{
  "type": "URL",
  "indicator": "https://postback.trafficmotor.com",
  "general": {
    "sections": [
      "general",
      "url_list",
      "http_scans",
      "screenshot"
    ],
    "indicator": "https://postback.trafficmotor.com",
    "type": "url",
    "type_title": "URL",
    "validation": [],
    "base_indicator": {
      "id": 2616776516,
      "indicator": "https://postback.trafficmotor.com",
      "type": "URL",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 11,
      "pulses": [
        {
          "id": "65c3bd803f15cd94aab6e287",
          "name": "Lumma Stealer | Colorado Medical Center HCA",
          "description": "Needs further investigation. Miscellaneous attack affecting Denver physicians directory. Visitors accessing the page using insecure devices may be affected. PII & PHI breached. Monitoring.",
          "modified": "2024-03-08T17:04:03.644000",
          "created": "2024-02-07T17:27:28.349000",
          "tags": [
            "whois record",
            "ssl certificate",
            "contacted",
            "historical ssl",
            "referrer",
            "execution",
            "resolutions",
            "problems",
            "siblings domain",
            "whois whois",
            "startpage",
            "httponly",
            "samesitenone",
            "http response",
            "final url",
            "serving ip",
            "address",
            "status code",
            "body length",
            "kb body",
            "sha256",
            "language",
            "html document",
            "unicode text",
            "utf8 text",
            "doctype",
            "anchor hrefs",
            "hrefs",
            "denver",
            "tsara brashears",
            "apple ios",
            "password bypass",
            "apple phone",
            "unlocker",
            "shell code",
            "script",
            "contacted urls",
            "hacktool",
            "malicious",
            "download",
            "malware",
            "relic",
            "monitoring",
            "domains",
            "eurodns sa",
            "markmonitor",
            "ip detections",
            "country",
            "graph",
            "https",
            "mitre att",
            "ta0007 network",
            "t1046 sends",
            "ssdp",
            "command",
            "control ta0011",
            "protocol t1071",
            "performs dns",
            "layer protocol",
            "number",
            "cus cndigicert",
            "ja3s",
            "subject",
            "sha2 secure",
            "server ca",
            "odigicert inc",
            "cus cnmicrosoft",
            "algorithm",
            "memory pattern",
            "file system",
            "registry",
            "registry keys",
            "process",
            "created",
            "processes tree",
            "february",
            "healthone",
            "gmbh version",
            "status page",
            "service privacy",
            "legal",
            "impressum",
            "url https",
            "reverse dns",
            "general full",
            "security tls",
            "protocol h2",
            "software",
            "frankfurt",
            "main",
            "germany",
            "resource hash",
            "de indicators",
            "hashes",
            "value",
            "scriptsrcelem",
            "variables",
            "boomrmq string",
            "boomrapikey",
            "boomr function",
            "system",
            "babelpolyfill",
            "assign function",
            "windows nt",
            "win64",
            "khtml",
            "gecko",
            "aes256gcm",
            "level",
            "akamaiasn1",
            "europeberlin",
            "generic malware",
            "tag count",
            "tue dec",
            "threat report",
            "url summary",
            "summary",
            "sample",
            "samples",
            "detection list",
            "blacklist",
            "root ca",
            "pattern match",
            "authority",
            "span",
            "presbyterianst",
            "luke",
            "medical center",
            "class",
            "accept",
            "date",
            "refresh",
            "blood",
            "liver cancer",
            "breast cancer",
            "lung cancer",
            "kidney cancer",
            "skin cancer",
            "sarcoma",
            "prostate cancer",
            "body",
            "facebook",
            "twitter",
            "hybrid",
            "general",
            "local",
            "click",
            "strings",
            "error",
            "tools",
            "look",
            "verify",
            "restart",
            "cookie",
            "command and control",
            "mitre",
            "scanning host",
            "exploit source",
            "trojan",
            "callback function",
            "targets",
            "targeting",
            "samesite=none",
            "kde",
            "konqueror",
            "phi",
            "pii",
            "wTJh.exe",
            "malware ransom trojan evader rat",
            "network",
            "rat trojan",
            "relacionada",
            "critical risk",
            "cyberstalking",
            "elf collection",
            "matches rule",
            "emotet",
            "lockbit",
            "critical",
            "copy",
            "installer",
            "dark power",
            "wiper",
            "ransomware",
            "cobalt strike",
            "ursnif",
            "core",
            "as55688 pt",
            "passive dns",
            "scan endpoints",
            "all octoseek",
            "ipv4",
            "pulse pulses",
            "urls",
            "files",
            "asn as55688",
            "threat",
            "paste",
            "iocs",
            "analyze",
            "hostnames",
            "united",
            "aaaa",
            "unknown",
            "a domains",
            "search",
            "creation date",
            "record value",
            "next",
            "pornhub",
            "anyxxxtube",
            "domain",
            "gandi sas",
            "hostname",
            "basic",
            "pe32",
            "intel",
            "ms windows",
            "generic windos",
            "executable",
            "dos executable",
            "generic",
            "pe32 packer",
            "petite",
            "vs98",
            "info compiler",
            "products",
            "header intel",
            "name md5",
            "type",
            "rticon neutral",
            "overlay",
            "dos exe",
            "threat roundup",
            "pe resource",
            "june",
            "lumma stealer",
            "ransomexx",
            "azorult",
            "njrat",
            "open",
            "problem",
            "plugx",
            "android",
            "sex_phot.jpg.exe",
            "win32 dynamic",
            "link library",
            "win16 ne",
            "delphi generic",
            "icons library",
            "pe32 linker",
            "lcc linker",
            "empty hash",
            "tulach",
            "sabey",
            "rat",
            "remote",
            "remote access trojan"
          ],
          "references": [
            "https://www.healthonecares.com/locations/presbyterian-st-lukes-medical-center/physicians",
            "https://www.hybrid-analysis.com/sample/63bf920be2401947bd686d7dd146af7f3e56800409307360105bf50cebb1c1ea",
            "www2.megawebfind.com [command and control]",
            "http://ifdnzact.com/?dn=megawebdeals.com&pid=9PO755G95 [ phishing]",
            "20.99.186.246 [exploit source]",
            "https://www.healthonecares.com/locations/presbyterian-st-lukes-medical-center/physicians/ [heuristic]",
            "Win32:RATX-gen [Trj] identified.",
            "CS Sigma Rules: Shadow Copies Deletion Using Operating Systems Utilities by Florian Roth (Nextron Systems), Michael Haag, Teymur Kheirkhabarov, Daniil Yugoslavskiy, oscd.community, Andreas Hunkeler (@Karneades)",
            "CS Sigma Rules: Disable UAC Using Registry by frack113",
            "http://45.159.189.105/bot/regex [ tracking | botnet]",
            "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian [Password cracker | Patient being tracked through multiple medical systems]",
            "0-173-x.msn.com | https://twitter.com/PORNO_SEXYBABES | 0-3.duckdns.org | 0-212.pornhub.org | 000web.pornhub.org",
            "https://www.anyxxxtube.net/search-porn/tsara-brashears/ [phishing]",
            "CS Sigma Rules: Wow6432Node CurrentVersion Autorun Keys Modification by Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split)",
            "Remote Access Trojan"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "Indonesia",
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "HackTool",
              "display_name": "HackTool",
              "target": null
            },
            {
              "id": "Relic",
              "display_name": "Relic",
              "target": null
            },
            {
              "id": "Win32:RATX-gen [Trj]",
              "display_name": "Win32:RATX-gen [Trj]",
              "target": null
            },
            {
              "id": "Ransomware",
              "display_name": "Ransomware",
              "target": null
            },
            {
              "id": "LockBit",
              "display_name": "LockBit",
              "target": null
            },
            {
              "id": "Ursnif",
              "display_name": "Ursnif",
              "target": null
            },
            {
              "id": "Dark Power",
              "display_name": "Dark Power",
              "target": null
            },
            {
              "id": "W32/Hupigon.NCU",
              "display_name": "W32/Hupigon.NCU",
              "target": null
            },
            {
              "id": "Cobalt Strike",
              "display_name": "Cobalt Strike",
              "target": null
            },
            {
              "id": "Tulach",
              "display_name": "Tulach",
              "target": null
