{
  "type": "URL",
  "indicator": "https://planet.tikalk.com/timetracker/login.php",
  "general": {
    "sections": [
      "general",
      "url_list",
      "http_scans",
      "screenshot"
    ],
    "indicator": "https://planet.tikalk.com/timetracker/login.php",
    "type": "url",
    "type_title": "URL",
    "validation": [],
    "base_indicator": {
      "id": 3378654726,
      "indicator": "https://planet.tikalk.com/timetracker/login.php",
      "type": "URL",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 6,
      "pulses": [
        {
          "id": "655076c123a5ab86eb0c8a34",
          "name": "Luna Moth/Silent Ransom Group Callback Phishing Extortion Campaign",
          "description": "",
          "modified": "2023-12-12T06:03:08.751000",
          "created": "2023-11-12T06:54:57.966000",
          "tags": [
            "unknown",
            "as8075",
            "united",
            "nxdomain",
            "a nxdomain",
            "asnone country",
            "search",
            "domain",
            "creation date",
            "scan endpoints",
            "date",
            "new zealand",
            "ns nxdomain",
            "aaaa nxdomain",
            "asnone united",
            "cname",
            "asnone",
            "soa nxdomain",
            "australia",
            "status hostname",
            "domains show",
            "domain related",
            "entrie",
            "ssl certificate",
            "whois record",
            "historical ssl",
            "resolutions",
            "whois whois",
            "referrer",
            "communicating",
            "siblings",
            "moth callback",
            "threat roundup",
            "june",
            "record type",
            "ttl value",
            "server",
            "privacy billing",
            "redacted for",
            "privacy admin",
            "postal code",
            "email",
            "admin email",
            "stateprovince",
            "city",
            "code",
            "pty ltd",
            "registrar abuse",
            "wholesale pty",
            "tpp wholesale",
            "registrar url",
            "execution",
            "contacted",
            "malware",
            "IPv4 13.75.251.189 scanning_host",
            "scanning_host",
            "phishing"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "Malware",
              "display_name": "Malware",
              "target": null
            }
          ],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 23,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 3487,
            "domain": 1111,
            "email": 7,
            "hostname": 1368,
            "FileHash-MD5": 102,
            "FileHash-SHA1": 102,
            "FileHash-SHA256": 663
          },
          "indicator_count": 6840,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 219,
          "modified_text": "859 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "655076c8f26b8ab3f641f4ae",
          "name": "Luna Moth/Silent Ransom Group Callback Phishing Extortion Campaign",
          "description": "",
          "modified": "2023-12-12T06:03:08.751000",
          "created": "2023-11-12T06:55:04.517000",
          "tags": [
            "unknown",
            "as8075",
            "united",
            "nxdomain",
            "a nxdomain",
            "asnone country",
            "search",
            "domain",
            "creation date",
            "scan endpoints",
            "date",
            "new zealand",
            "ns nxdomain",
            "aaaa nxdomain",
            "asnone united",
            "cname",
            "asnone",
            "soa nxdomain",
            "australia",
            "status hostname",
            "domains show",
            "domain related",
            "entrie",
            "ssl certificate",
            "whois record",
            "historical ssl",
            "resolutions",
            "whois whois",
            "referrer",
            "communicating",
            "siblings",
            "moth callback",
            "threat roundup",
            "june",
            "record type",
            "ttl value",
