{
  "type": "URL",
  "indicator": "https://outer.location.search",
  "general": {
    "sections": [
      "general",
      "url_list",
      "http_scans",
      "screenshot"
    ],
    "indicator": "https://outer.location.search",
    "type": "url",
    "type_title": "URL",
    "validation": [],
    "base_indicator": {
      "id": 3172055684,
      "indicator": "https://outer.location.search",
      "type": "URL",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 17,
      "pulses": [
        {
          "id": "6570a6b7ff4216fe9cd82625",
          "name": "DGA Domain",
          "description": "",
          "modified": "2023-12-06T16:52:05.939000",
          "created": "2023-12-06T16:52:05.939000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 8,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 1181,
            "CVE": 1,
            "FileHash-SHA256": 1556,
            "URL": 2748,
            "domain": 419,
            "FileHash-MD5": 646,
            "FileHash-SHA1": 348,
            "email": 3,
            "CIDR": 1
          },
          "indicator_count": 6903,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 111,
          "modified_text": "865 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6570a029f7654ae30157d89f",
          "name": "DGA Domain",
          "description": "",
          "modified": "2023-12-06T16:24:07.472000",
          "created": "2023-12-06T16:24:07.472000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 7,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 1181,
            "CVE": 1,
            "FileHash-SHA256": 1556,
            "URL": 2748,
            "domain": 419,
            "FileHash-MD5": 646,
            "FileHash-SHA1": 348,
            "email": 3,
            "CIDR": 1
          },
          "indicator_count": 6903,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 110,
          "modified_text": "865 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "657083e146e5b101fdbf176d",
          "name": "fb_stringify_congress",
          "description": "",
          "modified": "2023-12-06T14:23:29.639000",
          "created": "2023-12-06T14:23:29.639000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 213,
            "domain": 118,
            "hostname": 232,
            "URL": 823
          },
          "indicator_count": 1386,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "865 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "657080d20f7e10c1e37fcf89",
          "name": "TarrantCounty.com ~ 03.01.2022",
          "description": "",
          "modified": "2023-12-06T14:10:26.301000",
          "created": "2023-12-06T14:10:26.301000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 1078,
            "domain": 838,
            "hostname": 1607,
            "URL": 4134,
            "email": 3,
            "FileHash-SHA1": 2,
            "CIDR": 4,
            "FileHash-MD5": 15
          },
          "indicator_count": 7681,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "865 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "65707fe17dfdfe16066d16de",
          "name": "Bexar.org",
          "description": "",
          "modified": "2023-12-06T14:06:25.800000",
          "created": "2023-12-06T14:06:25.800000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 1735,
            "hostname": 1833,
            "domain": 1025,
            "URL": 4668,
            "email": 4,
            "FileHash-MD5": 133,
            "FileHash-SHA1": 6,
            "CIDR": 5
          },
          "indicator_count": 9409,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 110,
          "modified_text": "865 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "65707f7f79257c3b4f276f35",
          "name": "whitehouse.govapi_2.27.22",
          "description": "",
          "modified": "2023-12-06T14:04:47.874000",
          "created": "2023-12-06T14:04:47.874000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 489,
            "hostname": 405,
            "domain": 306,
            "URL": 1451,
            "email": 1,
            "FileHash-MD5": 4
          },
          "indicator_count": 2656,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "865 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "65707e5b7df6f60133e8fb50",
          "name": "Jeeng / Powerbox",
          "description": "",
          "modified": "2023-12-06T13:59:55.129000",
          "created": "2023-12-06T13:59:55.129000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "CVE": 3,
            "FileHash-SHA256": 9072,
            "domain": 2500,
            "hostname": 3584,
            "URL": 13548,
            "FileHash-MD5": 197,
            "FileHash-SHA1": 162,
            "email": 19,
            "CIDR": 20,
            "SSLCertFingerprint": 2,
            "BitcoinAddress": 1
          },
          "indicator_count": 29108,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "865 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "653f123278ba7a9e62fdc4cb",