            },
            {
              "id": "Azorult",
              "display_name": "Azorult",
              "target": null
            },
            {
              "id": "Wiper",
              "display_name": "Wiper",
              "target": null
            },
            {
              "id": "Virut",
              "display_name": "Virut",
              "target": null
            },
            {
              "id": "Lumma Stealer",
              "display_name": "Lumma Stealer",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1046",
              "name": "Network Service Scanning",
              "display_name": "T1046 - Network Service Scanning"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1095",
              "name": "Non-Application Layer Protocol",
              "display_name": "T1095 - Non-Application Layer Protocol"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1100",
              "name": "Web Shell",
              "display_name": "T1100 - Web Shell"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1114",
              "name": "Email Collection",
              "display_name": "T1114 - Email Collection"
            },
            {
              "id": "T1560",
              "name": "Archive Collected Data",
              "display_name": "T1560 - Archive Collected Data"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "TA0007",
              "name": "Discovery",
              "display_name": "TA0007 - Discovery"
            },
            {
              "id": "TA0011",
              "name": "Command and Control",
              "display_name": "TA0011 - Command and Control"
            }
          ],
          "industries": [
            "Healthcare",
            "Civil Society"
          ],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 68,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 1,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 883,
            "URL": 1412,
            "FileHash-MD5": 283,
            "FileHash-SHA1": 231,
            "FileHash-SHA256": 2909,
            "domain": 824,
            "email": 3,
            "CVE": 3
          },
          "indicator_count": 6548,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 224,
          "modified_text": "815 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "659331580cd1571f730b8de2",
          "name": "Agent Tesla | Spyware | Tracking Android & Apple users | Malware Attack",
          "description": "",
          "modified": "2024-01-31T14:03:30.344000",
          "created": "2024-01-01T21:40:40.242000",
          "tags": [
            "maxads0",
            "kld1063",
            "ioc search",
            "new ioc",
            "teams api",
            "contact",
            "threat analyzer",
            "threat",
            "paste",
            "iocs",
            "hostnames",
            "urls http",
            "ssl certificate",
            "whois record",
            "contacted",
            "referrer",
            "historical ssl",
            "march",
            "communicating",
            "copy",
            "january",
            "collections",
            "execution",
            "malware",
            "startpage",
            "malicious",
            "ransomware",
            "agent tesla",
            "attack",
            "android",
            "name verdict",
            "falcon sandbox",
            "reports",
            "falcon",
            "windir",
            "path",
            "programfiles",
            "pe32",
            "ms windows",
            "getprocaddress",
            "file type",
            "mitre att",
            "ck id",
            "show technique",
            "win64",
            "date",
            "open",
            "hybrid",
            "cookie",
            "tracking",
            "apple",
            "spyware",
            "malware",
            "tablet",
            "superwebbysearch",
            "hallrender",
            "pegasus",
            "briansabey",
            "aig",
            "abuse",
            "tulach"
          ],
          "references": [
            "findbetterresults.com",
            "https://hybrid-analysis.com/sample/bba36b3ae7c49d1cffcc5f8e045d81e9307a2e1a86b923f89008e9377d171fb6",
            "https://www.virustotal.com/gui/url/eed406872c2e6ef550b948510fe0b7b4c71f752f58551c2f8e61d31a19d2a153/summary",
            "http://www.applerewards.website/pl/3/index.html?voluumdata=BASE64dmlkLi4wMDAwMDAwMi00NGFiLTQzNDktODAwMC0wMDAwMDAwMDAwMDBfX3ZwaWQuLjJhYWQzMDAwLWJiMzYtMTFlNi04YTYyLTBlYzcxZTllMDMzMV9fY2FpZC4uNjBhMjIwOWUtNWMzNC00OGQ4LWIyNDctYWM5YzVkOTM3MzZhX19ydC4uUl9fbGlkLi4yYTRjOTA4My0zY2RmLTQyNDktOGJmOS0yODMxZWYzNGRhYTlfX29pZDEuLjUwMGE4NDhjLTA2NGEtNDYyZi05MDNmLTgxYzY4ODNmODEwZl9fdmFyMS4uNjA4OTYxX192YXIyLi42NzEwMjhfX3JkLi5vbmNsaWNrYWRzXC5cbmV0X19haWQuLl9fYWIuLl9fc2lkLi4&zoneid=608961&campaignid=671028&visitor_id=4003954",
            "www2.megawebfind.com                [command_and_control]",
            "https://search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas_sfp&command=   [command_and_control]   stolec kradnie krypto"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Agent Tesla",
              "display_name": "Agent Tesla",
              "target": null
            },
            {
              "id": "Ransomware",
              "display_name": "Ransomware",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1012",
              "name": "Query Registry",
              "display_name": "T1012 - Query Registry"
            },
            {
              "id": "T1033",
              "name": "System Owner/User Discovery",
              "display_name": "T1033 - System Owner/User Discovery"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1053",
              "name": "Scheduled Task/Job",
              "display_name": "T1053 - Scheduled Task/Job"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1070",
              "name": "Indicator Removal on Host",
              "display_name": "T1070 - Indicator Removal on Host"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1074",
              "name": "Data Staged",
              "display_name": "T1074 - Data Staged"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1112",
              "name": "Modify Registry",
              "display_name": "T1112 - Modify Registry"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1218",
              "name": "Signed Binary Proxy Execution",
              "display_name": "T1218 - Signed Binary Proxy Execution"
            },
            {
              "id": "T1518",
              "name": "Software Discovery",
              "display_name": "T1518 - Software Discovery"
            },
            {
              "id": "T1614",
              "name": "System Location Discovery",
              "display_name": "T1614 - System Location Discovery"
            },
            {
              "id": "TA0011",
              "name": "Command and Control",
              "display_name": "TA0011 - Command and Control"
            },
            {
              "id": "T1155",
              "name": "AppleScript",
              "display_name": "T1155 - AppleScript"
            },
            {
              "id": "T1449",
              "name": "Exploit SS7 to Redirect Phone Calls/SMS",
              "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
            },
            {
              "id": "T1031",
              "name": "Modify Existing Service",
              "display_name": "T1031 - Modify Existing Service"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 24,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 2368,
            "FileHash-SHA256": 4539,
            "hostname": 2892,
            "URL": 9741,
            "FileHash-MD5": 836,
            "FileHash-SHA1": 461,
            "CVE": 1
          },
          "indicator_count": 20838,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 222,
          "modified_text": "852 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "659331589faf01b909c1802d",
          "name": "Agent Tesla | Spyware | Tracking Android & Apple users | Malware Attack",
          "description": "",
          "modified": "2024-01-31T14:03:30.344000",
          "created": "2024-01-01T21:40:40.413000",
          "tags": [
            "maxads0",
            "kld1063",
            "ioc search",
            "new ioc",
            "teams api",
            "contact",
            "threat analyzer",
            "threat",
            "paste",
            "iocs",
            "hostnames",
            "urls http",
            "ssl certificate",
            "whois record",
            "contacted",
            "referrer",
            "historical ssl",
            "march",
            "communicating",
            "copy",
            "january",
            "collections",
            "execution",
            "malware",
            "startpage",
            "malicious",
            "ransomware",
            "agent tesla",
            "attack",
            "android",
            "name verdict",
            "falcon sandbox",
            "reports",
            "falcon",
            "windir",
            "path",
            "programfiles",
            "pe32",
            "ms windows",
            "getprocaddress",
            "file type",
            "mitre att",
            "ck id",
            "show technique",
            "win64",
            "date",
            "open",
            "hybrid",
            "cookie",
            "tracking",
            "apple",
            "spyware",
            "malware",
            "tablet",
            "superwebbysearch",
            "hallrender",
            "pegasus",
            "briansabey",
            "aig",
            "abuse",
            "tulach"
          ],
          "references": [
            "findbetterresults.com",
            "https://hybrid-analysis.com/sample/bba36b3ae7c49d1cffcc5f8e045d81e9307a2e1a86b923f89008e9377d171fb6",
            "https://www.virustotal.com/gui/url/eed406872c2e6ef550b948510fe0b7b4c71f752f58551c2f8e61d31a19d2a153/summary",
            "http://www.applerewards.website/pl/3/index.html?voluumdata=BASE64dmlkLi4wMDAwMDAwMi00NGFiLTQzNDktODAwMC0wMDAwMDAwMDAwMDBfX3ZwaWQuLjJhYWQzMDAwLWJiMzYtMTFlNi04YTYyLTBlYzcxZTllMDMzMV9fY2FpZC4uNjBhMjIwOWUtNWMzNC00OGQ4LWIyNDctYWM5YzVkOTM3MzZhX19ydC4uUl9fbGlkLi4yYTRjOTA4My0zY2RmLTQyNDktOGJmOS0yODMxZWYzNGRhYTlfX29pZDEuLjUwMGE4NDhjLTA2NGEtNDYyZi05MDNmLTgxYzY4ODNmODEwZl9fdmFyMS4uNjA4OTYxX192YXIyLi42NzEwMjhfX3JkLi5vbmNsaWNrYWRzXC5cbmV0X19haWQuLl9fYWIuLl9fc2lkLi4&zoneid=608961&campaignid=671028&visitor_id=4003954",