            "server",
            "privacy billing",
            "redacted for",
            "privacy admin",
            "postal code",
            "email",
            "admin email",
            "stateprovince",
            "city",
            "code",
            "pty ltd",
            "registrar abuse",
            "wholesale pty",
            "tpp wholesale",
            "registrar url",
            "execution",
            "contacted",
            "malware",
            "IPv4 13.75.251.189 scanning_host",
            "scanning_host",
            "phishing"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "Malware",
              "display_name": "Malware",
              "target": null
            }
          ],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 22,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 3487,
            "domain": 1111,
            "email": 7,
            "hostname": 1368,
            "FileHash-MD5": 102,
            "FileHash-SHA1": 102,
            "FileHash-SHA256": 663
          },
          "indicator_count": 6840,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 219,
          "modified_text": "859 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "65708e178755574d9812e4c9",
          "name": "Followed lead to brechlerinsurance.com",
          "description": "",
          "modified": "2023-12-06T15:07:03.528000",
          "created": "2023-12-06T15:07:03.528000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 3,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "CVE": 2,
            "FileHash-SHA256": 1329,
            "domain": 2068,
            "hostname": 4185,
            "URL": 12454,
            "email": 1,
            "FileHash-MD5": 3,
            "FileHash-SHA1": 1
          },
          "indicator_count": 20043,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 110,
          "modified_text": "865 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "628077c330f33dfd254e5a8b",
          "name": "Followed lead to brechlerinsurance.com",
          "description": "",
          "modified": "2022-06-13T00:00:32.864000",
          "created": "2022-05-15T03:47:15.835000",
          "tags": [
            "bomboraconsent",
            "gdpr",
            "ccpa",
            "date",
            "nthis",
            "array",
            "typeof e",
            "typeerror",
            "class",
            "image",
            "typeof symbol",
            "afsh",
            "copyright",
            "rights reserved",
            "comscore",
            "typeof o",
            "uspapi",
            "null",
            "s271733878",
            "secure hash",
            "algorithm",
            "sha1",
            "a1732584193",
            "1518500249",
            "imgurl",
            "oiqfpsjs",
            "script",
            "iframe",
            "oiqaddpagecat",
            "inte",
            "oiqdotag",
            "track",
            "regexp",
            "pseudo",
            "child",
            "typeof b",
            "error",
            "sufeffxa0",
            "attr",
            "void",
            "udc66udc67",
            "ud83d",
            "ufe0f",
            "ud83e",
            "udc68udc69",
            "udfcbudfcc",
            "u2640u2642",
            "uddb0uddb3",
            "udd74udd75",
            "wpbruiserclient",
            "browserinfo",
            "mozinnerscreenx",
            "xmlhttprequest",
            "activexobject",
            "bf7e56f2f3",
            "zpbcat",
            "zcluidkrs",
            "promise",
            "boolean",
            "verification",
            "object",
            "reflect",
            "typeof proxy",
            "demo",
            "shareaholic",
            "sfunction",
            "bearer",
            "patch",
            "accept",
            "function",
            "symbol",
            "weakmap",
            "dataview",
            "typeof module",
            "cfunction",
            "event",
            "afunction",
            "efunction",
            "mfunction",
            "binnerheightc",
            "number",
            "string",
            "trackevent",
            "click",
