{
  "type": "URL",
  "indicator": "https://resonantcavity.com/voloco/",
  "general": {
    "sections": [
      "general",
      "url_list",
      "http_scans",
      "screenshot"
    ],
    "indicator": "https://resonantcavity.com/voloco/",
    "type": "url",
    "type_title": "URL",
    "validation": [],
    "base_indicator": {
      "id": 3820349420,
      "indicator": "https://resonantcavity.com/voloco/",
      "type": "URL",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 5,
      "pulses": [
        {
          "id": "6a141c15cfec672ba39e6a17",
          "name": "S0094 clone credit score blue ",
          "description": "",
          "modified": "2026-05-25T10:03:13.774000",
          "created": "2026-05-25T09:53:25.429000",
          "tags": [
            "falcon sandbox",
            "sha256",
            "sha1",
            "et tor",
            "known tor",
            "relayrouter",
            "exit",
            "node traffic",
            "misc attack",
            "pattern match",
            "ascii text",
            "null",
            "hybrid",
            "refresh",
            "body",
            "span",
            "june",
            "click",
            "date",
            "strings",
            "error",
            "tools",
            "look",
            "verify",
            "restart",
            "contact",
            "historical ssl",
            "referrer",
            "httponly",
            "path",
            "secure",
            "maxage31557600",
            "expiresmon",
            "samesitenone",
            "expireswed",
            "etag w",
            "setcookie dids",
            "maxage864000",
            "http response",
            "final url",
            "serving ip",
            "address",
            "status code",
            "html document",
            "history",
            "utc names",
            "html info",
            "title assurance",
            "meta tags",
            "script tags",
            "anchor hrefs",
            "code",
            "requestid",
            "hostid",
            "xml file",
            "accessdenied",
            "message",
            "signature",
            "expires",
            "awsaccesskeyid",
            "log id",
            "gmtn",
            "passive dns",
            "urls",
            "digicert global",
            "g2 tls",
            "rsa sha256",
            "tls web",
            "full name",
            "self",
            "false",
            "united",
            "as8075",
            "unknown",
            "gmt server",
            "scan endpoints",
            "all scoreblue",
            "ipv4",
            "pulse submit",
            "url analysis",
            "url https",
            "pulse pulses",
            "http",
            "ip address",
            "related nids",
            "files location",
            "aaaa",
            "meta",
            "link",
            "search",
            "creation date",
            "wheels up",
            "moved",
            "homepage",
            "servers",
            "service",
            "name servers",
            "hostname",
            "next",
            "japan unknown",
            "as2510 fujitsu",
            "status",
            "page",
            "ltd dba",
            "com laude",
            "record value",
            "ireland",
            "germany",
            "australia",
            "as44786 adobe",
            "whitelisted",
            "win32",
            "present may",
            "trojan",
            "karaganye",
            "regsetvalueexa",
            "regdword",
            "default",
            "show",
            "presto",
            "regbinary",
            "medium",
            "create c",
            "query",
            "double",
            "malware",
            "copy",
            "karagany",
            "write",
            "showing",
            "as35908 krypt",
            "as45102 alibaba",
            "hong kong",
            "data service",
            "script script",
            "div div",
            "title",
            "entries",
            "files",
            "japan asn",
            "dns resolutions",
            "memory pattern",
            "ip traffic",
            "domains",
            "urls https",
            "files c",
            "filesgoogle c",
            "written c",
            "extensions",
            "as20446",
            "as14061",
            "emails",
            "threat roundup",
            "bashlite",
            "jupyter rising",
            "vmware",
            "security blog",
            "april",
            "september",
            "december",
            "january",
            "enemybot",
            "core"
          ],
          "references": [
            "Assurance",
            "IDS Detections: Trojan Internet Connectivity Check TrojanDownloader.Win32/Karagany.H checkin 2",
            "IDS Detections: Query for .cc TLD Suspicious User-Agent (Presto) Double User-Agent (User-Agent User-Agent)",
            "Alerts: network_icmp modifies_proxy_wpad network_http suspicious_tld allocates_rwx creates_exe antivm_network_adapters checks_debugger",
            "Domains Contacted: simplesausages.cx.cc adobe.com",
            "https://test2.ditproducts.com/dat/wannacry1.html",
            "http://email.critizr.com/asm/unsubscribe/?user_id=1464008&data=anW5I3azQrbEzQ84_I2zsSfJkpp1WTl08_zW0p5h4i5oMDAwdTAwMIqknJPIfal-ld9TvXgRLVf_F",
            "https://www.anyxxxtube.net/search-porn/tsara-brashears/",
            "CVE-2023-22518 | CVE-2023-4966"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America",
            "Netherlands"
          ],
          "malware_families": [
            {
              "id": "ALF:JASYP:TrojanDownloader:Win32/Karagany!atmn",
              "display_name": "ALF:JASYP:TrojanDownloader:Win32/Karagany!atmn",
              "target": null
            },
            {
              "id": "Win32:Karagany-D\\ [Trj]",
              "display_name": "Win32:Karagany-D\\ [Trj]",
              "target": null
            },
            {
              "id": "Win.Trojan.Xtoober-650",
              "display_name": "Win.Trojan.Xtoober-650",
              "target": null
            },
            {
              "id": "Trojan:Win32/Startpage.SS",
              "display_name": "Trojan:Win32/Startpage.SS",
              "target": "/malware/Trojan:Win32/Startpage.SS"
            },
            {
              "id": "Win.Packed.Pincav-7537597-0",
              "display_name": "Win.Packed.Pincav-7537597-0",
              "target": null
            },
            {
              "id": "Trojan.Karagany - S0094",
              "display_name": "Trojan.Karagany - S0094",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1568",
              "name": "Dynamic Resolution",
              "display_name": "T1568 - Dynamic Resolution"
            },
            {
              "id": "T1040",
              "name": "Network Sniffing",
              "display_name": "T1040 - Network Sniffing"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1574.002",
              "name": "DLL Side-Loading",
              "display_name": "T1574.002 - DLL Side-Loading"
            },
            {
              "id": "TA0002",
              "name": "Execution",
              "display_name": "TA0002 - Execution"
            },
            {
              "id": "TA0003",
              "name": "Persistence",
              "display_name": "TA0003 - Persistence"
            },
            {
              "id": "TA0004",
              "name": "Privilege Escalation",
              "display_name": "TA0004 - Privilege Escalation"
            },
            {
              "id": "TA0005",
              "name": "Defense Evasion",
              "display_name": "TA0005 - Defense Evasion"
            },
            {
              "id": "TA0008",
              "name": "Lateral Movement",
              "display_name": "TA0008 - Lateral Movement"
            },
            {
              "id": "TA0011",
              "name": "Command and Control",
              "display_name": "TA0011 - Command and Control"
            }
          ],
          "industries": [
            "Healthcare",
            "Technology",
            "Telecommunications",
            "Finance - Insurance Sector"
          ],
          "TLP": "green",
          "cloned_from": "6665d55d941729c5f283b3f7",
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 2951,
            "FileHash-MD5": 193,
            "FileHash-SHA1": 171,
            "FileHash-SHA256": 1885,
            "URL": 8907,
            "domain": 2945,
            "SSLCertFingerprint": 2,
            "email": 11,
            "CVE": 2
          },
          "indicator_count": 17067,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 67,
          "modified_text": "6 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6665d55d941729c5f283b3f7",
          "name": "S0094-Remote Access - Assurance [a Prudential company]",
          "description": "Assurance experienced an abrupt shutdown April 2024. Health Insurance agents were notified mid business;  Prudential [Assurance partner] had fully taken over thus ending all contracts amid business. Cyber investigations date back to 2023. health insurance agents Trojan.Karagany [old] is a modular remote access tool used for recon and linked to Dragonfly. Infostealer, malware and unwanted programs  downloader.\nPersistence. Severe | S0094 - Remote Access\nCVE-2023-22518 | CVE-2023-4966",
          "modified": "2024-07-09T15:02:04.111000",
          "created": "2024-06-09T16:16:29.634000",
          "tags": [
            "falcon sandbox",
            "sha256",
            "sha1",
            "et tor",
            "known tor",
            "relayrouter",
            "exit",
            "node traffic",
            "misc attack",
            "pattern match",
            "ascii text",
            "null",
            "hybrid",
            "refresh",
            "body",
            "span",
            "june",
            "click",
            "date",
            "strings",
            "error",
            "tools",
            "look",
            "verify",
            "restart",
            "contact",
            "historical ssl",
            "referrer",
            "httponly",
            "path",