            "www2.megawebfind.com                [command_and_control]",
            "https://search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas_sfp&command=   [command_and_control]   stolec kradnie krypto"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Agent Tesla",
              "display_name": "Agent Tesla",
              "target": null
            },
            {
              "id": "Ransomware",
              "display_name": "Ransomware",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1012",
              "name": "Query Registry",
              "display_name": "T1012 - Query Registry"
            },
            {
              "id": "T1033",
              "name": "System Owner/User Discovery",
              "display_name": "T1033 - System Owner/User Discovery"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1053",
              "name": "Scheduled Task/Job",
              "display_name": "T1053 - Scheduled Task/Job"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1070",
              "name": "Indicator Removal on Host",
              "display_name": "T1070 - Indicator Removal on Host"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1074",
              "name": "Data Staged",
              "display_name": "T1074 - Data Staged"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1112",
              "name": "Modify Registry",
              "display_name": "T1112 - Modify Registry"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1218",
              "name": "Signed Binary Proxy Execution",
              "display_name": "T1218 - Signed Binary Proxy Execution"
            },
            {
              "id": "T1518",
              "name": "Software Discovery",
              "display_name": "T1518 - Software Discovery"
            },
            {
              "id": "T1614",
              "name": "System Location Discovery",
              "display_name": "T1614 - System Location Discovery"
            },
            {
              "id": "TA0011",
              "name": "Command and Control",
              "display_name": "TA0011 - Command and Control"
            },
            {
              "id": "T1155",
              "name": "AppleScript",
              "display_name": "T1155 - AppleScript"
            },
            {
              "id": "T1449",
              "name": "Exploit SS7 to Redirect Phone Calls/SMS",
              "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
            },
            {
              "id": "T1031",
              "name": "Modify Existing Service",
              "display_name": "T1031 - Modify Existing Service"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 29,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 2368,
            "FileHash-SHA256": 4539,
            "hostname": 2892,
            "URL": 9741,
            "FileHash-MD5": 836,
            "FileHash-SHA1": 461,
            "CVE": 1
          },
          "indicator_count": 20838,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 221,
          "modified_text": "852 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "658b9e86f7a149333882bfb9",
          "name": "Hijacking | Typosquatting | Masquerading Shared Modules",
          "description": "*Shared Modules\t\nExecution\nAdversaries may execute malicious payloads via loading shared modules.\n\n*Masquerading\t\nDefense Evasion\nAdversaries may attempt to manipulate features of their artifacts to make them appear legitimate or benign to users and/or security tools.\n\nComponent Object Model Hijacking\t\nPersistence\nPrivilege Escalation\nAdversaries may establish persistence by executing malicious content triggered by hijacked references to Component Object Model (COM) objects.\nPulse: http://ww1.thecoolzipextractorapp.com/\nFound in: https://www.hallrender.com/attorney/brian-sabey/",
          "modified": "2024-01-26T01:05:54.754000",
          "created": "2023-12-27T03:48:22.319000",
          "tags": [
            "threat",
            "feeds ioc",
            "new ioc",
            "teams api",
            "contact",
            "maltiverse",
            "dinkle threat",
            "paste",
            "iocs",
            "analyze",
            "ssl certificate",
            "whois record",
            "contacted",
            "referrer",
            "historical ssl",
            "communicating",
            "whois whois",
            "siblings parent",
            "execution"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 28,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 12134,
            "FileHash-MD5": 102,
            "FileHash-SHA1": 101,
            "FileHash-SHA256": 3982,
            "hostname": 2878,
            "domain": 2159,
            "CVE": 1
          },
          "indicator_count": 21357,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 224,
          "modified_text": "857 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "658ca3f53717bb3a25e96065",
          "name": "Hijacking | Typosquatting | Masquerading Shared Modules | http://ww1.thecoolzipextractorapp.com/ via https://www.hallrender.com/attorney/brian-sabey/",
          "description": "",
          "modified": "2024-01-26T01:05:54.754000",
          "created": "2023-12-27T22:23:49.562000",
          "tags": [
            "threat",
            "feeds ioc",
            "new ioc",
            "teams api",
            "contact",
            "maltiverse",
            "dinkle threat",
            "paste",
            "iocs",
            "analyze",
            "ssl certificate",
            "whois record",
            "contacted",
            "referrer",
            "historical ssl",
            "communicating",
            "whois whois",
            "siblings parent",
            "execution"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": "658b9e86f7a149333882bfb9",
          "export_count": 25,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 12134,
            "FileHash-MD5": 102,
            "FileHash-SHA1": 101,
            "FileHash-SHA256": 3982,
            "hostname": 2878,
            "domain": 2159,
            "CVE": 1
          },
          "indicator_count": 21357,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 229,
          "modified_text": "857 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6570a7b4eb565273001e2e08",
          "name": "Ireland Netsky | Relay Router | Misc Attack on LTL Fright Outage",
          "description": "",
          "modified": "2023-12-06T16:56:20.491000",
          "created": "2023-12-06T16:56:20.491000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 8,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 1353,
            "CVE": 8,
            "FileHash-SHA256": 3611,
            "domain": 795,
            "URL": 2831,
            "FileHash-MD5": 663,
            "FileHash-SHA1": 398
          },
          "indicator_count": 9659,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "908 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "651cd4a6af63714f51c8d721",
          "name": "Ireland Netsky | Relay Router | Misc Attack on LTL Fright Outage",
          "description": "Cobalt Strike , FireHol anonymization,  IT Attack, Suricata Alert, MITRE. Appears to be a complete cyber attack against a well known LTL Fright lines IT system.",
          "modified": "2023-11-03T02:03:00.398000",
          "created": "2023-10-04T02:57:42.183000",
          "tags": [
            "united",
            "smtp service",
            "firehol",
            "pony",
            "s1us",
            "s1de",
            "spammer",
            "proxy",
            "ireland netsky",
            "anonymizer",
            "cisco umbrella",
            "site",
            "safe site",
            "million",
            "alexa top",
            "alexa",
            "detection list",
            "blacklist",
            "malicious url",
            "blacklist http",
            "linkid252669",
            "noname057",
            "url summary",
            "summary",
            "sample",
            "samples",
            "misc attack",
            "et tor",
            "known tor",
            "relayrouter",
            "exit",
            "node traffic",
            "misc activity",
            "et policy",
            "tor ssl",
            "Hostname: RecoveryStore-3.7.5.1.4.6.2.0-D917-11E7-B67B-080027A49",
            "cyber criminal",
            "FireHOL",
            "Suricata Alert",
            "HTML document, ASCII text",
            "mail spammer",
            "malware site",
            "heur",
            "malware",
            "adware",
            "malicious site",
            "phishing site",
            "artemis",
            "unsafe",
            "exploit",
            "iframe",
            "fakealert",
            "opencandy",
            "riskware",
            "genkryptik",
            "nircmd",
            "swrort",
            "downldr",
            "crack",
            "tiggre",
            "presenoker",
            "filetour",
            "cleaner",
            "conduit",
            "wacatac",
            "coinminer",
            "dropper",
            "cobalt strike",
            "acint",
            "systweak",
            "behav",
            "agent",
            "phishing",
            "maltiverse",
            "trojanspy",
            "webtoolbar",
            "phishing",
            "exploit-source"
          ],
          "references": [
            "-Hostname: RecoveryStore-3.7.5.1.4.6.2.0-D917-11E7-B67B-080027A49DD/",
            "https://www.hybrid-analysis.com/sample/fa1f15bd4c0cd287fe04f324d3363a8b5a295b57cb22d9ea0f3d6973eb442d17/651c94c00b17fb9324040f7c"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "Maltiverse",
              "display_name": "Maltiverse",
              "target": null
            },
            {
              "id": "TrojanSpy",
              "display_name": "TrojanSpy",
              "target": null
            },
            {
              "id": "WebToolbar",
              "display_name": "WebToolbar",
              "target": null
            },
            {