            "uint8array",
            "gtmng3vqql",
            "classes",
            "path",
            "code",
            "typeof r",
            "function code",
            "typeof n",
            "angular",
            "angularjs",
            "ember",
            "meteor",
            "zepto",
            "jquery",
            "vd",
            "utmb",
            "firefox",
            "shockwave flash",
            "utma",
            "utmz",
            "ieproto",
            "typeof",
            "widgetrootqa",
            "driftconductor",
            "addcookiedomain",
            "hubspot",
            "typeof t",
            "quora pixel",
            "4294967295",
            "uint32array",
            "viewcontent",
            "infinity",
            "register domain names",
            "domain registration",
            "business web hosting services",
            "web hosting provider",
            "business email accounts",
            "web site hosting",
            "domain name registration",
            "ecommerce hosting services",
            "buy domains",
            "bulk domain search",
            "domain name search",
            "domain hosting",
            "registrations",
            "websites",
            "whois",
            "registrar",
            "registry",
            "domainpeople",
            "domain name",
            "registration",
            "year discount",
            "web hosting",
            "us whois",
            "us contact",
            "lookup alerts",
            "support login",
            "call"
          ],
          "references": [
            "https://domainpeople.com",
            "xfe-URL-Domainpeople.com-stix2-2.1-export.json",
            "xfe-URL-shareaholic.com-stix2-2.1-export.json",
            "https://js.hubspot.com/analytics/1652585100000/210895.js",
            "https://js.driftt.com/include/1652585100000/mezhk4858hn8.js",
            "https://bam.nr-data.net/1/f37cf8a208?a=1772678&v=1216.487a282&to=dlwNQEdeWVgHSxlDV1JWEBtdXlhR&rst=1074&ck=1&ref=https://www.shareaholic.com/&ap=9&be=11&fe=795&dc=37&af=err,xhr,stn,ins&perf=%7B%22timing%22:%7B%22of%22:1652584962293,%22n%22:0,%22f%22:0,%22dn%22:0,%22dne%22:0,%22c%22:0,%22s%22:0,%22ce%22:0,%22rq%22:0,%22rp%22:0,%22rpe%22:0,%22dl%22:6,%22di%22:37,%22ds%22:37,%22de%22:45,%22dc%22:636,%22l%22:793,%22le%22:796%7D,%22navigation%22:%7B%22ty%22:2%7D%7D&fcp=123&jsonp=NREUM.setToken",
            "https://js-agent.newrelic.com/nr-1216.min.js",
            "https://js-na1.hs-scripts.com/210895.js",
            "https://www.googletagmanager.com/gtm.js?id=GTM-NG3VQQL",
            "https://dsms0mj1bbhn4.cloudfront.net/assets/pages-afd7ed46648f01def74df6e4c245da53bde609b863bf63ff94a87154f2f82de0.js",
            "https://dsms0mj1bbhn4.cloudfront.net/webpack/vendors~header~related-content~share-buttons~site-settings~user-settings~yarpp-header~yarpp-sites~ya~7d559390-c92fe44d0731743b2d8e.js",
            "https://dsms0mj1bbhn4.cloudfront.net/webpack/default~header~related-content~share-buttons~site-settings~user-settings~yarpp-header~yarpp-sites~ya~2fbcff42-06fb1418b4e0c0383855.js",
            "https://dsms0mj1bbhn4.cloudfront.net/ui-header/loader.js",
            "https://de.tynt.com/deb/v2?id=sh!sh&dn=AFSH&cc=1&r=",
            "http://www.brechlerinsurance.com/?gdbc-client=3.1.25-1652585170383",
            "http://www.brechlerinsurance.com/wwblcms/wp-includes/js/wp-emoji-release.min.js?ver=479aaeefa13948f8aa1a2479d7a751df",
            "http://www.brechlerinsurance.com/wwblcms/wp-includes/js/jquery/jquery.js?ver=1.12.4",
            "https://partner.shareaholic.com/partners.js?location=http%3A%2F%2Fwww.brechlerinsurance.com%2F&cl=en-US&id_sync=19da2f0f-8191-4a73-b27d-e95f97e9a686&minify=1&pvs=1&site=d016349f31f268b5ce94fa8e70f6eddd",
            "https://px.owneriq.net/stas/s/sholic.js",
            "https://i.simpli.fi/dpx.js?cid=66112&m=0&sifi_tuid=37830&referrer=http%3A%2F%2Fwww.brechlerinsurance.com%2F",
            "https://sb.scorecardresearch.com/beacon.js",
            "https://cdn.tynt.com/afsh.js",
            "xfe-URL-ml314.com-stix2-2.1-export.json",
            "xfe-URL-bombora.com-stix2-2.1-export.json",