          "name": "DGA Domain",
          "description": "",
          "modified": "2023-10-30T02:17:22.194000",
          "created": "2023-10-30T02:17:22.194000",
          "tags": [
            "domain related",
            "united",
            "as32244 liquid",
            "creation date",
            "search",
            "for privacy",
            "entries",
            "unknown",
            "moved",
            "frame",
            "passive dns",
            "date",
            "body",
            "footer",
            "apache",
            "abuse",
            "status hostname",
            "query type",
            "address first",
            "seen last",
            "seen asn",
            "country unknown"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": "65134ae8fc70cf6ef83d7d74",
          "export_count": 9,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 950,
            "email": 7,
            "CIDR": 2,
            "FileHash-MD5": 650,
            "FileHash-SHA256": 2081,
            "URL": 3334,
            "hostname": 1804,
            "CVE": 1,
            "FileHash-SHA1": 353
          },
          "indicator_count": 9182,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 219,
          "modified_text": "902 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "65134ae8fc70cf6ef83d7d74",
          "name": "DGA Domain",
          "description": "",
          "modified": "2023-09-26T21:19:36.331000",
          "created": "2023-09-26T21:19:36.331000",
          "tags": [
            "domain related",
            "united",
            "as32244 liquid",
            "creation date",
            "search",
            "for privacy",
            "entries",
            "unknown",
            "moved",
            "frame",
            "passive dns",
            "date",
            "body",
            "footer",
            "apache",
            "abuse",
            "status hostname",
            "query type",
            "address first",
            "seen last",
            "seen asn",
            "country unknown"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": "64df7031dfbe14bb4c3d7de0",
          "export_count": 6,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 950,
            "email": 7,
            "CIDR": 2,
            "FileHash-MD5": 650,
            "FileHash-SHA256": 2081,
            "URL": 3334,
            "hostname": 1804,
            "CVE": 1,
            "FileHash-SHA1": 353
          },
          "indicator_count": 9182,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 225,
          "modified_text": "935 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "64df7031dfbe14bb4c3d7de0",
          "name": "DGA Domain",
          "description": "nsis\ncontains-pe\ndownloads-pdf\nupx\nDGA domain. Host at least 2 malicious files.\nA domain generation algorithm (DGA) is a program that generates a large list of domain names. DGAs provide malware with new domains in order to evade security countermeasures. DGA can provide hundreds of new, random domains. This enables hackers to keep their servers up and running without being blocklisted or taken down by the victim. Malware switch between domains faster than security software can take them down.\nUsed by Adversarial businesses, authentication and especially law firms to silence victims of crime.",
          "modified": "2023-09-17T18:04:52.183000",
          "created": "2023-08-18T13:20:49.696000",
          "tags": [
            "domain related",
            "united",
            "as32244 liquid",
            "creation date",
            "search",
            "for privacy",
            "entries",
            "unknown",
            "moved",
            "frame",
            "passive dns",
            "date",
            "body",
            "footer",
            "apache",
            "abuse",
            "status hostname",
            "query type",
            "address first",
            "seen last",
            "seen asn",
            "country unknown"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 18,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 950,
            "email": 7,
            "CIDR": 2,
            "FileHash-MD5": 650,
            "FileHash-SHA256": 2081,
            "URL": 3334,
            "hostname": 1804,
            "CVE": 1,
            "FileHash-SHA1": 353
          },
          "indicator_count": 9182,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 220,
          "modified_text": "945 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "620c3b1f8af7ea0dcf2c1218",
          "name": "Jeeng / Powerbox",
          "description": "",
          "modified": "2022-06-12T22:01:23.105000",
          "created": "2022-02-15T23:45:35.234000",
          "tags": [
            "Jeeng",
            "tim pool",
            "timcast"
          ],
          "references": [