            "secure",
            "maxage31557600",
            "expiresmon",
            "samesitenone",
            "expireswed",
            "etag w",
            "setcookie dids",
            "maxage864000",
            "http response",
            "final url",
            "serving ip",
            "address",
            "status code",
            "html document",
            "history",
            "utc names",
            "html info",
            "title assurance",
            "meta tags",
            "script tags",
            "anchor hrefs",
            "code",
            "requestid",
            "hostid",
            "xml file",
            "accessdenied",
            "message",
            "signature",
            "expires",
            "awsaccesskeyid",
            "log id",
            "gmtn",
            "passive dns",
            "urls",
            "digicert global",
            "g2 tls",
            "rsa sha256",
            "tls web",
            "full name",
            "self",
            "false",
            "united",
            "as8075",
            "unknown",
            "gmt server",
            "scan endpoints",
            "all scoreblue",
            "ipv4",
            "pulse submit",
            "url analysis",
            "url https",
            "pulse pulses",
            "http",
            "ip address",
            "related nids",
            "files location",
            "aaaa",
            "meta",
            "link",
            "search",
            "creation date",
            "wheels up",
            "moved",
            "homepage",
            "servers",
            "service",
            "name servers",
            "hostname",
            "next",
            "japan unknown",
            "as2510 fujitsu",
            "status",
            "page",
            "ltd dba",
            "com laude",
            "record value",
            "ireland",
            "germany",
            "australia",
            "as44786 adobe",
            "whitelisted",
            "win32",
            "present may",
            "trojan",
            "karaganye",
            "regsetvalueexa",
            "regdword",
            "default",
            "show",
            "presto",
            "regbinary",
            "medium",
            "create c",
            "query",
            "double",
            "malware",
            "copy",
            "karagany",
            "write",
            "showing",
            "as35908 krypt",
            "as45102 alibaba",
            "hong kong",
            "data service",
            "script script",
            "div div",
            "title",
            "entries",
            "files",
            "japan asn",
            "dns resolutions",
            "memory pattern",
            "ip traffic",
            "domains",
            "urls https",
            "files c",
            "filesgoogle c",
            "written c",
            "extensions",
            "as20446",
            "as14061",
            "emails",
            "threat roundup",
            "bashlite",
            "jupyter rising",
            "vmware",
            "security blog",
            "april",
            "september",
            "december",
            "january",
            "enemybot",
            "core"
          ],
          "references": [
            "Assurance",
            "IDS Detections: Trojan Internet Connectivity Check TrojanDownloader.Win32/Karagany.H checkin 2",
            "IDS Detections: Query for .cc TLD Suspicious User-Agent (Presto) Double User-Agent (User-Agent User-Agent)",
            "Alerts: network_icmp modifies_proxy_wpad network_http suspicious_tld allocates_rwx creates_exe antivm_network_adapters checks_debugger",
            "Domains Contacted: simplesausages.cx.cc adobe.com",
            "https://test2.ditproducts.com/dat/wannacry1.html",
            "http://email.critizr.com/asm/unsubscribe/?user_id=1464008&data=anW5I3azQrbEzQ84_I2zsSfJkpp1WTl08_zW0p5h4i5oMDAwdTAwMIqknJPIfal-ld9TvXgRLVf_F",
            "https://www.anyxxxtube.net/search-porn/tsara-brashears/",
            "CVE-2023-22518 | CVE-2023-4966"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America",
            "Netherlands"
          ],
          "malware_families": [
            {
              "id": "ALF:JASYP:TrojanDownloader:Win32/Karagany!atmn",
              "display_name": "ALF:JASYP:TrojanDownloader:Win32/Karagany!atmn",
              "target": null
            },
            {
              "id": "Win32:Karagany-D\\ [Trj]",
              "display_name": "Win32:Karagany-D\\ [Trj]",
              "target": null
            },
            {
              "id": "Win.Trojan.Xtoober-650",
              "display_name": "Win.Trojan.Xtoober-650",
              "target": null
            },
            {
              "id": "Trojan:Win32/Startpage.SS",
              "display_name": "Trojan:Win32/Startpage.SS",
              "target": "/malware/Trojan:Win32/Startpage.SS"
            },
            {
              "id": "Win.Packed.Pincav-7537597-0",
              "display_name": "Win.Packed.Pincav-7537597-0",
              "target": null
            },
            {
              "id": "Trojan.Karagany - S0094",
              "display_name": "Trojan.Karagany - S0094",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1568",
              "name": "Dynamic Resolution",
              "display_name": "T1568 - Dynamic Resolution"
            },
            {
              "id": "T1040",
              "name": "Network Sniffing",
              "display_name": "T1040 - Network Sniffing"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1574.002",
              "name": "DLL Side-Loading",
              "display_name": "T1574.002 - DLL Side-Loading"
            },
            {
              "id": "TA0002",
              "name": "Execution",
              "display_name": "TA0002 - Execution"
            },
            {
              "id": "TA0003",
              "name": "Persistence",
              "display_name": "TA0003 - Persistence"
            },
            {
              "id": "TA0004",
              "name": "Privilege Escalation",
              "display_name": "TA0004 - Privilege Escalation"
            },
            {
              "id": "TA0005",
              "name": "Defense Evasion",
              "display_name": "TA0005 - Defense Evasion"
            },
            {
              "id": "TA0008",
              "name": "Lateral Movement",
              "display_name": "TA0008 - Lateral Movement"
            },
            {
              "id": "TA0011",
              "name": "Command and Control",
              "display_name": "TA0011 - Command and Control"
            }
          ],
          "industries": [
            "Healthcare",
            "Technology",
            "Telecommunications",
            "Finance - Insurance Sector"
          ],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 31,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 2950,
            "FileHash-MD5": 193,
            "FileHash-SHA1": 171,
            "FileHash-SHA256": 1885,
            "URL": 8907,
            "domain": 2945,
            "SSLCertFingerprint": 2,
            "email": 11,
            "CVE": 2
          },
          "indicator_count": 17066,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 228,
          "modified_text": "690 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6665d9ae1b06b560698b2a70",
          "name": "Assurance [a Prudential company] S0094-Remote Access",
          "description": "Assurance experienced an abrupt shutdown April 2024. Health Insurance agents were notified mid business;  Prudential [Assurance partner] had fully taken over thus ending all contracts amid business. Cyber investigations date back to 2023.    Trojan.Karagany [old] is a modular remote access tool used for recon and linked to Dragonfly/Crouching Yeti and more. Infostealer, malware and unwanted programs  downloader.\nPersistence. Severe | S0094 - Remote Access\nCVE-2023-22518 | CVE-2023-4966",
          "modified": "2024-07-09T15:02:04.111000",
          "created": "2024-06-09T16:34:54.161000",
          "tags": [
            "falcon sandbox",
            "sha256",
            "sha1",
            "et tor",
            "known tor",
            "relayrouter",
            "exit",
            "node traffic",
            "misc attack",
            "pattern match",
            "ascii text",
            "null",
            "hybrid",
            "refresh",
            "body",
            "span",
            "june",
            "click",
            "date",
            "strings",
            "error",
            "tools",
            "look",
            "verify",
            "restart",
            "contact",
            "historical ssl",
            "referrer",
            "httponly",
            "path",
            "secure",
            "maxage31557600",
            "expiresmon",
            "samesitenone",
            "expireswed",
            "etag w",
            "setcookie dids",
            "maxage864000",
            "http response",
            "final url",
            "serving ip",
            "address",
            "status code",
            "html document",
            "history",
            "utc names",
            "html info",
            "title assurance",
            "meta tags",
            "script tags",
            "anchor hrefs",
            "code",
            "requestid",
            "hostid",
            "xml file",
            "accessdenied",
            "message",
            "signature",
            "expires",
            "awsaccesskeyid",
            "log id",
            "gmtn",
            "passive dns",
            "urls",
            "digicert global",
            "g2 tls",
            "rsa sha256",
            "tls web",
            "full name",
            "self",
            "false",
            "united",
            "as8075",
            "unknown",
            "gmt server",
            "scan endpoints",
            "all scoreblue",
            "ipv4",
            "pulse submit",
            "url analysis",
            "url https",
            "pulse pulses",
            "http",
            "ip address",
            "related nids",
            "files location",
            "aaaa",
            "meta",
            "link",