            "xfe-URL-Owneriq.net-stix2-2.1-export.json"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "BomboraConsent",
              "display_name": "BomboraConsent",
              "target": null
            },
            {
              "id": "Vd",
              "display_name": "Vd",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 13,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "adjadex1@gmail.com",
            "id": "187163",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 4185,
            "URL": 12454,
            "FileHash-SHA256": 1329,
            "CVE": 2,
            "domain": 2068,
            "email": 1,
            "FileHash-MD5": 3,
            "FileHash-SHA1": 1
          },
          "indicator_count": 20043,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 68,
          "modified_text": "1406 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "620d08807af9ce9e3847a0ec",
          "name": "Inforcloudsuite.com",
          "description": "",
          "modified": "2022-03-18T00:04:44.902000",
          "created": "2022-02-16T14:21:52.273000",
          "tags": [
            "psiusa",
            "domain robot",
            "graph summary",
            "win32 exe",
            "server",
            "redacted for",
            "privacy tech",
            "privacy admin",
            "date",
            "country",
            "organization",
            "postal code",
            "stateprovince",
            "domain status",
            "umbrella",
            "code",
            "submission",
            "sophos",
            "comodo valkyrie",
            "verdict",
            "history first",
            "analysis",
            "utc http",
            "response final",
            "url http"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 5,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Kailula4",
            "id": "131997",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 1051,
            "URL": 2727,
            "domain": 438,
            "FileHash-SHA256": 113,
            "email": 1
          },
          "indicator_count": 4330,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 406,
          "modified_text": "1493 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "620d08a477f11b4221bfb402",
          "name": "inforcloudesuite",
          "description": "",
          "modified": "2022-03-18T00:04:44.902000",
          "created": "2022-02-16T14:22:28.691000",
          "tags": [
            "psiusa",
            "domain robot",
            "graph summary",
            "win32 exe",
            "server",
            "redacted for",
            "privacy tech",
            "privacy admin",
            "date",
            "country",
            "organization",
            "postal code",
            "stateprovince",
            "domain status",
            "umbrella",
            "code",
            "submission",
            "sophos",
            "comodo valkyrie",
            "verdict",
            "history first",
            "analysis",
            "utc http",
            "response final",
            "url http"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 4,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Kailula4",
            "id": "131997",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 3986,
            "domain": 560,
            "FileHash-SHA256": 652,
            "hostname": 1596,
            "email": 1
          },
          "indicator_count": 6795,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 407,
          "modified_text": "1493 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "https://de.tynt.com/deb/v2?id=sh!sh&dn=AFSH&cc=1&r=",
        "https://js-na1.hs-scripts.com/210895.js",
        "https://domainpeople.com",
        "https://sb.scorecardresearch.com/beacon.js",
        "https://partner.shareaholic.com/partners.js?location=http%3A%2F%2Fwww.brechlerinsurance.com%2F&cl=en-US&id_sync=19da2f0f-8191-4a73-b27d-e95f97e9a686&minify=1&pvs=1&site=d016349f31f268b5ce94fa8e70f6eddd",
        "https://js-agent.newrelic.com/nr-1216.min.js",
        "xfe-URL-bombora.com-stix2-2.1-export.json",
        "https://js.hubspot.com/analytics/1652585100000/210895.js",
