{
  "type": "URL",
  "indicator": "https://ra.prototype.compare",
  "general": {
    "sections": [
      "general",
      "url_list",
      "http_scans",
      "screenshot"
    ],
    "indicator": "https://ra.prototype.compare",
    "type": "url",
    "type_title": "URL",
    "validation": [],
    "base_indicator": {
      "id": 3279441553,
      "indicator": "https://ra.prototype.compare",
      "type": "URL",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 14,
      "pulses": [
        {
          "id": "698904c316bc7710b967d01d",
          "name": "Rare Tier 1 Persistence - Critical \"Patched\", Non Patched Vulnerabilities Remain bypassing Lockdown Mode",
          "description": "Researcher Note (Feb 08, 2026):\nThis artifact represents a sophisticated Cross-Protocol Mesh. Observations confirm that the Cymt/Nemucod wrapper is being utilized as a delivery vehicle for a Firmware-resident ELF binary (Mirai variant).\nThe persistence is notable for its ability to survive Full DFU Restores and Faraday-isolated states, likely due to JTAG-level interaction with the Power Management IC (Chip 4799). This is not a standard opportunistic infection; it is a targeted provisioning event leveraging IDMSA (Identity Management) bridges and Verizon/Akamai Edge infrastructure.\nThe integration with CalendarKit and Maps for geofenced execution suggests a highly coordinated surveillance objective. Forensic analysts should pay specific attention to the sizeofrawdata_antidbg anomalies, which indicate a focus on bypassing Apple Lockdown Mode and Secure Enclave. \nresearcher credit: msudoSOS",
          "modified": "2026-03-27T09:05:26.285000",
          "created": "2026-02-08T21:48:49.147000",
          "tags": [
            "#supportsitewebsiteabuse #rootcertificatefailure #cryptographicf"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 909,
            "URL": 1779,
            "CVE": 126,
            "domain": 659,
            "email": 23,
            "JA3": 1,
            "FileHash-MD5": 230,
            "FileHash-SHA1": 227,
            "FileHash-SHA256": 934,
            "CIDR": 13
          },
          "indicator_count": 4901,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 54,
          "modified_text": "23 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "65708dff34f37412488dda2a",
          "name": "Digital Ocean",
          "description": "",
          "modified": "2023-12-06T15:06:38.991000",
          "created": "2023-12-06T15:06:38.991000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "CVE": 1,
            "FileHash-SHA256": 703,
            "domain": 734,
            "URL": 5116,
            "hostname": 1266,
            "email": 3
          },
          "indicator_count": 7823,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "865 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "65708c37c54dd9e78f85c0fa",
          "name": "\u7ea2\u674f\u89c6\u9891 malware",
          "description": "",
          "modified": "2023-12-06T14:59:03.859000",
          "created": "2023-12-06T14:59:03.859000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 4,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 1686,
            "hostname": 2218,
            "URL": 5740,
            "domain": 901,
            "FileHash-MD5": 3
          },
          "indicator_count": 10548,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "865 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "65708c0f5981b6d81d0fa423",
          "name": "data102 and colohouse. Malware hosting",
          "description": "",
          "modified": "2023-12-06T14:58:23.206000",
          "created": "2023-12-06T14:58:23.206000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 458,
            "domain": 557,
            "URL": 2599,
            "hostname": 952
          },
          "indicator_count": 4566,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "865 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "65707fe17dfdfe16066d16de",
          "name": "Bexar.org",
          "description": "",
          "modified": "2023-12-06T14:06:25.800000",
          "created": "2023-12-06T14:06:25.800000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 1735,
            "hostname": 1833,
            "domain": 1025,
            "URL": 4668,
            "email": 4,
            "FileHash-MD5": 133,
            "FileHash-SHA1": 6,
            "CIDR": 5
          },
          "indicator_count": 9409,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 110,
          "modified_text": "865 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "65707e5b7df6f60133e8fb50",
          "name": "Jeeng / Powerbox",
          "description": "",
          "modified": "2023-12-06T13:59:55.129000",
          "created": "2023-12-06T13:59:55.129000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "CVE": 3,
            "FileHash-SHA256": 9072,
            "domain": 2500,
            "hostname": 3584,
            "URL": 13548,
            "FileHash-MD5": 197,
            "FileHash-SHA1": 162,
            "email": 19,
            "CIDR": 20,
            "SSLCertFingerprint": 2,
            "BitcoinAddress": 1
          },
          "indicator_count": 29108,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "865 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "627fe16ae54614d3d59de881",
          "name": "Digital Ocean",
          "description": "\u2026",
          "modified": "2022-06-13T00:00:32.864000",
          "created": "2022-05-14T17:05:46.360000",
          "tags": [
            "min",
            "qe",
            "photostatus",
            "hero stripe",
            "object",
            "boolean",
            "license",
            "urlsearchparams",
            "typeof t",
            "events",
            "pattrick hper",
            "bsd3clause",
            "typeerror",
            "react",
            "date",
            "error",
            "this",
            "flex",
            "open",
            "facebook",
            "close",
            "february",
            "april",
            "june",
            "august",
            "dead",
            "frozen",
            "blank",
            "null",
            "mutation",
            "roboto",
            "4096",
            "unknown",
            "clock",
            "period",
            "footer",
            "android",
            "service",
            "invisible",
            "sphinx",
            "checkbox",
            "click",
            "typeof e",
            "referenceerror",
            "typeof symbol",
            "router",
            "function",
            "intl",
            "push",
            "body",
            "meta",
            "string",
            "url path",
            "url object",
            "full",
            "url api",
            "nativeurl",
            "searchparams",
            "copyright",
            "closure library",
            "includes code",
            "regexp",
            "html",
            "plugindetect",
            "jeff mott",
            "quicktime",
            "flash shockwave",
            "vlc adobereader",
            "span",
            "or conditions",
            "post",
            "array",
            "apache license",
            "version",
            "this code",
            "is provided",
            "on an",
            "ud83d",
            "ud83e",
            "u2695u2696u2708",
            "udc66udc67",
            "udc68udc69",
            "ud83c",
            "dfunction",
            "typeof u",
            "u2640u2642",
            "9000",
            "typeof r",
            "weakmap",
            "asyncfunction",
            "proxy",
            "customevent",
            "uint8array",
            "09af",
            "ver0",
            "tag0",
            "extdata0",
            "ua ch",
            "window",
            "documentcookie",
            "typeof self",
            "blob",
            "promise",
            "reduceright",
            "number",
            "l420",
            "gnp82xmkw0p",
            "json",
            "void",
            "public",
            "github",
            "meetup",
            "swarm",
            "jump",
            "sign",
            "releases",
            "packages",
            "contributors",
            "topics",
            "star",
            "contact",
            "code",
            "stars"
          ],
          "references": [
            "xfe-URL-Meetup.com_pro_digitalocean_-stix2-2.1-export.json",
            "https://github.com/meetup/swarm-ui",
            "https://www.googletagmanager.com/gtag/js?id=G-NP82XMKW0P&l=dataLayer&cx=c",
            "https://www.meetup.com/proxydirectory/tags/239562121304/tag.js",
            "https://www.meetup.com/pro_static/en-US/0.f2cf4c3f.js",
            "https://dna8twue3dlxq.cloudfront.net/js/profitwell.js",
            "https://cdn.sift.com/s.js",
            "https://googleads.g.doubleclick.net/pagead/viewthroughconversion/922061185/?random=1652546907471&cv=9&fst=1652546907471&num=1&label=BaPJCIf2_WYQgZPWtwM&bg=ffffff&guid=ON&resp=GooglemKTybQhCsO&u_h=844&u_w=390&u_ah=844&u_aw=390&u_cd=32&u_his=2&u_tz=-240&u_java=false&u_nplug=0&u_nmime=0&gtm=2wg5b0&sendb=1&ig=1&frm=0&url=https%3A%2F%2Fwww.meetup.com%2FDigitalOceanMoscow%2F&ref=https%3A%2F%2Fwww.meetup.com%2Fpro%2Fdigitalocean%2F&tiba=DigitalOcean%20Moscow%20(Moscow%2C%20Russia)%20%7C%20Meetup&hn=www.googleadser",
            "https://cdn.polyfill.io/v2/polyfill.min.js?features=default-3.6,fetch,Intl,Intl.~locale.en-US,Array.prototype.find,Array.prototype.includes,Object.values&flags=gated",
            "https://www.meetup.com/mu_static/react.ddd38c26.js",
            "https://www.meetup.com/mu_static/en-US/app.0ff22766.js",
            "xfe-URL-Sift.com-stix2-2.1-export.json"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "MIN",
              "display_name": "MIN",
              "target": null
            },
            {
              "id": "PhotoStatus",
              "display_name": "PhotoStatus",
              "target": null
            },
            {
              "id": "Qe",
              "display_name": "Qe",
              "target": null
            },
            {
              "id": "Hero Stripe",
              "display_name": "Hero Stripe",
              "target": null
            },
            {
              "id": "DocumentCookie",
              "display_name": "DocumentCookie",
              "target": null
            },
            {
              "id": "ReduceRight",
              "display_name": "ReduceRight",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1110",
              "name": "Brute Force",
              "display_name": "T1110 - Brute Force"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 10,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "adjadex1@gmail.com",
            "id": "187163",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 1266,
            "URL": 5116,
            "domain": 734,
            "FileHash-SHA256": 703,
            "CVE": 1,
            "email": 3
          },
          "indicator_count": 7823,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 72,
          "modified_text": "1406 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "620c3b1f8af7ea0dcf2c1218",
          "name": "Jeeng / Powerbox",
          "description": "",
          "modified": "2022-06-12T22:01:23.105000",
          "created": "2022-02-15T23:45:35.234000",
          "tags": [
            "Jeeng",
            "tim pool",
            "timcast"
          ],
          "references": [
            "cf20ed53-cb6d-4dfd-a4e8-794fbe163efc.pcap"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 10,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scnrscnr",
            "id": "126475",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_126475/resized/80/avatar_67ca5b7bae.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 9072,
            "domain": 2500,
            "URL": 13548,
            "hostname": 3584,
            "FileHash-MD5": 197,
            "FileHash-SHA1": 162,
            "CVE": 3,
            "CIDR": 20,
            "SSLCertFingerprint": 2,
            "email": 19,
            "BitcoinAddress": 1
          },
          "indicator_count": 29108,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 97,
          "modified_text": "1406 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "62606584633e2b9a3bc935b9",
          "name": "\u7ea2\u674f\u89c6\u9891 malware",