            "cf20ed53-cb6d-4dfd-a4e8-794fbe163efc.pcap"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 10,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scnrscnr",
            "id": "126475",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_126475/resized/80/avatar_67ca5b7bae.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 9072,
            "domain": 2500,
            "URL": 13548,
            "hostname": 3584,
            "FileHash-MD5": 197,
            "FileHash-SHA1": 162,
            "CVE": 3,
            "CIDR": 20,
            "SSLCertFingerprint": 2,
            "email": 19,
            "BitcoinAddress": 1
          },
          "indicator_count": 29108,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 97,
          "modified_text": "1406 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "62276abfaa65cd33f64331f8",
          "name": "TarrantCounty.com ~ 03.01.2022",
          "description": "",
          "modified": "2022-04-07T00:04:02.553000",
          "created": "2022-03-08T14:39:59.235000",
          "tags": [
            "march",
            "lookup go",
            "rescan add",
            "verdict report",
            "de summary",
            "http",
            "redirects links",
            "behaviour",
            "similar dom",
            "content api",
            "value",
            "search url",
            "search domain",
            "scan url",
            "url search",
            "domain scan",
            "url url",
            "motor vehicle",
            "aqb1",
            "eventsevent10",
            "meta",
            "show",
            "download go",
            "full url",
            "reverse dns",
            "resource",
            "windows nt",
            "win64",
            "khtml",
            "gecko",
            "response",
            "main",
            "milan",
            "apache",
            "paris",
            "accept"
          ],
          "references": [
            "TarrantCounty3df.pdf",
            "TarantCounty2df.pdf",
            "TarrantCounty4df.pdf",
            "TarrantCounty5df.pdf",
            "tarrant23df.pdf",
            "TarrantCounty1df.pdf",
            "tarrantcounty.com:en:elections:Voter-Information:Voter- Registration.html%22,.pdf",
            "TarrantCounty6df.pdf",
            "TarrantCounty7df.pdf",
            "TarrantCounty10df.pdf",
            "TarrantCounty9df.pdf",
            "TarrantCounty17df.pdf",
            "TarrantCounty15df.pdf",
            "TarrantCounty12df.pdf",
            "TarrantCounty14df.pdf",
            "tarrantcounty8df.pdf",
            "TarrantCounty18df.pdf",
            "TarrantCounty19df.pdf",
            "TarrantCounty21df.pdf",
            "tarrantcounty22df.pdf",
            "TarrantCounty20df.pdf",
            "tarrantcountydf.pdf"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "Government"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 6,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Kailula4",
            "id": "131997",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 4134,
            "hostname": 1607,
            "domain": 838,
            "FileHash-SHA256": 1078,
            "FileHash-SHA1": 2,
            "email": 3,
            "CIDR": 4,
            "FileHash-MD5": 15
          },
          "indicator_count": 7681,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 406,
          "modified_text": "1473 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "621fff12d2c54f70fea90576",
          "name": "Bexar.org",
          "description": "",
          "modified": "2022-04-01T00:01:54.852000",
          "created": "2022-03-02T23:34:42.531000",
          "tags": [],
          "references": [
            "www.bexar.org - urlscan.io.pdf",
            "bexar api 4.pdf",
            "bexar api 8.pdf",
            "bexar 6.pdf",
            "bexar api 2.pdf",
            "bexar api 7.pdf",
            "bexar api 3.pdf",
            "bexar api 9.pdf",
            "bexar api 12.pdf",
            "bexar api 17.pdf",
            "bexar api 15.pdf",
            "bexar api 18.pdf",
            "bexar api 10.pdf",
            "bexar api 19.pdf",
            "bexar api 20.pdf",
            "bexar api 13.pdf",
            "bexar api 21.pdf",
            "bexar api 14.pdf",
            "bexar api 22.pdf",
            "bexar1.pdf",
            "bexar api5.pdf",
            "bexar2.pdf",
            "bexar3.pdf",
            "bexar.org 3.2.22.pdf",
            "bexar6.pdf",
            "bexar5.pdf",
            "bexar api_1.pdf",
            "bexar10.pdf",
            "bexar api.pdf",
            "bexar_v1df.pdf",
            "bexarv4df.pdf",
            "bexarv2df.pdf",
            "bexarv6df.pdf",
            "bexasv3df.pdf",
            "bexarv7df.pdf",
            "bear_v apidf.pdf"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "Government"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 7,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Kailula4",
