windows nt",
        "script",
        "mitre att",
        "ck id",
        "show technique",
        "hybrid",
        "general",
        "local",
        "forced login",
        "content reputation",
        "reputation",
        "scheme",
        "crime",
        "cyber criminals",
        "arizona",
        "colorado",
        "newyork",
        "british",
        "misc attack",
        "et tor",
        "known tor",
        "relayrouter",
        "exit",
        "node traffic",
        "suricata alerts",
        "event category",
        "description sid",
        "suricata",
        "suricata",
        "cloud",
        "device remotwd",
        "remote attack",
        "remote controlled devices",
        "tracking",
        "spyware",
        "florida",
        "united states",
        "canada",
        "estonia",
        "cyber criminal",
        "alert"
      ],
      "references": [
        "smartwishlist_1_.js",
        "https://www.hybrid-analysis.com/sample/ef02a04e1487fd373923ef2aa42b3d9af8d5fd600e5198150283b31aa7ed7558",
        "CVE-2012-1856",
        "CVE-2013-1331",
        "CVE-2017-8570",
        "CVE-2017-0147",
        "CVE-2017-11882",
        "CVE-2017-0199",
        "CVE-2018-8453",
        "https://the.sciencebehindecommerce.com/d9core",
        "https://pixel.tapad.com/idsync/ex/push static-tracking.klaviyo.com u002dtracking.klaviyo.com",
        "https://www.miraclebrand.co/apps/wonderment/tracking",
        "remote-access.net",
        "dev.remote-access.net",
        "hubspot.remote-access.net",
        "http://avient.remote-access.net/",
        "qa.remote-access.net",
        "http://www.remote-access.net",
        "https://avient.remote-access.net",
        "bam.nr-data.net",
        "appleaccessory.online",
        "init.ess.apple.com",
        "tv.apple.com",
        "http://icloud.ypcdce.com",
        "dr4qe3ddw9y32.cloudfront.net",
        "http://45.159.189.105/bot/regex",
        "http://clipper.guru/bot/regex",
        "http://45.159.189.105/bot/regex?key=afc950a4a18fd71c9d7be4c460e4cb77d0bcf29a49d097e4e739c17c332c3a34",
        "cloud.smartwishlist.webmarked.net",
        "http://dialacake.com/mumbai/yellow-pineapple-cake-2770.html",
        "https://hubspot.remote-access.net",
        "icloud.ypcdce.com",
        "Research and Data analysis"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "BR",
          "display_name": "BR",
          "target": null
        },
        {
          "id": "TrojanSpy",
          "display_name": "TrojanSpy",
          "target": null
        },
        {
          "id": "Maltiverse",
          "display_name": "Maltiverse",
          "target": null
        },
        {
          "id": "Ramnit",
          "display_name": "Ramnit",
          "target": null
        },
        {
          "id": "Emotet - S0367",
          "display_name": "Emotet - S0367",
          "target": null
        },
        {
          "id": "Squirrelwaffle",
          "display_name": "Squirrelwaffle",
          "target": null
        },
        {
          "id": "LaplasClipper",
          "display_name": "LaplasClipper",
          "target": null
        },
        {
          "id": "SuppoBox",
          "display_name": "SuppoBox",
          "target": null
        },
        {
          "id": "Virus:Win32/Daum",
          "display_name": "Virus:Win32/Daum",
          "target": "/malware/Virus:Win32/Daum"
        },
        {
          "id": "Cobalt Strike",
          "display_name": "Cobalt Strike",
          "target": null
        },
        {
          "id": "Backdoor:PHP/Artemis",
          "display_name": "Backdoor:PHP/Artemis",
          "target": "/malware/Backdoor:PHP/Artemis"
        },
        {
          "id": "TEL:HackTool:Win32/ArtemisUser",
          "display_name": "TEL:HackTool:Win32/ArtemisUser",
          "target": null
        },
        {
          "id": "Azorult - S0344",
          "display_name": "Azorult - S0344",
          "target": null
        },
        {
          "id": "Feodo",
          "display_name": "Feodo",
          "target": null
        },
        {
          "id": "Backdoor:Win32/Simda",
          "display_name": "Backdoor:Win32/Simda",
          "target": "/malware/Backdoor:Win32/Simda"