            "search",
            "creation date",
            "wheels up",
            "moved",
            "homepage",
            "servers",
            "service",
            "name servers",
            "hostname",
            "next",
            "japan unknown",
            "as2510 fujitsu",
            "status",
            "page",
            "ltd dba",
            "com laude",
            "record value",
            "ireland",
            "germany",
            "australia",
            "as44786 adobe",
            "whitelisted",
            "win32",
            "present may",
            "trojan",
            "karaganye",
            "regsetvalueexa",
            "regdword",
            "default",
            "show",
            "presto",
            "regbinary",
            "medium",
            "create c",
            "query",
            "double",
            "malware",
            "copy",
            "karagany",
            "write",
            "showing",
            "as35908 krypt",
            "as45102 alibaba",
            "hong kong",
            "data service",
            "script script",
            "div div",
            "title",
            "entries",
            "files",
            "japan asn",
            "dns resolutions",
            "memory pattern",
            "ip traffic",
            "domains",
            "urls https",
            "files c",
            "filesgoogle c",
            "written c",
            "extensions",
            "as20446",
            "as14061",
            "emails",
            "threat roundup",
            "bashlite",
            "jupyter rising",
            "vmware",
            "security blog",
            "april",
            "september",
            "december",
            "january",
            "enemybot",
            "core"
          ],
          "references": [
            "Assurance",
            "IDS Detections: Trojan Internet Connectivity Check TrojanDownloader.Win32/Karagany.H checkin 2",
            "IDS Detections: Query for .cc TLD Suspicious User-Agent (Presto) Double User-Agent (User-Agent User-Agent)",
            "Alerts: network_icmp modifies_proxy_wpad network_http suspicious_tld allocates_rwx creates_exe antivm_network_adapters checks_debugger",
            "Domains Contacted: simplesausages.cx.cc adobe.com",
            "https://test2.ditproducts.com/dat/wannacry1.html",
            "http://email.critizr.com/asm/unsubscribe/?user_id=1464008&data=anW5I3azQrbEzQ84_I2zsSfJkpp1WTl08_zW0p5h4i5oMDAwdTAwMIqknJPIfal-ld9TvXgRLVf_F",
            "https://www.anyxxxtube.net/search-porn/tsara-brashears/",
            "CVE-2023-22518 | CVE-2023-4966"
          ],
          "public": 1,
          "adversary": "Berserk Bear (also known as BROMINE, Crouching Yeti, Dragonfly,",
          "targeted_countries": [
            "United States of America",
            "Netherlands"
          ],
          "malware_families": [
            {
              "id": "ALF:JASYP:TrojanDownloader:Win32/Karagany!atmn",
              "display_name": "ALF:JASYP:TrojanDownloader:Win32/Karagany!atmn",
              "target": null
            },
            {
              "id": "Win32:Karagany-D\\ [Trj]",
              "display_name": "Win32:Karagany-D\\ [Trj]",
              "target": null
            },
            {
              "id": "Win.Trojan.Xtoober-650",
              "display_name": "Win.Trojan.Xtoober-650",
              "target": null
            },
            {
              "id": "Trojan:Win32/Startpage.SS",
              "display_name": "Trojan:Win32/Startpage.SS",
              "target": "/malware/Trojan:Win32/Startpage.SS"
            },
            {
              "id": "Win.Packed.Pincav-7537597-0",
              "display_name": "Win.Packed.Pincav-7537597-0",
              "target": null
            },
            {
              "id": "Trojan.Karagany - S0094",
              "display_name": "Trojan.Karagany - S0094",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1568",
              "name": "Dynamic Resolution",
              "display_name": "T1568 - Dynamic Resolution"
            },
            {
              "id": "T1040",
              "name": "Network Sniffing",
              "display_name": "T1040 - Network Sniffing"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1574.002",
              "name": "DLL Side-Loading",
              "display_name": "T1574.002 - DLL Side-Loading"
            },
            {
              "id": "TA0002",
              "name": "Execution",
              "display_name": "TA0002 - Execution"
            },
            {
              "id": "TA0003",
              "name": "Persistence",
              "display_name": "TA0003 - Persistence"
            },
            {
              "id": "TA0004",
              "name": "Privilege Escalation",
              "display_name": "TA0004 - Privilege Escalation"
            },
            {
              "id": "TA0005",
              "name": "Defense Evasion",
              "display_name": "TA0005 - Defense Evasion"
            },
            {
              "id": "TA0008",
              "name": "Lateral Movement",
              "display_name": "TA0008 - Lateral Movement"
            },
            {
              "id": "TA0011",
              "name": "Command and Control",
              "display_name": "TA0011 - Command and Control"
            }
          ],
          "industries": [
            "Healthcare",
            "Technology",
            "Telecommunications",
            "Finance - Insurance Sector"
          ],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 38,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 2950,
            "FileHash-MD5": 193,
            "FileHash-SHA1": 171,
            "FileHash-SHA256": 1885,
            "URL": 8907,
            "domain": 2945,
            "SSLCertFingerprint": 2,
            "email": 11,
            "CVE": 2
          },
          "indicator_count": 17066,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 229,
          "modified_text": "690 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "659b0fd1ac7cb4d83834db1f",
          "name": "Botnet Command and Control Server | Malware Distribution Site",
          "description": "",
          "modified": "2024-02-06T20:02:52.205000",
          "created": "2024-01-07T20:55:45.006000",
          "tags": [
            "passive dns",
            "urls",
            "scan endpoints",
            "all octoseek",
            "url http",
            "pulse pulses",
            "http",
            "ip address",
            "related nids",
            "files location",
            "http response",
            "final url",
            "status code",
            "body",
            "httponly",
            "ssl certificate",
            "historical ssl",
            "whois record",
            "parent referrer",
            "whois whois",
            "communicating",
            "contacted",
            "contacted urls",
            "bundled",
            "pe resource",
            "dropped",
            "army",
            "machinename",
            "execution",
            "referrer",
            "malware distribution site",
            "phishing dropbox",
            "evasive",
            "banker",
            "dde",
            "dridex",
            "exploit",
            "dyre",
            "dyreza",
            "ransomware",
            "mydoom",
            "backdoor",
            "svg",
            "phising",
            "locky",
            "e-mail provider phishing",
            "spear phishing",
            "retefe",
            "defacement",
            "phishing development bank of singapore",
            "banjori",
            "suppobox",
            "zeus",
            "pony",
            "solar",
            "ransomware locky distribution site",
            "nymaim",
            "shade",
            "troldesh",
            "tvrat",
            "zbot",
            "elocky",
            "wisdomeyes",
            "kryptic",
            "sinkhole",
            "exploit",
            "worm",
            "backdoor",
            "injector",
            "botnet command and control server",
            "unknown",
            "domain",
            "creation date",
            "search",
            "date",
            "hostname",
            "next",
            "all search",
            "otx octoseek",
            "united",
            "as13335",
            "ipv4",
            "pulse submit",
            "url analysis",
            "iocs",
            "ioc search",
            "new ioc",
            "teams api",
            "contact",
            "files",
            "nxdomain",
            "win32",
            "meta",
            "wabot",
            "gmt contenttype",
            "dnssec",
            "name",
            "win32 exe",
            "detections file",
            "file size",
            "kb file",
            "domains",
            "registrar",
            "markmonitor inc",
            "status",
            "susp",
            "expiration date",
            "name servers",
            "domain related",
            "entries",
            "johnnsabey",
            "m. brian sabey",
            "mark sabey",
            "sabey data center",
            "utah",
            "http method",
            "http requests",
            "connect http",
            "get dns",
            "resolutions",
            "ip traffic",
            "problems",
            "alienvault part",
            "kgs0",
            "kls0",
            "schema abuse",
            "sneaky server",
            "iframe",
            "apple",
            "data collection"
          ],
          "references": [
            "http://security.didici.cc/cve"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "virus.virlock/nabucur",
              "display_name": "virus.virlock/nabucur",
              "target": null
            },
            {
              "id": "Virut",
              "display_name": "Virut",
              "target": null
            },
            {
              "id": "MyDoom",
              "display_name": "MyDoom",
              "target": null
            },
            {
              "id": "Locky",
              "display_name": "Locky",
              "target": null
            },
            {
              "id": "Defacement",