          "description": "function s(t,e), o, is a new type of function, which throws new TypeError when it comes to trying to make a function out of its own language or its form.",
          "modified": "2022-05-20T00:01:19.453000",
          "created": "2022-04-20T19:56:52.162000",
          "tags": [
            "typeof t",
            "typeof define",
            "moztransform",
            "success",
            "error",
            "make sure",
            "stop",
            "ajax",
            "action",
            "click",
            "open",
            "active",
            "button",
            "toggle btn",
            "body",
            "scroll",
            "isotope",
            "preloader",
            "function",
            "javascript",
            "mit license",
            "typeof module",
            "gplv3",
            "license",
            "copyright",
            "metafizzy",
            "math",
            "typeof",
            "typeerror",
            "hidden",
            "show",
            "typeof n",
            "version",
            "hide",
            "focusin",
            "focusout",
            "shown",
            "startr",
            "endr",
            "federico zivolo",
            "distributed",
            "html",
            "statict",
            "flip",
            "regexp",
            "null",
            "void",
            "width",
            "object",
            "pseudo",
            "child",
            "class",
            "date",
            "accept",
            "webpackrequire",
            "name",
            "number",
            "arraybuffer",
            "iterator",
            "typedarray",
            "prototype",
            "string",
            "index",
            "meta",
            "target",
            "infinity",
            "zero",
            "epsilon",
            "observer",
            "android",
            "trim",
            "enumerate",
            "freeze",
            "internal",
            "bind",
            "window",
            "next",
            "find",
            "this",
            "rest",
            "middle",
            "canvas",
            "slidercaptcha",
            "createelement",
            "textdanger",
            "plugin",
            "rgba",
            "imagedata",
            "false",
            "touchstart",
            "trident",
            "applewebkit",
            "safari",
            "base",
            "presto",
            "gecko",
            "khtml",
            "micromessenger",
            "typeof e",
            "swiper",
            "most",
            "september",
            "customevent",
            "image",
            "typeof c",
            "twitter",
            "bootstrap",
            "rolemenu",
            "typeof f",
            "typeof g",
            "cookie plugin",
            "https",
            "klaus hartl",
            "register",
            "nodecommonjs",
            "factory",
            "jquery",
            "write",
            "typeof b",
            "array",
            "sufeffxa0",
            "attr",
            "\u706b\u7bad\u5185\u6d4b\u7b7e\u540d",
            "0x1d9131",
            "0x180bcc",
            "0x4b6177",
            "0x13f349",
            "0x3bcb54",
            "0xbbe80d",
            "0x57b7de",
            "0x2ea74e",
            "0x4fb0f2",
            "0x25f113",
            "push",
            "shift",
            "tencent",
            "barrio",
            "slice",
            "symbol",
            "typeof window",
            "maximum",
            "typeof symbol",
            "udc66udc67",
            "ud83d",
            "ufe0f",
            "ud83e",
            "udc68udc69",
            "udfcbudfcc",
            "u2640u2642",
            "ufe0fg",
            "ud83dudc6cud83c",
            "ud83dudc6dud83c",
            "welcome",
            "datav66d78640",
            "datav2f8052f5",
            "90deg",
            "datav5f1e575c",
            "datave97d7462",
            "helvetica neue",
            "helvetica",
            "10px",
            "pingfang sc",
            "arial",
            "45deg",
            "typenumber",
            "opacity0",
            "mozopacity0",
            "khtmlopacity0",
            "opacity100",
            "event",
            "boolean",
            "uint8array",
            "errordetails",
            "info",
            "checker",
            "generator",
            "blink",
            "keepalive",
            "4096",
            "unknown",
            "meteor",
            "rhino",
            "mini",
            "comment",
            "verify",
            "yeke",
            "codec",
            "media",
            "live",
            "speed",
            "headname",
            "axiostimeout",
            "apiurl",
            "bmi86hjtsk",
            "root",
            "length",
            "indexof",
            "x0ax20x20x20x20",
            "location",
            "0x10",
            "0x18",
            "history",
            "config",
            "cookie",
            "onload",
            "video",
            "afunction",
            "indexnotice",
            "sitehome",
            "x20trnf",
            "please",
            "strong"
          ],
          "references": [
            "xfe-URL-sys95.com-stix2-2.1-export.json",
            "https://2001.habyc.com/?channelNo=2001#/home",
            "https://sdk.51.la/event/js-sdk-event.min.js?u=JdoUNv3VSW0GHUpw",
            "https://2001.habyc.com/static/js/chunk-7d5d3bac.efb700c7.js",
            "https://sdk.51.la/js-sdk-pro.min.js",
            "https://2001.habyc.com/js/config.js",
            "xfe-URL-2001.habyc.com-stix2-2.1-export.json",
            "https://2001.habyc.com/static/js/chunk-vendors.9d7684f4.js",
            "xfe-URL-habyc.com-stix2-2.1-export.json",
            "https://2001.habyc.com/static/css/chunk-vendors.6a41b67e.css",
            "https://2001.habyc.com/static/css/app.88afcfd8.css",
            "https://2001.habyc.com/static/css/chunk-7d5d3bac.e1a32335.css",
            "https://2001.dwlww.com/?channelNo=2001#/home",
            "https://2001.dwlww.com/static/js/chunk-7d5d3bac.efb700c7.js",
            "https://2001.dwlww.com/js/config.js",
            "https://2001.dwlww.com/static/js/chunk-vendors.9d7684f4.js",
            "https://2001.dwlww.com/static/js/app.9d5d18d7.js",
            "https://2001.dwlww.com/static/css/chunk-vendors.6a41b67e.css",
            "https://2001.dwlww.com/static/css/app.88afcfd8.css",
            "https://2001.dwlww.com/static/css/chunk-7d5d3bac.e1a32335.css",
            "https://www.tidio.com/talk/kv6vcosd7tmhsetmarsoawzaglejnny4",
            "https://chatting.page/kv6vcosd7tmhsetmarsoawzaglejnny4",
            "https://widget-v4.tidiochat.com/code/kv6vcosd7tmhsetmarsoawzaglejnny4.js",
            "https://m4244.com:35003/",
            "https://www.8098.app:21568/?agent=7691755704",
            "https://www.8098.app:21568/js/jquery-1.11.3.min.js",
            "https://www.8098.app:21568/js/xinstall_inner_e.min.js?v=1004",
            "https://app.ynsdty.cn//package/GmCC6WISh",
            "https://app.ynsdty.cn/dist/js/jquery.min.js",
            "https://app.ynsdty.cn/dist/js/jquery.cookie.js",
            "https://app.ynsdty.cn/dist/vendors/bootstrap/js/bootstrap.min.js",
            "https://app.ynsdty.cn/dist/vendors/swiper/swiper.min.js",
            "https://app.ynsdty.cn/dist/js/app.base.js",
            "https://app.ynsdty.cn/dist/js/longbow.slidercaptcha.js",
            "https://app.ynsdty.cn/dist/vendors/core-js/core.js",
            "xfe-URL-sun.net.hk-stix2-2.1-export.json",
            "https://www.sunnetwork.com.sg/sun_21/js/vendor/jquery-3.5.0.min.js",
            "https://www.sunnetwork.com.sg/sun_21/js/popper.min.js",
            "https://www.sunnetwork.com.sg/sun_21/js/bootstrap.min.js",
            "https://www.sunnetwork.com.sg/sun_21/js/isotope.pkgd.min.js",
            "https://www.sunnetwork.com.sg/sun_21/js/imagesloaded.pkgd.min.js",
            "https://www.sunnetwork.com.sg/sun_21/js/main.js",
            "https://www.sunnetwork.com.sg/sun_21/js/ajax-form.js",
            "https://www.sunnetwork.com.sg/sun_21/js/slick.min.js"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 8,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "adjadex1@gmail.com",
            "id": "187163",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 901,
            "URL": 5740,
            "hostname": 2218,
            "FileHash-SHA256": 1686,
            "FileHash-MD5": 3
          },
          "indicator_count": 10548,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 69,
          "modified_text": "1430 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "625f3287d722d8d85700b75d",
          "name": "Leaseweb.com - malware hosting",
          "description": "function D(t,e,n), as well as window.com, has been frozen by a single function, as part of a series of \"snoopers' checks\"...",
          "modified": "2022-05-19T00:00:49.028000",
          "created": "2022-04-19T22:07:03.024000",
          "tags": [
            "11px center",
            "html",
            "typetext",
            "typeurl",
            "typeemail",
            "typetel",
            "typenumber",
            "typedate",
            "color",
            "marketo forms",
            "cross domain",
            "null",
            "click",
            "forceclose",
            "lightbox",
            "slideshow",
            "controls",
            "hide",
            "safari",
            "image",
            "mozilla",
            "explorer",
            "entity",
            "linear",
            "date",
            "jquery",
            "iframe",
            "close",
            "loops",
            "class",
            "stretch",
            "false",
            "function",
            "abbb",
            "typeerror",
            "boolean",
            "body",
            "object",
            "array",
            "regexp",
            "bind",
            "error",
            "void",
            "hammer",
            "form",
            "this",
            "views slideshow",
            "zindex1",
            "ajax",
            "href",
            "default",
            "thumb",
            "msgesture",
            "mspointerdown",
            "next",
            "stop",
            "type",
            "index",
            "event",
            "snapabugcbmbtn",
            "chat",
            "hidden",
            "leaf",
            "open",
            "dump",
            "window",
            "win32",
            "footer",
            "front",
            "drupal",
            "command",
            "implement",
            "copyright",
            "route",
            "foundation",
            "thecookie",
            "remove",
            "example",
            "backport",
            "grab",
            "span",
            "import",
            "attr",
            "string",
            "invalid json",
            "domparser",
            "number",
            "script",
            "closure library",
            "symbol",
            "array int8array",
            "caregexp",
            "legacy",
            "boardman",
            "fontface",
            "typeof d",
            "promise",
            "parseint",
            "marketo",
            "rangeerror",
            "uint8array",
            "typeof b",
            "buffer",
            "path",
            "takk",
            "kiitos",
            "buttons};kb(convertedmessage);break;case\"/sys\":var",
            "acum",
            "ufunction",
            "ffunction",
            "gfunction",
            "mchtd",
            "cancel",
            "thank",
            "enter",
            "please",
            "cobrowsing",
            "accept",
            "decline",
            "back",
            "comment",
            "grazie",
            "klik",
            "super",
            "dados",
            "hello",
            "vd",
            "reduceright",
            "trackevent",
            "lead",
            "query",
            "videos",
            "leaseweb",
            "trackpageview",
            "contact",
            "download",
            "metal",
            "code",
            "functional",
            "member",
            "hnew regexp",
            "qfunction",
            "adview",
            "addbillinginfo",
            "addtocart",
            "addtolist",
            "install",
            "cookiebot",
            "iabv2",
            "jsonversion",
            "cookie script",
            "methodstrict",
