{
  "type": "URL",
  "indicator": "https://pulsedive.com/indicator",
  "general": {
    "sections": [
      "general",
      "url_list",
      "http_scans",
      "screenshot"
    ],
    "indicator": "https://pulsedive.com/indicator",
    "type": "url",
    "type_title": "URL",
    "validation": [],
    "base_indicator": {
      "id": 4010061534,
      "indicator": "https://pulsedive.com/indicator",
      "type": "URL",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 9,
      "pulses": [
        {
          "id": "673dc97604d5c7076da96877",
          "name": "https://www.vgt.pl/js/jquery-3.2.1.min.js",
          "description": "JQuery v3.2.1 is released by the JS Foundation and is based on the code written by Jeremy Chilcot, the co-creator of the popular web browser, JQuery.",
          "modified": "2025-07-31T22:43:55.771000",
          "created": "2024-11-20T11:35:18.167000",
          "tags": [
            "regexp",
            "error",
            "pseudo",
            "child",
            "sufeffxa0",
            "class",
            "attr",
            "js foundation",
            "typeof module",
            "object",
            "date",
            "null"
          ],
          "references": [
            "https://www.vgt.pl/js/jquery-3.2.1.min.js"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 5,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Arek-BTC",
            "id": "212764",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_212764/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA1": 172,
            "hostname": 404,
            "URL": 969,
            "domain": 98,
            "FileHash-MD5": 178,
            "FileHash-SHA256": 355,
            "IPv4": 3
          },
          "indicator_count": 2179,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 123,
          "modified_text": "261 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "674afb83c67ff4443e9f953a",
          "name": "PolymodXT.exe",
          "description": "",
          "modified": "2025-05-14T21:18:19.590000",
          "created": "2024-11-30T11:48:19.052000",
          "tags": [
            "file",
            "flagi",
            "process sha256",
            "process disc",
            "pathway z",
            "identyfikator",
            "zawiera moliwo",
            "klucz",
            "zawiera",
            "wybierz",
            "nie mona",
            "przechowywanie",
            "haso",
            "obiekt",
            "cig uid",
            "zilla",
            "enumerate",
            "defender",
            "pragma",
            "security",
            "license v2",
            "ff ff",
            "fc e8",
            "f8 ff",
            "fc ff",
            "c9 c3",
            "e4 f8",
            "cc cc",
            "fc eb",
            "confuserex mod",
            "aspirecrypt",
            "detects",
            "reactor",
            "beds protector",
            "ps2exe",
            "bsjb",
            "boxedapp",
            "cyaxsharp",
            "cyaxpng",
            "smartassembly",
            "koivm",
            "confuserex",
            "obfuscator",
            "aspack",
            "titan",
            "enigma",
            "vmprotect",
            "strings",
            "rlpack",
            "antiem",
            "antisb",
            "themida",
            "loader",
            "sality",
            "dnguard",
            "windows nt",
            "gecko",
            "khtml",
            "msie",
            "wow64",
            "stealer",
            "win64",
            "error",
            "userprofile",
            "keylogger",
            "encrypt",
            "antivm",
            "span",
            "main",
            "grabber",
            "hello",
            "android",
            "dcrat",
            "win32",
            "kill",
            "revengerat",
            "sandbox",
            "pass",
            "chat",
            "first",
            "asyncrat",
            "crypto",
            "injector",
            "dropper",
            "infostealer",
            "lockfile",
            "worldwind",
            "stealerium",
            "toxiceye",
            "avemaria",
            "fast",
            "persistence",
            "trojan",
            "restart",
            "snakekeylogger",
            "snake",
            "accept",
            "cookie",
            "code",
            "killproc",
            "lazarus",
            "dearcry",
            "njrat",
            "cyrus",
            "powershell",
            "info",
            "body",
            "floodfix",
            "downloader",
            "ransomware",
            "core",
            "loki",
            "fpspy",
            "klogexe",
            "firebird",
            "patch",
            "explorer",
            "avkiller",
            "masslogger",
            "baldr",
            "modi rat",
            "helpme",
            "osno",
            "import",
            "keylog",
            "screencapture",
            "ransom",
            "crypted",
            "silent",
            "xorddos",
            "stormkitty",
            "ordinal",
            "locker",
            "hyperbro",
            "lamepyre",
            "parallaxrat",
            "null",
            "shurk steal",
            "arkeistealer",
            "strongpity",
            "desktop",
            "myagent",
            "bypass",
            "fatduke",
            "miniduke",
            "polyglotduke",
            "guildma",
            "spyeye",
            "corebot",
            "killmbr",
            "ooops",
            "lcpdot",
            "torisma",
            "codec",
            "prometheus",
            "spook",
            "crypt",
            "logger",
            "zegost",
            "poshkeylogger",
            "systembc",
            "hdlocker",
            "cryptolocker",
            "fivehands",
            "kitty",
            "goldmax",
            "rents",
            "maurigo",
            "done",
            "hidewindow",
            "bokbot",
            "bladabindi",
            "darktrack",
            "darksky",
            "alien",