        "https://www.googletagmanager.com/gtm.js?id=GTM-NG3VQQL",
        "https://dsms0mj1bbhn4.cloudfront.net/ui-header/loader.js",
        "http://www.brechlerinsurance.com/wwblcms/wp-includes/js/jquery/jquery.js?ver=1.12.4",
        "xfe-URL-Owneriq.net-stix2-2.1-export.json",
        "https://cdn.tynt.com/afsh.js",
        "http://www.brechlerinsurance.com/?gdbc-client=3.1.25-1652585170383",
        "https://dsms0mj1bbhn4.cloudfront.net/webpack/vendors~header~related-content~share-buttons~site-settings~user-settings~yarpp-header~yarpp-sites~ya~7d559390-c92fe44d0731743b2d8e.js",
        "xfe-URL-Domainpeople.com-stix2-2.1-export.json",
        "http://www.brechlerinsurance.com/wwblcms/wp-includes/js/wp-emoji-release.min.js?ver=479aaeefa13948f8aa1a2479d7a751df",
        "xfe-URL-ml314.com-stix2-2.1-export.json",
        "https://bam.nr-data.net/1/f37cf8a208?a=1772678&v=1216.487a282&to=dlwNQEdeWVgHSxlDV1JWEBtdXlhR&rst=1074&ck=1&ref=https://www.shareaholic.com/&ap=9&be=11&fe=795&dc=37&af=err,xhr,stn,ins&perf=%7B%22timing%22:%7B%22of%22:1652584962293,%22n%22:0,%22f%22:0,%22dn%22:0,%22dne%22:0,%22c%22:0,%22s%22:0,%22ce%22:0,%22rq%22:0,%22rp%22:0,%22rpe%22:0,%22dl%22:6,%22di%22:37,%22ds%22:37,%22de%22:45,%22dc%22:636,%22l%22:793,%22le%22:796%7D,%22navigation%22:%7B%22ty%22:2%7D%7D&fcp=123&jsonp=NREUM.setToken",
        "xfe-URL-shareaholic.com-stix2-2.1-export.json",
        "https://i.simpli.fi/dpx.js?cid=66112&m=0&sifi_tuid=37830&referrer=http%3A%2F%2Fwww.brechlerinsurance.com%2F",
        "https://dsms0mj1bbhn4.cloudfront.net/assets/pages-afd7ed46648f01def74df6e4c245da53bde609b863bf63ff94a87154f2f82de0.js",
        "https://js.driftt.com/include/1652585100000/mezhk4858hn8.js",
        "https://dsms0mj1bbhn4.cloudfront.net/webpack/default~header~related-content~share-buttons~site-settings~user-settings~yarpp-header~yarpp-sites~ya~2fbcff42-06fb1418b4e0c0383855.js",
        "https://px.owneriq.net/stas/s/sholic.js"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 0
        },
        "other": {
          "adversary": [],
          "malware_families": [
            "Bomboraconsent",
            "Malware",
            "Vd"
          ],
          "industries": [],
          "unique_indicators": 34659
        }
      }
    },
    "false_positive": [],
    "alexa": "http://www.alexa.com/siteinfo/tikalk.com",
    "whois": "http://whois.domaintools.com/tikalk.com",
    "domain": "tikalk.com",
    "hostname": "planet.tikalk.com"
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 6,
  "pulses": [
    {
      "id": "655076c123a5ab86eb0c8a34",
      "name": "Luna Moth/Silent Ransom Group Callback Phishing Extortion Campaign",
      "description": "",
      "modified": "2023-12-12T06:03:08.751000",
      "created": "2023-11-12T06:54:57.966000",
      "tags": [
        "unknown",
        "as8075",
        "united",
        "nxdomain",
        "a nxdomain",
        "asnone country",
        "search",
        "domain",
        "creation date",
        "scan endpoints",
        "date",
        "new zealand",
        "ns nxdomain",
        "aaaa nxdomain",
        "asnone united",
        "cname",
        "asnone",
        "soa nxdomain",
        "australia",
        "status hostname",
        "domains show",
        "domain related",
        "entrie",
        "ssl certificate",
        "whois record",
        "historical ssl",
        "resolutions",
        "whois whois",
        "referrer",
        "communicating",
        "siblings",
        "moth callback",
        "threat roundup",
        "june",
        "record type",
        "ttl value",
        "server",
        "privacy billing",
        "redacted for",
        "privacy admin",
        "postal code",
        "email",
        "admin email",
        "stateprovince",
        "city",
        "code",
        "pty ltd",
        "registrar abuse",
        "wholesale pty",
        "tpp wholesale",
        "registrar url",
        "execution",
        "contacted",
        "malware",
        "IPv4 13.75.251.189 scanning_host",
        "scanning_host",
        "phishing"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "Malware",
          "display_name": "Malware",
          "target": null