            "ticket",
            "id attribute",
            "cookiebot setup",
            "cookieconsent",
            "customevent",
            "09af",
            "ver0",
            "tag0",
            "extdata0",
            "ua ch",
            "invalid",
            "iterator",
            "service",
            "phonenumber",
            "facebook",
            "meta",
            "ytconfig",
            "edge",
            "swhealthlog",
            "logsdatabasev2",
            "trident",
            "android",
            "infinity",
            "pnull",
            "style",
            "ctnull",
            "post",
            "uint32array",
            "fanull",
            "license",
            "ynull",
            "config"
          ],
          "references": [
            "https://consent.cookiebot.com/1e27dadb-e278-4c02-aa4f-43f9222c4fbb/cc.js?renew=false&referer=www.leaseweb.com&culture=en&dnt=false",
            "https://j.clarity.ms/s/0.6.34/clarity.js",
            "https://www.google-analytics.com/plugins/ua/linkid.js",
            "https://www.youtube.com/s/player/19eb72e4/www-widgetapi.vflset/www-widgetapi.js",
            "https://www.youtube.com/iframe_api",
            "https://connect.facebook.net/signals/config/399164440484826?v=2.9.57&r=stable",
            "https://bat.bing.com/bat.js",
            "https://consent.cookiebot.com/uc.js?cbid=1e27dadb-e278-4c02-aa4f-43f9222c4fbb&culture=en",
            "https://snap.licdn.com/li.lms-analytics/insight.min.js",
            "https://www.googletagmanager.com/gtm.js?id=GTM-NWPHSS",
            "https://storage.googleapis.com/snapengage-eu/js/e9219576-8f74-40b5-8b6f-bbad33f6ca57.js",
            "https://munchkin.marketo.net/161/munchkin.js",
            "https://app-lon04.marketo.com/js/forms2/js/forms2.min.js",
            "https://munchkin.marketo.net/munchkin.js",
            "https://www.leaseweb.com/sites/all/modules/custom/lsw_marketo/js/lsw_marketo_forms.js",
            "https://use.fortawesome.com/03018d9d.js",
            "https://googleads.g.doubleclick.net/pagead/viewthroughconversion/1001847692/?random=1650405011980&cv=9&fst=1650405011980&num=1&bg=ffffff&guid=ON&resp=GooglemKTybQhCsO&eid=376635471&u_h=844&u_w=390&u_ah=844&u_aw=390&u_cd=32&u_his=1&u_tz=-240&u_java=false&u_nplug=0&u_nmime=0&gtm=2wg4i1&sendb=1&ig=1&frm=0&url=https%3A%2F%2Fwww.leaseweb.com%2F&tiba=Leaseweb%20%7C%20Global%20Hosted%20Infrastructure%20(IaaS)%20and%20Cloud%20Solutions&hn=www.googleadservices.com&async=1&rfmt=3&fmt=4",
            "https://googleads.g.doubleclick.net/pagead/viewthroughconversion/952389962/?random=1650405011982&cv=9&fst=1650405011982&num=1&bg=ffffff&guid=ON&resp=GooglemKTybQhCsO&eid=376635471&u_h=844&u_w=390&u_ah=844&u_aw=390&u_cd=32&u_his=1&u_tz=-240&u_java=false&u_nplug=0&u_nmime=0&gtm=2wg4i1&sendb=1&ig=1&frm=0&url=https%3A%2F%2Fwww.leaseweb.com%2F&tiba=Leaseweb%20%7C%20Global%20Hosted%20Infrastructure%20(IaaS)%20and%20Cloud%20Solutions&hn=www.googleadservices.com&async=1&rfmt=3&fmt=4",
            "https://eu.snapengage.com/chatjs/ServiceGetConfig?w=e9219576-8f74-40b5-8b6f-bbad33f6ca57",
            "https://eu.snapengage.com/chatjs/servicegetproactivegeodata?w=e9219576-8f74-40b5-8b6f-bbad33f6ca57",
            "https://bat.bing.com/p/action/5602105.js",
            "https://eu.snapengage.com/chatjs/servicegetallavailableagents?w=e9219576-8f74-40b5-8b6f-bbad33f6ca57&t=1",
            "https://www.googleadservices.com/pagead/conversion_async.js",
            "https://www.leaseweb.com/sites/default/files/js/js_kwxcSFD2Y0_BPtdJClYUy5H8THI_5EycUmIgIGWaGYs.js",
            "https://www.leaseweb.com/sites/default/files/js/js_wcSNEXVJ4Xjhkf8qhMguEPZJTDTMNmPaJM-YWdAOhQE.js",
            "https://www.leaseweb.com/sites/default/files/js/js_kI_QwKJlaBz9CzQdENdUBFiEl4aehfjf4_-9taiwcCE.js",
            "https://www.leaseweb.com/sites/default/files/js/js_zoLA7TweXam0kYiqJrXepqBWmyDoP1sLSlHoZcveFnY.js",
            "https://www.leaseweb.com/sites/default/files/js/js_6FowaFXT9bT78hf9earPdGcdTmvsFiaBzKgFl9P4fSo.js",
            "https://www.leaseweb.com/sites/default/files/js/js_6lTJ_m6ahwXas7Efbw8ZYEMSaecrGw8ilNALfvIPNUw.js",
            "https://analytics.twitter.com/i/adsct?type=javascript&version=2.0.4&p_id=Twitter&p_user_id=0&txn_id=nxsfu&events=%5B%5B%22pageview%22%2Cnull%5D%5D&tw_sale_amount=0&tw_order_quantity=0&tw_iframe_status=0&event_id=511b6f48-2639-478c-a251-b09fcbae76e7&tw_document_href=https%3A%2F%2Fwww.leaseweb.com%2F&tpx_cb=twttr.conversion.loadPixels",
            "https://bid.g.doubleclick.net/xbbe/pixel?d=KAE",
            "https://consentcdn.cookiebot.com/sdk/bc-v4.min.html",
            "https://app-lon04.marketo.com/index.php/form/XDFrame",
            "https://app-lon04.marketo.com/js/forms2/css/forms2-theme-plain.css",
            "https://www.leaseweb.com/sites/default/files/css/css_47DEQpj8HBSa-_TImW-5JCeuQeRkm5NMpJWZG3hSuFU.css",
            "https://www.leaseweb.com/sites/default/files/css/css_7CYF9En6DNp6AojfSKnT8USKR3GvzPwznmTqLTKT9VM.css"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "Tunisia"
          ],
          "malware_families": [
            {
              "id": "Ajax",
              "display_name": "Ajax",
              "target": null
            },
            {
              "id": "Kiitos",
              "display_name": "Kiitos",
              "target": null
            },
            {
              "id": "Takk",
              "display_name": "Takk",
              "target": null
            },
            {
              "id": "Acum",
              "display_name": "Acum",
              "target": null
            },
            {
              "id": "buttons};kb(convertedMessage);break;case\"/SYS\":var",
              "display_name": "buttons};kb(convertedMessage);break;case\"/SYS\":var",
              "target": null
            },
            {
              "id": "Vd",
              "display_name": "Vd",
              "target": null
            },
            {
              "id": "ReduceRight",
              "display_name": "ReduceRight",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1056",
              "name": "Input Capture",
              "display_name": "T1056 - Input Capture"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1176",
              "name": "Browser Extensions",
              "display_name": "T1176 - Browser Extensions"
            },
            {
              "id": "T1490",
              "name": "Inhibit System Recovery",
              "display_name": "T1490 - Inhibit System Recovery"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 4,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "adjadex1@gmail.com",
            "id": "187163",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 648,
            "domain": 469,
            "URL": 2037,
            "FileHash-SHA256": 705,
            "email": 7
          },
          "indicator_count": 3866,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 68,
          "modified_text": "1431 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "625f42dcc369f59f6a1e8b58",
          "name": "data102 and colohouse. Malware hosting",
          "description": "var a,b,c,d, f.substr(d),a=f, a.href, and a number of other elements:a.b.search.com.",
          "modified": "2022-05-19T00:00:49.028000",
          "created": "2022-04-19T23:16:44.418000",
          "tags": [
            "regexp",
            "rangeerror",
            "typeerror",
            "date",
            "array",
            "error",
            "this",
            "uint8array",
            "typeof b",
            "buffer",
            "class",
            "null",
            "path",
            "void",
            "marketo forms",
            "cross domain",
            "typetext",
            "typeurl",
            "typeemail",
            "typetel",
            "typenumber",
            "typedate",
            "color",
            "label",
            "input",
            "typerange",
            "typecheckbox",
            "woff2",
            "fontface",
            "u1c801c88",
            "u20b4",
            "u2de02dff",
            "ua640a69f",
            "ufe2efe2f",
            "u04b004b1",
            "u2116",
            "u1ea01ef9",
            "franklin",
            "woff",
            "u20ab",
            "u0259",
            "u1e001eff",
            "u2020",
            "u20a020ab",
            "u20ad20cf",
            "gradienttype0",
            "webkitkeyframes",
            "span",
            "button",
            "tbody",
            "textarea",
            "helvetica neue",
            "tfoot",
            "body",
            "alpha",
            "twitter",
            "roboto",
            "pitch",
            "datasecret",
            "q1kg",
            "q17g",
            "d2dg",
            "c d3r",
            "q171zg",
            "e c2ttttb",
            "c g7",
            "6n184z",
            "6f6g",
            "typeof",
            "wpcf7redirect",
            "cf7mlscurrentfs",
            "handle fire",
            "popuptemplate",
            "templatename",
            "click",
            "fieldset",
            "cf7mlsbackfs",
            "section",
            "classwidget",
            "idmenu",
            "idfooter",
            "idwidget",
            "idcomment",
            "classmenu",
            "classfooter",
            "classcomment",
            "target",
            "blank",
            "typeof e",
            "formdata",
            "typeof symbol",
            "customevent",
            "post",
            "refill",
            "wpcf7",
            "wpcf7locale",
            "wpcf7unittag",
            "typeof wpcf7",
            "boolean",
            "modernizr",
            "custom build",
            "build",
            "afunction",
            "cfunction",
            "object",
            "documenttouch",
            "websocket",
            "symbol",
            "generator",
            "function",
            "select",
            "harvest",
            "mit license",
            "optgroup",
            "nnn n",
            "n nnnn",
            "explorer",
            "options",
            "abbr",
            "element",
            "unknownerror",
            "overquerylimit",
            "requestdenied",
            "zeroresults",
            "node",
            "edge",
            "android",
            "trident",
            "unknown",
            "false",
            "iframe",
            "marker",
            "hybrid",
            "tawkspinner",
            "failed",
            "resend",
            "tawkavatar",
            "tawkvideo",
            "tawkalert",
            "tawkemoji",
            "tawkicon",
            "enter",
            "number",
            "startchatbutton",
            "u26a1",
            "typeof t",
            "invalid attempt",
            "copyright",
            "marketo",
            "remove",
            "commentform",
            "author",
            "mouseenter",
            "secure",
            "ccpa",
            "bottom",
            "fixed",
            "widget",
            "embed",
            "trigger",
            "antispam",
            "please",
            "cleantalk",
            "typeof o",
            "ajaxnonce",
            "unkown",
            "apbctajaxerror",
            "typeof define",
            "typeof module",
            "html tags",
            "ox20trnf",
            "dom element",
            "attr",
            "pseudo",
            "child",
            "udc66udc67",
            "ud83d",
            "ufe0f",
            "ud83e",
            "udc68udc69",
            "udfcbudfcc",
            "u2640u2642",
            "source",
            "image",
            "ud83dudc6cud83c",
            "qe",
            "string",
            "xhfunction",
            "yhfunction",
            "gtmptxlxz4",
            "host",
            "code",
            "script",
            "promise",
            "complete",
            "reduceright",
            "g7be8pmlskx",
            "r300",
            "typeof d",
            "caca",
            "ufunction",
            "ffunction",
            "gfunction",
            "mchtd",
            "azaz",
            "firefox",
            "opera",
            "chrome",
            "iemobile",
            "black",
            "incorrect",
            "xfunction",
            "typeof p",
            "typeof btoa",
            "vnode",
            "colohouse",
            "york",
            "learn more",
            "data center",