            "karkoff",
            "inject",
            "windigo",
            "rest",
            "softcnapp",
            "elysiumstealer",
            "leivion",
            "banload",
            "ultrareach",
            "ultrasurf",
            "buterat",
            "tools",
            "beasty",
            "shut",
            "gravityrat",
            "fatalrat",
            "discord",
            "deadwood",
            "turian",
            "markirat",
            "mark",
            "klingonrat",
            "path",
            "reverserat",
            "grab",
            "meta",
            "voidcrypt",
            "darkvnc",
            "ryzerlo",
            "hiddentear",
            "boxcaon",
            "stream",
            "crimsonrat",
            "delfi",
            "infinity",
            "stealthworker",
            "gasket",
            "spoolss",
            "lu0bot",
            "target",
            "attack",
            "cobaltstrike",
            "bits",
            "chaos",
            "bitcoin",
            "wiper",
            "delphi",
            "slackbot",
            "neshta",
            "belarus",
            "apanas",
            "runner",
            "darkcomet",
            "macoute",
            "iframe",
            "vanillarat",
            "sectoprat",
            "melt",
            "tomiris",
            "apostle",
            "blackbyte",
            "kutaki",
            "override",
            "windealer",
            "mkdir",
            "brbbot",
            "config",
            "babylon rat",
            "spynet",
            "bazarloader",
            "clipper",
            "banker",
            "gh0st",
            "piratestealer",
            "witch",
            "killme",
            "vulturi",
            "tofsee",
            "slow",
            "owowa",
            "flagpro",
            "write",
            "dazzlespy",
            "decryptor",
            "bandit stealer",
            "bandit",
            "darkeye",
            "recordbreaker",
            "truebot",
            "svchost",
            "clipbanker",
            "service",
            "arrowrat",
            "ducktail",
            "confuser",
            "gobrat",
            "modiloader",
            "chilelocker",
            "noclose",
            "strelastealer",
            "comfoo",
            "babar",
            "blankgrabber",
            "solarmarker",
            "darkgate",
            "stub",
            "banned",
            "globeimposter",
            "rhysida",
            "janelarat",
            "kraken",
            "recon",
            "quiterat",
            "venomrat",
            "venom rat",
            "sapphirestealer",
            "ntospy",
            "raccoon",
            "shifu",
            "mediapi",
            "poolrat",
            "cicada3301",
            "remoteexec"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 528,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Arek-BTC",
            "id": "212764",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_212764/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 414,
            "FileHash-SHA1": 410,
            "FileHash-SHA256": 1940,
            "URL": 171,
            "hostname": 56,
            "domain": 134,
            "YARA": 759,
            "email": 4
          },
          "indicator_count": 3888,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 122,
          "modified_text": "339 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "66ce8795f74ccdc8a4ad972f",
          "name": "Home | Sanselo | Realizare site web \u0219i aplica\u021bii de mobil",
          "description": "Aplica\u021bii mobile, \u00c2\u00a31bn, \u00e2\u201a\u00ac1.5bn \u00e2\u20ac\u00b5\u00a6 \u00c3\u20ac\u201c  \u00f4l iau i'r iddo.",
          "modified": "2025-05-14T21:14:50.899000",
          "created": "2024-08-28T02:12:37.280000",
          "tags": [
            "sanselo",
            "i aplicaii",
            "home",
            "realizare site",
            "servicii web",
            "mobile app",
            "contact blog",
            "selecteaz",
            "pagin",
            "future",
            "adres url",
            "ipv4",
            "ccro asnas39668",
            "intersat srl",
            "rola",
            "url http",
            "odcisk palca"
          ],
          "references": [
            "https://sanselo.com/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 3,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Arek-BTC",
            "id": "212764",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_212764/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "IPv4": 11,
            "URL": 1533,
            "domain": 150,
            "email": 2,
            "hostname": 471,
            "FileHash-MD5": 236,
            "FileHash-SHA1": 141,
            "FileHash-SHA256": 979,
            "SSLCertFingerprint": 4
          },
          "indicator_count": 3527,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 123,
          "modified_text": "339 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "670d6eddfef3c506b89ceae9",
          "name": "https:://www.fonts.com  correo.fhdux.pl  94.152.58.192 cert: vgt.pl",
          "description": "https://www.criminalip.io/asset/report/94.152.58.192  vgt.pl\nhttps://urlscan.io/result/240096e3-fe4f-46cf-bae4-2ee2f0b278ec/#transactions\nhttps://fonts.gstatic.com/s/roboto/v32/KFOmCnqEu92Fr1Mu4mxK.woff2\n89978e658e840b927dddb5cb3a835c7d8526ece79933bd9f3096b301fe1a8571\n0b5c41fa20267271d30a61a113f707f319398232666304793d7d15d98b9fdb04\n97511dae443d722cdbb59c69a1bd99ccdbb3bf833c2a85acd74f7092fc6a0324\na79dc08d6442545c5bc444feb881b4e9025ad2557a67ea13b3cdc919fadc91c4\nf4602b083181bf931b5ab428a4fe12536309c50de41755ec18d12a39d8f09c52\nfb1a7c9500d4b6a9cedd47fa96b04144e26a5f0325c0f3b52c4362392f710eaf",
          "modified": "2025-05-14T20:46:18.601000",
          "created": "2024-10-14T19:19:57.749000",
          "tags": [
            "subject key",
            "extended key",
            "usage",
            "auth",
            "server auth",
            "certificate",