        },
        {
          "id": "Ransomware",
          "display_name": "Ransomware",
          "target": null
        },
        {
          "id": "Formbook",
          "display_name": "Formbook",
          "target": null
        },
        {
          "id": "REvil (ELF)",
          "display_name": "REvil (ELF)",
          "target": null
        },
        {
          "id": "Trojan:Win32/Matsnu",
          "display_name": "Trojan:Win32/Matsnu",
          "target": "/malware/Trojan:Win32/Matsnu"
        },
        {
          "id": "Virut",
          "display_name": "Virut",
          "target": null
        },
        {
          "id": "Backdoor:Win32/Zbot",
          "display_name": "Backdoor:Win32/Zbot",
          "target": "/malware/Backdoor:Win32/Zbot"
        },
        {
          "id": "ZeuS",
          "display_name": "ZeuS",
          "target": null
        },
        {
          "id": "Pony - S0453",
          "display_name": "Pony - S0453",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1176",
          "name": "Browser Extensions",
          "display_name": "T1176 - Browser Extensions"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1496",
          "name": "Resource Hijacking",
          "display_name": "T1496 - Resource Hijacking"
        },
        {
          "id": "T1041",
          "name": "Exfiltration Over C2 Channel",
          "display_name": "T1041 - Exfiltration Over C2 Channel"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1497",
          "name": "Virtualization/Sandbox Evasion",
          "display_name": "T1497 - Virtualization/Sandbox Evasion"
        },
        {
          "id": "T1071.001",
          "name": "Web Protocols",
          "display_name": "T1071.001 - Web Protocols"
        },
        {
          "id": "T1071.004",
          "name": "DNS",
          "display_name": "T1071.004 - DNS"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 41,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "scoreblue",
        "id": "254100",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "CVE": 7,
        "hostname": 403,
        "domain": 583,
        "URL": 1814,
        "FileHash-MD5": 175,
        "FileHash-SHA1": 95,
        "FileHash-SHA256": 598
      },
      "indicator_count": 3675,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 227,
      "modified_text": "894 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "653f1b570ce3f6227774113b",
      "name": "Remote Access |Trick Clicks | C2 | False evidence appearing real. ",
      "description": "",
      "modified": "2023-11-07T08:04:06.581000",
      "created": "2023-10-30T02:56:23.462000",
      "tags": [
        "heur",
        "cyber threat",
        "engineering",
        "covid19",
        "united",
        "phishing site",
        "telefonica peru",
        "malicious site",
        "control server",
        "phishing",
        "suppobox",
        "malware",
        "team",
        "ransomware",
        "download",
        "facebook",
        "daum",
        "cobalt strike",
        "pony",
        "artemis",
        "simda",
        "sodinokibi",
        "zbot",
        "bank",
        "feodo",
        "laplasclipper",
        "squirrelwaffle",
        "binder",
        "virut",
        "ramnit",
        "dropper",
        "formbook",
        "azorult",
        "revil",
        "matsnu",
        "service",
        "generic",
        "malicious",
        "emotet",
        "br",
        "trojanspy",
        "cisco umbrella",
        "site",
        "safe site",
        "alexa top",
        "million",
        "malware site",
        "blacklist",
        "alexa",
        "malicious url",
        "detection list",
        "INDICATOR ROLE TITLE DESCRIPTION EXPIRATION RELATED PULSES  URL ",
        "C2",
        "command_and_control",
        "nr-data",
        "cyber crime",
        "impersonation",
        "fraud",
        "intellectual property",
        "targets",
        "kedence",
        "song culture",
        "tsara lynn",
        "k\u00e9dence",
        "tsara",
        "tsara brashears",
        "social engineering",
        "interface exchange",
        "abuse",
        "privilege",
        "indicator",
        "file",
        "pattern match",