            "miami",
            "e cermak",
            "springs",
            "read",
            "cloud",
            "managed",
            "fast",
            "philadelphia",
            "bare",
            "metal",
            "chat",
            "accept",
            "placeheld",
            "minimum",
            "tooshort",
            "wpcf7wfreetext",
            "alert",
            "invert",
            "form",
            "animation",
            "value",
            "foundation",
            "migrate",
            "backcompat",
            "quirks mode",
            "typeof f",
            "html",
            "sufeffxa0",
            "legacy",
            "contenttype",
            "wivobjkey",
            "typehit",
            "data",
            "closure library",
            "pfunction",
            "zfunction",
            "bfunction",
            "mvoid",
            "ofunction"
          ],
          "references": [
            "xfe-URL-Data102.com-stix2-2.1-export.json",
            "https://www.google-analytics.com/analytics.js",
            "https://chimpstatic.com/mcjs-connected/js/users/6c3abfa7ff8634c75cdb2b22e/ddf7a436c1746be666f330e4a.js",
            "https://app.whoisvisiting.com/who.js",
            "https://www.data102.com/wp-includes/js/jquery/jquery.js?ver=1.12.4-wp",
            "https://www.data102.com/wp-includes/js/jquery/jquery-migrate.min.js?ver=1.4.1",
            "https://www.data102.com/?wordfence_lh=1&hid=2D6A812A7EB197E80D5A3978A6386BE4&r=0.5029022326538093",
            "https://www.data102.com/wp-includes/js/wp-embed.min.js?ver=00b0ffc433836dcf9f57035fded0b908",
            "https://www.data102.com/wp-content/plugins/cta/shared//shortcodes/js/spin.min.js",
            "https://www.data102.com/wp-content/plugins/contact-form-7/includes/js/scripts.js",
            "https://colohouse.com/",
            "xfe-URL-colohouse.com-stix2-2.1-export.json",
            "https://embed.tawk.to/_s/v4/app/625d36b405c/js/twk-main.js",
            "https://embed.tawk.to/_s/v4/app/625d36b405c/js/twk-vendor.js",
            "https://embed.tawk.to/_s/v4/app/625d36b405c/js/twk-chunk-vendors.js",
            "https://embed.tawk.to/_s/v4/app/625d36b405c/js/twk-chunk-common.js",
            "https://embed.tawk.to/_s/v4/app/625d36b405c/js/twk-runtime.js",
            "https://embed.tawk.to/_s/v4/app/625d36b405c/js/twk-app.js",
            "https://munchkin.marketo.net/161/munchkin.js",
            "https://www.googletagmanager.com/gtag/js?id=G-7BE8PMLSKX&l=dataLayer&cx=c",
            "https://embed.tawk.to/5697c34527b9b5d40b66960f/default",
            "https://www.googletagmanager.com/gtm.js?id=GTM-PTXLXZ4",
            "https://colohouse.com/wp-includes/js/wp-emoji-release.min.js?ver=5.8",
            "https://colohouse.com/wp-includes/js/jquery/jquery.min.js?ver=3.6.0",
            "https://colohouse.com/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.3.2",
            "https://colohouse.com/wp-content/plugins/cleantalk-spam-protect/js/apbct-public--functions.min.js?ver=5.173",
            "https://colohouse.com/wp-content/plugins/cleantalk-spam-protect/js/apbct-public.min.js?ver=5.173",
            "https://colohouse.com/wp-content/plugins/cleantalk-spam-protect/js/cleantalk-modal.min.js?ver=5.173",
            "https://colohouse.com/wp-content/plugins/cookie-law-info/public/js/cookie-law-info-public.js?ver=2.0.4",
            "https://colohouse.com/wp-content/plugins/stop-user-enumeration/frontend/js/frontend.js?ver=1.3.31",
            "https://colohouse.com/wp-content/plugins/duracelltomi-google-tag-manager/js/gtm4wp-form-move-tracker.js?ver=1.13.1",
            "https://munchkin.marketo.net/munchkin.js",
            "https://embed.tawk.to/_s/v4/app/625d36b405c/js/twk-chunk-2d0d2b7c.js",
            "https://embed.tawk.to/_s/v4/app/625d36b405c/js/twk-chunk-32507910.js",
            "https://embed.tawk.to/_s/v4/app/625d36b405c/js/twk-chunk-f163fcd0.js",
            "https://embed.tawk.to/_s/v4/app/625d36b405c/js/twk-chunk-2d0b9454.js",
            "https://embed.tawk.to/_s/v4/app/625d36b405c/js/twk-chunk-4fe9d5dd.js",
            "https://app-ab02.marketo.com/js/forms2/js/forms2.min.js",
            "https://maps.googleapis.com/maps/api/js?v=3.exp&key=AIzaSyDR76rjQL_2raonHiZ6ZrPqJr-FPb7pGH0",
            "https://colohouse.com/wp-content/themes/Netrouting/assets/chosen/chosen.jquery.min.js",
            "https://colohouse.com/wp-includes/js/dist/vendor/regenerator-runtime.min.js?ver=0.13.7",
            "https://colohouse.com/wp-content/themes/Netrouting/js/vendor/modernizr-2.8.3-respond-1.4.2.min.js",
            "https://colohouse.com/wp-content/plugins/contact-form-7/includes/js/index.js?ver=5.4.2",
            "https://colohouse.com/wp-content/plugins/link-whisper-premium/js/frontend.js?ver=1632756485",
            "https://colohouse.com/wp-content/plugins/wpcf7-redirect/build/js/wpcf7-redirect-frontend-script.js?ver=1.1",
            "https://colohouse.com/wp-content/plugins/kingcomposer/assets/frontend/js/kingcomposer.min.js?ver=2.9.6",
            "https://colohouse.com/wp-includes/js/wp-embed.min.js?ver=5.8",
            "https://colohouse.com/wp-content/plugins/wp-schema-pro/admin/assets/min-js/frontend.min.js?ver=2.7.2",
            "https://colohouse.com/wp-content/cache/autoptimize/css/autoptimize_5e11636f7dd8fb4f55e0ff84f0ed5faa.css",
            "https://fonts.googleapis.com/css?family=Libre+Franklin%3A300%2C300i%2C400%2C400i%2C600%2C600i%2C800%2C800i&subset=latin%2Clatin-ext",
            "https://fonts.googleapis.com/css?family=Roboto%3A100%2C100italic%2C300%2C300italic%2Cregular%2Citalic%2C500%2C500italic%2C700%2C700italic%2C900%2C900italic&subset=greek%2Clatin%2Cvietnamese%2Clatin-ext%2Ccyrillic%2Ccyrillic-ext%2Cgreek-ext&ver=2.9.6",
            "https://app-ab02.marketo.com/js/forms2/css/forms2.css",
            "https://app-ab02.marketo.com/js/forms2/css/forms2-theme-simple.css",
            "https://app-ab02.marketo.com/index.php/form/XDFrame"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Qe",
              "display_name": "Qe",
              "target": null
            },
            {
              "id": "ReduceRight",
              "display_name": "ReduceRight",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1049",
              "name": "System Network Connections Discovery",
              "display_name": "T1049 - System Network Connections Discovery"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 3,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "adjadex1@gmail.com",
            "id": "187163",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 2599,
            "hostname": 952,
            "FileHash-SHA256": 458,
            "domain": 557
          },
          "indicator_count": 4566,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 69,
          "modified_text": "1431 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "624da4e23e7e153ec40c8f8b",
          "name": "'+titlestr+' -APP STORE- C&C",
          "description": "This is the full text of the code for the BBC's Newsround app, using the fakeElem and its fakeHandlerCallback to remove fake elements from the page. and add them to the screen.",
          "modified": "2022-05-06T00:03:41.989000",
          "created": "2022-04-06T14:34:10.482000",
          "tags": [
            "datav4d9cb9db",
            "object",
            "typeof content",
            "dtnocomment1",
            "appn",
            "wlan",
            "appstore",
            "potato 24hn",
            "getdownload",
            "getdownloadlog",
            "datave49f1a26",
            "desktopview",
            "datav16fe8306",
            "mobileview",
            "array",
            "typeerror",
            "typeof t",
            "function",
            "string",
            "symbol",
            "typeof symbol",
            "vnode",
            "boolean",
            "error",
            "null",
            "number",
            "rangeerror",
            "regexp",
            "this",
            "promise",
            "date",
            "generator",
            "4096",
            "invalid attempt",
            "nuxt",
            "nuxtchild",
            "preventtran",
            "guozhihan",
            "center",
            "email",
            "fixed",
            "hidden",
            "99999",
            "body",
            "imgdata",
            "request",
            "getrequest",
            "tongji",
            "cnzzdata",
            "czuuid",
            "umdistinctid",
            "vuelazyload log",
            "mit license",
            "typeof",
            "typeof define",
            "customevent",
            "zfunction",
            "ifunction",
            "tfunction",
            "image",
            "int32array",
            "uint8array",
            "htmlelement",
            "htmlcollection",
            "nodelist",
            "https",
            "zeno rocha",
            "unescape",
            "void",
            "messagechannel",
            "array methods",
            "please",
            "canvas",
            "base64toblob",
            "click",
            "blob",
            "f25d61",
            "ff0163",
            "dedddd",
            "ff0168",
            "span",
            "helvetica neue",
            "arial",
            "pingfang sc",
            "45deg",
            "helvetica",
            "segoe ui",
            "roboto",
            "sans gb",
            "yahei",
            "woff2",
            "meta",
            "viewport"
          ],
          "references": [
            "http://www.testbyczx.top/common.js",
            "http://www.testbyczx.top/tj.js",
            "https://sps666.com/",
            "https://xflaa.com/static/css/vant.min.css",
            "https://xflaa.com/static/css/common.css",
            "https://c.cnzz.com/core.php?web_id=1280697987&t=z",
            "https://xflaa.com/static/js/base64Toimg.js",
            "https://v1.cnzz.com/z_stat.php?id=1280697987&web_id=1280697987",
            "https://xflaa.com/static/js/es6-promise.auto.min.js",
            "https://xflaa.com/static/js/query.js",
            "https://xflaa.com/static/js/clipboard.min.js",
            "https://xflaa.com/static/js/vue-qr.min.js",
            "https://apk.tatwa.cn/vue-lazyload.js",
            "https://s4.cnzz.com/z_stat.php?id=1280740854&web_id=1280740854",
            "https://mtaoaa.com/js/tongji.js",
            "https://mtaoaa.com/js/screenHorizntal.js",
            "https://mtaoaa.com/_nuxt/49a5e4f.js",
            "https://mtaoaa.com/_nuxt/517adf2.js",
            "https://mtaoaa.com/_nuxt/06dc766.js",
            "https://mtaoaa.com/_nuxt/31ce4ff.js",
            "https://mtaoaa.com/_nuxt/0bc6515.js",
            "https://mtaoaa.com/_nuxt/4ca1314.js"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 4,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "adjadex1@gmail.com",
            "id": "187163",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 244,
            "domain": 154,
            "URL": 862,
            "FileHash-SHA256": 173,
            "email": 1,
            "FileHash-MD5": 1
          },
          "indicator_count": 1435,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 68,
          "modified_text": "1444 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "624da4e55644a1e8e4de3fc7",
          "name": "'+titlestr+' -APP STORE- C&C",
          "description": "This is the full text of the code for the BBC's Newsround app, using the fakeElem and its fakeHandlerCallback to remove fake elements from the page. and add them to the screen.",
          "modified": "2022-05-06T00:03:41.989000",
          "created": "2022-04-06T14:34:13.114000",
          "tags": [
            "datav4d9cb9db",
            "object",
            "typeof content",
            "dtnocomment1",
            "appn",
            "wlan",
            "appstore",
            "potato 24hn",
            "getdownload",
            "getdownloadlog",
            "datave49f1a26",
            "desktopview",
            "datav16fe8306",
            "mobileview",
            "array",
            "typeerror",
            "typeof t",
            "function",
            "string",
            "symbol",
            "typeof symbol",
            "vnode",
            "boolean",
            "error",
            "null",
            "number",
            "rangeerror",
            "regexp",
            "this",
            "promise",
            "date",
            "generator",
            "4096",
            "invalid attempt",