              "id": "OpenCandy",
              "display_name": "OpenCandy",
              "target": null
            },
            {
              "id": "Trojan:Win32/Tiggre",
              "display_name": "Trojan:Win32/Tiggre",
              "target": "/malware/Trojan:Win32/Tiggre"
            },
            {
              "id": "Cobalt Strike",
              "display_name": "Cobalt Strike",
              "target": null
            },
            {
              "id": "Artemis",
              "display_name": "Artemis",
              "target": null
            },
            {
              "id": "Ireland Netsky",
              "display_name": "Ireland Netsky",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1059.007",
              "name": "JavaScript",
              "display_name": "T1059.007 - JavaScript"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1071.004",
              "name": "DNS",
              "display_name": "T1071.004 - DNS"
            },
            {
              "id": "T1147",
              "name": "Hidden Users",
              "display_name": "T1147 - Hidden Users"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1114",
              "name": "Email Collection",
              "display_name": "T1114 - Email Collection"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            }
          ],
          "industries": [
            "Transportation",
            "Technology"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 29,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 795,
            "FileHash-MD5": 663,
            "hostname": 1353,
            "URL": 2831,
            "FileHash-SHA1": 398,
            "FileHash-SHA256": 3611,
            "CVE": 8
          },
          "indicator_count": 9659,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 230,
          "modified_text": "941 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "653f1a8f35a050560dcd3b00",
          "name": "Ireland Netsky | Relay Router | Misc Attack on LTL Fright Outage",
          "description": "",
          "modified": "2023-11-03T02:03:00.398000",
          "created": "2023-10-30T02:53:03.811000",
          "tags": [
            "united",
            "smtp service",
            "firehol",
            "pony",
            "s1us",
            "s1de",
            "spammer",
            "proxy",
            "ireland netsky",
            "anonymizer",
            "cisco umbrella",
            "site",
            "safe site",
            "million",
            "alexa top",
            "alexa",
            "detection list",
            "blacklist",
            "malicious url",
            "blacklist http",
            "linkid252669",
            "noname057",
            "url summary",
            "summary",
            "sample",
            "samples",
            "misc attack",
            "et tor",
            "known tor",
            "relayrouter",
            "exit",
            "node traffic",
            "misc activity",
            "et policy",
            "tor ssl",
            "Hostname: RecoveryStore-3.7.5.1.4.6.2.0-D917-11E7-B67B-080027A49",
            "cyber criminal",
            "FireHOL",
            "Suricata Alert",
            "HTML document, ASCII text",
            "mail spammer",
            "malware site",
            "heur",
            "malware",
            "adware",
            "malicious site",
            "phishing site",
            "artemis",
            "unsafe",
            "exploit",
            "iframe",
            "fakealert",
            "opencandy",
            "riskware",
            "genkryptik",
            "nircmd",
            "swrort",
            "downldr",
            "crack",
            "tiggre",
            "presenoker",
            "filetour",
            "cleaner",
            "conduit",
            "wacatac",
            "coinminer",
            "dropper",
            "cobalt strike",
            "acint",
            "systweak",
            "behav",
            "agent",
            "phishing",
            "maltiverse",
            "trojanspy",
            "webtoolbar",
            "phishing",
            "exploit-source"
          ],
          "references": [
            "-Hostname: RecoveryStore-3.7.5.1.4.6.2.0-D917-11E7-B67B-080027A49DD/",
            "https://www.hybrid-analysis.com/sample/fa1f15bd4c0cd287fe04f324d3363a8b5a295b57cb22d9ea0f3d6973eb442d17/651c94c00b17fb9324040f7c"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "Maltiverse",
              "display_name": "Maltiverse",
              "target": null
            },
            {
              "id": "TrojanSpy",
              "display_name": "TrojanSpy",
              "target": null
            },
            {
              "id": "WebToolbar",
              "display_name": "WebToolbar",
              "target": null
            },
            {
              "id": "OpenCandy",
              "display_name": "OpenCandy",
              "target": null
            },
            {
              "id": "Trojan:Win32/Tiggre",
              "display_name": "Trojan:Win32/Tiggre",
              "target": "/malware/Trojan:Win32/Tiggre"
            },
            {
              "id": "Cobalt Strike",
              "display_name": "Cobalt Strike",
              "target": null
            },
            {
              "id": "Artemis",
              "display_name": "Artemis",
              "target": null
            },
            {
              "id": "Ireland Netsky",
              "display_name": "Ireland Netsky",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1059.007",
              "name": "JavaScript",
              "display_name": "T1059.007 - JavaScript"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1071.004",
              "name": "DNS",
              "display_name": "T1071.004 - DNS"
            },
            {
              "id": "T1147",
              "name": "Hidden Users",
              "display_name": "T1147 - Hidden Users"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1114",
              "name": "Email Collection",
              "display_name": "T1114 - Email Collection"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            }
          ],
          "industries": [
            "Transportation",
            "Technology"
          ],
          "TLP": "white",
          "cloned_from": "651cd4a6af63714f51c8d721",
          "export_count": 13,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 795,
            "FileHash-MD5": 663,
            "hostname": 1353,
            "URL": 2831,
            "FileHash-SHA1": 398,
            "FileHash-SHA256": 3611,
            "CVE": 8
          },
          "indicator_count": 9659,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 220,
          "modified_text": "941 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "651795a9d541bac4a870983c",
          "name": "Apple and iOS fraud, phishing, tracking + FindMyiPhone.us",
          "description": "fraud, phishing, C2, backdoors, tracking, spyware, attack, trojan,malicious, non reputable, exploit source, malicious adware, tracks, iPhone, iPad iPods unaddressed iPhone vulnerabilities.",
          "modified": "2023-10-30T03:05:33.884000",
          "created": "2023-09-30T03:27:37.578000",
          "tags": [
            "whois record",
            "ssl certificate",
            "communicating",
            "threat roundup",
            "august",
            "whois whois",
            "october",
            "july",
            "september",
            "historical ssl",
            "june",
            "february"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 8,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 90,
            "FileHash-SHA1": 90,
            "FileHash-SHA256": 699,
            "URL": 1167,
            "domain": 532,
            "hostname": 318
          },
          "indicator_count": 2896,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 228,
          "modified_text": "945 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "651795b2b839d974e73cb9e3",
          "name": "Apple and iOS fraud, phishing, tracking + FindMyiPhone.us",
          "description": "fraud, phishing, C2, backdoors, tracking, spyware, attack, trojan,malicious, non reputable, exploit source, malicious adware, tracks, iPhone, iPad iPods unaddressed iPhone vulnerabilities.",
          "modified": "2023-10-30T03:05:33.884000",
          "created": "2023-09-30T03:27:46.181000",
          "tags": [
            "whois record",
            "ssl certificate",
            "communicating",
            "threat roundup",
            "august",
            "whois whois",
            "october",
            "july",
            "september",
            "historical ssl",
            "june",
            "february"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 8,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 90,
            "FileHash-SHA1": 90,
            "FileHash-SHA256": 699,
            "URL": 1167,
            "domain": 532,
            "hostname": 318
          },
          "indicator_count": 2896,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 228,
          "modified_text": "945 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "653f07da92fc9327947f08f9",
          "name": "Apple and iOS fraud, phishing, tracking + FindMyiPhone.us",
          "description": "",
          "modified": "2023-10-30T03:05:33.884000",
          "created": "2023-10-30T01:33:14.318000",
          "tags": [
            "whois record",
            "ssl certificate",
            "communicating",
            "threat roundup",
            "august",
            "whois whois",
            "october",
            "july",
            "september",
            "historical ssl",
            "june",
            "february"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": "651795b2b839d974e73cb9e3",
          "export_count": 10,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 90,
            "FileHash-SHA1": 90,
            "FileHash-SHA256": 699,
            "URL": 1167,
            "domain": 532,
            "hostname": 318
          },
          "indicator_count": 2896,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 220,
          "modified_text": "945 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "www2.megawebfind.com [command and control]",