        "ascii text",
        "appdata",
        "windows nt",
        "script",
        "mitre att",
        "ck id",
        "show technique",
        "hybrid",
        "general",
        "local",
        "forced login",
        "content reputation",
        "reputation",
        "scheme",
        "crime",
        "cyber criminals",
        "arizona",
        "colorado",
        "newyork",
        "british",
        "misc attack",
        "et tor",
        "known tor",
        "relayrouter",
        "exit",
        "node traffic",
        "suricata alerts",
        "event category",
        "description sid",
        "suricata",
        "suricata",
        "cloud",
        "device remotwd",
        "remote attack",
        "remote controlled devices",
        "tracking",
        "spyware",
        "florida",
        "united states",
        "canada",
        "estonia",
        "cyber criminal",
        "alert"
      ],
      "references": [
        "smartwishlist_1_.js",
        "https://www.hybrid-analysis.com/sample/ef02a04e1487fd373923ef2aa42b3d9af8d5fd600e5198150283b31aa7ed7558",
        "CVE-2012-1856",
        "CVE-2013-1331",
        "CVE-2017-8570",
        "CVE-2017-0147",
        "CVE-2017-11882",
        "CVE-2017-0199",
        "CVE-2018-8453",
        "https://the.sciencebehindecommerce.com/d9core",
        "https://pixel.tapad.com/idsync/ex/push static-tracking.klaviyo.com u002dtracking.klaviyo.com",
        "https://www.miraclebrand.co/apps/wonderment/tracking",
        "remote-access.net",
        "dev.remote-access.net",
        "hubspot.remote-access.net",
        "http://avient.remote-access.net/",
        "qa.remote-access.net",
        "http://www.remote-access.net",
        "https://avient.remote-access.net",
        "bam.nr-data.net",
        "appleaccessory.online",
        "init.ess.apple.com",
        "tv.apple.com",
        "http://icloud.ypcdce.com",
        "dr4qe3ddw9y32.cloudfront.net",
        "http://45.159.189.105/bot/regex",
        "http://clipper.guru/bot/regex",
        "http://45.159.189.105/bot/regex?key=afc950a4a18fd71c9d7be4c460e4cb77d0bcf29a49d097e4e739c17c332c3a34",
        "cloud.smartwishlist.webmarked.net",
        "http://dialacake.com/mumbai/yellow-pineapple-cake-2770.html",
        "https://hubspot.remote-access.net",
        "icloud.ypcdce.com",
        "Research and Data analysis"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "BR",
          "display_name": "BR",
          "target": null
        },
        {
          "id": "TrojanSpy",
          "display_name": "TrojanSpy",
          "target": null
        },
        {
          "id": "Maltiverse",
          "display_name": "Maltiverse",
          "target": null
        },
        {
          "id": "Ramnit",
          "display_name": "Ramnit",
          "target": null
        },
        {
          "id": "Emotet - S0367",
          "display_name": "Emotet - S0367",
          "target": null
        },
        {
          "id": "Squirrelwaffle",
          "display_name": "Squirrelwaffle",
          "target": null
        },
        {
          "id": "LaplasClipper",
          "display_name": "LaplasClipper",
          "target": null
        },
        {
          "id": "SuppoBox",
          "display_name": "SuppoBox",
          "target": null
        },
        {
          "id": "Virus:Win32/Daum",
          "display_name": "Virus:Win32/Daum",
          "target": "/malware/Virus:Win32/Daum"
        },
        {
          "id": "Cobalt Strike",
          "display_name": "Cobalt Strike",
          "target": null
        },
        {
          "id": "Backdoor:PHP/Artemis",
          "display_name": "Backdoor:PHP/Artemis",
          "target": "/malware/Backdoor:PHP/Artemis"
        },
        {
          "id": "TEL:HackTool:Win32/ArtemisUser",
          "display_name": "TEL:HackTool:Win32/ArtemisUser",
          "target": null
        },
        {
          "id": "Azorult - S0344",
          "display_name": "Azorult - S0344",
          "target": null
        },
        {
          "id": "Feodo",
          "display_name": "Feodo",
          "target": null
        },
        {
          "id": "Backdoor:Win32/Simda",
          "display_name": "Backdoor:Win32/Simda",