            "authority",
            "info access",
            "ocsp urls",
            "issuer urls",
            "win32 exe",
            "age flash",
            "player",
            "win32 dll",
            "flash player",
            "dos exe",
            "albert harrill",
            "paul",
            "apostle",
            "life",
            "legacy",
            "dostawa"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1543",
              "name": "Create or Modify System Process",
              "display_name": "T1543 - Create or Modify System Process"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 39,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Arek-BTC",
            "id": "212764",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_212764/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "IPv4": 268,
            "URL": 622,
            "domain": 105,
            "hostname": 294,
            "FileHash-SHA256": 1187,
            "FileHash-MD5": 95,
            "FileHash-SHA1": 76,
            "IPv6": 1,
            "CVE": 8
          },
          "indicator_count": 2656,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 125,
          "modified_text": "339 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6739ed21897f1541c521f712",
          "name": "gen.zip (vgt.pl and adorno.pl)  Ransom_CyberVolk.R002C0DG524",
          "description": "Dane archiwum ZIP, co najmniej v2.0 do wyodr\u0119bnienia, bez przeplotu o'rhywolaethol.",
          "modified": "2025-01-06T23:11:01.995000",
          "created": "2024-11-17T13:18:25.453000",
          "tags": [
            "sha256",
            "javascript z",
            "sha1",
            "imphasz",
            "pejzasz",
            "wirustotal",
            "wykrycia yara",
            "nazwa smyczki",
            "interesujce",
            "whasz",
            "ju sama",
            "a dziki",
            "edgecast w",
            "w przypadku",
            "ciekapliku",
            "filename ma",
            "remoteip",
            "nazwapliku ma",
            "email",
            "zero trust",
            "lub ciekapliku",
            "remoteurl ma",
            "test zgodnoci",
            "szybki start",
            "crlf",
            "dane obrazu",
            "tekst ascii",
            "z terminatorami",
            "rgba",
            "dane archiwum",
            "pe32",
            "intel",
            "ms windows",
            "z bardzo"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 17,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Arek-BTC",
            "id": "212764",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_212764/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 456,
            "URL": 1540,
            "hostname": 504,
            "BitcoinAddress": 1,
            "FileHash-MD5": 149,
            "FileHash-SHA1": 91,
            "domain": 234,
            "IPv4": 94,
            "email": 4
          },
          "indicator_count": 3073,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 122,
          "modified_text": "467 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "675297b9110af13304ed97d6",
          "name": "http://regnator.com/Program/Regnator.exe",
          "description": "D7Eok8kO9fuM6YCmU4O wedi i'w'r gael ei gyn-gwrnod o'i'u gyda'n sgil.",
          "modified": "2025-01-06T23:11:01.995000",
          "created": "2024-12-06T06:20:41.420000",
          "tags": [
            "serial number",
            "certum trusted",
            "network ca",
            "algorithm",
            "trusted network",
            "valid",
            "valid usage",
            "thumbprint",
            "name certum",
            "valid from",
            "whasz",
            "sha256",
            "ssdeep",
            "xml c",
            "pdf c",
            "pliki wzoru",
            "vhash"
          ],
          "references": [
            "http://crd.gov.pl/wzor/2020/11/13/10091/wyroznik.xml",
            "http://crd.gov.pl/wzor/2022/11/09/11890/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1056",
              "name": "Input Capture",
              "display_name": "T1056 - Input Capture"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 25,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Arek-BTC",
            "id": "212764",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_212764/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 1046,
            "FileHash-MD5": 217,
            "FileHash-SHA1": 191,
            "URL": 202,
            "domain": 39,
            "email": 1,
            "hostname": 212,
            "IPv4": 12
          },
          "indicator_count": 1920,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 122,
          "modified_text": "467 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "670ffc8487aaf80605755b62",
          "name": "vgt.pl (VGT.pl) or plix.pl (plix.net) 104.21.40.140 172.67.186.229",
          "description": "You can get help with your computer problems using the Help and Support section or via Skype or Telegram, if you want to get in touch with the support team or use the help of the UK's TalkTalk service.",
          "modified": "2024-12-30T17:38:55.943000",
          "created": "2024-10-16T17:48:52.704000",
          "tags": [
            "pe32",
            "intel",
            "ms windows",
            "plik",
            "trojandropper",
            "trojan",
            "win32",
            "msil",
            "sha1",
            "sha256",
            "imphasz",
            "tekst ascii",
            "dane obrazu",
            "crlf",
            "dokument html",
            "unicode",
            "z bom",
            "rgba",
            "z terminatorami",
            "z bardzo",
            "utf8 unicode",
            "sobota",
            "sie usertrust",
            "salford o",
            "comodo ca",
            "limited st",
            "salt lake",
            "city o",
            "wto cze",
            "worldsetup c",
            "il l",
            "error",
            "null",
            "mapa",
            "liczba",
            "string",
            "bigint",