              "display_name": "Defacement",
              "target": null
            },
            {
              "id": "Banjori",
              "display_name": "Banjori",
              "target": null
            },
            {
              "id": "Trojan.AvsEtecer",
              "display_name": "Trojan.AvsEtecer",
              "target": null
            },
            {
              "id": "SuppoBox",
              "display_name": "SuppoBox",
              "target": null
            },
            {
              "id": "ZeuS",
              "display_name": "ZeuS",
              "target": null
            },
            {
              "id": "Pony",
              "display_name": "Pony",
              "target": null
            },
            {
              "id": "Solar",
              "display_name": "Solar",
              "target": null
            },
            {
              "id": "Nymaim",
              "display_name": "Nymaim",
              "target": null
            },
            {
              "id": "TV RAT",
              "display_name": "TV RAT",
              "target": null
            },
            {
              "id": "Zbot",
              "display_name": "Zbot",
              "target": null
            },
            {
              "id": "Dyre",
              "display_name": "Dyre",
              "target": null
            },
            {
              "id": "ELocky",
              "display_name": "ELocky",
              "target": null
            },
            {
              "id": "Dridex",
              "display_name": "Dridex",
              "target": null
            },
            {
              "id": "Locky (Decryptor)",
              "display_name": "Locky (Decryptor)",
              "target": null
            },
            {
              "id": "Ransomware",
              "display_name": "Ransomware",
              "target": null
            },
            {
              "id": "Trojan.WisdomEyes.16070401.9500",
              "display_name": "Trojan.WisdomEyes.16070401.9500",
              "target": null
            },
            {
              "id": "Gen:Variant.Strictor",
              "display_name": "Gen:Variant.Strictor",
              "target": null
            },
            {
              "id": "Adware.BrowseFox",
              "display_name": "Adware.BrowseFox",
              "target": null
            },
            {
              "id": "W32.eHeur",
              "display_name": "W32.eHeur",
              "target": null
            },
            {
              "id": "MSIL_Kryptik.P.gen",
              "display_name": "MSIL_Kryptik.P.gen",
              "target": null
            },
            {
              "id": "pykspa_v2_fake",
              "display_name": "pykspa_v2_fake",
              "target": null
            },
            {
              "id": "Worm:Win32/Pykspa",
              "display_name": "Worm:Win32/Pykspa",
              "target": "/malware/Worm:Win32/Pykspa"
            },
            {
              "id": "Pykspa",
              "display_name": "Pykspa",
              "target": null
            },
            {
              "id": "TEL:Exploit:Win32/Sinkers",
              "display_name": "TEL:Exploit:Win32/Sinkers",
              "target": null
            },
            {
              "id": "Sabey",
              "display_name": "Sabey",
              "target": null
            },
            {
              "id": "HallRender",
              "display_name": "HallRender",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1583.005",
              "name": "Botnet",
              "display_name": "T1583.005 - Botnet"
            },
            {
              "id": "T1001",
              "name": "Data Obfuscation",
              "display_name": "T1001 - Data Obfuscation"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1449",
              "name": "Exploit SS7 to Redirect Phone Calls/SMS",
              "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
            },
            {
              "id": "T1041",
              "name": "Exfiltration Over C2 Channel",
              "display_name": "T1041 - Exfiltration Over C2 Channel"
            },
            {
              "id": "TA0011",
              "name": "Command and Control",
              "display_name": "TA0011 - Command and Control"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1059.002",
              "name": "AppleScript",
              "display_name": "T1059.002 - AppleScript"
            },
            {
              "id": "T1491",
              "name": "Defacement",
              "display_name": "T1491 - Defacement"
            },
            {
              "id": "T1410",
              "name": "Network Traffic Capture or Redirection",
              "display_name": "T1410 - Network Traffic Capture or Redirection"
            },
            {
              "id": "T1185",
              "name": "Man in the Browser",
              "display_name": "T1185 - Man in the Browser"
            },
            {
              "id": "T1594",
              "name": "Search Victim-Owned Websites",
              "display_name": "T1594 - Search Victim-Owned Websites"
            },
            {
              "id": "T1593.002",
              "name": "Search Engines",
              "display_name": "T1593.002 - Search Engines"
            },
            {
              "id": "T1574.008",
              "name": "Path Interception by Search Order Hijacking",
              "display_name": "T1574.008 - Path Interception by Search Order Hijacking"
            },
            {
              "id": "T1114",
              "name": "Email Collection",
              "display_name": "T1114 - Email Collection"
            },
            {
              "id": "T1114.002",
              "name": "Remote Email Collection",
              "display_name": "T1114.002 - Remote Email Collection"
            },
            {
              "id": "TA0009",
              "name": "Collection",
              "display_name": "TA0009 - Collection"
            },
            {
              "id": "T1457",
              "name": "Malicious Media Content",
              "display_name": "T1457 - Malicious Media Content"
            },
            {
              "id": "T1587.001",
              "name": "Malware",
              "display_name": "T1587.001 - Malware"
            },
            {
              "id": "T1608.001",
              "name": "Upload Malware",
              "display_name": "T1608.001 - Upload Malware"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 35,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 231,
            "FileHash-SHA256": 3121,
            "URL": 4225,
            "domain": 1725,
            "hostname": 1416,
            "FileHash-SHA1": 225,
            "CVE": 2,
            "email": 3
          },
          "indicator_count": 10948,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 224,
          "modified_text": "844 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "65a48ab7cd0bd218b17ccf6c",
          "name": "Botnet Command and Control Server | Malware",
          "description": "",
          "modified": "2024-02-06T20:02:52.205000",
          "created": "2024-01-15T01:30:31.655000",
          "tags": [
            "passive dns",
            "urls",
            "scan endpoints",
            "all octoseek",
            "url http",
            "pulse pulses",
            "http",
            "ip address",
            "related nids",
            "files location",
            "http response",
            "final url",
            "status code",
            "body",
            "httponly",
            "ssl certificate",
            "historical ssl",
            "whois record",
            "parent referrer",
            "whois whois",
            "communicating",
            "contacted",
            "contacted urls",
            "bundled",
            "pe resource",
            "dropped",
            "army",
            "machinename",
            "execution",
            "referrer",
            "malware distribution site",
            "phishing dropbox",
            "evasive",
            "banker",
            "dde",
            "dridex",
            "exploit",
            "dyre",
            "dyreza",
            "ransomware",
            "mydoom",
            "backdoor",
            "svg",
            "phising",
            "locky",
            "e-mail provider phishing",
            "spear phishing",
            "retefe",
            "defacement",
            "phishing development bank of singapore",
            "banjori",
            "suppobox",
            "zeus",
            "pony",
            "solar",
            "ransomware locky distribution site",
            "nymaim",
            "shade",
            "troldesh",
            "tvrat",
            "zbot",
            "elocky",
            "wisdomeyes",
            "kryptic",
            "sinkhole",
            "exploit",
            "worm",
            "backdoor",
            "injector",
            "botnet command and control server",
            "unknown",
            "domain",
            "creation date",
            "search",
            "date",
            "hostname",
            "next",
            "all search",
            "otx octoseek",
            "united",
            "as13335",
            "ipv4",
            "pulse submit",
            "url analysis",
            "iocs",
            "ioc search",
            "new ioc",
            "teams api",
            "contact",
            "files",
            "nxdomain",
            "win32",
            "meta",
            "wabot",
            "gmt contenttype",
            "dnssec",
            "name",
            "win32 exe",
            "detections file",
            "file size",
            "kb file",
            "domains",
            "registrar",
            "markmonitor inc",
            "status",
            "susp",
            "expiration date",
            "name servers",
            "domain related",
            "entries",
            "johnnsabey",
            "m. brian sabey",
            "mark sabey",
            "sabey data center",
            "utah",
            "http method",
            "http requests",
            "connect http",
            "get dns",
            "resolutions",
            "ip traffic",