            "nuxt",
            "nuxtchild",
            "preventtran",
            "guozhihan",
            "center",
            "email",
            "fixed",
            "hidden",
            "99999",
            "body",
            "imgdata",
            "request",
            "getrequest",
            "tongji",
            "cnzzdata",
            "czuuid",
            "umdistinctid",
            "vuelazyload log",
            "mit license",
            "typeof",
            "typeof define",
            "customevent",
            "zfunction",
            "ifunction",
            "tfunction",
            "image",
            "int32array",
            "uint8array",
            "htmlelement",
            "htmlcollection",
            "nodelist",
            "https",
            "zeno rocha",
            "unescape",
            "void",
            "messagechannel",
            "array methods",
            "please",
            "canvas",
            "base64toblob",
            "click",
            "blob",
            "f25d61",
            "ff0163",
            "dedddd",
            "ff0168",
            "span",
            "helvetica neue",
            "arial",
            "pingfang sc",
            "45deg",
            "helvetica",
            "segoe ui",
            "roboto",
            "sans gb",
            "yahei",
            "woff2",
            "meta",
            "viewport"
          ],
          "references": [
            "http://www.testbyczx.top/common.js",
            "http://www.testbyczx.top/tj.js",
            "https://sps666.com/",
            "https://xflaa.com/static/css/vant.min.css",
            "https://xflaa.com/static/css/common.css",
            "https://c.cnzz.com/core.php?web_id=1280697987&t=z",
            "https://xflaa.com/static/js/base64Toimg.js",
            "https://v1.cnzz.com/z_stat.php?id=1280697987&web_id=1280697987",
            "https://xflaa.com/static/js/es6-promise.auto.min.js",
            "https://xflaa.com/static/js/query.js",
            "https://xflaa.com/static/js/clipboard.min.js",
            "https://xflaa.com/static/js/vue-qr.min.js",
            "https://apk.tatwa.cn/vue-lazyload.js",
            "https://s4.cnzz.com/z_stat.php?id=1280740854&web_id=1280740854",
            "https://mtaoaa.com/js/tongji.js",
            "https://mtaoaa.com/js/screenHorizntal.js",
            "https://mtaoaa.com/_nuxt/49a5e4f.js",
            "https://mtaoaa.com/_nuxt/517adf2.js",
            "https://mtaoaa.com/_nuxt/06dc766.js",
            "https://mtaoaa.com/_nuxt/31ce4ff.js",
            "https://mtaoaa.com/_nuxt/0bc6515.js",
            "https://mtaoaa.com/_nuxt/4ca1314.js"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 5,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "adjadex1@gmail.com",
            "id": "187163",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 244,
            "domain": 154,
            "URL": 862,
            "FileHash-SHA256": 173,
            "email": 1,
            "FileHash-MD5": 1
          },
          "indicator_count": 1435,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 69,
          "modified_text": "1444 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "621fff12d2c54f70fea90576",
          "name": "Bexar.org",
          "description": "",
          "modified": "2022-04-01T00:01:54.852000",
          "created": "2022-03-02T23:34:42.531000",
          "tags": [],
          "references": [
            "www.bexar.org - urlscan.io.pdf",
            "bexar api 4.pdf",
            "bexar api 8.pdf",
            "bexar 6.pdf",
            "bexar api 2.pdf",
            "bexar api 7.pdf",
            "bexar api 3.pdf",
            "bexar api 9.pdf",
            "bexar api 12.pdf",
            "bexar api 17.pdf",
            "bexar api 15.pdf",
            "bexar api 18.pdf",
            "bexar api 10.pdf",
            "bexar api 19.pdf",
            "bexar api 20.pdf",
            "bexar api 13.pdf",
            "bexar api 21.pdf",
            "bexar api 14.pdf",
            "bexar api 22.pdf",
            "bexar1.pdf",
            "bexar api5.pdf",
            "bexar2.pdf",
            "bexar3.pdf",
            "bexar.org 3.2.22.pdf",
            "bexar6.pdf",
            "bexar5.pdf",
            "bexar api_1.pdf",
            "bexar10.pdf",
            "bexar api.pdf",
            "bexar_v1df.pdf",
            "bexarv4df.pdf",
            "bexarv2df.pdf",
            "bexarv6df.pdf",
            "bexasv3df.pdf",
            "bexarv7df.pdf",
            "bear_v apidf.pdf"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "Government"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 7,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Kailula4",
            "id": "131997",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 1833,
            "URL": 4669,
            "domain": 1025,
            "FileHash-SHA256": 1735,
            "email": 4,
            "FileHash-MD5": 133,
            "FileHash-SHA1": 6,
            "CIDR": 5
          },
          "indicator_count": 9410,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 407,
          "modified_text": "1479 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "https://googleads.g.doubleclick.net/pagead/viewthroughconversion/952389962/?random=1650405011982&cv=9&fst=1650405011982&num=1&bg=ffffff&guid=ON&resp=GooglemKTybQhCsO&eid=376635471&u_h=844&u_w=390&u_ah=844&u_aw=390&u_cd=32&u_his=1&u_tz=-240&u_java=false&u_nplug=0&u_nmime=0&gtm=2wg4i1&sendb=1&ig=1&frm=0&url=https%3A%2F%2Fwww.leaseweb.com%2F&tiba=Leaseweb%20%7C%20Global%20Hosted%20Infrastructure%20(IaaS)%20and%20Cloud%20Solutions&hn=www.googleadservices.com&async=1&rfmt=3&fmt=4",
        "https://colohouse.com/wp-content/plugins/cleantalk-spam-protect/js/cleantalk-modal.min.js?ver=5.173",
        "https://2001.dwlww.com/static/js/chunk-7d5d3bac.efb700c7.js",
        "https://mtaoaa.com/js/screenHorizntal.js",
        "https://www.leaseweb.com/sites/default/files/js/js_6lTJ_m6ahwXas7Efbw8ZYEMSaecrGw8ilNALfvIPNUw.js",
        "https://munchkin.marketo.net/161/munchkin.js",
        "https://fonts.googleapis.com/css?family=Libre+Franklin%3A300%2C300i%2C400%2C400i%2C600%2C600i%2C800%2C800i&subset=latin%2Clatin-ext",
        "https://www.leaseweb.com/sites/default/files/js/js_wcSNEXVJ4Xjhkf8qhMguEPZJTDTMNmPaJM-YWdAOhQE.js",
        "https://apk.tatwa.cn/vue-lazyload.js",
        "https://www.sunnetwork.com.sg/sun_21/js/bootstrap.min.js",
        "bexar api.pdf",
        "https://www.leaseweb.com/sites/default/files/js/js_zoLA7TweXam0kYiqJrXepqBWmyDoP1sLSlHoZcveFnY.js",
        "https://xflaa.com/static/js/vue-qr.min.js",
        "bexar api 22.pdf",
        "www.bexar.org - urlscan.io.pdf",
        "https://colohouse.com/wp-content/themes/Netrouting/js/vendor/modernizr-2.8.3-respond-1.4.2.min.js",
        "https://colohouse.com/wp-content/plugins/duracelltomi-google-tag-manager/js/gtm4wp-form-move-tracker.js?ver=1.13.1",
        "https://colohouse.com/wp-includes/js/wp-embed.min.js?ver=5.8",
        "https://embed.tawk.to/_s/v4/app/625d36b405c/js/twk-chunk-2d0d2b7c.js",
        "https://www.meetup.com/pro_static/en-US/0.f2cf4c3f.js",
        "https://app-lon04.marketo.com/js/forms2/css/forms2-theme-plain.css",
        "https://colohouse.com/wp-includes/js/wp-emoji-release.min.js?ver=5.8",
        "https://2001.dwlww.com/static/css/app.88afcfd8.css",
        "https://www.youtube.com/iframe_api",
        "https://colohouse.com/wp-includes/js/dist/vendor/regenerator-runtime.min.js?ver=0.13.7",
        "https://xflaa.com/static/js/es6-promise.auto.min.js",
        "https://dna8twue3dlxq.cloudfront.net/js/profitwell.js",
        "https://googleads.g.doubleclick.net/pagead/viewthroughconversion/922061185/?random=1652546907471&cv=9&fst=1652546907471&num=1&label=BaPJCIf2_WYQgZPWtwM&bg=ffffff&guid=ON&resp=GooglemKTybQhCsO&u_h=844&u_w=390&u_ah=844&u_aw=390&u_cd=32&u_his=2&u_tz=-240&u_java=false&u_nplug=0&u_nmime=0&gtm=2wg5b0&sendb=1&ig=1&frm=0&url=https%3A%2F%2Fwww.meetup.com%2FDigitalOceanMoscow%2F&ref=https%3A%2F%2Fwww.meetup.com%2Fpro%2Fdigitalocean%2F&tiba=DigitalOcean%20Moscow%20(Moscow%2C%20Russia)%20%7C%20Meetup&hn=www.googleadser",
        "https://www.sunnetwork.com.sg/sun_21/js/vendor/jquery-3.5.0.min.js",
        "https://www.googletagmanager.com/gtm.js?id=GTM-NWPHSS",
        "https://colohouse.com/wp-content/plugins/cleantalk-spam-protect/js/apbct-public.min.js?ver=5.173",
        "https://storage.googleapis.com/snapengage-eu/js/e9219576-8f74-40b5-8b6f-bbad33f6ca57.js",
        "https://www.data102.com/wp-includes/js/jquery/jquery-migrate.min.js?ver=1.4.1",
        "https://www.google-analytics.com/analytics.js",
        "https://chatting.page/kv6vcosd7tmhsetmarsoawzaglejnny4",
        "https://consent.cookiebot.com/uc.js?cbid=1e27dadb-e278-4c02-aa4f-43f9222c4fbb&culture=en",
        "https://www.googletagmanager.com/gtag/js?id=G-NP82XMKW0P&l=dataLayer&cx=c",
        "https://app.ynsdty.cn/dist/vendors/core-js/core.js",
        "https://embed.tawk.to/_s/v4/app/625d36b405c/js/twk-chunk-vendors.js",
        "https://sdk.51.la/event/js-sdk-event.min.js?u=JdoUNv3VSW0GHUpw",
        "https://2001.habyc.com/static/css/chunk-vendors.6a41b67e.css",
        "https://colohouse.com/wp-includes/js/jquery/jquery.min.js?ver=3.6.0",
        "https://app-ab02.marketo.com/index.php/form/XDFrame",
        "https://mtaoaa.com/js/tongji.js",
        "https://mtaoaa.com/_nuxt/517adf2.js",
        "bexar api 19.pdf",
        "bexarv7df.pdf",
        "https://www.googletagmanager.com/gtag/js?id=G-7BE8PMLSKX&l=dataLayer&cx=c",
        "xfe-URL-Data102.com-stix2-2.1-export.json",
        "https://colohouse.com/wp-content/plugins/wpcf7-redirect/build/js/wpcf7-redirect-frontend-script.js?ver=1.1",
        "https://www.8098.app:21568/?agent=7691755704",
        "bexar api 3.pdf",
        "https://sdk.51.la/js-sdk-pro.min.js",
        "https://xflaa.com/static/js/base64Toimg.js",
        "xfe-URL-habyc.com-stix2-2.1-export.json",
        "https://embed.tawk.to/5697c34527b9b5d40b66960f/default",
        "https://app.ynsdty.cn/dist/vendors/swiper/swiper.min.js",
        "https://eu.snapengage.com/chatjs/servicegetallavailableagents?w=e9219576-8f74-40b5-8b6f-bbad33f6ca57&t=1",
        "bexar.org 3.2.22.pdf",
        "https://2001.habyc.com/static/css/chunk-7d5d3bac.e1a32335.css",
        "https://bat.bing.com/bat.js",
        "https://www.tidio.com/talk/kv6vcosd7tmhsetmarsoawzaglejnny4",
        "https://app.ynsdty.cn//package/GmCC6WISh",
        "https://sps666.com/",
        "https://embed.tawk.to/_s/v4/app/625d36b405c/js/twk-chunk-f163fcd0.js",
        "https://www.leaseweb.com/sites/default/files/css/css_7CYF9En6DNp6AojfSKnT8USKR3GvzPwznmTqLTKT9VM.css",
        "xfe-URL-colohouse.com-stix2-2.1-export.json",
        "https://www.sunnetwork.com.sg/sun_21/js/main.js",
        "https://embed.tawk.to/_s/v4/app/625d36b405c/js/twk-vendor.js",
        "bexar api 10.pdf",
        "https://mtaoaa.com/_nuxt/06dc766.js",
        "bexar api 12.pdf",
        "https://www.sunnetwork.com.sg/sun_21/js/ajax-form.js",
        "https://mtaoaa.com/_nuxt/0bc6515.js",
        "bexar10.pdf",
        "bexar_v1df.pdf",
        "https://www.sunnetwork.com.sg/sun_21/js/slick.min.js",
        "https://connect.facebook.net/signals/config/399164440484826?v=2.9.57&r=stable",
        "https://colohouse.com/wp-content/themes/Netrouting/assets/chosen/chosen.jquery.min.js",
        "https://xflaa.com/static/css/common.css",
        "bexarv4df.pdf",
        "https://bid.g.doubleclick.net/xbbe/pixel?d=KAE",
        "bexar api 20.pdf",
        "https://c.cnzz.com/core.php?web_id=1280697987&t=z",
        "https://www.leaseweb.com/sites/default/files/css/css_47DEQpj8HBSa-_TImW-5JCeuQeRkm5NMpJWZG3hSuFU.css",
        "https://app.ynsdty.cn/dist/vendors/bootstrap/js/bootstrap.min.js",
        "https://www.sunnetwork.com.sg/sun_21/js/isotope.pkgd.min.js",
        "https://www.data102.com/?wordfence_lh=1&hid=2D6A812A7EB197E80D5A3978A6386BE4&r=0.5029022326538093",
        "https://colohouse.com/wp-content/cache/autoptimize/css/autoptimize_5e11636f7dd8fb4f55e0ff84f0ed5faa.css",
        "https://2001.habyc.com/static/js/chunk-vendors.9d7684f4.js",
        "bexasv3df.pdf",
        "https://j.clarity.ms/s/0.6.34/clarity.js",
        "https://s4.cnzz.com/z_stat.php?id=1280740854&web_id=1280740854",
        "bexar6.pdf",
        "https://www.8098.app:21568/js/jquery-1.11.3.min.js",
        "https://eu.snapengage.com/chatjs/servicegetproactivegeodata?w=e9219576-8f74-40b5-8b6f-bbad33f6ca57",
        "bexar2.pdf",