            "obiekt",
            "prawa autorskie",
            "nieznanybd",
            "uint8array",
            "android",
            "void",
            "unknown",
            "false",
            "roboto",
            "body",
            "this",
            "infinity",
            "outside",
            "span",
            "as13335",
            "cloudflare",
            "datasheet",
            "arkusz",
            "wyszukiwarka",
            "control panel",
            "support",
            "email",
            "a letter",
            "help",
            "mail",
            "management",
            "jpeg",
            "jfif",
            "dane",
            "dpcm",
            "ascii z",
            "dane archiwalne",
            "windows"
          ],
          "references": [
            "https://www.plix.pl/system/companies/logos/000/000/526/original/gigainternet-logo.png",
            "http://plix.net",
            "http://www.plix.net",
            "https://www.plix.pl",
            "http://www.plix.pl"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1218",
              "name": "Signed Binary Proxy Execution",
              "display_name": "T1218 - Signed Binary Proxy Execution"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 291,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Arek-BTC",
            "id": "212764",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_212764/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 516,
            "hostname": 705,
            "URL": 1831,
            "FileHash-SHA256": 3315,
            "CIDR": 4,
            "IPv6": 4,
            "IPv4": 49,
            "FileHash-MD5": 794,
            "FileHash-SHA1": 572,
            "email": 1,
            "CVE": 14
          },
          "indicator_count": 7805,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 127,
          "modified_text": "474 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "670b8e607683fbb3b8b484a5",
          "name": "Font Finder \ud83d\udd0e by What Font Is",
          "description": "What Font Is - the best font finder tool in the world - is here to help you find the right font from any image, or to find out where you can download or buy it.",
          "modified": "2024-12-17T14:35:45.139000",
          "created": "2024-10-13T09:09:52.039000",
          "tags": [
            "vhash htm",
            "ssdeep",
            "anchor hrefs",
            "sans",
            "woff2",
            "fontface",
            "u0329",
            "u25cc",
            "u2190",
            "u2192",
            "u0304",
            "u0308",
            "u1c801c88",
            "woff",
            "u03080309",
            "u0323",
            "u1ea01ef9",
            "u20ab",
            "fontawesome",
            "etmodules",
            "oszczdno",
            "font",
            "find",
            "whatfontis",
            "sign",
            "font finder",
            "sign up",
            "free",
            "upload",
            "drop",
            "different",
            "enjoy",
            "first",
            "accept",
            "close",
            "generator",
            "cookie",
            "contact",
            "html",
            "dokument office",
            "open xml",
            "rar theme",
            "win32 exe",
            "office open",
            "xml document",
            "text",
            "javascript",
            "query language",
            "ms word",
            "web design",
            "biblioteka dll",
            "win32",
            "anna"
          ],
          "references": [
            "http://www.whatfontis.com",
            "https://fonts.googleapis.com/css?family=Barlow+Condensed:100,100italic,200,200italic,300,300italic,regular,italic,500,500italic,600,600italic,700,700italic,800,800italic,900,900italic|Archivo:100,200,300,regular,500,600,700,800,900,100italic,200italic,300italic,italic,500italic,600italic,700italic,800italic,900italic&subset=latin,latin-ext&display=swap",
            "https://fonts.googleapis.com/css?family=Open+Sans:300italic,400italic,600italic,700italic,800italic,400,300,600,700,800&subset=latin,latin-ext&display=swap"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1543",
              "name": "Create or Modify System Process",
              "display_name": "T1543 - Create or Modify System Process"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 25,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Arek-BTC",
            "id": "212764",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_212764/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 455,
            "FileHash-SHA256": 292,
            "FileHash-MD5": 74,
            "FileHash-SHA1": 69,
            "hostname": 163,
            "domain": 30,
            "IPv4": 6,
            "CVE": 3
          },
          "indicator_count": 1092,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 123,
          "modified_text": "487 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "66e99ca508b46127bd4d552a",
          "name": "94.152.58.192",
          "description": "Researchers have developed a new way of storing data on a computer that can be stored in a secure secure system, as well as a network of secure networks, for use in Syria, Iraq and Iran.",
          "modified": "2024-12-17T14:35:39.173000",
          "created": "2024-09-17T15:13:41.714000",
          "tags": [
            "rticon serbian",
            "arabic libya",
            "vhash",
            "authentihash",
            "ssdeep",
            "ico rtgroupicon",
            "serbian arabic",
            "libya",
            "userprofile",
            "peexe c",
            "peexe",
            "user",
            "text c",
            "number",
            "ja3s",
            "win32 exe",
            "plik",
            "data rozwizania",
            "domena",
            "typ nazwa",
            "y0yxxhpr",
            "win32",
            "zawarte",
            "whasz",
            "oszczdno",
            "typ pliku",
            "biblioteka dll",
            "magia plik",
            "pe32 dla",
            "ms windows",
