{
  "type": "URL",
  "indicator": "https://res.public.onecdn.static.microsoft/designer/designerapp/create-moduleThemeSuggestions5",
  "general": {
    "sections": [
      "general",
      "url_list",
      "http_scans",
      "screenshot"
    ],
    "indicator": "https://res.public.onecdn.static.microsoft/designer/designerapp/create-moduleThemeSuggestions5",
    "type": "url",
    "type_title": "URL",
    "validation": [],
    "base_indicator": {
      "id": 4348824099,
      "indicator": "https://res.public.onecdn.static.microsoft/designer/designerapp/create-moduleThemeSuggestions5",
      "type": "URL",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 5,
      "pulses": [
        {
          "id": "6a03cc521e13c5d6d34555d0",
          "name": "Judgement Day. VirusTotal report                    for index.html",
          "description": "[Apple.com has sent a series of \"fl flushMessages\" to its servers, but what exactly is the data and what is it going to get out of the system and how does it feel?]",
          "modified": "2026-05-15T10:22:00.139000",
          "created": "2026-05-13T00:56:50.182000",
          "tags": [
            "darwin kernel",
            "version",
            "wed feb",
            "apfs4kobjs",
            "instagram",
            "mosaic",
            "free",
            "get http",
            "dns resolutions",
            "ip traffic",
            "pattern domains",
            "memory pattern",
            "urls https",
            "tls sni",
            "algorithm",
            "key identifier",
            "x509v3 subject",
            "v3 serial",
            "number",
            "cus olet",
            "encrypt cnr13",
            "validity",
            "subject public",
            "key info",
            "performs dns",
            "https",
            "urls",
            "united",
            "mitre attack",
            "network info",
            "processes extra",
            "t1055 process",
            "layer protocol",
            "overview",
            "phishing",
            "defense evasion",
            "next",
            "default",
            "parent pid",
            "full path",
            "command line",
            "k netsvcs",
            "k localservice",
            "s w32time",
            "event provider",
            "device",
            "registry keys"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1095",
              "name": "Non-Application Layer Protocol",
              "display_name": "T1095 - Non-Application Layer Protocol"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 132,
            "FileHash-MD5": 43,
            "FileHash-SHA1": 6,
            "hostname": 364,
            "IPv4": 75,
            "URL": 574,
            "Mutex": 1,
            "FileHash-SHA256": 404
          },
          "indicator_count": 1599,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 67,
          "modified_text": "17 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6a04e84167efe8b5fa43e0ca",
          "name": "cve-2020-0601 + spoof signing",
          "description": "CVE2020-0601 is a Curveball vulnerability that could allow attackers to spoof signatures and is a high cryptographic validation flaw. Per NIST, \"A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates. An attacker could exploit the vulnerability by using a spoofed code-signing certificate to sign a malicious executable, making it appear the file was from a trusted, legitimate source, aka 'Windows CryptoAPI Spoofing Vulnerability',\".",
          "modified": "2026-05-14T01:04:28.762000",
          "created": "2026-05-13T21:08:17.669000",
          "tags": [
            "indicators show",
            "search",
            "type indicator",
            "role title",
            "added active",
            "related pulses",
            "instagram",
            "identifier",
            "cve-2020-0601"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "CVE": 51,
            "hostname": 147,
            "FileHash-SHA1": 4,
            "domain": 119,
            "URL": 169,
            "IPv4": 282,
            "FileHash-MD5": 3,
            "FileHash-SHA256": 283
          },
          "indicator_count": 1058,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 67,
          "modified_text": "18 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6a04e8423bba51f1e0ff3030",
          "name": "cve-2020-0601 + spoof signing",
          "description": "CVE2020-0601 is a Curveball vulnerability that could allow attackers to spoof signatures and is a high cryptographic validation flaw. Per NIST, \"A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates. An attacker could exploit the vulnerability by using a spoofed code-signing certificate to sign a malicious executable, making it appear the file was from a trusted, legitimate source, aka 'Windows CryptoAPI Spoofing Vulnerability',\".",
          "modified": "2026-05-13T22:50:49.596000",
          "created": "2026-05-13T21:08:18.159000",
          "tags": [
            "indicators show",
            "search",
            "type indicator",
            "role title",
            "added active",
            "related pulses",
            "instagram",
            "identifier",
            "cve-2020-0601"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "CVE": 51,
            "hostname": 147,
            "FileHash-SHA1": 4,
            "domain": 119,
            "URL": 169,
            "IPv4": 281,
            "FileHash-MD5": 3,
            "FileHash-SHA256": 283
          },
          "indicator_count": 1057,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 67,
          "modified_text": "18 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6a04e83b9a762101e54d6a4f",
          "name": "cve-2020-0601 + spoof signing",
          "description": "CVE2020-0601 is a Curveball vulnerability that could allow attackers to spoof signatures and is a high cryptographic validation flaw. Per NIST, \"A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates. An attacker could exploit the vulnerability by using a spoofed code-signing certificate to sign a malicious executable, making it appear the file was from a trusted, legitimate source, aka 'Windows CryptoAPI Spoofing Vulnerability',\".",