        "findbetterresults.com",
        "https://hybrid-analysis.com/sample/bba36b3ae7c49d1cffcc5f8e045d81e9307a2e1a86b923f89008e9377d171fb6",
        "https://search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas_sfp&command=   [command_and_control]   stolec kradnie krypto",
        "-Hostname: RecoveryStore-3.7.5.1.4.6.2.0-D917-11E7-B67B-080027A49DD/",
        "CS Sigma Rules: Disable UAC Using Registry by frack113",
        "http://ifdnzact.com/?dn=megawebdeals.com&pid=9PO755G95 [ phishing]",
        "20.99.186.246 [exploit source]",
        "www2.megawebfind.com                [command_and_control]",
        "CS Sigma Rules: Shadow Copies Deletion Using Operating Systems Utilities by Florian Roth (Nextron Systems), Michael Haag, Teymur Kheirkhabarov, Daniil Yugoslavskiy, oscd.community, Andreas Hunkeler (@Karneades)",
        "http://www.applerewards.website/pl/3/index.html?voluumdata=BASE64dmlkLi4wMDAwMDAwMi00NGFiLTQzNDktODAwMC0wMDAwMDAwMDAwMDBfX3ZwaWQuLjJhYWQzMDAwLWJiMzYtMTFlNi04YTYyLTBlYzcxZTllMDMzMV9fY2FpZC4uNjBhMjIwOWUtNWMzNC00OGQ4LWIyNDctYWM5YzVkOTM3MzZhX19ydC4uUl9fbGlkLi4yYTRjOTA4My0zY2RmLTQyNDktOGJmOS0yODMxZWYzNGRhYTlfX29pZDEuLjUwMGE4NDhjLTA2NGEtNDYyZi05MDNmLTgxYzY4ODNmODEwZl9fdmFyMS4uNjA4OTYxX192YXIyLi42NzEwMjhfX3JkLi5vbmNsaWNrYWRzXC5cbmV0X19haWQuLl9fYWIuLl9fc2lkLi4&zoneid=608961&campaignid=671028&visitor_id=4003954",
        "https://www.healthonecares.com/locations/presbyterian-st-lukes-medical-center/physicians/ [heuristic]",
        "Remote Access Trojan",
        "CS Sigma Rules: Wow6432Node CurrentVersion Autorun Keys Modification by Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split)",
        "https://www.virustotal.com/gui/url/eed406872c2e6ef550b948510fe0b7b4c71f752f58551c2f8e61d31a19d2a153/summary",
        "https://www.healthonecares.com/locations/presbyterian-st-lukes-medical-center/physicians",
        "https://www.hybrid-analysis.com/sample/fa1f15bd4c0cd287fe04f324d3363a8b5a295b57cb22d9ea0f3d6973eb442d17/651c94c00b17fb9324040f7c",
        "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian [Password cracker | Patient being tracked through multiple medical systems]",
        "Win32:RATX-gen [Trj] identified.",
        "https://www.anyxxxtube.net/search-porn/tsara-brashears/ [phishing]",
        "http://45.159.189.105/bot/regex [ tracking | botnet]",
        "https://www.hybrid-analysis.com/sample/63bf920be2401947bd686d7dd146af7f3e56800409307360105bf50cebb1c1ea",
        "0-173-x.msn.com | https://twitter.com/PORNO_SEXYBABES | 0-3.duckdns.org | 0-212.pornhub.org | 000web.pornhub.org"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 0
        },
        "other": {
          "adversary": [],
          "malware_families": [
            "Artemis",
            "Relic",
            "Ursnif",
            "Dark power",
            "Win32:ratx-gen [trj]",
            "Trojan:win32/tiggre",
            "Virut",
            "Opencandy",
            "Webtoolbar",
            "Trojanspy",
            "Lockbit",
            "Tulach",
            "Ransomware",
            "Maltiverse",
            "Wiper",
            "Agent tesla",
            "Azorult",
            "Ireland netsky",
            "Cobalt strike",
            "Hacktool",
            "W32/hupigon.ncu",
            "Lumma stealer"
          ],
          "industries": [
            "Technology",
            "Healthcare",
            "Transportation",
            "Civil society"
          ],
          "unique_indicators": 59228
        }
      }
    },
    "false_positive": [],
    "alexa": "http://www.alexa.com/siteinfo/trafficmotor.com",
    "whois": "http://whois.domaintools.com/trafficmotor.com",
    "domain": "trafficmotor.com",
    "hostname": "postback.trafficmotor.com"
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 11,
  "pulses": [
    {
      "id": "65c3bd803f15cd94aab6e287",
      "name": "Lumma Stealer | Colorado Medical Center HCA",
      "description": "Needs further investigation. Miscellaneous attack affecting Denver physicians directory. Visitors accessing the page using insecure devices may be affected. PII & PHI breached. Monitoring.",
      "modified": "2024-03-08T17:04:03.644000",
      "created": "2024-02-07T17:27:28.349000",
      "tags": [
        "whois record",
        "ssl certificate",
        "contacted",
        "historical ssl",
        "referrer",
        "execution",
        "resolutions",
        "problems",
        "siblings domain",
        "whois whois",
        "startpage",
        "httponly",
        "samesitenone",
        "http response",
        "final url",
        "serving ip",
        "address",
        "status code",
        "body length",
        "kb body",
        "sha256",
        "language",
        "html document",
        "unicode text",
        "utf8 text",
        "doctype",
        "anchor hrefs",
        "hrefs",
        "denver",
        "tsara brashears",
        "apple ios",
        "password bypass",
        "apple phone",
        "unlocker",
        "shell code",
        "script",
        "contacted urls",
        "hacktool",
        "malicious",
        "download",
        "malware",
        "relic",
        "monitoring",
        "domains",
        "eurodns sa",
        "markmonitor",
        "ip detections",
        "country",
        "graph",
        "https",
        "mitre att",
        "ta0007 network",
        "t1046 sends",
        "ssdp",
        "command",
        "control ta0011",
        "protocol t1071",
        "performs dns",
        "layer protocol",
        "number",
        "cus cndigicert",
        "ja3s",
        "subject",
        "sha2 secure",
        "server ca",
        "odigicert inc",
        "cus cnmicrosoft",
        "algorithm",
        "memory pattern",
        "file system",
        "registry",
        "registry keys",
        "process",
        "created",
        "processes tree",
        "february",
        "healthone",
        "gmbh version",
        "status page",
        "service privacy",
        "legal",
        "impressum",
        "url https",
        "reverse dns",
        "general full",
        "security tls",
        "protocol h2",
        "software",
        "frankfurt",
        "main",
        "germany",
        "resource hash",
        "de indicators",
        "hashes",
        "value",
        "scriptsrcelem",
        "variables",
        "boomrmq string",
        "boomrapikey",
        "boomr function",
        "system",
        "babelpolyfill",
        "assign function",
        "windows nt",
        "win64",
        "khtml",
        "gecko",
        "aes256gcm",
        "level",
        "akamaiasn1",
        "europeberlin",
        "generic malware",
        "tag count",
        "tue dec",
        "threat report",
        "url summary",
        "summary",
        "sample",
        "samples",
        "detection list",
        "blacklist",
        "root ca",
        "pattern match",
        "authority",
        "span",
        "presbyterianst",
        "luke",
        "medical center",
        "class",
        "accept",
        "date",
        "refresh",
        "blood",
        "liver cancer",
        "breast cancer",
        "lung cancer",
        "kidney cancer",
        "skin cancer",
        "sarcoma",
        "prostate cancer",
        "body",
        "facebook",
        "twitter",
        "hybrid",
        "general",
        "local",
        "click",
        "strings",
        "error",
        "tools",
        "look",
        "verify",
        "restart",
        "cookie",
        "command and control",
        "mitre",
        "scanning host",
        "exploit source",
        "trojan",
        "callback function",
        "targets",
        "targeting",
        "samesite=none",
        "kde",
        "konqueror",
        "phi",
        "pii",
        "wTJh.exe",
        "malware ransom trojan evader rat",
        "network",
        "rat trojan",
        "relacionada",
        "critical risk",
        "cyberstalking",
        "elf collection",
        "matches rule",
        "emotet",
        "lockbit",
        "critical",
        "copy",
        "installer",
        "dark power",
        "wiper",
        "ransomware",
        "cobalt strike",
        "ursnif",
        "core",
        "as55688 pt",
        "passive dns",
        "scan endpoints",
        "all octoseek",
        "ipv4",
        "pulse pulses",
        "urls",
        "files",
        "asn as55688",
        "threat",
        "paste",
        "iocs",
        "analyze",
        "hostnames",
        "united",
        "aaaa",
        "unknown",
        "a domains",
        "search",
        "creation date",
        "record value",
        "next",
        "pornhub",
        "anyxxxtube",
        "domain",
        "gandi sas",
        "hostname",
        "basic",
        "pe32",
        "intel",
        "ms windows",
        "generic windos",
        "executable",
        "dos executable",
        "generic",
        "pe32 packer",
        "petite",
        "vs98",
        "info compiler",
        "products",
        "header intel",
        "name md5",
        "type",
        "rticon neutral",
        "overlay",
        "dos exe",
        "threat roundup",
        "pe resource",
        "june",
        "lumma stealer",
        "ransomexx",
        "azorult",
        "njrat",
        "open",
        "problem",
        "plugx",
        "android",
        "sex_phot.jpg.exe",
        "win32 dynamic",
        "link library",
        "win16 ne",
        "delphi generic",
        "icons library",
        "pe32 linker",
        "lcc linker",
        "empty hash",
        "tulach",
        "sabey",
        "rat",
        "remote",
        "remote access trojan"
      ],
      "references": [
        "https://www.healthonecares.com/locations/presbyterian-st-lukes-medical-center/physicians",
        "https://www.hybrid-analysis.com/sample/63bf920be2401947bd686d7dd146af7f3e56800409307360105bf50cebb1c1ea",
        "www2.megawebfind.com [command and control]",
        "http://ifdnzact.com/?dn=megawebdeals.com&pid=9PO755G95 [ phishing]",
        "20.99.186.246 [exploit source]",
        "https://www.healthonecares.com/locations/presbyterian-st-lukes-medical-center/physicians/ [heuristic]",
        "Win32:RATX-gen [Trj] identified.",