            "intel",
            "historical ssl",
            "whois"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1056",
              "name": "Input Capture",
              "display_name": "T1056 - Input Capture"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 4,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Arek-BTC",
            "id": "212764",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_212764/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 2136,
            "domain": 6110,
            "URL": 6946,
            "hostname": 6003,
            "IPv4": 85,
            "FileHash-MD5": 406,
            "FileHash-SHA1": 402,
            "CVE": 2
          },
          "indicator_count": 22090,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 127,
          "modified_text": "487 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "http://www.plix.pl",
        "https://www.vgt.pl/js/jquery-3.2.1.min.js",
        "https://fonts.googleapis.com/css?family=Open+Sans:300italic,400italic,600italic,700italic,800italic,400,300,600,700,800&subset=latin,latin-ext&display=swap",
        "https://fonts.googleapis.com/css?family=Barlow+Condensed:100,100italic,200,200italic,300,300italic,regular,italic,500,500italic,600,600italic,700,700italic,800,800italic,900,900italic|Archivo:100,200,300,regular,500,600,700,800,900,100italic,200italic,300italic,italic,500italic,600italic,700italic,800italic,900italic&subset=latin,latin-ext&display=swap",
        "http://plix.net",
        "https://www.plix.pl",
        "http://crd.gov.pl/wzor/2022/11/09/11890/",
        "http://www.plix.net",
        "https://www.plix.pl/system/companies/logos/000/000/526/original/gigainternet-logo.png",
        "http://www.whatfontis.com",
        "https://sanselo.com/",
        "http://crd.gov.pl/wzor/2020/11/13/10091/wyroznik.xml"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 0
        },
        "other": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 46112
        }
      }
    },
    "false_positive": [],
    "alexa": "http://www.alexa.com/siteinfo/pulsedive.com",
    "whois": "http://whois.domaintools.com/pulsedive.com",
    "domain": "pulsedive.com",
    "hostname": "Unavailable"
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 9,
  "pulses": [
    {
      "id": "673dc97604d5c7076da96877",
      "name": "https://www.vgt.pl/js/jquery-3.2.1.min.js",
      "description": "JQuery v3.2.1 is released by the JS Foundation and is based on the code written by Jeremy Chilcot, the co-creator of the popular web browser, JQuery.",
      "modified": "2025-07-31T22:43:55.771000",
      "created": "2024-11-20T11:35:18.167000",
      "tags": [
        "regexp",
        "error",
        "pseudo",
        "child",
        "sufeffxa0",
        "class",
        "attr",
        "js foundation",
        "typeof module",
        "object",
        "date",
        "null"
      ],
      "references": [
        "https://www.vgt.pl/js/jquery-3.2.1.min.js"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 5,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Arek-BTC",
        "id": "212764",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_212764/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA1": 172,
        "hostname": 404,
        "URL": 969,
        "domain": 98,
        "FileHash-MD5": 178,
        "FileHash-SHA256": 355,
        "IPv4": 3
      },
      "indicator_count": 2179,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 123,
      "modified_text": "261 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "674afb83c67ff4443e9f953a",
      "name": "PolymodXT.exe",
      "description": "",
      "modified": "2025-05-14T21:18:19.590000",
      "created": "2024-11-30T11:48:19.052000",
      "tags": [
        "file",
        "flagi",
        "process sha256",
        "process disc",
        "pathway z",
        "identyfikator",
        "zawiera moliwo",
        "klucz",
        "zawiera",
        "wybierz",
        "nie mona",
        "przechowywanie",
        "haso",
        "obiekt",
        "cig uid",
        "zilla",
        "enumerate",
        "defender",
        "pragma",
        "security",
        "license v2",
        "ff ff",
        "fc e8",
        "f8 ff",
        "fc ff",
        "c9 c3",
        "e4 f8",
        "cc cc",
        "fc eb",
        "confuserex mod",
        "aspirecrypt",
        "detects",
        "reactor",
        "beds protector",
        "ps2exe",
        "bsjb",
        "boxedapp",
        "cyaxsharp",
        "cyaxpng",
        "smartassembly",
        "koivm",
        "confuserex",
        "obfuscator",
        "aspack",
        "titan",
        "enigma",
        "vmprotect",
        "strings",
        "rlpack",
        "antiem",
        "antisb",
        "themida",
        "loader",
        "sality",
        "dnguard",
        "windows nt",
        "gecko",
        "khtml",
        "msie",
        "wow64",
        "stealer",
        "win64",
        "error",
        "userprofile",
        "keylogger",
        "encrypt",
        "antivm",
        "span",
        "main",
        "grabber",
        "hello",
        "android",
        "dcrat",
        "win32",
        "kill",
        "revengerat",
        "sandbox",
        "pass",
        "chat",
        "first",
        "asyncrat",
        "crypto",
        "injector",
        "dropper",
        "infostealer",
        "lockfile",
        "worldwind",
        "stealerium",
        "toxiceye",
        "avemaria",
        "fast",
        "persistence",
        "trojan",
        "restart",
        "snakekeylogger",
        "snake",
        "accept",
        "cookie",
        "code",
        "killproc",
        "lazarus",
        "dearcry",
        "njrat",
        "cyrus",
        "powershell",
        "info",
        "body",
        "floodfix",
        "downloader",
        "ransomware",
        "core",
        "loki",
        "fpspy",
        "klogexe",
        "firebird",
        "patch",
        "explorer",
        "avkiller",
        "masslogger",
        "baldr",
        "modi rat",
        "helpme",
        "osno",
        "import",
        "keylog",
        "screencapture",