            "id": "131997",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 1833,
            "URL": 4669,
            "domain": 1025,
            "FileHash-SHA256": 1735,
            "email": 4,
            "FileHash-MD5": 133,
            "FileHash-SHA1": 6,
            "CIDR": 5
          },
          "indicator_count": 9410,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 407,
          "modified_text": "1479 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "621cd787f6506db23725e2d3",
          "name": "302 Found - http://dungcoivb.googlepages.com/NDM.txt -worm",
          "description": "5574a0a405bdeea91c7493772c85a3a5f8e20297ccc22d1732c654dd933436c5 - \nFile Name\n5kk For BTC By beak.txt - 15 feb 2022",
          "modified": "2022-03-30T00:00:10.458000",
          "created": "2022-02-28T14:09:11.463000",
          "tags": [
            "pageaction",
            "pageview",
            "contentupdate",
            "outgoingrequest",
            "clienterror",
            "partnerapicall",
            "trackedscenario",
            "accountcontrols",
            "date",
            "yfunction",
            "found",
            "yorker skip",
            "slower",
            "yorker",
            "get cricket",
            "search search",
            "blog",
            "me slower",
            "yorker visit",
            "report abuse",
            "powered",
            "script script",
            "div div",
            "javascript x",
            "content type",
            "link",
            "registered",
            "javascript var",
            "javascript",
            "a domains",
            "body doctype",
            "corporate",
            "server",
            "brother nc8900h",
            "printer",
            "mega well",
            "well limited",
            "1475110285886",
            "raspberry pi",
            "american power",
            "intel corporate",
            "android",
            "internal",
            "22bda033958f7586a9ca064c834c6a74e305bc69e5d7f945516c8ceed82ac925",
            "http://dungcoivb.googlepages.com/ND.txt",
            "http://dungcoivb.googlepages.com/NDM.txt",
            "https://d1lxhc4jvstzrp.cloudfront.net/themes/registrar/images/na"
          ],
          "references": [
            "asset-discovery-services-20210401162753.cvs.csv",
            "ch1wfp-hist02b.cqgnet.com",
            "dungcoivb.googlepages.com - delivering worm",
            "22bda033958f7586a9ca064c834c6a74e305bc69e5d7f945516c8ceed82ac925",
            "http://dungcoivb.googlepages.com/NDM.txt",
            "https://d1lxhc4jvstzrp.cloudfront.net/themes/registrar/images/namecheap1.svg",
            "http://www.sloweryorker.com",
            "http://www.planlight.eu/",
            "hpty2hj2xm.dattolocal.net",
            "https://mem.gfx.ms/meversion?partner=MSHomePage&market=en-us&uhf=1",
            "http://www.microsoft.com/pkiops/crl/Microsoft%20Windows%20Verification%20PCA(1).crl"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Worm:Win32/DungCoi",
              "display_name": "Worm:Win32/DungCoi",
              "target": "/malware/Worm:Win32/DungCoi"
            }
          ],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 3,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "dorkingbeauty1",
            "id": "80137",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 258,
            "hostname": 379,
            "FileHash-SHA256": 112,
            "domain": 41,
            "FileHash-MD5": 1
          },
          "indicator_count": 791,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 394,
          "modified_text": "1481 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "621bc13f579cdd25d609b309",
          "name": "whitehouse.govapi_2.27.22",
          "description": "",
          "modified": "2022-03-29T00:03:34.773000",
          "created": "2022-02-27T18:21:51.099000",
          "tags": [
            "show",
            "download go",
            "full url",
            "reverse dns",
            "request",
            "windows nt",
            "win64",
            "khtml",
            "gecko",
            "response",
            "main",
            "accept",
            "february",
            "behaviour",
            "lookup go",
            "rescan add",
            "verdict report",
            "de summary",
            "http",
            "redirects links",
            "similar dom",
            "content api",
            "value",
            "search domain",
            "scan url",
            "search url",
            "meta",
            "detected",
            "akamaiasn1",
            "google",
            "expand overall",
            "page url",
            "iframe"
          ],
          "references": [
            "whitehouse.govapi_2.27.22.pdf",
            "whithouse.gov 2.27.22 4.pdf",
            "whitehouse.gov 2.27.22 2.pdf",