        }
      ],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 23,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 3487,
        "domain": 1111,
        "email": 7,
        "hostname": 1368,
        "FileHash-MD5": 102,
        "FileHash-SHA1": 102,
        "FileHash-SHA256": 663
      },
      "indicator_count": 6840,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 219,
      "modified_text": "859 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "655076c8f26b8ab3f641f4ae",
      "name": "Luna Moth/Silent Ransom Group Callback Phishing Extortion Campaign",
      "description": "",
      "modified": "2023-12-12T06:03:08.751000",
      "created": "2023-11-12T06:55:04.517000",
      "tags": [
        "unknown",
        "as8075",
        "united",
        "nxdomain",
        "a nxdomain",
        "asnone country",
        "search",
        "domain",
        "creation date",
        "scan endpoints",
        "date",
        "new zealand",
        "ns nxdomain",
        "aaaa nxdomain",
        "asnone united",
        "cname",
        "asnone",
        "soa nxdomain",
        "australia",
        "status hostname",
        "domains show",
        "domain related",
        "entrie",
        "ssl certificate",
        "whois record",
        "historical ssl",
        "resolutions",
        "whois whois",
        "referrer",
        "communicating",
        "siblings",
        "moth callback",
        "threat roundup",
        "june",
        "record type",
        "ttl value",
        "server",
        "privacy billing",
        "redacted for",
        "privacy admin",
        "postal code",
        "email",
        "admin email",
        "stateprovince",
        "city",
        "code",
        "pty ltd",
        "registrar abuse",
        "wholesale pty",
        "tpp wholesale",
        "registrar url",
        "execution",
        "contacted",
        "malware",
        "IPv4 13.75.251.189 scanning_host",
        "scanning_host",
        "phishing"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "Malware",
          "display_name": "Malware",
          "target": null
        }
      ],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 22,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 3487,
        "domain": 1111,
        "email": 7,
        "hostname": 1368,
        "FileHash-MD5": 102,
        "FileHash-SHA1": 102,
        "FileHash-SHA256": 663
      },
      "indicator_count": 6840,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 219,
      "modified_text": "859 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "65708e178755574d9812e4c9",
      "name": "Followed lead to brechlerinsurance.com",
      "description": "",
      "modified": "2023-12-06T15:07:03.528000",
      "created": "2023-12-06T15:07:03.528000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 3,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "CVE": 2,
        "FileHash-SHA256": 1329,
        "domain": 2068,
        "hostname": 4185,
        "URL": 12454,
        "email": 1,
        "FileHash-MD5": 3,
        "FileHash-SHA1": 1
      },
      "indicator_count": 20043,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 110,
      "modified_text": "865 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "628077c330f33dfd254e5a8b",
      "name": "Followed lead to brechlerinsurance.com",
      "description": "",
      "modified": "2022-06-13T00:00:32.864000",
      "created": "2022-05-15T03:47:15.835000",
      "tags": [
        "bomboraconsent",
        "gdpr",
        "ccpa",
        "date",
        "nthis",
        "array",
        "typeof e",
        "typeerror",
        "class",
        "image",
        "typeof symbol",
        "afsh",
        "copyright",
        "rights reserved",
        "comscore",
        "typeof o",
        "uspapi",
        "null",
        "s271733878",
        "secure hash",
        "algorithm",
        "sha1",
        "a1732584193",
        "1518500249",
        "imgurl",
        "oiqfpsjs",
        "script",
        "iframe",
        "oiqaddpagecat",
        "inte",
        "oiqdotag",
        "track",
        "regexp",
        "pseudo",
        "child",
        "typeof b",
        "error",