        "ransom",
        "crypted",
        "silent",
        "xorddos",
        "stormkitty",
        "ordinal",
        "locker",
        "hyperbro",
        "lamepyre",
        "parallaxrat",
        "null",
        "shurk steal",
        "arkeistealer",
        "strongpity",
        "desktop",
        "myagent",
        "bypass",
        "fatduke",
        "miniduke",
        "polyglotduke",
        "guildma",
        "spyeye",
        "corebot",
        "killmbr",
        "ooops",
        "lcpdot",
        "torisma",
        "codec",
        "prometheus",
        "spook",
        "crypt",
        "logger",
        "zegost",
        "poshkeylogger",
        "systembc",
        "hdlocker",
        "cryptolocker",
        "fivehands",
        "kitty",
        "goldmax",
        "rents",
        "maurigo",
        "done",
        "hidewindow",
        "bokbot",
        "bladabindi",
        "darktrack",
        "darksky",
        "alien",
        "karkoff",
        "inject",
        "windigo",
        "rest",
        "softcnapp",
        "elysiumstealer",
        "leivion",
        "banload",
        "ultrareach",
        "ultrasurf",
        "buterat",
        "tools",
        "beasty",
        "shut",
        "gravityrat",
        "fatalrat",
        "discord",
        "deadwood",
        "turian",
        "markirat",
        "mark",
        "klingonrat",
        "path",
        "reverserat",
        "grab",
        "meta",
        "voidcrypt",
        "darkvnc",
        "ryzerlo",
        "hiddentear",
        "boxcaon",
        "stream",
        "crimsonrat",
        "delfi",
        "infinity",
        "stealthworker",
        "gasket",
        "spoolss",
        "lu0bot",
        "target",
        "attack",
        "cobaltstrike",
        "bits",
        "chaos",
        "bitcoin",
        "wiper",
        "delphi",
        "slackbot",
        "neshta",
        "belarus",
        "apanas",
        "runner",
        "darkcomet",
        "macoute",
        "iframe",
        "vanillarat",
        "sectoprat",
        "melt",
        "tomiris",
        "apostle",
        "blackbyte",
        "kutaki",
        "override",
        "windealer",
        "mkdir",
        "brbbot",
        "config",
        "babylon rat",
        "spynet",
        "bazarloader",
        "clipper",
        "banker",
        "gh0st",
        "piratestealer",
        "witch",
        "killme",
        "vulturi",
        "tofsee",
        "slow",
        "owowa",
        "flagpro",
        "write",
        "dazzlespy",
        "decryptor",
        "bandit stealer",
        "bandit",
        "darkeye",
        "recordbreaker",
        "truebot",
        "svchost",
        "clipbanker",
        "service",
        "arrowrat",
        "ducktail",
        "confuser",
        "gobrat",
        "modiloader",
        "chilelocker",
        "noclose",
        "strelastealer",
        "comfoo",
        "babar",
        "blankgrabber",
        "solarmarker",
        "darkgate",
        "stub",
        "banned",
        "globeimposter",
        "rhysida",
        "janelarat",
        "kraken",
        "recon",
        "quiterat",
        "venomrat",
        "venom rat",
        "sapphirestealer",
        "ntospy",
        "raccoon",
        "shifu",
        "mediapi",
        "poolrat",
        "cicada3301",
        "remoteexec"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 528,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Arek-BTC",
        "id": "212764",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_212764/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 414,
        "FileHash-SHA1": 410,
        "FileHash-SHA256": 1940,
        "URL": 171,
        "hostname": 56,
        "domain": 134,
        "YARA": 759,
        "email": 4
      },
      "indicator_count": 3888,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 122,
      "modified_text": "339 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "66ce8795f74ccdc8a4ad972f",
      "name": "Home | Sanselo | Realizare site web \u0219i aplica\u021bii de mobil",
      "description": "Aplica\u021bii mobile, \u00c2\u00a31bn, \u00e2\u201a\u00ac1.5bn \u00e2\u20ac\u00b5\u00a6 \u00c3\u20ac\u201c  \u00f4l iau i'r iddo.",
      "modified": "2025-05-14T21:14:50.899000",
      "created": "2024-08-28T02:12:37.280000",
      "tags": [
        "sanselo",
        "i aplicaii",
        "home",
        "realizare site",
        "servicii web",
        "mobile app",
        "contact blog",
        "selecteaz",
        "pagin",
        "future",
        "adres url",
        "ipv4",
        "ccro asnas39668",
        "intersat srl",
        "rola",
        "url http",
        "odcisk palca"
      ],
      "references": [
        "https://sanselo.com/"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 3,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Arek-BTC",
        "id": "212764",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_212764/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "IPv4": 11,
        "URL": 1533,
        "domain": 150,
        "email": 2,
        "hostname": 471,
        "FileHash-MD5": 236,
        "FileHash-SHA1": 141,
        "FileHash-SHA256": 979,
        "SSLCertFingerprint": 4
      },
      "indicator_count": 3527,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 123,
      "modified_text": "339 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "670d6eddfef3c506b89ceae9",
      "name": "https:://www.fonts.com  correo.fhdux.pl  94.152.58.192 cert: vgt.pl",
      "description": "https://www.criminalip.io/asset/report/94.152.58.192  vgt.pl\nhttps://urlscan.io/result/240096e3-fe4f-46cf-bae4-2ee2f0b278ec/#transactions\nhttps://fonts.gstatic.com/s/roboto/v32/KFOmCnqEu92Fr1Mu4mxK.woff2\n89978e658e840b927dddb5cb3a835c7d8526ece79933bd9f3096b301fe1a8571\n0b5c41fa20267271d30a61a113f707f319398232666304793d7d15d98b9fdb04\n97511dae443d722cdbb59c69a1bd99ccdbb3bf833c2a85acd74f7092fc6a0324\na79dc08d6442545c5bc444feb881b4e9025ad2557a67ea13b3cdc919fadc91c4\nf4602b083181bf931b5ab428a4fe12536309c50de41755ec18d12a39d8f09c52\nfb1a7c9500d4b6a9cedd47fa96b04144e26a5f0325c0f3b52c4362392f710eaf",