            "whitehouse.gov 2.27.22 1.pdf",
            "whitehouse.gov 2.27.22 6.pdf",
            "whitehouse.gov 2.27.22 3.pdf",
            "whitehouse.gov 2.27.22 5.pdf",
            "whitehouse.gov 2.28.22 8.pdf",
            "whitehouse.gov 2.27.22 7.pdf",
            "whitehouse.gov 2.27.22 8.pdf"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1199",
              "name": "Trusted Relationship",
              "display_name": "T1199 - Trusted Relationship"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 6,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Kailula4",
            "id": "131997",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 1452,
            "hostname": 405,
            "domain": 306,
            "FileHash-SHA256": 489,
            "email": 1,
            "FileHash-MD5": 4
          },
          "indicator_count": 2657,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 408,
          "modified_text": "1482 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "62316de6f16f2373aef19725",
          "name": "fb_stringify_congress",
          "description": "",
          "modified": "2022-03-16T04:56:06.960000",
          "created": "2022-03-16T04:56:06.960000",
          "tags": [],
          "references": [
            "fb_stringify_congress.pdf"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 5,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Kailula4",
            "id": "131997",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 823,
            "hostname": 232,
            "FileHash-SHA256": 213,
            "domain": 118
          },
          "indicator_count": 1386,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 406,
          "modified_text": "1495 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "622278c9acba04d1e5c98f66",
          "name": "https://net.kojinbango-card.go.jp/SS_SERVICE_OUT/pages/ssf/FG08S001.jsp",
          "description": "",
          "modified": "2022-03-04T20:38:33.054000",
          "created": "2022-03-04T20:38:33.054000",
          "tags": [
            "input",
            "meta",
            "please",
            "secure",
            "httponly",
            "cdata",
            "function",
            "ss service",
            "response code",
            "expires",
            "form"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 5,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Kailula4",
            "id": "131997",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 22,
            "hostname": 21,
            "FileHash-SHA256": 20,
            "FileHash-MD5": 2,
            "domain": 3
          },
          "indicator_count": 68,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 406,
          "modified_text": "1506 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "TarrantCounty14df.pdf",
        "whitehouse.gov 2.27.22 8.pdf",
        "whitehouse.gov 2.27.22 3.pdf",
        "bexar api 15.pdf",
        "https://d1lxhc4jvstzrp.cloudfront.net/themes/registrar/images/namecheap1.svg",
        "bexar api 14.pdf",
        "whitehouse.gov 2.28.22 8.pdf",
        "TarrantCounty3df.pdf",
        "dungcoivb.googlepages.com - delivering worm",
        "asset-discovery-services-20210401162753.cvs.csv",
        "bexar3.pdf",
        "TarrantCounty21df.pdf",
        "bexar_v1df.pdf",
        "http://dungcoivb.googlepages.com/NDM.txt",
        "bexar10.pdf",
        "bexar api.pdf",
        "bexar 6.pdf",
        "whitehouse.gov 2.27.22 1.pdf",
        "TarrantCounty15df.pdf",
        "TarrantCounty1df.pdf",
        "bexar api5.pdf",
        "TarantCounty2df.pdf",
        "bexarv4df.pdf",
        "bexar api 17.pdf",
        "tarrantcounty8df.pdf",
        "whitehouse.gov 2.27.22 7.pdf",
        "tarrantcounty22df.pdf",
        "bexar api 19.pdf",
        "http://www.microsoft.com/pkiops/crl/Microsoft%20Windows%20Verification%20PCA(1).crl",
        "bexar api 21.pdf",
        "bexar api_1.pdf",
        "bexar6.pdf",
        "bexar api 4.pdf",
        "bexarv7df.pdf",
        "bexar2.pdf",
        "TarrantCounty4df.pdf",
        "TarrantCounty9df.pdf",
        "bexarv2df.pdf",
        "bexar api 10.pdf",
        "bexar api 12.pdf",
        "bexar5.pdf",
        "http://www.planlight.eu/",
        "tarrantcounty.com:en:elections:Voter-Information:Voter- Registration.html%22,.pdf",
        "bexar api 2.pdf",
        "bexarv6df.pdf",
        "bexar api 3.pdf",
        "tarrant23df.pdf",
        "TarrantCounty17df.pdf",
        "hpty2hj2xm.dattolocal.net",
        "whitehouse.gov 2.27.22 2.pdf",
        "TarrantCounty19df.pdf",
        "bexar api 8.pdf",
        "whitehouse.govapi_2.27.22.pdf",
        "whitehouse.gov 2.27.22 5.pdf",
        "bexar api 20.pdf",
        "bexar api 9.pdf",
        "bear_v apidf.pdf",
        "http://www.sloweryorker.com",
        "bexar api 7.pdf",
        "bexasv3df.pdf",
        "whitehouse.gov 2.27.22 6.pdf",
        "cf20ed53-cb6d-4dfd-a4e8-794fbe163efc.pcap",