          "modified": "2026-05-13T22:50:48.345000",
          "created": "2026-05-13T21:08:11.231000",
          "tags": [
            "indicators show",
            "search",
            "type indicator",
            "role title",
            "added active",
            "related pulses",
            "instagram",
            "identifier",
            "cve-2020-0601"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 1,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "CVE": 53,
            "hostname": 147,
            "FileHash-SHA1": 24,
            "domain": 119,
            "URL": 167,
            "IPv4": 281,
            "FileHash-MD5": 15,
            "FileHash-SHA256": 469,
            "Mutex": 2
          },
          "indicator_count": 1277,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 67,
          "modified_text": "18 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "69fd8fcf280068179ca6d174",
          "name": "Over 1 Million Comm. Files. 158 referring malic tagged.",
          "description": "0befb3ee094b270c981816a69da00a000572f38d71772578cd7e2001d, as part of a series of events.\nacroipm2.adobe.[com]\nadobe.[com]",
          "modified": "2026-05-08T07:59:04.198000",
          "created": "2026-05-08T07:25:03.312000",
          "tags": [
            "win32 dll",
            "win32 exe",
            "com laude",
            "readermessages",
            "microsoft",
            "ltd dba",
            "nomiq",
            "network capture",
            "text",
            "gzip",
            "first",
            "thumbprint",
            "code",
            "email",
            "san jose",
            "server",
            "registrar abuse",
            "admin country",
            "expiration date",
            "registry domain",
            "registrar iana",
            "date",
            "iana id",
            "contact phone",
            "dnssec",
            "domain status",
            "registrar url",
            "registrar whois",
            "cname",
            "aaaa",
            "ttl value",
            "key identifier",
            "full name",
            "v3 serial",
            "number",
            "cus odigicert",
            "inc cndigicert",
            "global g3",
            "tls ecc",
            "sha384",
            "ca1 validity",
            "info",
            "domain",
            "expiry date",
            "united",
            "update date"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1056",
              "name": "Input Capture",
              "display_name": "T1056 - Input Capture"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 1,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 145,
            "FileHash-SHA1": 159,
            "FileHash-SHA256": 546,
            "IPv4": 314,
            "URL": 164,
            "domain": 52,
            "hostname": 210,
            "email": 6,
            "IPv6": 2,
            "CIDR": 6
          },
          "indicator_count": 1604,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 66,
          "modified_text": "24 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        }
      ],
      "references": [],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 0
        },
        "other": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 3834
        }
      }
    },
    "false_positive": [],
    "alexa": "http://www.alexa.com/siteinfo/static.microsoft",
    "whois": "http://whois.domaintools.com/static.microsoft",
    "domain": "static.microsoft",
    "hostname": "res.public.onecdn.static.microsoft"
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 5,
  "pulses": [
    {
      "id": "6a03cc521e13c5d6d34555d0",
      "name": "Judgement Day. VirusTotal report                    for index.html",
      "description": "[Apple.com has sent a series of \"fl flushMessages\" to its servers, but what exactly is the data and what is it going to get out of the system and how does it feel?]",
      "modified": "2026-05-15T10:22:00.139000",
      "created": "2026-05-13T00:56:50.182000",
      "tags": [
        "darwin kernel",
        "version",
        "wed feb",
        "apfs4kobjs",
        "instagram",
        "mosaic",
        "free",
        "get http",
        "dns resolutions",
        "ip traffic",
        "pattern domains",
        "memory pattern",
        "urls https",
        "tls sni",
        "algorithm",
        "key identifier",
        "x509v3 subject",
        "v3 serial",
        "number",
        "cus olet",
        "encrypt cnr13",
        "validity",
        "subject public",
        "key info",
        "performs dns",
        "https",
        "urls",
        "united",
        "mitre attack",
        "network info",
        "processes extra",
        "t1055 process",
        "layer protocol",
        "overview",
        "phishing",
        "defense evasion",
        "next",
        "default",
        "parent pid",
        "full path",
        "command line",
        "k netsvcs",
        "k localservice",
        "s w32time",
        "event provider",
        "device",
        "registry keys"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1095",
          "name": "Non-Application Layer Protocol",
          "display_name": "T1095 - Non-Application Layer Protocol"
        },
        {
          "id": "T1573",
          "name": "Encrypted Channel",
          "display_name": "T1573 - Encrypted Channel"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 1,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 132,
        "FileHash-MD5": 43,
        "FileHash-SHA1": 6,
        "hostname": 364,
        "IPv4": 75,
        "URL": 574,
        "Mutex": 1,
        "FileHash-SHA256": 404
      },
      "indicator_count": 1599,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 67,
      "modified_text": "17 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6a04e84167efe8b5fa43e0ca",
      "name": "cve-2020-0601 + spoof signing",