        "xfe-URL-sys95.com-stix2-2.1-export.json",
        "https://embed.tawk.to/_s/v4/app/625d36b405c/js/twk-chunk-32507910.js",
        "https://www.sunnetwork.com.sg/sun_21/js/imagesloaded.pkgd.min.js",
        "https://embed.tawk.to/_s/v4/app/625d36b405c/js/twk-app.js",
        "https://app.whoisvisiting.com/who.js",
        "https://xflaa.com/static/js/query.js",
        "https://chimpstatic.com/mcjs-connected/js/users/6c3abfa7ff8634c75cdb2b22e/ddf7a436c1746be666f330e4a.js",
        "bexar api 15.pdf",
        "https://www.data102.com/wp-content/plugins/contact-form-7/includes/js/scripts.js",
        "https://cdn.polyfill.io/v2/polyfill.min.js?features=default-3.6,fetch,Intl,Intl.~locale.en-US,Array.prototype.find,Array.prototype.includes,Object.values&flags=gated",
        "bexar3.pdf",
        "https://maps.googleapis.com/maps/api/js?v=3.exp&key=AIzaSyDR76rjQL_2raonHiZ6ZrPqJr-FPb7pGH0",
        "https://www.leaseweb.com/sites/default/files/js/js_6FowaFXT9bT78hf9earPdGcdTmvsFiaBzKgFl9P4fSo.js",
        "https://use.fortawesome.com/03018d9d.js",
        "https://fonts.googleapis.com/css?family=Roboto%3A100%2C100italic%2C300%2C300italic%2Cregular%2Citalic%2C500%2C500italic%2C700%2C700italic%2C900%2C900italic&subset=greek%2Clatin%2Cvietnamese%2Clatin-ext%2Ccyrillic%2Ccyrillic-ext%2Cgreek-ext&ver=2.9.6",
        "bexar api_1.pdf",
        "https://2001.habyc.com/static/js/chunk-7d5d3bac.efb700c7.js",
        "https://2001.dwlww.com/js/config.js",
        "https://2001.dwlww.com/static/css/chunk-vendors.6a41b67e.css",
        "https://www.meetup.com/mu_static/en-US/app.0ff22766.js",
        "https://colohouse.com/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.3.2",
        "bexarv2df.pdf",
        "https://2001.habyc.com/?channelNo=2001#/home",
        "https://eu.snapengage.com/chatjs/ServiceGetConfig?w=e9219576-8f74-40b5-8b6f-bbad33f6ca57",
        "https://www.sunnetwork.com.sg/sun_21/js/popper.min.js",
        "https://2001.habyc.com/js/config.js",
        "https://www.data102.com/wp-content/plugins/cta/shared//shortcodes/js/spin.min.js",
        "bexar api 14.pdf",
        "https://consent.cookiebot.com/1e27dadb-e278-4c02-aa4f-43f9222c4fbb/cc.js?renew=false&referer=www.leaseweb.com&culture=en&dnt=false",
        "http://www.testbyczx.top/tj.js",
        "https://munchkin.marketo.net/munchkin.js",
        "https://app.ynsdty.cn/dist/js/longbow.slidercaptcha.js",
        "bexar api 17.pdf",
        "https://embed.tawk.to/_s/v4/app/625d36b405c/js/twk-main.js",
        "https://embed.tawk.to/_s/v4/app/625d36b405c/js/twk-chunk-common.js",
        "xfe-URL-Meetup.com_pro_digitalocean_-stix2-2.1-export.json",
        "bexar api 2.pdf",
        "https://colohouse.com/wp-content/plugins/cleantalk-spam-protect/js/apbct-public--functions.min.js?ver=5.173",
        "https://v1.cnzz.com/z_stat.php?id=1280697987&web_id=1280697987",
        "https://embed.tawk.to/_s/v4/app/625d36b405c/js/twk-runtime.js",
        "https://2001.dwlww.com/static/js/app.9d5d18d7.js",
        "https://app-ab02.marketo.com/js/forms2/css/forms2.css",
        "https://www.googleadservices.com/pagead/conversion_async.js",
        "https://www.googletagmanager.com/gtm.js?id=GTM-PTXLXZ4",
        "https://www.data102.com/wp-includes/js/jquery/jquery.js?ver=1.12.4-wp",
        "https://embed.tawk.to/_s/v4/app/625d36b405c/js/twk-chunk-4fe9d5dd.js",
        "bexar api 7.pdf",
        "cf20ed53-cb6d-4dfd-a4e8-794fbe163efc.pcap",
        "https://xflaa.com/static/css/vant.min.css",
        "bexar api5.pdf",
        "https://www.leaseweb.com/sites/default/files/js/js_kI_QwKJlaBz9CzQdENdUBFiEl4aehfjf4_-9taiwcCE.js",
        "https://cdn.sift.com/s.js",
        "https://app.ynsdty.cn/dist/js/jquery.cookie.js",
        "https://www.meetup.com/mu_static/react.ddd38c26.js",
        "https://colohouse.com/wp-content/plugins/contact-form-7/includes/js/index.js?ver=5.4.2",
        "xfe-URL-Sift.com-stix2-2.1-export.json",
        "https://colohouse.com/wp-content/plugins/cookie-law-info/public/js/cookie-law-info-public.js?ver=2.0.4",
        "https://mtaoaa.com/_nuxt/49a5e4f.js",
        "https://mtaoaa.com/_nuxt/4ca1314.js",
        "xfe-URL-sun.net.hk-stix2-2.1-export.json",
        "https://colohouse.com/wp-content/plugins/stop-user-enumeration/frontend/js/frontend.js?ver=1.3.31",
        "bexar api 8.pdf",
        "bexar api 9.pdf",
        "https://app.ynsdty.cn/dist/js/app.base.js",
        "https://www.meetup.com/proxydirectory/tags/239562121304/tag.js",
        "https://www.leaseweb.com/sites/default/files/js/js_kwxcSFD2Y0_BPtdJClYUy5H8THI_5EycUmIgIGWaGYs.js",
        "https://www.google-analytics.com/plugins/ua/linkid.js",
        "https://2001.dwlww.com/static/js/chunk-vendors.9d7684f4.js",
        "https://analytics.twitter.com/i/adsct?type=javascript&version=2.0.4&p_id=Twitter&p_user_id=0&txn_id=nxsfu&events=%5B%5B%22pageview%22%2Cnull%5D%5D&tw_sale_amount=0&tw_order_quantity=0&tw_iframe_status=0&event_id=511b6f48-2639-478c-a251-b09fcbae76e7&tw_document_href=https%3A%2F%2Fwww.leaseweb.com%2F&tpx_cb=twttr.conversion.loadPixels",
        "bexar 6.pdf",
        "https://colohouse.com/wp-content/plugins/link-whisper-premium/js/frontend.js?ver=1632756485",
        "https://app-lon04.marketo.com/index.php/form/XDFrame",
        "https://app-lon04.marketo.com/js/forms2/js/forms2.min.js",
        "https://2001.dwlww.com/?channelNo=2001#/home",
        "https://2001.dwlww.com/static/css/chunk-7d5d3bac.e1a32335.css",
        "https://mtaoaa.com/_nuxt/31ce4ff.js",
        "https://www.leaseweb.com/sites/all/modules/custom/lsw_marketo/js/lsw_marketo_forms.js",
        "bexar api 18.pdf",
        "https://bat.bing.com/p/action/5602105.js",
        "https://app-ab02.marketo.com/js/forms2/js/forms2.min.js",
        "bear_v apidf.pdf",
        "https://snap.licdn.com/li.lms-analytics/insight.min.js",
        "http://www.testbyczx.top/common.js",
        "bexar api 21.pdf",
        "https://embed.tawk.to/_s/v4/app/625d36b405c/js/twk-chunk-2d0b9454.js",
        "https://app-ab02.marketo.com/js/forms2/css/forms2-theme-simple.css",
        "https://xflaa.com/static/js/clipboard.min.js",
        "bexar1.pdf",
        "bexarv6df.pdf",
        "https://colohouse.com/wp-content/plugins/wp-schema-pro/admin/assets/min-js/frontend.min.js?ver=2.7.2",
        "https://github.com/meetup/swarm-ui",
        "bexar5.pdf",
        "https://www.8098.app:21568/js/xinstall_inner_e.min.js?v=1004",
        "xfe-URL-2001.habyc.com-stix2-2.1-export.json",
        "https://app.ynsdty.cn/dist/js/jquery.min.js",
        "https://colohouse.com/wp-content/plugins/kingcomposer/assets/frontend/js/kingcomposer.min.js?ver=2.9.6",
        "https://www.youtube.com/s/player/19eb72e4/www-widgetapi.vflset/www-widgetapi.js",
        "https://widget-v4.tidiochat.com/code/kv6vcosd7tmhsetmarsoawzaglejnny4.js",
        "https://2001.habyc.com/static/css/app.88afcfd8.css",
        "bexar api 13.pdf",
        "https://www.data102.com/wp-includes/js/wp-embed.min.js?ver=00b0ffc433836dcf9f57035fded0b908",
        "https://googleads.g.doubleclick.net/pagead/viewthroughconversion/1001847692/?random=1650405011980&cv=9&fst=1650405011980&num=1&bg=ffffff&guid=ON&resp=GooglemKTybQhCsO&eid=376635471&u_h=844&u_w=390&u_ah=844&u_aw=390&u_cd=32&u_his=1&u_tz=-240&u_java=false&u_nplug=0&u_nmime=0&gtm=2wg4i1&sendb=1&ig=1&frm=0&url=https%3A%2F%2Fwww.leaseweb.com%2F&tiba=Leaseweb%20%7C%20Global%20Hosted%20Infrastructure%20(IaaS)%20and%20Cloud%20Solutions&hn=www.googleadservices.com&async=1&rfmt=3&fmt=4",
        "https://m4244.com:35003/",
        "https://consentcdn.cookiebot.com/sdk/bc-v4.min.html",
        "https://colohouse.com/",
        "bexar api 4.pdf"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 0
        },
        "other": {
          "adversary": [],
          "malware_families": [
            "Hero stripe",
            "Documentcookie",
            "Min",
            "Vd",
            "Photostatus",
            "Reduceright",
            "Buttons};kb(convertedmessage);break;case\"/sys\":var",
            "Takk",
            "Kiitos",
            "Qe",
            "Ajax",
            "Acum"
          ],
          "industries": [
            "Government"
          ],
          "unique_indicators": 62147
        }
      }
    },
    "false_positive": [],
    "alexa": "http://www.alexa.com/siteinfo/prototype.compare",
    "whois": "http://whois.domaintools.com/prototype.compare",
    "domain": "prototype.compare",
    "hostname": "ra.prototype.compare"
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 14,
  "pulses": [
    {
      "id": "698904c316bc7710b967d01d",
      "name": "Rare Tier 1 Persistence - Critical \"Patched\", Non Patched Vulnerabilities Remain bypassing Lockdown Mode",
      "description": "Researcher Note (Feb 08, 2026):\nThis artifact represents a sophisticated Cross-Protocol Mesh. Observations confirm that the Cymt/Nemucod wrapper is being utilized as a delivery vehicle for a Firmware-resident ELF binary (Mirai variant).\nThe persistence is notable for its ability to survive Full DFU Restores and Faraday-isolated states, likely due to JTAG-level interaction with the Power Management IC (Chip 4799). This is not a standard opportunistic infection; it is a targeted provisioning event leveraging IDMSA (Identity Management) bridges and Verizon/Akamai Edge infrastructure.\nThe integration with CalendarKit and Maps for geofenced execution suggests a highly coordinated surveillance objective. Forensic analysts should pay specific attention to the sizeofrawdata_antidbg anomalies, which indicate a focus on bypassing Apple Lockdown Mode and Secure Enclave. \nresearcher credit: msudoSOS",
      "modified": "2026-03-27T09:05:26.285000",
      "created": "2026-02-08T21:48:49.147000",
      "tags": [
        "#supportsitewebsiteabuse #rootcertificatefailure #cryptographicf"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 909,
        "URL": 1779,
        "CVE": 126,
        "domain": 659,
        "email": 23,
        "JA3": 1,
        "FileHash-MD5": 230,
        "FileHash-SHA1": 227,
        "FileHash-SHA256": 934,
        "CIDR": 13
      },
      "indicator_count": 4901,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 54,
      "modified_text": "23 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "65708dff34f37412488dda2a",
      "name": "Digital Ocean",
      "description": "",
      "modified": "2023-12-06T15:06:38.991000",
      "created": "2023-12-06T15:06:38.991000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "CVE": 1,
        "FileHash-SHA256": 703,
        "domain": 734,
        "URL": 5116,
        "hostname": 1266,
        "email": 3
      },
      "indicator_count": 7823,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "865 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "65708c37c54dd9e78f85c0fa",
      "name": "\u7ea2\u674f\u89c6\u9891 malware",
      "description": "",
      "modified": "2023-12-06T14:59:03.859000",
      "created": "2023-12-06T14:59:03.859000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 4,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 1686,
        "hostname": 2218,
        "URL": 5740,
        "domain": 901,
        "FileHash-MD5": 3
      },
      "indicator_count": 10548,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "865 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "65708c0f5981b6d81d0fa423",
      "name": "data102 and colohouse. Malware hosting",
      "description": "",
      "modified": "2023-12-06T14:58:23.206000",
      "created": "2023-12-06T14:58:23.206000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 458,
        "domain": 557,
        "URL": 2599,
        "hostname": 952
      },
      "indicator_count": 4566,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "865 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "65707fe17dfdfe16066d16de",
      "name": "Bexar.org",
      "description": "",
      "modified": "2023-12-06T14:06:25.800000",
      "created": "2023-12-06T14:06:25.800000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 1735,
        "hostname": 1833,
        "domain": 1025,
        "URL": 4668,
        "email": 4,
        "FileHash-MD5": 133,
        "FileHash-SHA1": 6,
        "CIDR": 5
      },
      "indicator_count": 9409,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 110,
      "modified_text": "865 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "65707e5b7df6f60133e8fb50",
      "name": "Jeeng / Powerbox",
      "description": "",
      "modified": "2023-12-06T13:59:55.129000",