        "bexar.org 3.2.22.pdf",
        "bexar api 22.pdf",
        "TarrantCounty12df.pdf",
        "tarrantcountydf.pdf",
        "TarrantCounty7df.pdf",
        "bexar api 18.pdf",
        "TarrantCounty10df.pdf",
        "bexar1.pdf",
        "TarrantCounty18df.pdf",
        "bexar api 13.pdf",
        "https://mem.gfx.ms/meversion?partner=MSHomePage&market=en-us&uhf=1",
        "TarrantCounty5df.pdf",
        "ch1wfp-hist02b.cqgnet.com",
        "22bda033958f7586a9ca064c834c6a74e305bc69e5d7f945516c8ceed82ac925",
        "whithouse.gov 2.27.22 4.pdf",
        "TarrantCounty20df.pdf",
        "TarrantCounty6df.pdf",
        "fb_stringify_congress.pdf",
        "www.bexar.org - urlscan.io.pdf"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 0
        },
        "other": {
          "adversary": [],
          "malware_families": [
            "Worm:win32/dungcoi"
          ],
          "industries": [
            "Government"
          ],
          "unique_indicators": 51429
        }
      }
    },
    "false_positive": [],
    "alexa": "http://www.alexa.com/siteinfo/location.search",
    "whois": "http://whois.domaintools.com/location.search",
    "domain": "location.search",
    "hostname": "outer.location.search"
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 17,
  "pulses": [
    {
      "id": "6570a6b7ff4216fe9cd82625",
      "name": "DGA Domain",
      "description": "",
      "modified": "2023-12-06T16:52:05.939000",
      "created": "2023-12-06T16:52:05.939000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 8,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 1181,
        "CVE": 1,
        "FileHash-SHA256": 1556,
        "URL": 2748,
        "domain": 419,
        "FileHash-MD5": 646,
        "FileHash-SHA1": 348,
        "email": 3,
        "CIDR": 1
      },
      "indicator_count": 6903,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 111,
      "modified_text": "865 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6570a029f7654ae30157d89f",
      "name": "DGA Domain",
      "description": "",
      "modified": "2023-12-06T16:24:07.472000",
      "created": "2023-12-06T16:24:07.472000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 7,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 1181,
        "CVE": 1,
        "FileHash-SHA256": 1556,
        "URL": 2748,
        "domain": 419,
        "FileHash-MD5": 646,
        "FileHash-SHA1": 348,
        "email": 3,
        "CIDR": 1
      },
      "indicator_count": 6903,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 110,
      "modified_text": "865 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "657083e146e5b101fdbf176d",
      "name": "fb_stringify_congress",
      "description": "",
      "modified": "2023-12-06T14:23:29.639000",
      "created": "2023-12-06T14:23:29.639000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 213,
        "domain": 118,
        "hostname": 232,
        "URL": 823
      },
      "indicator_count": 1386,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "865 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "657080d20f7e10c1e37fcf89",
      "name": "TarrantCounty.com ~ 03.01.2022",
      "description": "",
      "modified": "2023-12-06T14:10:26.301000",
      "created": "2023-12-06T14:10:26.301000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 1078,
        "domain": 838,
        "hostname": 1607,
        "URL": 4134,
        "email": 3,
        "FileHash-SHA1": 2,
        "CIDR": 4,
        "FileHash-MD5": 15
      },
      "indicator_count": 7681,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "865 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "65707fe17dfdfe16066d16de",
      "name": "Bexar.org",
      "description": "",
      "modified": "2023-12-06T14:06:25.800000",
      "created": "2023-12-06T14:06:25.800000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 1735,
        "hostname": 1833,
        "domain": 1025,
        "URL": 4668,
        "email": 4,
        "FileHash-MD5": 133,
        "FileHash-SHA1": 6,
        "CIDR": 5
      },
      "indicator_count": 9409,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 110,
      "modified_text": "865 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "65707f7f79257c3b4f276f35",
      "name": "whitehouse.govapi_2.27.22",
      "description": "",
      "modified": "2023-12-06T14:04:47.874000",
      "created": "2023-12-06T14:04:47.874000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 489,
        "hostname": 405,
        "domain": 306,
        "URL": 1451,
        "email": 1,
        "FileHash-MD5": 4
      },
      "indicator_count": 2656,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "865 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "65707e5b7df6f60133e8fb50",
      "name": "Jeeng / Powerbox",
      "description": "",
      "modified": "2023-12-06T13:59:55.129000",