        "CS Sigma Rules: Shadow Copies Deletion Using Operating Systems Utilities by Florian Roth (Nextron Systems), Michael Haag, Teymur Kheirkhabarov, Daniil Yugoslavskiy, oscd.community, Andreas Hunkeler (@Karneades)",
        "CS Sigma Rules: Disable UAC Using Registry by frack113",
        "http://45.159.189.105/bot/regex [ tracking | botnet]",
        "https://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian [Password cracker | Patient being tracked through multiple medical systems]",
        "0-173-x.msn.com | https://twitter.com/PORNO_SEXYBABES | 0-3.duckdns.org | 0-212.pornhub.org | 000web.pornhub.org",
        "https://www.anyxxxtube.net/search-porn/tsara-brashears/ [phishing]",
        "CS Sigma Rules: Wow6432Node CurrentVersion Autorun Keys Modification by Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split)",
        "Remote Access Trojan"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "Indonesia",
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "HackTool",
          "display_name": "HackTool",
          "target": null
        },
        {
          "id": "Relic",
          "display_name": "Relic",
          "target": null
        },
        {
          "id": "Win32:RATX-gen [Trj]",
          "display_name": "Win32:RATX-gen [Trj]",
          "target": null
        },
        {
          "id": "Ransomware",
          "display_name": "Ransomware",
          "target": null
        },
        {
          "id": "LockBit",
          "display_name": "LockBit",
          "target": null
        },
        {
          "id": "Ursnif",
          "display_name": "Ursnif",
          "target": null
        },
        {
          "id": "Dark Power",
          "display_name": "Dark Power",
          "target": null
        },
        {
          "id": "W32/Hupigon.NCU",
          "display_name": "W32/Hupigon.NCU",
          "target": null
        },
        {
          "id": "Cobalt Strike",
          "display_name": "Cobalt Strike",
          "target": null
        },
        {
          "id": "Tulach",
          "display_name": "Tulach",
          "target": null
        },
        {
          "id": "Azorult",
          "display_name": "Azorult",
          "target": null
        },
        {
          "id": "Wiper",
          "display_name": "Wiper",
          "target": null
        },
        {
          "id": "Virut",
          "display_name": "Virut",
          "target": null
        },
        {
          "id": "Lumma Stealer",
          "display_name": "Lumma Stealer",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1046",
          "name": "Network Service Scanning",
          "display_name": "T1046 - Network Service Scanning"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1095",
          "name": "Non-Application Layer Protocol",
          "display_name": "T1095 - Non-Application Layer Protocol"
        },
        {
          "id": "T1573",
          "name": "Encrypted Channel",
          "display_name": "T1573 - Encrypted Channel"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1100",
          "name": "Web Shell",
          "display_name": "T1100 - Web Shell"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1114",
          "name": "Email Collection",
          "display_name": "T1114 - Email Collection"
        },
        {
          "id": "T1560",
          "name": "Archive Collected Data",
          "display_name": "T1560 - Archive Collected Data"
        },
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        },
        {
          "id": "TA0007",
          "name": "Discovery",
          "display_name": "TA0007 - Discovery"
        },
        {
          "id": "TA0011",
          "name": "Command and Control",
          "display_name": "TA0011 - Command and Control"
        }
      ],
      "industries": [
        "Healthcare",
        "Civil Society"
      ],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 68,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 1,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 883,
        "URL": 1412,
        "FileHash-MD5": 283,
        "FileHash-SHA1": 231,
        "FileHash-SHA256": 2909,
        "domain": 824,
        "email": 3,
        "CVE": 3
      },
      "indicator_count": 6548,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 224,
      "modified_text": "815 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "659331580cd1571f730b8de2",
      "name": "Agent Tesla | Spyware | Tracking Android & Apple users | Malware Attack",
      "description": "",
      "modified": "2024-01-31T14:03:30.344000",
      "created": "2024-01-01T21:40:40.242000",
      "tags": [
        "maxads0",
        "kld1063",
        "ioc search",
        "new ioc",
        "teams api",
        "contact",
        "threat analyzer",
        "threat",
        "paste",
        "iocs",
        "hostnames",
        "urls http",
        "ssl certificate",
        "whois record",
        "contacted",
        "referrer",
        "historical ssl",
        "march",
        "communicating",
        "copy",
        "january",
        "collections",
        "execution",
        "malware",
        "startpage",
        "malicious",
        "ransomware",
        "agent tesla",
        "attack",
        "android",
        "name verdict",
        "falcon sandbox",
        "reports",
        "falcon",
        "windir",
        "path",
        "programfiles",
        "pe32",
        "ms windows",
        "getprocaddress",
        "file type",
        "mitre att",
        "ck id",
        "show technique",
        "win64",
        "date",
        "open",
        "hybrid",
        "cookie",
        "tracking",
        "apple",
        "spyware",
        "malware",
        "tablet",
        "superwebbysearch",
        "hallrender",
        "pegasus",
        "briansabey",
        "aig",
        "abuse",
        "tulach"
      ],
      "references": [
        "findbetterresults.com",
        "https://hybrid-analysis.com/sample/bba36b3ae7c49d1cffcc5f8e045d81e9307a2e1a86b923f89008e9377d171fb6",
        "https://www.virustotal.com/gui/url/eed406872c2e6ef550b948510fe0b7b4c71f752f58551c2f8e61d31a19d2a153/summary",
        "http://www.applerewards.website/pl/3/index.html?voluumdata=BASE64dmlkLi4wMDAwMDAwMi00NGFiLTQzNDktODAwMC0wMDAwMDAwMDAwMDBfX3ZwaWQuLjJhYWQzMDAwLWJiMzYtMTFlNi04YTYyLTBlYzcxZTllMDMzMV9fY2FpZC4uNjBhMjIwOWUtNWMzNC00OGQ4LWIyNDctYWM5YzVkOTM3MzZhX19ydC4uUl9fbGlkLi4yYTRjOTA4My0zY2RmLTQyNDktOGJmOS0yODMxZWYzNGRhYTlfX29pZDEuLjUwMGE4NDhjLTA2NGEtNDYyZi05MDNmLTgxYzY4ODNmODEwZl9fdmFyMS4uNjA4OTYxX192YXIyLi42NzEwMjhfX3JkLi5vbmNsaWNrYWRzXC5cbmV0X19haWQuLl9fYWIuLl9fc2lkLi4&zoneid=608961&campaignid=671028&visitor_id=4003954",
        "www2.megawebfind.com                [command_and_control]",
        "https://search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas_sfp&command=   [command_and_control]   stolec kradnie krypto"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Agent Tesla",
          "display_name": "Agent Tesla",
          "target": null
        },
        {
          "id": "Ransomware",
          "display_name": "Ransomware",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1012",
          "name": "Query Registry",
          "display_name": "T1012 - Query Registry"
        },
        {
          "id": "T1033",
          "name": "System Owner/User Discovery",
          "display_name": "T1033 - System Owner/User Discovery"
        },
        {
          "id": "T1036",
          "name": "Masquerading",
          "display_name": "T1036 - Masquerading"
        },
        {
          "id": "T1053",
          "name": "Scheduled Task/Job",
          "display_name": "T1053 - Scheduled Task/Job"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1070",
          "name": "Indicator Removal on Host",
          "display_name": "T1070 - Indicator Removal on Host"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1074",
          "name": "Data Staged",
          "display_name": "T1074 - Data Staged"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1106",
          "name": "Native API",
          "display_name": "T1106 - Native API"
        },
        {
          "id": "T1112",
          "name": "Modify Registry",
          "display_name": "T1112 - Modify Registry"
        },
        {
          "id": "T1129",
          "name": "Shared Modules",
          "display_name": "T1129 - Shared Modules"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1218",
          "name": "Signed Binary Proxy Execution",
          "display_name": "T1218 - Signed Binary Proxy Execution"
        },
        {
          "id": "T1518",
          "name": "Software Discovery",
          "display_name": "T1518 - Software Discovery"
        },
        {
          "id": "T1614",
          "name": "System Location Discovery",
          "display_name": "T1614 - System Location Discovery"
        },
        {
          "id": "TA0011",
          "name": "Command and Control",
          "display_name": "TA0011 - Command and Control"
        },
        {
          "id": "T1155",
          "name": "AppleScript",
          "display_name": "T1155 - AppleScript"
        },
        {
          "id": "T1449",
          "name": "Exploit SS7 to Redirect Phone Calls/SMS",
          "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
        },
        {
          "id": "T1031",
          "name": "Modify Existing Service",
          "display_name": "T1031 - Modify Existing Service"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 24,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 2368,
        "FileHash-SHA256": 4539,
        "hostname": 2892,
        "URL": 9741,
        "FileHash-MD5": 836,
        "FileHash-SHA1": 461,
        "CVE": 1
      },
      "indicator_count": 20838,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 222,
      "modified_text": "852 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "659331589faf01b909c1802d",
      "name": "Agent Tesla | Spyware | Tracking Android & Apple users | Malware Attack",
      "description": "",
      "modified": "2024-01-31T14:03:30.344000",
      "created": "2024-01-01T21:40:40.413000",
      "tags": [
        "maxads0",
        "kld1063",
        "ioc search",
        "new ioc",
        "teams api",
        "contact",
        "threat analyzer",
        "threat",
        "paste",
        "iocs",
        "hostnames",
        "urls http",
        "ssl certificate",
        "whois record",