      "created": "2023-12-06T13:59:55.129000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "CVE": 3,
        "FileHash-SHA256": 9072,
        "domain": 2500,
        "hostname": 3584,
        "URL": 13548,
        "FileHash-MD5": 197,
        "FileHash-SHA1": 162,
        "email": 19,
        "CIDR": 20,
        "SSLCertFingerprint": 2,
        "BitcoinAddress": 1
      },
      "indicator_count": 29108,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "865 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "627fe16ae54614d3d59de881",
      "name": "Digital Ocean",
      "description": "\u2026",
      "modified": "2022-06-13T00:00:32.864000",
      "created": "2022-05-14T17:05:46.360000",
      "tags": [
        "min",
        "qe",
        "photostatus",
        "hero stripe",
        "object",
        "boolean",
        "license",
        "urlsearchparams",
        "typeof t",
        "events",
        "pattrick hper",
        "bsd3clause",
        "typeerror",
        "react",
        "date",
        "error",
        "this",
        "flex",
        "open",
        "facebook",
        "close",
        "february",
        "april",
        "june",
        "august",
        "dead",
        "frozen",
        "blank",
        "null",
        "mutation",
        "roboto",
        "4096",
        "unknown",
        "clock",
        "period",
        "footer",
        "android",
        "service",
        "invisible",
        "sphinx",
        "checkbox",
        "click",
        "typeof e",
        "referenceerror",
        "typeof symbol",
        "router",
        "function",
        "intl",
        "push",
        "body",
        "meta",
        "string",
        "url path",
        "url object",
        "full",
        "url api",
        "nativeurl",
        "searchparams",
        "copyright",
        "closure library",
        "includes code",
        "regexp",
        "html",
        "plugindetect",
        "jeff mott",
        "quicktime",
        "flash shockwave",
        "vlc adobereader",
        "span",
        "or conditions",
        "post",
        "array",
        "apache license",
        "version",
        "this code",
        "is provided",
        "on an",
        "ud83d",
        "ud83e",
        "u2695u2696u2708",
        "udc66udc67",
        "udc68udc69",
        "ud83c",
        "dfunction",
        "typeof u",
        "u2640u2642",
        "9000",
        "typeof r",
        "weakmap",
        "asyncfunction",
        "proxy",
        "customevent",
        "uint8array",
        "09af",
        "ver0",
        "tag0",
        "extdata0",
        "ua ch",
        "window",
        "documentcookie",
        "typeof self",
        "blob",
        "promise",
        "reduceright",
        "number",
        "l420",
        "gnp82xmkw0p",
        "json",
        "void",
        "public",
        "github",
        "meetup",
        "swarm",
        "jump",
        "sign",
        "releases",
        "packages",
        "contributors",
        "topics",
        "star",
        "contact",
        "code",
        "stars"
      ],
      "references": [
        "xfe-URL-Meetup.com_pro_digitalocean_-stix2-2.1-export.json",
        "https://github.com/meetup/swarm-ui",
        "https://www.googletagmanager.com/gtag/js?id=G-NP82XMKW0P&l=dataLayer&cx=c",
        "https://www.meetup.com/proxydirectory/tags/239562121304/tag.js",
        "https://www.meetup.com/pro_static/en-US/0.f2cf4c3f.js",
        "https://dna8twue3dlxq.cloudfront.net/js/profitwell.js",
        "https://cdn.sift.com/s.js",
        "https://googleads.g.doubleclick.net/pagead/viewthroughconversion/922061185/?random=1652546907471&cv=9&fst=1652546907471&num=1&label=BaPJCIf2_WYQgZPWtwM&bg=ffffff&guid=ON&resp=GooglemKTybQhCsO&u_h=844&u_w=390&u_ah=844&u_aw=390&u_cd=32&u_his=2&u_tz=-240&u_java=false&u_nplug=0&u_nmime=0&gtm=2wg5b0&sendb=1&ig=1&frm=0&url=https%3A%2F%2Fwww.meetup.com%2FDigitalOceanMoscow%2F&ref=https%3A%2F%2Fwww.meetup.com%2Fpro%2Fdigitalocean%2F&tiba=DigitalOcean%20Moscow%20(Moscow%2C%20Russia)%20%7C%20Meetup&hn=www.googleadser",
        "https://cdn.polyfill.io/v2/polyfill.min.js?features=default-3.6,fetch,Intl,Intl.~locale.en-US,Array.prototype.find,Array.prototype.includes,Object.values&flags=gated",
        "https://www.meetup.com/mu_static/react.ddd38c26.js",
        "https://www.meetup.com/mu_static/en-US/app.0ff22766.js",
        "xfe-URL-Sift.com-stix2-2.1-export.json"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "MIN",
          "display_name": "MIN",
          "target": null
        },
        {
          "id": "PhotoStatus",
          "display_name": "PhotoStatus",
          "target": null
        },
        {
          "id": "Qe",
          "display_name": "Qe",
          "target": null
        },
        {
          "id": "Hero Stripe",
          "display_name": "Hero Stripe",
          "target": null
        },
        {
          "id": "DocumentCookie",
          "display_name": "DocumentCookie",
          "target": null
        },
        {
          "id": "ReduceRight",
          "display_name": "ReduceRight",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1110",
          "name": "Brute Force",
          "display_name": "T1110 - Brute Force"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 10,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "adjadex1@gmail.com",
        "id": "187163",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 1266,
        "URL": 5116,
        "domain": 734,
        "FileHash-SHA256": 703,
        "CVE": 1,
        "email": 3
      },
      "indicator_count": 7823,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 72,
      "modified_text": "1406 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "620c3b1f8af7ea0dcf2c1218",
      "name": "Jeeng / Powerbox",
      "description": "",
      "modified": "2022-06-12T22:01:23.105000",
      "created": "2022-02-15T23:45:35.234000",
      "tags": [
        "Jeeng",
        "tim pool",
        "timcast"
      ],
      "references": [
        "cf20ed53-cb6d-4dfd-a4e8-794fbe163efc.pcap"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 10,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "scnrscnr",
        "id": "126475",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_126475/resized/80/avatar_67ca5b7bae.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 9072,
        "domain": 2500,
        "URL": 13548,
        "hostname": 3584,
        "FileHash-MD5": 197,
        "FileHash-SHA1": 162,
        "CVE": 3,
        "CIDR": 20,
        "SSLCertFingerprint": 2,
        "email": 19,
        "BitcoinAddress": 1
      },
      "indicator_count": 29108,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 97,
      "modified_text": "1406 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "62606584633e2b9a3bc935b9",
      "name": "\u7ea2\u674f\u89c6\u9891 malware",
      "description": "function s(t,e), o, is a new type of function, which throws new TypeError when it comes to trying to make a function out of its own language or its form.",
      "modified": "2022-05-20T00:01:19.453000",
      "created": "2022-04-20T19:56:52.162000",
      "tags": [
        "typeof t",
        "typeof define",
        "moztransform",
        "success",
        "error",
        "make sure",
        "stop",
        "ajax",
        "action",
        "click",
        "open",
        "active",
        "button",
        "toggle btn",
        "body",
        "scroll",
        "isotope",
        "preloader",
        "function",
        "javascript",
        "mit license",
        "typeof module",
        "gplv3",
        "license",
        "copyright",
        "metafizzy",
        "math",
        "typeof",
        "typeerror",
        "hidden",
        "show",
        "typeof n",
        "version",
        "hide",
        "focusin",
        "focusout",
        "shown",
        "startr",
        "endr",
        "federico zivolo",
        "distributed",
        "html",
        "statict",
        "flip",
        "regexp",
        "null",
        "void",
        "width",
        "object",
        "pseudo",
        "child",
        "class",
        "date",
        "accept",
        "webpackrequire",
        "name",
        "number",
        "arraybuffer",
        "iterator",
        "typedarray",
        "prototype",
        "string",
        "index",
        "meta",
        "target",
        "infinity",
        "zero",
        "epsilon",
        "observer",
        "android",
        "trim",
        "enumerate",
        "freeze",
        "internal",
        "bind",
        "window",
        "next",
        "find",
        "this",
        "rest",
        "middle",
        "canvas",
        "slidercaptcha",
        "createelement",
        "textdanger",
        "plugin",
        "rgba",
        "imagedata",
        "false",
        "touchstart",
        "trident",
        "applewebkit",
        "safari",
        "base",
        "presto",
        "gecko",
        "khtml",
        "micromessenger",
        "typeof e",
        "swiper",
        "most",
        "september",
        "customevent",
        "image",
        "typeof c",
        "twitter",
        "bootstrap",
        "rolemenu",
        "typeof f",
        "typeof g",
        "cookie plugin",
        "https",
        "klaus hartl",
        "register",
        "nodecommonjs",
        "factory",
        "jquery",
        "write",
        "typeof b",
        "array",
        "sufeffxa0",
        "attr",
        "\u706b\u7bad\u5185\u6d4b\u7b7e\u540d",
        "0x1d9131",
        "0x180bcc",
        "0x4b6177",
        "0x13f349",
        "0x3bcb54",
        "0xbbe80d",
        "0x57b7de",
        "0x2ea74e",
        "0x4fb0f2",
        "0x25f113",
        "push",
        "shift",
        "tencent",
        "barrio",
        "slice",
        "symbol",
        "typeof window",
        "maximum",
        "typeof symbol",
        "udc66udc67",
        "ud83d",
        "ufe0f",
        "ud83e",
        "udc68udc69",
        "udfcbudfcc",
        "u2640u2642",
        "ufe0fg",
        "ud83dudc6cud83c",
        "ud83dudc6dud83c",
        "welcome",
        "datav66d78640",
        "datav2f8052f5",
        "90deg",
        "datav5f1e575c",
        "datave97d7462",
        "helvetica neue",
        "helvetica",
        "10px",
        "pingfang sc",
        "arial",
        "45deg",
        "typenumber",
        "opacity0",
        "mozopacity0",
        "khtmlopacity0",
        "opacity100",
        "event",
        "boolean",
        "uint8array",
        "errordetails",
        "info",
        "checker",
        "generator",
        "blink",
        "keepalive",
        "4096",
        "unknown",
        "meteor",
        "rhino",
        "mini",
        "comment",
        "verify",
        "yeke",
        "codec",
        "media",
        "live",
        "speed",
        "headname",
        "axiostimeout",
        "apiurl",
        "bmi86hjtsk",
        "root",
        "length",
        "indexof",
        "x0ax20x20x20x20",
        "location",
        "0x10",
        "0x18",
        "history",
        "config",
        "cookie",
        "onload",
        "video",
        "afunction",
        "indexnotice",
        "sitehome",
        "x20trnf",
        "please",
        "strong"
      ],
      "references": [
        "xfe-URL-sys95.com-stix2-2.1-export.json",
        "https://2001.habyc.com/?channelNo=2001#/home",
        "https://sdk.51.la/event/js-sdk-event.min.js?u=JdoUNv3VSW0GHUpw",
        "https://2001.habyc.com/static/js/chunk-7d5d3bac.efb700c7.js",
        "https://sdk.51.la/js-sdk-pro.min.js",
        "https://2001.habyc.com/js/config.js",
        "xfe-URL-2001.habyc.com-stix2-2.1-export.json",
        "https://2001.habyc.com/static/js/chunk-vendors.9d7684f4.js",
        "xfe-URL-habyc.com-stix2-2.1-export.json",
        "https://2001.habyc.com/static/css/chunk-vendors.6a41b67e.css",
        "https://2001.habyc.com/static/css/app.88afcfd8.css",
        "https://2001.habyc.com/static/css/chunk-7d5d3bac.e1a32335.css",
        "https://2001.dwlww.com/?channelNo=2001#/home",
        "https://2001.dwlww.com/static/js/chunk-7d5d3bac.efb700c7.js",
        "https://2001.dwlww.com/js/config.js",
        "https://2001.dwlww.com/static/js/chunk-vendors.9d7684f4.js",
        "https://2001.dwlww.com/static/js/app.9d5d18d7.js",
        "https://2001.dwlww.com/static/css/chunk-vendors.6a41b67e.css",
        "https://2001.dwlww.com/static/css/app.88afcfd8.css",
        "https://2001.dwlww.com/static/css/chunk-7d5d3bac.e1a32335.css",
        "https://www.tidio.com/talk/kv6vcosd7tmhsetmarsoawzaglejnny4",