            "problems",
            "alienvault part",
            "kgs0",
            "kls0",
            "schema abuse",
            "sneaky server",
            "iframe",
            "apple",
            "data collection"
          ],
          "references": [
            "http://security.didici.cc/cve"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "virus.virlock/nabucur",
              "display_name": "virus.virlock/nabucur",
              "target": null
            },
            {
              "id": "Virut",
              "display_name": "Virut",
              "target": null
            },
            {
              "id": "MyDoom",
              "display_name": "MyDoom",
              "target": null
            },
            {
              "id": "Locky",
              "display_name": "Locky",
              "target": null
            },
            {
              "id": "Defacement",
              "display_name": "Defacement",
              "target": null
            },
            {
              "id": "Banjori",
              "display_name": "Banjori",
              "target": null
            },
            {
              "id": "Trojan.AvsEtecer",
              "display_name": "Trojan.AvsEtecer",
              "target": null
            },
            {
              "id": "SuppoBox",
              "display_name": "SuppoBox",
              "target": null
            },
            {
              "id": "ZeuS",
              "display_name": "ZeuS",
              "target": null
            },
            {
              "id": "Pony",
              "display_name": "Pony",
              "target": null
            },
            {
              "id": "Solar",
              "display_name": "Solar",
              "target": null
            },
            {
              "id": "Nymaim",
              "display_name": "Nymaim",
              "target": null
            },
            {
              "id": "TV RAT",
              "display_name": "TV RAT",
              "target": null
            },
            {
              "id": "Zbot",
              "display_name": "Zbot",
              "target": null
            },
            {
              "id": "Dyre",
              "display_name": "Dyre",
              "target": null
            },
            {
              "id": "ELocky",
              "display_name": "ELocky",
              "target": null
            },
            {
              "id": "Dridex",
              "display_name": "Dridex",
              "target": null
            },
            {
              "id": "Locky (Decryptor)",
              "display_name": "Locky (Decryptor)",
              "target": null
            },
            {
              "id": "Ransomware",
              "display_name": "Ransomware",
              "target": null
            },
            {
              "id": "Trojan.WisdomEyes.16070401.9500",
              "display_name": "Trojan.WisdomEyes.16070401.9500",
              "target": null
            },
            {
              "id": "Gen:Variant.Strictor",
              "display_name": "Gen:Variant.Strictor",
              "target": null
            },
            {
              "id": "Adware.BrowseFox",
              "display_name": "Adware.BrowseFox",
              "target": null
            },
            {
              "id": "W32.eHeur",
              "display_name": "W32.eHeur",
              "target": null
            },
            {
              "id": "MSIL_Kryptik.P.gen",
              "display_name": "MSIL_Kryptik.P.gen",
              "target": null
            },
            {
              "id": "pykspa_v2_fake",
              "display_name": "pykspa_v2_fake",
              "target": null
            },
            {
              "id": "Worm:Win32/Pykspa",
              "display_name": "Worm:Win32/Pykspa",
              "target": "/malware/Worm:Win32/Pykspa"
            },
            {
              "id": "Pykspa",
              "display_name": "Pykspa",
              "target": null
            },
            {
              "id": "TEL:Exploit:Win32/Sinkers",
              "display_name": "TEL:Exploit:Win32/Sinkers",
              "target": null
            },
            {
              "id": "Sabey",
              "display_name": "Sabey",
              "target": null
            },
            {
              "id": "HallRender",
              "display_name": "HallRender",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1583.005",
              "name": "Botnet",
              "display_name": "T1583.005 - Botnet"
            },
            {
              "id": "T1001",
              "name": "Data Obfuscation",
              "display_name": "T1001 - Data Obfuscation"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1449",
              "name": "Exploit SS7 to Redirect Phone Calls/SMS",
              "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
            },
            {
              "id": "T1041",
              "name": "Exfiltration Over C2 Channel",
              "display_name": "T1041 - Exfiltration Over C2 Channel"
            },
            {
              "id": "TA0011",
              "name": "Command and Control",
              "display_name": "TA0011 - Command and Control"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1059.002",
              "name": "AppleScript",
              "display_name": "T1059.002 - AppleScript"
            },
            {
              "id": "T1491",
              "name": "Defacement",
              "display_name": "T1491 - Defacement"
            },
            {
              "id": "T1410",
              "name": "Network Traffic Capture or Redirection",
              "display_name": "T1410 - Network Traffic Capture or Redirection"
            },
            {
              "id": "T1185",
              "name": "Man in the Browser",
              "display_name": "T1185 - Man in the Browser"
            },
            {
              "id": "T1594",
              "name": "Search Victim-Owned Websites",
              "display_name": "T1594 - Search Victim-Owned Websites"
            },
            {
              "id": "T1593.002",
              "name": "Search Engines",
              "display_name": "T1593.002 - Search Engines"
            },
            {
              "id": "T1574.008",
              "name": "Path Interception by Search Order Hijacking",
              "display_name": "T1574.008 - Path Interception by Search Order Hijacking"
            },
            {
              "id": "T1114",
              "name": "Email Collection",
              "display_name": "T1114 - Email Collection"
            },
            {
              "id": "T1114.002",
              "name": "Remote Email Collection",
              "display_name": "T1114.002 - Remote Email Collection"
            },
            {
              "id": "TA0009",
              "name": "Collection",
              "display_name": "TA0009 - Collection"
            },
            {
              "id": "T1457",
              "name": "Malicious Media Content",
              "display_name": "T1457 - Malicious Media Content"
            },
            {
              "id": "T1587.001",
              "name": "Malware",
              "display_name": "T1587.001 - Malware"
            },
            {
              "id": "T1608.001",
              "name": "Upload Malware",
              "display_name": "T1608.001 - Upload Malware"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": "659b0fd1ac7cb4d83834db1f",
          "export_count": 25,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 231,
            "FileHash-SHA256": 3121,
            "URL": 4225,
            "domain": 1725,
            "hostname": 1416,
            "FileHash-SHA1": 225,
            "CVE": 2,
            "email": 3
          },
          "indicator_count": 10948,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 231,
          "modified_text": "844 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "Alerts: network_icmp modifies_proxy_wpad network_http suspicious_tld allocates_rwx creates_exe antivm_network_adapters checks_debugger",
        "IDS Detections: Query for .cc TLD Suspicious User-Agent (Presto) Double User-Agent (User-Agent User-Agent)",
        "https://www.anyxxxtube.net/search-porn/tsara-brashears/",
        "http://security.didici.cc/cve",
        "Assurance",
        "Domains Contacted: simplesausages.cx.cc adobe.com",
        "http://email.critizr.com/asm/unsubscribe/?user_id=1464008&data=anW5I3azQrbEzQ84_I2zsSfJkpp1WTl08_zW0p5h4i5oMDAwdTAwMIqknJPIfal-ld9TvXgRLVf_F",
        "https://test2.ditproducts.com/dat/wannacry1.html",
        "CVE-2023-22518 | CVE-2023-4966",
        "IDS Detections: Trojan Internet Connectivity Check TrojanDownloader.Win32/Karagany.H checkin 2"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 0
        },
        "other": {
          "adversary": [
            "Berserk Bear (also known as BROMINE, Crouching Yeti, Dragonfly,"
          ],
          "malware_families": [
            "Adware.browsefox",
            "Virut",
            "Pykspa_v2_fake",
            "Sabey",
            "Trojan.avsetecer",
            "Trojan:win32/startpage.ss",
            "Trojan.karagany - s0094",
            "Defacement",
            "Virus.virlock/nabucur",
            "Pony",
            "Suppobox",
            "Tel:exploit:win32/sinkers",
            "Win.packed.pincav-7537597-0",
            "Nymaim",
            "Locky",
            "Locky (decryptor)",
            "Zbot",
            "Worm:win32/pykspa",
            "Tv rat",
            "Dridex",
            "Solar",
            "Win32:karagany-d\\ [trj]",
            "Trojan.wisdomeyes.16070401.9500",
            "Msil_kryptik.p.gen",
            "Zeus",
            "Alf:jasyp:trojandownloader:win32/karagany!atmn",
            "W32.eheur",
            "Elocky",
            "Pykspa",
            "Banjori",
            "Mydoom",
            "Dyre",
            "Ransomware",
            "Hallrender",
            "Win.trojan.xtoober-650",
            "Gen:variant.strictor"
          ],
          "industries": [
            "Technology",
            "Finance - insurance sector",
            "Telecommunications",
            "Healthcare"
          ],
          "unique_indicators": 28517
        }
      }
    },
    "false_positive": [],