        "contacted",
        "referrer",
        "historical ssl",
        "march",
        "communicating",
        "copy",
        "january",
        "collections",
        "execution",
        "malware",
        "startpage",
        "malicious",
        "ransomware",
        "agent tesla",
        "attack",
        "android",
        "name verdict",
        "falcon sandbox",
        "reports",
        "falcon",
        "windir",
        "path",
        "programfiles",
        "pe32",
        "ms windows",
        "getprocaddress",
        "file type",
        "mitre att",
        "ck id",
        "show technique",
        "win64",
        "date",
        "open",
        "hybrid",
        "cookie",
        "tracking",
        "apple",
        "spyware",
        "malware",
        "tablet",
        "superwebbysearch",
        "hallrender",
        "pegasus",
        "briansabey",
        "aig",
        "abuse",
        "tulach"
      ],
      "references": [
        "findbetterresults.com",
        "https://hybrid-analysis.com/sample/bba36b3ae7c49d1cffcc5f8e045d81e9307a2e1a86b923f89008e9377d171fb6",
        "https://www.virustotal.com/gui/url/eed406872c2e6ef550b948510fe0b7b4c71f752f58551c2f8e61d31a19d2a153/summary",
        "http://www.applerewards.website/pl/3/index.html?voluumdata=BASE64dmlkLi4wMDAwMDAwMi00NGFiLTQzNDktODAwMC0wMDAwMDAwMDAwMDBfX3ZwaWQuLjJhYWQzMDAwLWJiMzYtMTFlNi04YTYyLTBlYzcxZTllMDMzMV9fY2FpZC4uNjBhMjIwOWUtNWMzNC00OGQ4LWIyNDctYWM5YzVkOTM3MzZhX19ydC4uUl9fbGlkLi4yYTRjOTA4My0zY2RmLTQyNDktOGJmOS0yODMxZWYzNGRhYTlfX29pZDEuLjUwMGE4NDhjLTA2NGEtNDYyZi05MDNmLTgxYzY4ODNmODEwZl9fdmFyMS4uNjA4OTYxX192YXIyLi42NzEwMjhfX3JkLi5vbmNsaWNrYWRzXC5cbmV0X19haWQuLl9fYWIuLl9fc2lkLi4&zoneid=608961&campaignid=671028&visitor_id=4003954",
        "www2.megawebfind.com                [command_and_control]",
        "https://search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas_sfp&command=   [command_and_control]   stolec kradnie krypto"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Agent Tesla",
          "display_name": "Agent Tesla",
          "target": null
        },
        {
          "id": "Ransomware",
          "display_name": "Ransomware",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1012",
          "name": "Query Registry",
          "display_name": "T1012 - Query Registry"
        },
        {
          "id": "T1033",
          "name": "System Owner/User Discovery",
          "display_name": "T1033 - System Owner/User Discovery"
        },
        {
          "id": "T1036",
          "name": "Masquerading",
          "display_name": "T1036 - Masquerading"
        },
        {
          "id": "T1053",
          "name": "Scheduled Task/Job",
          "display_name": "T1053 - Scheduled Task/Job"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1070",
          "name": "Indicator Removal on Host",
          "display_name": "T1070 - Indicator Removal on Host"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1074",
          "name": "Data Staged",
          "display_name": "T1074 - Data Staged"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1106",
          "name": "Native API",
          "display_name": "T1106 - Native API"
        },
        {
          "id": "T1112",
          "name": "Modify Registry",
          "display_name": "T1112 - Modify Registry"
        },
        {
          "id": "T1129",
          "name": "Shared Modules",
          "display_name": "T1129 - Shared Modules"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1218",
          "name": "Signed Binary Proxy Execution",
          "display_name": "T1218 - Signed Binary Proxy Execution"
        },
        {
          "id": "T1518",
          "name": "Software Discovery",
          "display_name": "T1518 - Software Discovery"
        },
        {
          "id": "T1614",
          "name": "System Location Discovery",
          "display_name": "T1614 - System Location Discovery"
        },
        {
          "id": "TA0011",
          "name": "Command and Control",
          "display_name": "TA0011 - Command and Control"
        },
        {
          "id": "T1155",
          "name": "AppleScript",
          "display_name": "T1155 - AppleScript"
        },
        {
          "id": "T1449",
          "name": "Exploit SS7 to Redirect Phone Calls/SMS",
          "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
        },
        {
          "id": "T1031",
          "name": "Modify Existing Service",
          "display_name": "T1031 - Modify Existing Service"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 29,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 2368,
        "FileHash-SHA256": 4539,
        "hostname": 2892,
        "URL": 9741,
        "FileHash-MD5": 836,
        "FileHash-SHA1": 461,
        "CVE": 1
      },
      "indicator_count": 20838,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 221,
      "modified_text": "852 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "658b9e86f7a149333882bfb9",
      "name": "Hijacking | Typosquatting | Masquerading Shared Modules",
      "description": "*Shared Modules\t\nExecution\nAdversaries may execute malicious payloads via loading shared modules.\n\n*Masquerading\t\nDefense Evasion\nAdversaries may attempt to manipulate features of their artifacts to make them appear legitimate or benign to users and/or security tools.\n\nComponent Object Model Hijacking\t\nPersistence\nPrivilege Escalation\nAdversaries may establish persistence by executing malicious content triggered by hijacked references to Component Object Model (COM) objects.\nPulse: http://ww1.thecoolzipextractorapp.com/\nFound in: https://www.hallrender.com/attorney/brian-sabey/",
      "modified": "2024-01-26T01:05:54.754000",
      "created": "2023-12-27T03:48:22.319000",
      "tags": [
        "threat",
        "feeds ioc",
        "new ioc",
        "teams api",
        "contact",
        "maltiverse",
        "dinkle threat",
        "paste",
        "iocs",
        "analyze",
        "ssl certificate",
        "whois record",
        "contacted",
        "referrer",
        "historical ssl",
        "communicating",
        "whois whois",
        "siblings parent",
        "execution"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 28,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 12134,
        "FileHash-MD5": 102,
        "FileHash-SHA1": 101,
        "FileHash-SHA256": 3982,
        "hostname": 2878,
        "domain": 2159,
        "CVE": 1
      },
      "indicator_count": 21357,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 224,
      "modified_text": "857 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "658ca3f53717bb3a25e96065",
      "name": "Hijacking | Typosquatting | Masquerading Shared Modules | http://ww1.thecoolzipextractorapp.com/ via https://www.hallrender.com/attorney/brian-sabey/",
      "description": "",
      "modified": "2024-01-26T01:05:54.754000",
      "created": "2023-12-27T22:23:49.562000",
      "tags": [
        "threat",
        "feeds ioc",
        "new ioc",
        "teams api",
        "contact",
        "maltiverse",
        "dinkle threat",
        "paste",
        "iocs",
        "analyze",
        "ssl certificate",
        "whois record",
        "contacted",
        "referrer",
        "historical ssl",
        "communicating",
        "whois whois",
        "siblings parent",
        "execution"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": "658b9e86f7a149333882bfb9",
      "export_count": 25,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "scoreblue",
        "id": "254100",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 12134,
        "FileHash-MD5": 102,
        "FileHash-SHA1": 101,
        "FileHash-SHA256": 3982,
        "hostname": 2878,
        "domain": 2159,
        "CVE": 1
      },
      "indicator_count": 21357,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 229,
      "modified_text": "857 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6570a7b4eb565273001e2e08",
      "name": "Ireland Netsky | Relay Router | Misc Attack on LTL Fright Outage",
      "description": "",
      "modified": "2023-12-06T16:56:20.491000",
      "created": "2023-12-06T16:56:20.491000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 8,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 1353,
        "CVE": 8,
        "FileHash-SHA256": 3611,
        "domain": 795,
        "URL": 2831,
        "FileHash-MD5": 663,
        "FileHash-SHA1": 398
      },
      "indicator_count": 9659,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "908 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "651cd4a6af63714f51c8d721",
      "name": "Ireland Netsky | Relay Router | Misc Attack on LTL Fright Outage",
      "description": "Cobalt Strike , FireHol anonymization,  IT Attack, Suricata Alert, MITRE. Appears to be a complete cyber attack against a well known LTL Fright lines IT system.",
      "modified": "2023-11-03T02:03:00.398000",
      "created": "2023-10-04T02:57:42.183000",
      "tags": [
        "united",
        "smtp service",
        "firehol",
        "pony",
        "s1us",
        "s1de",
        "spammer",
        "proxy",
        "ireland netsky",
        "anonymizer",
        "cisco umbrella",
        "site",
        "safe site",
        "million",
        "alexa top",
        "alexa",
        "detection list",
        "blacklist",
        "malicious url",
        "blacklist http",
        "linkid252669",
        "noname057",
        "url summary",
        "summary",
        "sample",
        "samples",
        "misc attack",
        "et tor",
        "known tor",
        "relayrouter",
        "exit",
        "node traffic",
        "misc activity",
        "et policy",
        "tor ssl",
        "Hostname: RecoveryStore-3.7.5.1.4.6.2.0-D917-11E7-B67B-080027A49",
        "cyber criminal",
        "FireHOL",
        "Suricata Alert",
        "HTML document, ASCII text",
        "mail spammer",
        "malware site",
        "heur",
        "malware",
        "adware",
        "malicious site",
        "phishing site",
        "artemis",
        "unsafe",
        "exploit",
        "iframe",
        "fakealert",
        "opencandy",
        "riskware",
        "genkryptik",
        "nircmd",
        "swrort",
        "downldr",
        "crack",
        "tiggre",