          "target": "/malware/Backdoor:Win32/Simda"
        },
        {
          "id": "Ransomware",
          "display_name": "Ransomware",
          "target": null
        },
        {
          "id": "Formbook",
          "display_name": "Formbook",
          "target": null
        },
        {
          "id": "REvil (ELF)",
          "display_name": "REvil (ELF)",
          "target": null
        },
        {
          "id": "Trojan:Win32/Matsnu",
          "display_name": "Trojan:Win32/Matsnu",
          "target": "/malware/Trojan:Win32/Matsnu"
        },
        {
          "id": "Virut",
          "display_name": "Virut",
          "target": null
        },
        {
          "id": "Backdoor:Win32/Zbot",
          "display_name": "Backdoor:Win32/Zbot",
          "target": "/malware/Backdoor:Win32/Zbot"
        },
        {
          "id": "ZeuS",
          "display_name": "ZeuS",
          "target": null
        },
        {
          "id": "Pony - S0453",
          "display_name": "Pony - S0453",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1176",
          "name": "Browser Extensions",
          "display_name": "T1176 - Browser Extensions"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1496",
          "name": "Resource Hijacking",
          "display_name": "T1496 - Resource Hijacking"
        },
        {
          "id": "T1041",
          "name": "Exfiltration Over C2 Channel",
          "display_name": "T1041 - Exfiltration Over C2 Channel"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1497",
          "name": "Virtualization/Sandbox Evasion",
          "display_name": "T1497 - Virtualization/Sandbox Evasion"
        },
        {
          "id": "T1071.001",
          "name": "Web Protocols",
          "display_name": "T1071.001 - Web Protocols"
        },
        {
          "id": "T1071.004",
          "name": "DNS",
          "display_name": "T1071.004 - DNS"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": "6522804c01930c8d2f1ad71f",
      "export_count": 30,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "CVE": 7,
        "hostname": 403,
        "domain": 583,
        "URL": 1814,
        "FileHash-MD5": 175,
        "FileHash-SHA1": 95,
        "FileHash-SHA256": 598
      },
      "indicator_count": 3675,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 218,
      "modified_text": "894 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "652214c652025febf66cde33",
      "name": "BLOG | cloak-and-dagger | Page 4 of 8",
      "description": "C2 | scanning_host | Malicious|",
      "modified": "2023-11-07T01:01:57.592000",
      "created": "2023-10-08T02:32:38.609000",
      "tags": [
        "ssl certificate",
        "whois record",
        "historical ssl",
        "threat roundup",
        "whois whois",
        "october",
        "referrer",
        "resolutions",
        "december",
        "september",
        "hacktool",
        "united",
        "anonymizer",
        "firehol",
        "microsoft",
        "phishing site",
        "malware site",
        "paypal",
        "latam",
        "phishing",
        "malicious site",
        "myetherwallet",
        "heur",
        "malware",
        "zeus",
        "zbot",
        "facebook",
        "artemis",
        "bank",
        "bradesco",
        "riskware",
        "download",
        "telecom",
        "dropper",
        "emotet",
        "formbook",
        "cisco umbrella",
        "site",
        "safe site",
        "blacklist https",
        "generic malware",
        "detection list",
        "blacklist",
        "generic",
        "pe resource",
        "contacted",
        "red team",
        "whois",
        "execution",
        "skynet",
        "u4e0b",
        "falcon sandbox",
        "flag",
        "date",
        "server",
        "name server",
        "markmonitor",
        "domain address",
        "gandi sas",
        "mesh digital",
        "vimeo",
        "static engine",
        "alexa top",
        "million",
        "adwarex",
        "alexa",
        "xrat",
        "downldr",
        "presenoker",
        "maltiverse",
        "ocidmy01rz",
        "runtime process",
        "copy md5",
        "sha1",
        "copy sha1",