      "created": "2023-12-06T13:59:55.129000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "CVE": 3,
        "FileHash-SHA256": 9072,
        "domain": 2500,
        "hostname": 3584,
        "URL": 13548,
        "FileHash-MD5": 197,
        "FileHash-SHA1": 162,
        "email": 19,
        "CIDR": 20,
        "SSLCertFingerprint": 2,
        "BitcoinAddress": 1
      },
      "indicator_count": 29108,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "865 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "653f123278ba7a9e62fdc4cb",
      "name": "DGA Domain",
      "description": "",
      "modified": "2023-10-30T02:17:22.194000",
      "created": "2023-10-30T02:17:22.194000",
      "tags": [
        "domain related",
        "united",
        "as32244 liquid",
        "creation date",
        "search",
        "for privacy",
        "entries",
        "unknown",
        "moved",
        "frame",
        "passive dns",
        "date",
        "body",
        "footer",
        "apache",
        "abuse",
        "status hostname",
        "query type",
        "address first",
        "seen last",
        "seen asn",
        "country unknown"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": "65134ae8fc70cf6ef83d7d74",
      "export_count": 9,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 950,
        "email": 7,
        "CIDR": 2,
        "FileHash-MD5": 650,
        "FileHash-SHA256": 2081,
        "URL": 3334,
        "hostname": 1804,
        "CVE": 1,
        "FileHash-SHA1": 353
      },
      "indicator_count": 9182,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 219,
      "modified_text": "902 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "65134ae8fc70cf6ef83d7d74",
      "name": "DGA Domain",
      "description": "",
      "modified": "2023-09-26T21:19:36.331000",
      "created": "2023-09-26T21:19:36.331000",
      "tags": [
        "domain related",
        "united",
        "as32244 liquid",
        "creation date",
        "search",
        "for privacy",
        "entries",
        "unknown",
        "moved",
        "frame",
        "passive dns",
        "date",
        "body",
        "footer",
        "apache",
        "abuse",
        "status hostname",
        "query type",
        "address first",
        "seen last",
        "seen asn",
        "country unknown"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": "64df7031dfbe14bb4c3d7de0",
      "export_count": 6,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "scoreblue",
        "id": "254100",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 950,
        "email": 7,
        "CIDR": 2,
        "FileHash-MD5": 650,
        "FileHash-SHA256": 2081,
        "URL": 3334,
        "hostname": 1804,
        "CVE": 1,
        "FileHash-SHA1": 353
      },
      "indicator_count": 9182,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 225,
      "modified_text": "935 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "64df7031dfbe14bb4c3d7de0",
      "name": "DGA Domain",
      "description": "nsis\ncontains-pe\ndownloads-pdf\nupx\nDGA domain. Host at least 2 malicious files.\nA domain generation algorithm (DGA) is a program that generates a large list of domain names. DGAs provide malware with new domains in order to evade security countermeasures. DGA can provide hundreds of new, random domains. This enables hackers to keep their servers up and running without being blocklisted or taken down by the victim. Malware switch between domains faster than security software can take them down.\nUsed by Adversarial businesses, authentication and especially law firms to silence victims of crime.",
      "modified": "2023-09-17T18:04:52.183000",
      "created": "2023-08-18T13:20:49.696000",
      "tags": [
        "domain related",
        "united",
        "as32244 liquid",
        "creation date",
        "search",
        "for privacy",
        "entries",
        "unknown",
        "moved",
        "frame",
        "passive dns",
        "date",
        "body",
        "footer",
        "apache",
        "abuse",
        "status hostname",
        "query type",
        "address first",
        "seen last",
        "seen asn",
        "country unknown"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 18,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 950,
        "email": 7,
        "CIDR": 2,
        "FileHash-MD5": 650,
        "FileHash-SHA256": 2081,
        "URL": 3334,
        "hostname": 1804,
        "CVE": 1,
        "FileHash-SHA1": 353
      },
      "indicator_count": 9182,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 220,
      "modified_text": "945 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "https://outer.location.search",
    "type": "URL"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "https://outer.location.search",
    "type": "URL",
    "found": false,
    "verdict": "clean",
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1776629735.7567046
}