      "description": "CVE2020-0601 is a Curveball vulnerability that could allow attackers to spoof signatures and is a high cryptographic validation flaw. Per NIST, \"A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates. An attacker could exploit the vulnerability by using a spoofed code-signing certificate to sign a malicious executable, making it appear the file was from a trusted, legitimate source, aka 'Windows CryptoAPI Spoofing Vulnerability',\".",
      "modified": "2026-05-14T01:04:28.762000",
      "created": "2026-05-13T21:08:17.669000",
      "tags": [
        "indicators show",
        "search",
        "type indicator",
        "role title",
        "added active",
        "related pulses",
        "instagram",
        "identifier",
        "cve-2020-0601"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "CVE": 51,
        "hostname": 147,
        "FileHash-SHA1": 4,
        "domain": 119,
        "URL": 169,
        "IPv4": 282,
        "FileHash-MD5": 3,
        "FileHash-SHA256": 283
      },
      "indicator_count": 1058,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 67,
      "modified_text": "18 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6a04e8423bba51f1e0ff3030",
      "name": "cve-2020-0601 + spoof signing",
      "description": "CVE2020-0601 is a Curveball vulnerability that could allow attackers to spoof signatures and is a high cryptographic validation flaw. Per NIST, \"A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates. An attacker could exploit the vulnerability by using a spoofed code-signing certificate to sign a malicious executable, making it appear the file was from a trusted, legitimate source, aka 'Windows CryptoAPI Spoofing Vulnerability',\".",
      "modified": "2026-05-13T22:50:49.596000",
      "created": "2026-05-13T21:08:18.159000",
      "tags": [
        "indicators show",
        "search",
        "type indicator",
        "role title",
        "added active",
        "related pulses",
        "instagram",
        "identifier",
        "cve-2020-0601"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "CVE": 51,
        "hostname": 147,
        "FileHash-SHA1": 4,
        "domain": 119,
        "URL": 169,
        "IPv4": 281,
        "FileHash-MD5": 3,
        "FileHash-SHA256": 283
      },
      "indicator_count": 1057,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 67,
      "modified_text": "18 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6a04e83b9a762101e54d6a4f",
      "name": "cve-2020-0601 + spoof signing",
      "description": "CVE2020-0601 is a Curveball vulnerability that could allow attackers to spoof signatures and is a high cryptographic validation flaw. Per NIST, \"A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates. An attacker could exploit the vulnerability by using a spoofed code-signing certificate to sign a malicious executable, making it appear the file was from a trusted, legitimate source, aka 'Windows CryptoAPI Spoofing Vulnerability',\".",
      "modified": "2026-05-13T22:50:48.345000",
      "created": "2026-05-13T21:08:11.231000",
      "tags": [
        "indicators show",
        "search",
        "type indicator",
        "role title",
        "added active",
        "related pulses",
        "instagram",
        "identifier",
        "cve-2020-0601"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 1,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "CVE": 53,
        "hostname": 147,
        "FileHash-SHA1": 24,
        "domain": 119,
        "URL": 167,
        "IPv4": 281,
        "FileHash-MD5": 15,
        "FileHash-SHA256": 469,
        "Mutex": 2
      },
      "indicator_count": 1277,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 67,
      "modified_text": "18 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "69fd8fcf280068179ca6d174",
      "name": "Over 1 Million Comm. Files. 158 referring malic tagged.",
      "description": "0befb3ee094b270c981816a69da00a000572f38d71772578cd7e2001d, as part of a series of events.\nacroipm2.adobe.[com]\nadobe.[com]",
      "modified": "2026-05-08T07:59:04.198000",
      "created": "2026-05-08T07:25:03.312000",
      "tags": [
        "win32 dll",
        "win32 exe",
        "com laude",
        "readermessages",
        "microsoft",
        "ltd dba",
        "nomiq",
        "network capture",
        "text",
        "gzip",
        "first",
        "thumbprint",
        "code",
        "email",
        "san jose",
        "server",
        "registrar abuse",
        "admin country",
        "expiration date",
        "registry domain",
        "registrar iana",
        "date",
        "iana id",
        "contact phone",
        "dnssec",
        "domain status",
        "registrar url",
        "registrar whois",
        "cname",
        "aaaa",
        "ttl value",
        "key identifier",
        "full name",
        "v3 serial",
        "number",
        "cus odigicert",
        "inc cndigicert",
        "global g3",
        "tls ecc",
        "sha384",
        "ca1 validity",
        "info",
        "domain",
        "expiry date",
        "united",
        "update date"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1056",
          "name": "Input Capture",
          "display_name": "T1056 - Input Capture"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 1,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 1,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 145,
        "FileHash-SHA1": 159,
        "FileHash-SHA256": 546,
        "IPv4": 314,
        "URL": 164,
        "domain": 52,
        "hostname": 210,
        "email": 6,
        "IPv6": 2,
        "CIDR": 6
      },
      "indicator_count": 1604,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 66,
      "modified_text": "24 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "https://res.public.onecdn.static.microsoft/designer/designerapp/create-moduleThemeSuggestions5",
    "type": "URL"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "https://res.public.onecdn.static.microsoft/designer/designerapp/create-moduleThemeSuggestions5",
    "type": "URL",
    "found": false,
    "verdict": "clean",
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780332737.409285
}