      "modified": "2025-05-14T20:46:18.601000",
      "created": "2024-10-14T19:19:57.749000",
      "tags": [
        "subject key",
        "extended key",
        "usage",
        "auth",
        "server auth",
        "certificate",
        "authority",
        "info access",
        "ocsp urls",
        "issuer urls",
        "win32 exe",
        "age flash",
        "player",
        "win32 dll",
        "flash player",
        "dos exe",
        "albert harrill",
        "paul",
        "apostle",
        "life",
        "legacy",
        "dostawa"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1543",
          "name": "Create or Modify System Process",
          "display_name": "T1543 - Create or Modify System Process"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 39,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Arek-BTC",
        "id": "212764",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_212764/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "IPv4": 268,
        "URL": 622,
        "domain": 105,
        "hostname": 294,
        "FileHash-SHA256": 1187,
        "FileHash-MD5": 95,
        "FileHash-SHA1": 76,
        "IPv6": 1,
        "CVE": 8
      },
      "indicator_count": 2656,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 125,
      "modified_text": "339 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6739ed21897f1541c521f712",
      "name": "gen.zip (vgt.pl and adorno.pl)  Ransom_CyberVolk.R002C0DG524",
      "description": "Dane archiwum ZIP, co najmniej v2.0 do wyodr\u0119bnienia, bez przeplotu o'rhywolaethol.",
      "modified": "2025-01-06T23:11:01.995000",
      "created": "2024-11-17T13:18:25.453000",
      "tags": [
        "sha256",
        "javascript z",
        "sha1",
        "imphasz",
        "pejzasz",
        "wirustotal",
        "wykrycia yara",
        "nazwa smyczki",
        "interesujce",
        "whasz",
        "ju sama",
        "a dziki",
        "edgecast w",
        "w przypadku",
        "ciekapliku",
        "filename ma",
        "remoteip",
        "nazwapliku ma",
        "email",
        "zero trust",
        "lub ciekapliku",
        "remoteurl ma",
        "test zgodnoci",
        "szybki start",
        "crlf",
        "dane obrazu",
        "tekst ascii",
        "z terminatorami",
        "rgba",
        "dane archiwum",
        "pe32",
        "intel",
        "ms windows",
        "z bardzo"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 17,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Arek-BTC",
        "id": "212764",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_212764/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 456,
        "URL": 1540,
        "hostname": 504,
        "BitcoinAddress": 1,
        "FileHash-MD5": 149,
        "FileHash-SHA1": 91,
        "domain": 234,
        "IPv4": 94,
        "email": 4
      },
      "indicator_count": 3073,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 122,
      "modified_text": "467 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "675297b9110af13304ed97d6",
      "name": "http://regnator.com/Program/Regnator.exe",
      "description": "D7Eok8kO9fuM6YCmU4O wedi i'w'r gael ei gyn-gwrnod o'i'u gyda'n sgil.",
      "modified": "2025-01-06T23:11:01.995000",
      "created": "2024-12-06T06:20:41.420000",
      "tags": [
        "serial number",
        "certum trusted",
        "network ca",
        "algorithm",
        "trusted network",
        "valid",
        "valid usage",
        "thumbprint",
        "name certum",
        "valid from",
        "whasz",
        "sha256",
        "ssdeep",
        "xml c",
        "pdf c",
        "pliki wzoru",
        "vhash"
      ],
      "references": [
        "http://crd.gov.pl/wzor/2020/11/13/10091/wyroznik.xml",
        "http://crd.gov.pl/wzor/2022/11/09/11890/"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1056",
          "name": "Input Capture",
          "display_name": "T1056 - Input Capture"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 25,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Arek-BTC",
        "id": "212764",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_212764/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 1046,
        "FileHash-MD5": 217,
        "FileHash-SHA1": 191,
        "URL": 202,
        "domain": 39,
        "email": 1,
        "hostname": 212,
        "IPv4": 12
      },
      "indicator_count": 1920,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 122,
      "modified_text": "467 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "670ffc8487aaf80605755b62",
      "name": "vgt.pl (VGT.pl) or plix.pl (plix.net) 104.21.40.140 172.67.186.229",
      "description": "You can get help with your computer problems using the Help and Support section or via Skype or Telegram, if you want to get in touch with the support team or use the help of the UK's TalkTalk service.",
      "modified": "2024-12-30T17:38:55.943000",
      "created": "2024-10-16T17:48:52.704000",
      "tags": [
        "pe32",
        "intel",
        "ms windows",
        "plik",
        "trojandropper",
        "trojan",
        "win32",
        "msil",
        "sha1",
        "sha256",
        "imphasz",
        "tekst ascii",
        "dane obrazu",
        "crlf",
        "dokument html",
        "unicode",
        "z bom",
        "rgba",
        "z terminatorami",
        "z bardzo",
        "utf8 unicode",
        "sobota",
        "sie usertrust",
        "salford o",
        "comodo ca",
        "limited st",
        "salt lake",
        "city o",
        "wto cze",
        "worldsetup c",
        "il l",
        "error",
        "null",
        "mapa",
        "liczba",
        "string",
        "bigint",
        "obiekt",
        "prawa autorskie",
        "nieznanybd",
        "uint8array",
        "android",
        "void",
        "unknown",
        "false",
        "roboto",
        "body",
        "this",
        "infinity",
        "outside",
        "span",
        "as13335",
        "cloudflare",
        "datasheet",
        "arkusz",
        "wyszukiwarka",
        "control panel",
        "support",
        "email",