        "sufeffxa0",
        "attr",
        "void",
        "udc66udc67",
        "ud83d",
        "ufe0f",
        "ud83e",
        "udc68udc69",
        "udfcbudfcc",
        "u2640u2642",
        "uddb0uddb3",
        "udd74udd75",
        "wpbruiserclient",
        "browserinfo",
        "mozinnerscreenx",
        "xmlhttprequest",
        "activexobject",
        "bf7e56f2f3",
        "zpbcat",
        "zcluidkrs",
        "promise",
        "boolean",
        "verification",
        "object",
        "reflect",
        "typeof proxy",
        "demo",
        "shareaholic",
        "sfunction",
        "bearer",
        "patch",
        "accept",
        "function",
        "symbol",
        "weakmap",
        "dataview",
        "typeof module",
        "cfunction",
        "event",
        "afunction",
        "efunction",
        "mfunction",
        "binnerheightc",
        "number",
        "string",
        "trackevent",
        "click",
        "uint8array",
        "gtmng3vqql",
        "classes",
        "path",
        "code",
        "typeof r",
        "function code",
        "typeof n",
        "angular",
        "angularjs",
        "ember",
        "meteor",
        "zepto",
        "jquery",
        "vd",
        "utmb",
        "firefox",
        "shockwave flash",
        "utma",
        "utmz",
        "ieproto",
        "typeof",
        "widgetrootqa",
        "driftconductor",
        "addcookiedomain",
        "hubspot",
        "typeof t",
        "quora pixel",
        "4294967295",
        "uint32array",
        "viewcontent",
        "infinity",
        "register domain names",
        "domain registration",
        "business web hosting services",
        "web hosting provider",
        "business email accounts",
        "web site hosting",
        "domain name registration",
        "ecommerce hosting services",
        "buy domains",
        "bulk domain search",
        "domain name search",
        "domain hosting",
        "registrations",
        "websites",
        "whois",
        "registrar",
        "registry",
        "domainpeople",
        "domain name",
        "registration",
        "year discount",
        "web hosting",
        "us whois",
        "us contact",
        "lookup alerts",
        "support login",
        "call"
      ],
      "references": [
        "https://domainpeople.com",
        "xfe-URL-Domainpeople.com-stix2-2.1-export.json",
        "xfe-URL-shareaholic.com-stix2-2.1-export.json",
        "https://js.hubspot.com/analytics/1652585100000/210895.js",
        "https://js.driftt.com/include/1652585100000/mezhk4858hn8.js",
        "https://bam.nr-data.net/1/f37cf8a208?a=1772678&v=1216.487a282&to=dlwNQEdeWVgHSxlDV1JWEBtdXlhR&rst=1074&ck=1&ref=https://www.shareaholic.com/&ap=9&be=11&fe=795&dc=37&af=err,xhr,stn,ins&perf=%7B%22timing%22:%7B%22of%22:1652584962293,%22n%22:0,%22f%22:0,%22dn%22:0,%22dne%22:0,%22c%22:0,%22s%22:0,%22ce%22:0,%22rq%22:0,%22rp%22:0,%22rpe%22:0,%22dl%22:6,%22di%22:37,%22ds%22:37,%22de%22:45,%22dc%22:636,%22l%22:793,%22le%22:796%7D,%22navigation%22:%7B%22ty%22:2%7D%7D&fcp=123&jsonp=NREUM.setToken",
        "https://js-agent.newrelic.com/nr-1216.min.js",
        "https://js-na1.hs-scripts.com/210895.js",
        "https://www.googletagmanager.com/gtm.js?id=GTM-NG3VQQL",
        "https://dsms0mj1bbhn4.cloudfront.net/assets/pages-afd7ed46648f01def74df6e4c245da53bde609b863bf63ff94a87154f2f82de0.js",
        "https://dsms0mj1bbhn4.cloudfront.net/webpack/vendors~header~related-content~share-buttons~site-settings~user-settings~yarpp-header~yarpp-sites~ya~7d559390-c92fe44d0731743b2d8e.js",
        "https://dsms0mj1bbhn4.cloudfront.net/webpack/default~header~related-content~share-buttons~site-settings~user-settings~yarpp-header~yarpp-sites~ya~2fbcff42-06fb1418b4e0c0383855.js",
        "https://dsms0mj1bbhn4.cloudfront.net/ui-header/loader.js",
        "https://de.tynt.com/deb/v2?id=sh!sh&dn=AFSH&cc=1&r=",
        "http://www.brechlerinsurance.com/?gdbc-client=3.1.25-1652585170383",
        "http://www.brechlerinsurance.com/wwblcms/wp-includes/js/wp-emoji-release.min.js?ver=479aaeefa13948f8aa1a2479d7a751df",