        "https://chatting.page/kv6vcosd7tmhsetmarsoawzaglejnny4",
        "https://widget-v4.tidiochat.com/code/kv6vcosd7tmhsetmarsoawzaglejnny4.js",
        "https://m4244.com:35003/",
        "https://www.8098.app:21568/?agent=7691755704",
        "https://www.8098.app:21568/js/jquery-1.11.3.min.js",
        "https://www.8098.app:21568/js/xinstall_inner_e.min.js?v=1004",
        "https://app.ynsdty.cn//package/GmCC6WISh",
        "https://app.ynsdty.cn/dist/js/jquery.min.js",
        "https://app.ynsdty.cn/dist/js/jquery.cookie.js",
        "https://app.ynsdty.cn/dist/vendors/bootstrap/js/bootstrap.min.js",
        "https://app.ynsdty.cn/dist/vendors/swiper/swiper.min.js",
        "https://app.ynsdty.cn/dist/js/app.base.js",
        "https://app.ynsdty.cn/dist/js/longbow.slidercaptcha.js",
        "https://app.ynsdty.cn/dist/vendors/core-js/core.js",
        "xfe-URL-sun.net.hk-stix2-2.1-export.json",
        "https://www.sunnetwork.com.sg/sun_21/js/vendor/jquery-3.5.0.min.js",
        "https://www.sunnetwork.com.sg/sun_21/js/popper.min.js",
        "https://www.sunnetwork.com.sg/sun_21/js/bootstrap.min.js",
        "https://www.sunnetwork.com.sg/sun_21/js/isotope.pkgd.min.js",
        "https://www.sunnetwork.com.sg/sun_21/js/imagesloaded.pkgd.min.js",
        "https://www.sunnetwork.com.sg/sun_21/js/main.js",
        "https://www.sunnetwork.com.sg/sun_21/js/ajax-form.js",
        "https://www.sunnetwork.com.sg/sun_21/js/slick.min.js"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1547",
          "name": "Boot or Logon Autostart Execution",
          "display_name": "T1547 - Boot or Logon Autostart Execution"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 8,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "adjadex1@gmail.com",
        "id": "187163",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 901,
        "URL": 5740,
        "hostname": 2218,
        "FileHash-SHA256": 1686,
        "FileHash-MD5": 3
      },
      "indicator_count": 10548,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 69,
      "modified_text": "1430 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "625f3287d722d8d85700b75d",
      "name": "Leaseweb.com - malware hosting",
      "description": "function D(t,e,n), as well as window.com, has been frozen by a single function, as part of a series of \"snoopers' checks\"...",
      "modified": "2022-05-19T00:00:49.028000",
      "created": "2022-04-19T22:07:03.024000",
      "tags": [
        "11px center",
        "html",
        "typetext",
        "typeurl",
        "typeemail",
        "typetel",
        "typenumber",
        "typedate",
        "color",
        "marketo forms",
        "cross domain",
        "null",
        "click",
        "forceclose",
        "lightbox",
        "slideshow",
        "controls",
        "hide",
        "safari",
        "image",
        "mozilla",
        "explorer",
        "entity",
        "linear",
        "date",
        "jquery",
        "iframe",
        "close",
        "loops",
        "class",
        "stretch",
        "false",
        "function",
        "abbb",
        "typeerror",
        "boolean",
        "body",
        "object",
        "array",
        "regexp",
        "bind",
        "error",
        "void",
        "hammer",
        "form",
        "this",
        "views slideshow",
        "zindex1",
        "ajax",
        "href",
        "default",
        "thumb",
        "msgesture",
        "mspointerdown",
        "next",
        "stop",
        "type",
        "index",
        "event",
        "snapabugcbmbtn",
        "chat",
        "hidden",
        "leaf",
        "open",
        "dump",
        "window",
        "win32",
        "footer",
        "front",
        "drupal",
        "command",
        "implement",
        "copyright",
        "route",
        "foundation",
        "thecookie",
        "remove",
        "example",
        "backport",
        "grab",
        "span",
        "import",
        "attr",
        "string",
        "invalid json",
        "domparser",
        "number",
        "script",
        "closure library",
        "symbol",
        "array int8array",
        "caregexp",
        "legacy",
        "boardman",
        "fontface",
        "typeof d",
        "promise",
        "parseint",
        "marketo",
        "rangeerror",
        "uint8array",
        "typeof b",
        "buffer",
        "path",
        "takk",
        "kiitos",
        "buttons};kb(convertedmessage);break;case\"/sys\":var",
        "acum",
        "ufunction",
        "ffunction",
        "gfunction",
        "mchtd",
        "cancel",
        "thank",
        "enter",
        "please",
        "cobrowsing",
        "accept",
        "decline",
        "back",
        "comment",
        "grazie",
        "klik",
        "super",
        "dados",
        "hello",
        "vd",
        "reduceright",
        "trackevent",
        "lead",
        "query",
        "videos",
        "leaseweb",
        "trackpageview",
        "contact",
        "download",
        "metal",
        "code",
        "functional",
        "member",
        "hnew regexp",
        "qfunction",
        "adview",
        "addbillinginfo",
        "addtocart",
        "addtolist",
        "install",
        "cookiebot",
        "iabv2",
        "jsonversion",
        "cookie script",
        "methodstrict",
        "ticket",
        "id attribute",
        "cookiebot setup",
        "cookieconsent",
        "customevent",
        "09af",
        "ver0",
        "tag0",
        "extdata0",
        "ua ch",
        "invalid",
        "iterator",
        "service",
        "phonenumber",
        "facebook",
        "meta",
        "ytconfig",
        "edge",
        "swhealthlog",
        "logsdatabasev2",
        "trident",
        "android",
        "infinity",
        "pnull",
        "style",
        "ctnull",
        "post",
        "uint32array",
        "fanull",
        "license",
        "ynull",
        "config"
      ],
      "references": [
        "https://consent.cookiebot.com/1e27dadb-e278-4c02-aa4f-43f9222c4fbb/cc.js?renew=false&referer=www.leaseweb.com&culture=en&dnt=false",
        "https://j.clarity.ms/s/0.6.34/clarity.js",
        "https://www.google-analytics.com/plugins/ua/linkid.js",
        "https://www.youtube.com/s/player/19eb72e4/www-widgetapi.vflset/www-widgetapi.js",
        "https://www.youtube.com/iframe_api",
        "https://connect.facebook.net/signals/config/399164440484826?v=2.9.57&r=stable",
        "https://bat.bing.com/bat.js",
        "https://consent.cookiebot.com/uc.js?cbid=1e27dadb-e278-4c02-aa4f-43f9222c4fbb&culture=en",
        "https://snap.licdn.com/li.lms-analytics/insight.min.js",
        "https://www.googletagmanager.com/gtm.js?id=GTM-NWPHSS",
        "https://storage.googleapis.com/snapengage-eu/js/e9219576-8f74-40b5-8b6f-bbad33f6ca57.js",
        "https://munchkin.marketo.net/161/munchkin.js",
        "https://app-lon04.marketo.com/js/forms2/js/forms2.min.js",
        "https://munchkin.marketo.net/munchkin.js",
        "https://www.leaseweb.com/sites/all/modules/custom/lsw_marketo/js/lsw_marketo_forms.js",
        "https://use.fortawesome.com/03018d9d.js",
        "https://googleads.g.doubleclick.net/pagead/viewthroughconversion/1001847692/?random=1650405011980&cv=9&fst=1650405011980&num=1&bg=ffffff&guid=ON&resp=GooglemKTybQhCsO&eid=376635471&u_h=844&u_w=390&u_ah=844&u_aw=390&u_cd=32&u_his=1&u_tz=-240&u_java=false&u_nplug=0&u_nmime=0&gtm=2wg4i1&sendb=1&ig=1&frm=0&url=https%3A%2F%2Fwww.leaseweb.com%2F&tiba=Leaseweb%20%7C%20Global%20Hosted%20Infrastructure%20(IaaS)%20and%20Cloud%20Solutions&hn=www.googleadservices.com&async=1&rfmt=3&fmt=4",
        "https://googleads.g.doubleclick.net/pagead/viewthroughconversion/952389962/?random=1650405011982&cv=9&fst=1650405011982&num=1&bg=ffffff&guid=ON&resp=GooglemKTybQhCsO&eid=376635471&u_h=844&u_w=390&u_ah=844&u_aw=390&u_cd=32&u_his=1&u_tz=-240&u_java=false&u_nplug=0&u_nmime=0&gtm=2wg4i1&sendb=1&ig=1&frm=0&url=https%3A%2F%2Fwww.leaseweb.com%2F&tiba=Leaseweb%20%7C%20Global%20Hosted%20Infrastructure%20(IaaS)%20and%20Cloud%20Solutions&hn=www.googleadservices.com&async=1&rfmt=3&fmt=4",
        "https://eu.snapengage.com/chatjs/ServiceGetConfig?w=e9219576-8f74-40b5-8b6f-bbad33f6ca57",
        "https://eu.snapengage.com/chatjs/servicegetproactivegeodata?w=e9219576-8f74-40b5-8b6f-bbad33f6ca57",
        "https://bat.bing.com/p/action/5602105.js",
        "https://eu.snapengage.com/chatjs/servicegetallavailableagents?w=e9219576-8f74-40b5-8b6f-bbad33f6ca57&t=1",
        "https://www.googleadservices.com/pagead/conversion_async.js",
        "https://www.leaseweb.com/sites/default/files/js/js_kwxcSFD2Y0_BPtdJClYUy5H8THI_5EycUmIgIGWaGYs.js",
        "https://www.leaseweb.com/sites/default/files/js/js_wcSNEXVJ4Xjhkf8qhMguEPZJTDTMNmPaJM-YWdAOhQE.js",
        "https://www.leaseweb.com/sites/default/files/js/js_kI_QwKJlaBz9CzQdENdUBFiEl4aehfjf4_-9taiwcCE.js",
        "https://www.leaseweb.com/sites/default/files/js/js_zoLA7TweXam0kYiqJrXepqBWmyDoP1sLSlHoZcveFnY.js",
        "https://www.leaseweb.com/sites/default/files/js/js_6FowaFXT9bT78hf9earPdGcdTmvsFiaBzKgFl9P4fSo.js",
        "https://www.leaseweb.com/sites/default/files/js/js_6lTJ_m6ahwXas7Efbw8ZYEMSaecrGw8ilNALfvIPNUw.js",
        "https://analytics.twitter.com/i/adsct?type=javascript&version=2.0.4&p_id=Twitter&p_user_id=0&txn_id=nxsfu&events=%5B%5B%22pageview%22%2Cnull%5D%5D&tw_sale_amount=0&tw_order_quantity=0&tw_iframe_status=0&event_id=511b6f48-2639-478c-a251-b09fcbae76e7&tw_document_href=https%3A%2F%2Fwww.leaseweb.com%2F&tpx_cb=twttr.conversion.loadPixels",
        "https://bid.g.doubleclick.net/xbbe/pixel?d=KAE",
        "https://consentcdn.cookiebot.com/sdk/bc-v4.min.html",
        "https://app-lon04.marketo.com/index.php/form/XDFrame",
        "https://app-lon04.marketo.com/js/forms2/css/forms2-theme-plain.css",
        "https://www.leaseweb.com/sites/default/files/css/css_47DEQpj8HBSa-_TImW-5JCeuQeRkm5NMpJWZG3hSuFU.css",
        "https://www.leaseweb.com/sites/default/files/css/css_7CYF9En6DNp6AojfSKnT8USKR3GvzPwznmTqLTKT9VM.css"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "Tunisia"
      ],
      "malware_families": [
        {
          "id": "Ajax",
          "display_name": "Ajax",
          "target": null
        },
        {
          "id": "Kiitos",
          "display_name": "Kiitos",
          "target": null
        },
        {
          "id": "Takk",
          "display_name": "Takk",
          "target": null
        },
        {
          "id": "Acum",
          "display_name": "Acum",
          "target": null
        },
        {
          "id": "buttons};kb(convertedMessage);break;case\"/SYS\":var",
          "display_name": "buttons};kb(convertedMessage);break;case\"/SYS\":var",
          "target": null
        },
        {
          "id": "Vd",
          "display_name": "Vd",
          "target": null
        },
        {
          "id": "ReduceRight",
          "display_name": "ReduceRight",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1056",
          "name": "Input Capture",
          "display_name": "T1056 - Input Capture"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1106",
          "name": "Native API",
          "display_name": "T1106 - Native API"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1176",
          "name": "Browser Extensions",
          "display_name": "T1176 - Browser Extensions"
        },
        {
          "id": "T1490",
          "name": "Inhibit System Recovery",
          "display_name": "T1490 - Inhibit System Recovery"
        },
        {
          "id": "T1547",
          "name": "Boot or Logon Autostart Execution",
          "display_name": "T1547 - Boot or Logon Autostart Execution"
        },
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 4,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "adjadex1@gmail.com",
        "id": "187163",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 648,
        "domain": 469,
        "URL": 2037,
        "FileHash-SHA256": 705,
        "email": 7
      },
      "indicator_count": 3866,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 68,
      "modified_text": "1431 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "https://ra.prototype.compare",
    "type": "URL"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "https://ra.prototype.compare",
    "type": "URL",
    "found": false,
    "verdict": "clean",
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1776629393.622769
}