    "alexa": "http://www.alexa.com/siteinfo/resonantcavity.com",
    "whois": "http://whois.domaintools.com/resonantcavity.com",
    "domain": "resonantcavity.com",
    "hostname": "Unavailable"
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 5,
  "pulses": [
    {
      "id": "6a141c15cfec672ba39e6a17",
      "name": "S0094 clone credit score blue ",
      "description": "",
      "modified": "2026-05-25T10:03:13.774000",
      "created": "2026-05-25T09:53:25.429000",
      "tags": [
        "falcon sandbox",
        "sha256",
        "sha1",
        "et tor",
        "known tor",
        "relayrouter",
        "exit",
        "node traffic",
        "misc attack",
        "pattern match",
        "ascii text",
        "null",
        "hybrid",
        "refresh",
        "body",
        "span",
        "june",
        "click",
        "date",
        "strings",
        "error",
        "tools",
        "look",
        "verify",
        "restart",
        "contact",
        "historical ssl",
        "referrer",
        "httponly",
        "path",
        "secure",
        "maxage31557600",
        "expiresmon",
        "samesitenone",
        "expireswed",
        "etag w",
        "setcookie dids",
        "maxage864000",
        "http response",
        "final url",
        "serving ip",
        "address",
        "status code",
        "html document",
        "history",
        "utc names",
        "html info",
        "title assurance",
        "meta tags",
        "script tags",
        "anchor hrefs",
        "code",
        "requestid",
        "hostid",
        "xml file",
        "accessdenied",
        "message",
        "signature",
        "expires",
        "awsaccesskeyid",
        "log id",
        "gmtn",
        "passive dns",
        "urls",
        "digicert global",
        "g2 tls",
        "rsa sha256",
        "tls web",
        "full name",
        "self",
        "false",
        "united",
        "as8075",
        "unknown",
        "gmt server",
        "scan endpoints",
        "all scoreblue",
        "ipv4",
        "pulse submit",
        "url analysis",
        "url https",
        "pulse pulses",
        "http",
        "ip address",
        "related nids",
        "files location",
        "aaaa",
        "meta",
        "link",
        "search",
        "creation date",
        "wheels up",
        "moved",
        "homepage",
        "servers",
        "service",
        "name servers",
        "hostname",
        "next",
        "japan unknown",
        "as2510 fujitsu",
        "status",
        "page",
        "ltd dba",
        "com laude",
        "record value",
        "ireland",
        "germany",
        "australia",
        "as44786 adobe",
        "whitelisted",
        "win32",
        "present may",
        "trojan",
        "karaganye",
        "regsetvalueexa",
        "regdword",
        "default",
        "show",
        "presto",
        "regbinary",
        "medium",
        "create c",
        "query",
        "double",
        "malware",
        "copy",
        "karagany",
        "write",
        "showing",
        "as35908 krypt",
        "as45102 alibaba",
        "hong kong",
        "data service",
        "script script",
        "div div",
        "title",
        "entries",
        "files",
        "japan asn",
        "dns resolutions",
        "memory pattern",
        "ip traffic",
        "domains",
        "urls https",
        "files c",
        "filesgoogle c",
        "written c",
        "extensions",
        "as20446",
        "as14061",
        "emails",
        "threat roundup",
        "bashlite",
        "jupyter rising",
        "vmware",
        "security blog",
        "april",
        "september",
        "december",
        "january",
        "enemybot",
        "core"
      ],
      "references": [
        "Assurance",
        "IDS Detections: Trojan Internet Connectivity Check TrojanDownloader.Win32/Karagany.H checkin 2",
        "IDS Detections: Query for .cc TLD Suspicious User-Agent (Presto) Double User-Agent (User-Agent User-Agent)",
        "Alerts: network_icmp modifies_proxy_wpad network_http suspicious_tld allocates_rwx creates_exe antivm_network_adapters checks_debugger",
        "Domains Contacted: simplesausages.cx.cc adobe.com",
        "https://test2.ditproducts.com/dat/wannacry1.html",
        "http://email.critizr.com/asm/unsubscribe/?user_id=1464008&data=anW5I3azQrbEzQ84_I2zsSfJkpp1WTl08_zW0p5h4i5oMDAwdTAwMIqknJPIfal-ld9TvXgRLVf_F",
        "https://www.anyxxxtube.net/search-porn/tsara-brashears/",
        "CVE-2023-22518 | CVE-2023-4966"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America",
        "Netherlands"
      ],
      "malware_families": [
        {
          "id": "ALF:JASYP:TrojanDownloader:Win32/Karagany!atmn",
          "display_name": "ALF:JASYP:TrojanDownloader:Win32/Karagany!atmn",
          "target": null
        },
        {
          "id": "Win32:Karagany-D\\ [Trj]",
          "display_name": "Win32:Karagany-D\\ [Trj]",
          "target": null
        },
        {
          "id": "Win.Trojan.Xtoober-650",
          "display_name": "Win.Trojan.Xtoober-650",
          "target": null
        },
        {
          "id": "Trojan:Win32/Startpage.SS",
          "display_name": "Trojan:Win32/Startpage.SS",
          "target": "/malware/Trojan:Win32/Startpage.SS"
        },
        {
          "id": "Win.Packed.Pincav-7537597-0",
          "display_name": "Win.Packed.Pincav-7537597-0",
          "target": null
        },
        {
          "id": "Trojan.Karagany - S0094",
          "display_name": "Trojan.Karagany - S0094",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1568",
          "name": "Dynamic Resolution",
          "display_name": "T1568 - Dynamic Resolution"
        },
        {
          "id": "T1040",
          "name": "Network Sniffing",
          "display_name": "T1040 - Network Sniffing"
        },
        {
          "id": "T1129",
          "name": "Shared Modules",
          "display_name": "T1129 - Shared Modules"
        },
        {
          "id": "T1574.002",
          "name": "DLL Side-Loading",
          "display_name": "T1574.002 - DLL Side-Loading"
        },
        {
          "id": "TA0002",
          "name": "Execution",
          "display_name": "TA0002 - Execution"
        },
        {
          "id": "TA0003",
          "name": "Persistence",
          "display_name": "TA0003 - Persistence"
        },
        {
          "id": "TA0004",
          "name": "Privilege Escalation",
          "display_name": "TA0004 - Privilege Escalation"
        },
        {
          "id": "TA0005",
          "name": "Defense Evasion",
          "display_name": "TA0005 - Defense Evasion"
        },
        {
          "id": "TA0008",
          "name": "Lateral Movement",
          "display_name": "TA0008 - Lateral Movement"
        },
        {
          "id": "TA0011",
          "name": "Command and Control",
          "display_name": "TA0011 - Command and Control"
        }
      ],
      "industries": [
        "Healthcare",
        "Technology",
        "Telecommunications",
        "Finance - Insurance Sector"
      ],
      "TLP": "green",
      "cloned_from": "6665d55d941729c5f283b3f7",
      "export_count": 1,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 2951,
        "FileHash-MD5": 193,
        "FileHash-SHA1": 171,
        "FileHash-SHA256": 1885,
        "URL": 8907,
        "domain": 2945,
        "SSLCertFingerprint": 2,
        "email": 11,
        "CVE": 2
      },
      "indicator_count": 17067,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 67,
      "modified_text": "6 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6665d55d941729c5f283b3f7",
      "name": "S0094-Remote Access - Assurance [a Prudential company]",
      "description": "Assurance experienced an abrupt shutdown April 2024. Health Insurance agents were notified mid business;  Prudential [Assurance partner] had fully taken over thus ending all contracts amid business. Cyber investigations date back to 2023. health insurance agents Trojan.Karagany [old] is a modular remote access tool used for recon and linked to Dragonfly. Infostealer, malware and unwanted programs  downloader.\nPersistence. Severe | S0094 - Remote Access\nCVE-2023-22518 | CVE-2023-4966",
      "modified": "2024-07-09T15:02:04.111000",
      "created": "2024-06-09T16:16:29.634000",
      "tags": [
        "falcon sandbox",
        "sha256",
        "sha1",
        "et tor",
        "known tor",
        "relayrouter",
        "exit",
        "node traffic",
        "misc attack",
        "pattern match",
        "ascii text",
        "null",
        "hybrid",
        "refresh",
        "body",
        "span",
        "june",
        "click",
        "date",
        "strings",
        "error",
        "tools",
        "look",
        "verify",
        "restart",
        "contact",
        "historical ssl",
        "referrer",
        "httponly",
        "path",
        "secure",
        "maxage31557600",
        "expiresmon",
        "samesitenone",
        "expireswed",
        "etag w",
        "setcookie dids",
        "maxage864000",
        "http response",
        "final url",
        "serving ip",
        "address",
        "status code",
        "html document",
        "history",
        "utc names",
        "html info",
        "title assurance",
        "meta tags",
        "script tags",
        "anchor hrefs",
        "code",
        "requestid",
        "hostid",
        "xml file",
        "accessdenied",
        "message",
        "signature",
        "expires",
        "awsaccesskeyid",
        "log id",
        "gmtn",
        "passive dns",
        "urls",
        "digicert global",
        "g2 tls",
        "rsa sha256",
        "tls web",
        "full name",
        "self",
        "false",
        "united",
        "as8075",
        "unknown",
        "gmt server",
        "scan endpoints",
        "all scoreblue",
        "ipv4",
        "pulse submit",
        "url analysis",
        "url https",
        "pulse pulses",
        "http",
        "ip address",
        "related nids",
        "files location",
        "aaaa",
        "meta",
        "link",
        "search",
        "creation date",
        "wheels up",
        "moved",