        "presenoker",
        "filetour",
        "cleaner",
        "conduit",
        "wacatac",
        "coinminer",
        "dropper",
        "cobalt strike",
        "acint",
        "systweak",
        "behav",
        "agent",
        "phishing",
        "maltiverse",
        "trojanspy",
        "webtoolbar",
        "phishing",
        "exploit-source"
      ],
      "references": [
        "-Hostname: RecoveryStore-3.7.5.1.4.6.2.0-D917-11E7-B67B-080027A49DD/",
        "https://www.hybrid-analysis.com/sample/fa1f15bd4c0cd287fe04f324d3363a8b5a295b57cb22d9ea0f3d6973eb442d17/651c94c00b17fb9324040f7c"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "Maltiverse",
          "display_name": "Maltiverse",
          "target": null
        },
        {
          "id": "TrojanSpy",
          "display_name": "TrojanSpy",
          "target": null
        },
        {
          "id": "WebToolbar",
          "display_name": "WebToolbar",
          "target": null
        },
        {
          "id": "OpenCandy",
          "display_name": "OpenCandy",
          "target": null
        },
        {
          "id": "Trojan:Win32/Tiggre",
          "display_name": "Trojan:Win32/Tiggre",
          "target": "/malware/Trojan:Win32/Tiggre"
        },
        {
          "id": "Cobalt Strike",
          "display_name": "Cobalt Strike",
          "target": null
        },
        {
          "id": "Artemis",
          "display_name": "Artemis",
          "target": null
        },
        {
          "id": "Ireland Netsky",
          "display_name": "Ireland Netsky",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1059.007",
          "name": "JavaScript",
          "display_name": "T1059.007 - JavaScript"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1071.001",
          "name": "Web Protocols",
          "display_name": "T1071.001 - Web Protocols"
        },
        {
          "id": "T1071.004",
          "name": "DNS",
          "display_name": "T1071.004 - DNS"
        },
        {
          "id": "T1147",
          "name": "Hidden Users",
          "display_name": "T1147 - Hidden Users"
        },
        {
          "id": "T1497",
          "name": "Virtualization/Sandbox Evasion",
          "display_name": "T1497 - Virtualization/Sandbox Evasion"
        },
        {
          "id": "T1114",
          "name": "Email Collection",
          "display_name": "T1114 - Email Collection"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        }
      ],
      "industries": [
        "Transportation",
        "Technology"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 29,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "scoreblue",
        "id": "254100",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 795,
        "FileHash-MD5": 663,
        "hostname": 1353,
        "URL": 2831,
        "FileHash-SHA1": 398,
        "FileHash-SHA256": 3611,
        "CVE": 8
      },
      "indicator_count": 9659,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 230,
      "modified_text": "941 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "653f1a8f35a050560dcd3b00",
      "name": "Ireland Netsky | Relay Router | Misc Attack on LTL Fright Outage",
      "description": "",
      "modified": "2023-11-03T02:03:00.398000",
      "created": "2023-10-30T02:53:03.811000",
      "tags": [
        "united",
        "smtp service",
        "firehol",
        "pony",
        "s1us",
        "s1de",
        "spammer",
        "proxy",
        "ireland netsky",
        "anonymizer",
        "cisco umbrella",
        "site",
        "safe site",
        "million",
        "alexa top",
        "alexa",
        "detection list",
        "blacklist",
        "malicious url",
        "blacklist http",
        "linkid252669",
        "noname057",
        "url summary",
        "summary",
        "sample",
        "samples",
        "misc attack",
        "et tor",
        "known tor",
        "relayrouter",
        "exit",
        "node traffic",
        "misc activity",
        "et policy",
        "tor ssl",
        "Hostname: RecoveryStore-3.7.5.1.4.6.2.0-D917-11E7-B67B-080027A49",
        "cyber criminal",
        "FireHOL",
        "Suricata Alert",
        "HTML document, ASCII text",
        "mail spammer",
        "malware site",
        "heur",
        "malware",
        "adware",
        "malicious site",
        "phishing site",
        "artemis",
        "unsafe",
        "exploit",
        "iframe",
        "fakealert",
        "opencandy",
        "riskware",
        "genkryptik",
        "nircmd",
        "swrort",
        "downldr",
        "crack",
        "tiggre",
        "presenoker",
        "filetour",
        "cleaner",
        "conduit",
        "wacatac",
        "coinminer",
        "dropper",
        "cobalt strike",
        "acint",
        "systweak",
        "behav",
        "agent",
        "phishing",
        "maltiverse",
        "trojanspy",
        "webtoolbar",
        "phishing",
        "exploit-source"
      ],
      "references": [
        "-Hostname: RecoveryStore-3.7.5.1.4.6.2.0-D917-11E7-B67B-080027A49DD/",
        "https://www.hybrid-analysis.com/sample/fa1f15bd4c0cd287fe04f324d3363a8b5a295b57cb22d9ea0f3d6973eb442d17/651c94c00b17fb9324040f7c"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "Maltiverse",
          "display_name": "Maltiverse",
          "target": null
        },
        {
          "id": "TrojanSpy",
          "display_name": "TrojanSpy",
          "target": null
        },
        {
          "id": "WebToolbar",
          "display_name": "WebToolbar",
          "target": null
        },
        {
          "id": "OpenCandy",
          "display_name": "OpenCandy",
          "target": null
        },
        {
          "id": "Trojan:Win32/Tiggre",
          "display_name": "Trojan:Win32/Tiggre",
          "target": "/malware/Trojan:Win32/Tiggre"
        },
        {
          "id": "Cobalt Strike",
          "display_name": "Cobalt Strike",
          "target": null
        },
        {
          "id": "Artemis",
          "display_name": "Artemis",
          "target": null
        },
        {
          "id": "Ireland Netsky",
          "display_name": "Ireland Netsky",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1059.007",
          "name": "JavaScript",
          "display_name": "T1059.007 - JavaScript"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1071.001",
          "name": "Web Protocols",
          "display_name": "T1071.001 - Web Protocols"
        },
        {
          "id": "T1071.004",
          "name": "DNS",
          "display_name": "T1071.004 - DNS"
        },
        {
          "id": "T1147",
          "name": "Hidden Users",
          "display_name": "T1147 - Hidden Users"
        },
        {
          "id": "T1497",
          "name": "Virtualization/Sandbox Evasion",
          "display_name": "T1497 - Virtualization/Sandbox Evasion"
        },
        {
          "id": "T1114",
          "name": "Email Collection",
          "display_name": "T1114 - Email Collection"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        }
      ],
      "industries": [
        "Transportation",
        "Technology"
      ],
      "TLP": "white",
      "cloned_from": "651cd4a6af63714f51c8d721",
      "export_count": 13,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 795,
        "FileHash-MD5": 663,
        "hostname": 1353,
        "URL": 2831,
        "FileHash-SHA1": 398,
        "FileHash-SHA256": 3611,
        "CVE": 8
      },
      "indicator_count": 9659,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 220,
      "modified_text": "941 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "651795a9d541bac4a870983c",
      "name": "Apple and iOS fraud, phishing, tracking + FindMyiPhone.us",
      "description": "fraud, phishing, C2, backdoors, tracking, spyware, attack, trojan,malicious, non reputable, exploit source, malicious adware, tracks, iPhone, iPad iPods unaddressed iPhone vulnerabilities.",
      "modified": "2023-10-30T03:05:33.884000",
      "created": "2023-09-30T03:27:37.578000",
      "tags": [
        "whois record",
        "ssl certificate",
        "communicating",
        "threat roundup",
        "august",
        "whois whois",
        "october",
        "july",
        "september",
        "historical ssl",
        "june",
        "february"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 8,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "scoreblue",
        "id": "254100",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 90,
        "FileHash-SHA1": 90,
        "FileHash-SHA256": 699,
        "URL": 1167,
        "domain": 532,
        "hostname": 318
      },
      "indicator_count": 2896,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 228,
      "modified_text": "945 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "651795b2b839d974e73cb9e3",
      "name": "Apple and iOS fraud, phishing, tracking + FindMyiPhone.us",
      "description": "fraud, phishing, C2, backdoors, tracking, spyware, attack, trojan,malicious, non reputable, exploit source, malicious adware, tracks, iPhone, iPad iPods unaddressed iPhone vulnerabilities.",
      "modified": "2023-10-30T03:05:33.884000",
      "created": "2023-09-30T03:27:46.181000",
      "tags": [
        "whois record",
        "ssl certificate",
        "communicating",
        "threat roundup",
        "august",
        "whois whois",
        "october",
        "july",
        "september",
        "historical ssl",
        "june",
        "february"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 8,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "scoreblue",
        "id": "254100",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 90,
        "FileHash-SHA1": 90,
        "FileHash-SHA256": 699,
        "URL": 1167,
        "domain": 532,
        "hostname": 318
      },
      "indicator_count": 2896,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 228,
      "modified_text": "945 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "https://postback.trafficmotor.com",
    "type": "URL"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "https://postback.trafficmotor.com",
    "type": "URL",
    "found": false,
    "verdict": "clean",
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780360384.4451964
}