        "http://www.brechlerinsurance.com/wwblcms/wp-includes/js/jquery/jquery.js?ver=1.12.4",
        "https://partner.shareaholic.com/partners.js?location=http%3A%2F%2Fwww.brechlerinsurance.com%2F&cl=en-US&id_sync=19da2f0f-8191-4a73-b27d-e95f97e9a686&minify=1&pvs=1&site=d016349f31f268b5ce94fa8e70f6eddd",
        "https://px.owneriq.net/stas/s/sholic.js",
        "https://i.simpli.fi/dpx.js?cid=66112&m=0&sifi_tuid=37830&referrer=http%3A%2F%2Fwww.brechlerinsurance.com%2F",
        "https://sb.scorecardresearch.com/beacon.js",
        "https://cdn.tynt.com/afsh.js",
        "xfe-URL-ml314.com-stix2-2.1-export.json",
        "xfe-URL-bombora.com-stix2-2.1-export.json",
        "xfe-URL-Owneriq.net-stix2-2.1-export.json"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "BomboraConsent",
          "display_name": "BomboraConsent",
          "target": null
        },
        {
          "id": "Vd",
          "display_name": "Vd",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 13,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "adjadex1@gmail.com",
        "id": "187163",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 4185,
        "URL": 12454,
        "FileHash-SHA256": 1329,
        "CVE": 2,
        "domain": 2068,
        "email": 1,
        "FileHash-MD5": 3,
        "FileHash-SHA1": 1
      },
      "indicator_count": 20043,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 68,
      "modified_text": "1406 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "620d08807af9ce9e3847a0ec",
      "name": "Inforcloudsuite.com",
      "description": "",
      "modified": "2022-03-18T00:04:44.902000",
      "created": "2022-02-16T14:21:52.273000",
      "tags": [
        "psiusa",
        "domain robot",
        "graph summary",
        "win32 exe",
        "server",
        "redacted for",
        "privacy tech",
        "privacy admin",
        "date",
        "country",
        "organization",
        "postal code",
        "stateprovince",
        "domain status",
        "umbrella",
        "code",
        "submission",
        "sophos",
        "comodo valkyrie",
        "verdict",
        "history first",
        "analysis",
        "utc http",
        "response final",
        "url http"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 5,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Kailula4",
        "id": "131997",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 1051,
        "URL": 2727,
        "domain": 438,
        "FileHash-SHA256": 113,
        "email": 1
      },
      "indicator_count": 4330,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 406,
      "modified_text": "1493 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "620d08a477f11b4221bfb402",
      "name": "inforcloudesuite",
      "description": "",
      "modified": "2022-03-18T00:04:44.902000",
      "created": "2022-02-16T14:22:28.691000",
      "tags": [
        "psiusa",
        "domain robot",
        "graph summary",
        "win32 exe",
        "server",
        "redacted for",
        "privacy tech",
        "privacy admin",
        "date",
        "country",
        "organization",
        "postal code",
        "stateprovince",
        "domain status",
        "umbrella",
        "code",
        "submission",
        "sophos",
        "comodo valkyrie",
        "verdict",
        "history first",
        "analysis",
        "utc http",
        "response final",
        "url http"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 4,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Kailula4",
        "id": "131997",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 3986,
        "domain": 560,
        "FileHash-SHA256": 652,
        "hostname": 1596,
        "email": 1
      },
      "indicator_count": 6795,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 407,
      "modified_text": "1493 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "https://planet.tikalk.com/timetracker/login.php",
    "type": "URL"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "https://planet.tikalk.com/timetracker/login.php",
    "type": "URL",
    "found": false,
    "verdict": "clean",
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1776641621.8392277
}