        "homepage",
        "servers",
        "service",
        "name servers",
        "hostname",
        "next",
        "japan unknown",
        "as2510 fujitsu",
        "status",
        "page",
        "ltd dba",
        "com laude",
        "record value",
        "ireland",
        "germany",
        "australia",
        "as44786 adobe",
        "whitelisted",
        "win32",
        "present may",
        "trojan",
        "karaganye",
        "regsetvalueexa",
        "regdword",
        "default",
        "show",
        "presto",
        "regbinary",
        "medium",
        "create c",
        "query",
        "double",
        "malware",
        "copy",
        "karagany",
        "write",
        "showing",
        "as35908 krypt",
        "as45102 alibaba",
        "hong kong",
        "data service",
        "script script",
        "div div",
        "title",
        "entries",
        "files",
        "japan asn",
        "dns resolutions",
        "memory pattern",
        "ip traffic",
        "domains",
        "urls https",
        "files c",
        "filesgoogle c",
        "written c",
        "extensions",
        "as20446",
        "as14061",
        "emails",
        "threat roundup",
        "bashlite",
        "jupyter rising",
        "vmware",
        "security blog",
        "april",
        "september",
        "december",
        "january",
        "enemybot",
        "core"
      ],
      "references": [
        "Assurance",
        "IDS Detections: Trojan Internet Connectivity Check TrojanDownloader.Win32/Karagany.H checkin 2",
        "IDS Detections: Query for .cc TLD Suspicious User-Agent (Presto) Double User-Agent (User-Agent User-Agent)",
        "Alerts: network_icmp modifies_proxy_wpad network_http suspicious_tld allocates_rwx creates_exe antivm_network_adapters checks_debugger",
        "Domains Contacted: simplesausages.cx.cc adobe.com",
        "https://test2.ditproducts.com/dat/wannacry1.html",
        "http://email.critizr.com/asm/unsubscribe/?user_id=1464008&data=anW5I3azQrbEzQ84_I2zsSfJkpp1WTl08_zW0p5h4i5oMDAwdTAwMIqknJPIfal-ld9TvXgRLVf_F",
        "https://www.anyxxxtube.net/search-porn/tsara-brashears/",
        "CVE-2023-22518 | CVE-2023-4966"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America",
        "Netherlands"
      ],
      "malware_families": [
        {
          "id": "ALF:JASYP:TrojanDownloader:Win32/Karagany!atmn",
          "display_name": "ALF:JASYP:TrojanDownloader:Win32/Karagany!atmn",
          "target": null
        },
        {
          "id": "Win32:Karagany-D\\ [Trj]",
          "display_name": "Win32:Karagany-D\\ [Trj]",
          "target": null
        },
        {
          "id": "Win.Trojan.Xtoober-650",
          "display_name": "Win.Trojan.Xtoober-650",
          "target": null
        },
        {
          "id": "Trojan:Win32/Startpage.SS",
          "display_name": "Trojan:Win32/Startpage.SS",
          "target": "/malware/Trojan:Win32/Startpage.SS"
        },
        {
          "id": "Win.Packed.Pincav-7537597-0",
          "display_name": "Win.Packed.Pincav-7537597-0",
          "target": null
        },
        {
          "id": "Trojan.Karagany - S0094",
          "display_name": "Trojan.Karagany - S0094",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1568",
          "name": "Dynamic Resolution",
          "display_name": "T1568 - Dynamic Resolution"
        },
        {
          "id": "T1040",
          "name": "Network Sniffing",
          "display_name": "T1040 - Network Sniffing"
        },
        {
          "id": "T1129",
          "name": "Shared Modules",
          "display_name": "T1129 - Shared Modules"
        },
        {
          "id": "T1574.002",
          "name": "DLL Side-Loading",
          "display_name": "T1574.002 - DLL Side-Loading"
        },
        {
          "id": "TA0002",
          "name": "Execution",
          "display_name": "TA0002 - Execution"
        },
        {
          "id": "TA0003",
          "name": "Persistence",
          "display_name": "TA0003 - Persistence"
        },
        {
          "id": "TA0004",
          "name": "Privilege Escalation",
          "display_name": "TA0004 - Privilege Escalation"
        },
        {
          "id": "TA0005",
          "name": "Defense Evasion",
          "display_name": "TA0005 - Defense Evasion"
        },
        {
          "id": "TA0008",
          "name": "Lateral Movement",
          "display_name": "TA0008 - Lateral Movement"
        },
        {
          "id": "TA0011",
          "name": "Command and Control",
          "display_name": "TA0011 - Command and Control"
        }
      ],
      "industries": [
        "Healthcare",
        "Technology",
        "Telecommunications",
        "Finance - Insurance Sector"
      ],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 31,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "scoreblue",
        "id": "254100",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 2950,
        "FileHash-MD5": 193,
        "FileHash-SHA1": 171,
        "FileHash-SHA256": 1885,
        "URL": 8907,
        "domain": 2945,
        "SSLCertFingerprint": 2,
        "email": 11,
        "CVE": 2
      },
      "indicator_count": 17066,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 228,
      "modified_text": "690 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6665d9ae1b06b560698b2a70",
      "name": "Assurance [a Prudential company] S0094-Remote Access",
      "description": "Assurance experienced an abrupt shutdown April 2024. Health Insurance agents were notified mid business;  Prudential [Assurance partner] had fully taken over thus ending all contracts amid business. Cyber investigations date back to 2023.    Trojan.Karagany [old] is a modular remote access tool used for recon and linked to Dragonfly/Crouching Yeti and more. Infostealer, malware and unwanted programs  downloader.\nPersistence. Severe | S0094 - Remote Access\nCVE-2023-22518 | CVE-2023-4966",
      "modified": "2024-07-09T15:02:04.111000",
      "created": "2024-06-09T16:34:54.161000",
      "tags": [
        "falcon sandbox",
        "sha256",
        "sha1",
        "et tor",
        "known tor",
        "relayrouter",
        "exit",
        "node traffic",
        "misc attack",
        "pattern match",
        "ascii text",
        "null",
        "hybrid",
        "refresh",
        "body",
        "span",
        "june",
        "click",
        "date",
        "strings",
        "error",
        "tools",
        "look",
        "verify",
        "restart",
        "contact",
        "historical ssl",
        "referrer",
        "httponly",
        "path",
        "secure",
        "maxage31557600",
        "expiresmon",
        "samesitenone",
        "expireswed",
        "etag w",
        "setcookie dids",
        "maxage864000",
        "http response",
        "final url",
        "serving ip",
        "address",
        "status code",
        "html document",
        "history",
        "utc names",
        "html info",
        "title assurance",
        "meta tags",
        "script tags",
        "anchor hrefs",
        "code",
        "requestid",
        "hostid",
        "xml file",
        "accessdenied",
        "message",
        "signature",
        "expires",
        "awsaccesskeyid",
        "log id",
        "gmtn",
        "passive dns",
        "urls",
        "digicert global",
        "g2 tls",
        "rsa sha256",
        "tls web",
        "full name",
        "self",
        "false",
        "united",
        "as8075",
        "unknown",
        "gmt server",
        "scan endpoints",
        "all scoreblue",
        "ipv4",
        "pulse submit",
        "url analysis",
        "url https",
        "pulse pulses",
        "http",
        "ip address",
        "related nids",
        "files location",
        "aaaa",
        "meta",
        "link",
        "search",
        "creation date",
        "wheels up",
        "moved",
        "homepage",
        "servers",
        "service",
        "name servers",
        "hostname",
        "next",
        "japan unknown",
        "as2510 fujitsu",
        "status",
        "page",
        "ltd dba",
        "com laude",
        "record value",
        "ireland",
        "germany",
        "australia",
        "as44786 adobe",
        "whitelisted",
        "win32",
        "present may",
        "trojan",
        "karaganye",
        "regsetvalueexa",
        "regdword",
        "default",
        "show",
        "presto",
        "regbinary",
        "medium",
        "create c",
        "query",
        "double",
        "malware",
        "copy",
        "karagany",
        "write",
        "showing",
        "as35908 krypt",
        "as45102 alibaba",
        "hong kong",
        "data service",
        "script script",
        "div div",
        "title",
        "entries",
        "files",
        "japan asn",
        "dns resolutions",
        "memory pattern",
        "ip traffic",
        "domains",
        "urls https",
        "files c",
        "filesgoogle c",
        "written c",
        "extensions",
        "as20446",
        "as14061",
        "emails",
        "threat roundup",
        "bashlite",
        "jupyter rising",
        "vmware",
        "security blog",
        "april",
        "september",
        "december",
        "january",
        "enemybot",
        "core"
      ],
      "references": [
        "Assurance",
        "IDS Detections: Trojan Internet Connectivity Check TrojanDownloader.Win32/Karagany.H checkin 2",
        "IDS Detections: Query for .cc TLD Suspicious User-Agent (Presto) Double User-Agent (User-Agent User-Agent)",
        "Alerts: network_icmp modifies_proxy_wpad network_http suspicious_tld allocates_rwx creates_exe antivm_network_adapters checks_debugger",
        "Domains Contacted: simplesausages.cx.cc adobe.com",
        "https://test2.ditproducts.com/dat/wannacry1.html",
        "http://email.critizr.com/asm/unsubscribe/?user_id=1464008&data=anW5I3azQrbEzQ84_I2zsSfJkpp1WTl08_zW0p5h4i5oMDAwdTAwMIqknJPIfal-ld9TvXgRLVf_F",
        "https://www.anyxxxtube.net/search-porn/tsara-brashears/",
        "CVE-2023-22518 | CVE-2023-4966"
      ],
      "public": 1,
      "adversary": "Berserk Bear (also known as BROMINE, Crouching Yeti, Dragonfly,",