        "copy sha256"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Generic",
          "display_name": "Generic",
          "target": null
        },
        {
          "id": "Maltiverse",
          "display_name": "Maltiverse",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1547",
          "name": "Boot or Logon Autostart Execution",
          "display_name": "T1547 - Boot or Logon Autostart Execution"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1115",
          "name": "Clipboard Data",
          "display_name": "T1115 - Clipboard Data"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 17,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "scoreblue",
        "id": "254100",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 367,
        "FileHash-SHA1": 237,
        "FileHash-SHA256": 1664,
        "URL": 6466,
        "domain": 1950,
        "hostname": 2346,
        "CVE": 4,
        "email": 1
      },
      "indicator_count": 13035,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 226,
      "modified_text": "894 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "653f15cbb17119f3334c0c57",
      "name": "BLOG | cloak-and-dagger | Page 4 of 8",
      "description": "",
      "modified": "2023-11-07T01:01:57.592000",
      "created": "2023-10-30T02:32:43.922000",
      "tags": [
        "ssl certificate",
        "whois record",
        "historical ssl",
        "threat roundup",
        "whois whois",
        "october",
        "referrer",
        "resolutions",
        "december",
        "september",
        "hacktool",
        "united",
        "anonymizer",
        "firehol",
        "microsoft",
        "phishing site",
        "malware site",
        "paypal",
        "latam",
        "phishing",
        "malicious site",
        "myetherwallet",
        "heur",
        "malware",
        "zeus",
        "zbot",
        "facebook",
        "artemis",
        "bank",
        "bradesco",
        "riskware",
        "download",
        "telecom",
        "dropper",
        "emotet",
        "formbook",
        "cisco umbrella",
        "site",
        "safe site",
        "blacklist https",
        "generic malware",
        "detection list",
        "blacklist",
        "generic",
        "pe resource",
        "contacted",
        "red team",
        "whois",
        "execution",
        "skynet",
        "u4e0b",
        "falcon sandbox",
        "flag",
        "date",
        "server",
        "name server",
        "markmonitor",
        "domain address",
        "gandi sas",
        "mesh digital",
        "vimeo",
        "static engine",
        "alexa top",
        "million",
        "adwarex",
        "alexa",
        "xrat",
        "downldr",
        "presenoker",
        "maltiverse",
        "ocidmy01rz",
        "runtime process",
        "copy md5",
        "sha1",
        "copy sha1",
        "copy sha256"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Generic",
          "display_name": "Generic",
          "target": null
        },
        {
          "id": "Maltiverse",
          "display_name": "Maltiverse",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1547",
          "name": "Boot or Logon Autostart Execution",
          "display_name": "T1547 - Boot or Logon Autostart Execution"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1115",
          "name": "Clipboard Data",
          "display_name": "T1115 - Clipboard Data"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": "652214c652025febf66cde33",
      "export_count": 12,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 367,
        "FileHash-SHA1": 237,
        "FileHash-SHA256": 1664,
        "URL": 6466,
        "domain": 1950,
        "hostname": 2346,
        "CVE": 4,
        "email": 1
      },
      "indicator_count": 13035,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 218,
      "modified_text": "894 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "https://onsapay.com/loaderSe",
    "type": "URL"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "https://onsapay.com/loaderSe",
    "type": "URL",
    "found": false,
    "verdict": "clean",
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1776639435.1990466
}