        "a letter",
        "help",
        "mail",
        "management",
        "jpeg",
        "jfif",
        "dane",
        "dpcm",
        "ascii z",
        "dane archiwalne",
        "windows"
      ],
      "references": [
        "https://www.plix.pl/system/companies/logos/000/000/526/original/gigainternet-logo.png",
        "http://plix.net",
        "http://www.plix.net",
        "https://www.plix.pl",
        "http://www.plix.pl"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1218",
          "name": "Signed Binary Proxy Execution",
          "display_name": "T1218 - Signed Binary Proxy Execution"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 291,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Arek-BTC",
        "id": "212764",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_212764/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 516,
        "hostname": 705,
        "URL": 1831,
        "FileHash-SHA256": 3315,
        "CIDR": 4,
        "IPv6": 4,
        "IPv4": 49,
        "FileHash-MD5": 794,
        "FileHash-SHA1": 572,
        "email": 1,
        "CVE": 14
      },
      "indicator_count": 7805,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 127,
      "modified_text": "474 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "670b8e607683fbb3b8b484a5",
      "name": "Font Finder \ud83d\udd0e by What Font Is",
      "description": "What Font Is - the best font finder tool in the world - is here to help you find the right font from any image, or to find out where you can download or buy it.",
      "modified": "2024-12-17T14:35:45.139000",
      "created": "2024-10-13T09:09:52.039000",
      "tags": [
        "vhash htm",
        "ssdeep",
        "anchor hrefs",
        "sans",
        "woff2",
        "fontface",
        "u0329",
        "u25cc",
        "u2190",
        "u2192",
        "u0304",
        "u0308",
        "u1c801c88",
        "woff",
        "u03080309",
        "u0323",
        "u1ea01ef9",
        "u20ab",
        "fontawesome",
        "etmodules",
        "oszczdno",
        "font",
        "find",
        "whatfontis",
        "sign",
        "font finder",
        "sign up",
        "free",
        "upload",
        "drop",
        "different",
        "enjoy",
        "first",
        "accept",
        "close",
        "generator",
        "cookie",
        "contact",
        "html",
        "dokument office",
        "open xml",
        "rar theme",
        "win32 exe",
        "office open",
        "xml document",
        "text",
        "javascript",
        "query language",
        "ms word",
        "web design",
        "biblioteka dll",
        "win32",
        "anna"
      ],
      "references": [
        "http://www.whatfontis.com",
        "https://fonts.googleapis.com/css?family=Barlow+Condensed:100,100italic,200,200italic,300,300italic,regular,italic,500,500italic,600,600italic,700,700italic,800,800italic,900,900italic|Archivo:100,200,300,regular,500,600,700,800,900,100italic,200italic,300italic,italic,500italic,600italic,700italic,800italic,900italic&subset=latin,latin-ext&display=swap",
        "https://fonts.googleapis.com/css?family=Open+Sans:300italic,400italic,600italic,700italic,800italic,400,300,600,700,800&subset=latin,latin-ext&display=swap"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1543",
          "name": "Create or Modify System Process",
          "display_name": "T1543 - Create or Modify System Process"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 25,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Arek-BTC",
        "id": "212764",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_212764/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 455,
        "FileHash-SHA256": 292,
        "FileHash-MD5": 74,
        "FileHash-SHA1": 69,
        "hostname": 163,
        "domain": 30,
        "IPv4": 6,
        "CVE": 3
      },
      "indicator_count": 1092,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 123,
      "modified_text": "487 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "66e99ca508b46127bd4d552a",
      "name": "94.152.58.192",
      "description": "Researchers have developed a new way of storing data on a computer that can be stored in a secure secure system, as well as a network of secure networks, for use in Syria, Iraq and Iran.",
      "modified": "2024-12-17T14:35:39.173000",
      "created": "2024-09-17T15:13:41.714000",
      "tags": [
        "rticon serbian",
        "arabic libya",
        "vhash",
        "authentihash",
        "ssdeep",
        "ico rtgroupicon",
        "serbian arabic",
        "libya",
        "userprofile",
        "peexe c",
        "peexe",
        "user",
        "text c",
        "number",
        "ja3s",
        "win32 exe",
        "plik",
        "data rozwizania",
        "domena",
        "typ nazwa",
        "y0yxxhpr",
        "win32",
        "zawarte",
        "whasz",
        "oszczdno",
        "typ pliku",
        "biblioteka dll",
        "magia plik",
        "pe32 dla",
        "ms windows",
        "intel",
        "historical ssl",
        "whois"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1056",
          "name": "Input Capture",
          "display_name": "T1056 - Input Capture"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 4,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Arek-BTC",
        "id": "212764",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_212764/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 2136,
        "domain": 6110,
        "URL": 6946,
        "hostname": 6003,
        "IPv4": 85,
        "FileHash-MD5": 406,
        "FileHash-SHA1": 402,
        "CVE": 2
      },
      "indicator_count": 22090,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 127,
      "modified_text": "487 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "https://pulsedive.com/indicator",
    "type": "URL"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "https://pulsedive.com/indicator",
    "type": "URL",
    "found": false,
    "verdict": "clean",
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1776596648.9171154
}