      "targeted_countries": [
        "United States of America",
        "Netherlands"
      ],
      "malware_families": [
        {
          "id": "ALF:JASYP:TrojanDownloader:Win32/Karagany!atmn",
          "display_name": "ALF:JASYP:TrojanDownloader:Win32/Karagany!atmn",
          "target": null
        },
        {
          "id": "Win32:Karagany-D\\ [Trj]",
          "display_name": "Win32:Karagany-D\\ [Trj]",
          "target": null
        },
        {
          "id": "Win.Trojan.Xtoober-650",
          "display_name": "Win.Trojan.Xtoober-650",
          "target": null
        },
        {
          "id": "Trojan:Win32/Startpage.SS",
          "display_name": "Trojan:Win32/Startpage.SS",
          "target": "/malware/Trojan:Win32/Startpage.SS"
        },
        {
          "id": "Win.Packed.Pincav-7537597-0",
          "display_name": "Win.Packed.Pincav-7537597-0",
          "target": null
        },
        {
          "id": "Trojan.Karagany - S0094",
          "display_name": "Trojan.Karagany - S0094",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1568",
          "name": "Dynamic Resolution",
          "display_name": "T1568 - Dynamic Resolution"
        },
        {
          "id": "T1040",
          "name": "Network Sniffing",
          "display_name": "T1040 - Network Sniffing"
        },
        {
          "id": "T1129",
          "name": "Shared Modules",
          "display_name": "T1129 - Shared Modules"
        },
        {
          "id": "T1574.002",
          "name": "DLL Side-Loading",
          "display_name": "T1574.002 - DLL Side-Loading"
        },
        {
          "id": "TA0002",
          "name": "Execution",
          "display_name": "TA0002 - Execution"
        },
        {
          "id": "TA0003",
          "name": "Persistence",
          "display_name": "TA0003 - Persistence"
        },
        {
          "id": "TA0004",
          "name": "Privilege Escalation",
          "display_name": "TA0004 - Privilege Escalation"
        },
        {
          "id": "TA0005",
          "name": "Defense Evasion",
          "display_name": "TA0005 - Defense Evasion"
        },
        {
          "id": "TA0008",
          "name": "Lateral Movement",
          "display_name": "TA0008 - Lateral Movement"
        },
        {
          "id": "TA0011",
          "name": "Command and Control",
          "display_name": "TA0011 - Command and Control"
        }
      ],
      "industries": [
        "Healthcare",
        "Technology",
        "Telecommunications",
        "Finance - Insurance Sector"
      ],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 38,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "scoreblue",
        "id": "254100",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 2950,
        "FileHash-MD5": 193,
        "FileHash-SHA1": 171,
        "FileHash-SHA256": 1885,
        "URL": 8907,
        "domain": 2945,
        "SSLCertFingerprint": 2,
        "email": 11,
        "CVE": 2
      },
      "indicator_count": 17066,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 229,
      "modified_text": "690 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "659b0fd1ac7cb4d83834db1f",
      "name": "Botnet Command and Control Server | Malware Distribution Site",
      "description": "",
      "modified": "2024-02-06T20:02:52.205000",
      "created": "2024-01-07T20:55:45.006000",
      "tags": [
        "passive dns",
        "urls",
        "scan endpoints",
        "all octoseek",
        "url http",
        "pulse pulses",
        "http",
        "ip address",
        "related nids",
        "files location",
        "http response",
        "final url",
        "status code",
        "body",
        "httponly",
        "ssl certificate",
        "historical ssl",
        "whois record",
        "parent referrer",
        "whois whois",
        "communicating",
        "contacted",
        "contacted urls",
        "bundled",
        "pe resource",
        "dropped",
        "army",
        "machinename",
        "execution",
        "referrer",
        "malware distribution site",
        "phishing dropbox",
        "evasive",
        "banker",
        "dde",
        "dridex",
        "exploit",
        "dyre",
        "dyreza",
        "ransomware",
        "mydoom",
        "backdoor",
        "svg",
        "phising",
        "locky",
        "e-mail provider phishing",
        "spear phishing",
        "retefe",
        "defacement",
        "phishing development bank of singapore",
        "banjori",
        "suppobox",
        "zeus",
        "pony",
        "solar",
        "ransomware locky distribution site",
        "nymaim",
        "shade",
        "troldesh",
        "tvrat",
        "zbot",
        "elocky",
        "wisdomeyes",
        "kryptic",
        "sinkhole",
        "exploit",
        "worm",
        "backdoor",
        "injector",
        "botnet command and control server",
        "unknown",
        "domain",
        "creation date",
        "search",
        "date",
        "hostname",
        "next",
        "all search",
        "otx octoseek",
        "united",
        "as13335",
        "ipv4",
        "pulse submit",
        "url analysis",
        "iocs",
        "ioc search",
        "new ioc",
        "teams api",
        "contact",
        "files",
        "nxdomain",
        "win32",
        "meta",
        "wabot",
        "gmt contenttype",
        "dnssec",
        "name",
        "win32 exe",
        "detections file",
        "file size",
        "kb file",
        "domains",
        "registrar",
        "markmonitor inc",
        "status",
        "susp",
        "expiration date",
        "name servers",
        "domain related",
        "entries",
        "johnnsabey",
        "m. brian sabey",
        "mark sabey",
        "sabey data center",
        "utah",
        "http method",
        "http requests",
        "connect http",
        "get dns",
        "resolutions",
        "ip traffic",
        "problems",
        "alienvault part",
        "kgs0",
        "kls0",
        "schema abuse",
        "sneaky server",
        "iframe",
        "apple",
        "data collection"
      ],
      "references": [
        "http://security.didici.cc/cve"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "virus.virlock/nabucur",
          "display_name": "virus.virlock/nabucur",
          "target": null
        },
        {
          "id": "Virut",
          "display_name": "Virut",
          "target": null
        },
        {
          "id": "MyDoom",
          "display_name": "MyDoom",
          "target": null
        },
        {
          "id": "Locky",
          "display_name": "Locky",
          "target": null
        },
        {
          "id": "Defacement",
          "display_name": "Defacement",
          "target": null
        },
        {
          "id": "Banjori",
          "display_name": "Banjori",
          "target": null
        },
        {
          "id": "Trojan.AvsEtecer",
          "display_name": "Trojan.AvsEtecer",
          "target": null
        },
        {
          "id": "SuppoBox",
          "display_name": "SuppoBox",
          "target": null
        },
        {
          "id": "ZeuS",
          "display_name": "ZeuS",
          "target": null
        },
        {
          "id": "Pony",
          "display_name": "Pony",
          "target": null
        },
        {
          "id": "Solar",
          "display_name": "Solar",
          "target": null
        },
        {
          "id": "Nymaim",
          "display_name": "Nymaim",
          "target": null
        },
        {
          "id": "TV RAT",
          "display_name": "TV RAT",
          "target": null
        },
        {
          "id": "Zbot",
          "display_name": "Zbot",
          "target": null
        },
        {
          "id": "Dyre",
          "display_name": "Dyre",
          "target": null
        },
        {
          "id": "ELocky",
          "display_name": "ELocky",
          "target": null
        },
        {
          "id": "Dridex",
          "display_name": "Dridex",
          "target": null
        },
        {
          "id": "Locky (Decryptor)",
          "display_name": "Locky (Decryptor)",
          "target": null
        },
        {
          "id": "Ransomware",
          "display_name": "Ransomware",
          "target": null
        },
        {
          "id": "Trojan.WisdomEyes.16070401.9500",
          "display_name": "Trojan.WisdomEyes.16070401.9500",
          "target": null
        },
        {
          "id": "Gen:Variant.Strictor",
          "display_name": "Gen:Variant.Strictor",
          "target": null
        },
        {
          "id": "Adware.BrowseFox",
          "display_name": "Adware.BrowseFox",
          "target": null
        },
        {
          "id": "W32.eHeur",
          "display_name": "W32.eHeur",
          "target": null
        },
        {
          "id": "MSIL_Kryptik.P.gen",
          "display_name": "MSIL_Kryptik.P.gen",
          "target": null
        },
        {
          "id": "pykspa_v2_fake",
          "display_name": "pykspa_v2_fake",
          "target": null
        },
        {
          "id": "Worm:Win32/Pykspa",
          "display_name": "Worm:Win32/Pykspa",
          "target": "/malware/Worm:Win32/Pykspa"
        },
        {
          "id": "Pykspa",
          "display_name": "Pykspa",
          "target": null
        },
        {
          "id": "TEL:Exploit:Win32/Sinkers",
          "display_name": "TEL:Exploit:Win32/Sinkers",
          "target": null
        },
        {
          "id": "Sabey",
          "display_name": "Sabey",
          "target": null
        },
        {
          "id": "HallRender",
          "display_name": "HallRender",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1583.005",
          "name": "Botnet",
          "display_name": "T1583.005 - Botnet"
        },
        {
          "id": "T1001",
          "name": "Data Obfuscation",
          "display_name": "T1001 - Data Obfuscation"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1449",
          "name": "Exploit SS7 to Redirect Phone Calls/SMS",
          "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
        },
        {
          "id": "T1041",
          "name": "Exfiltration Over C2 Channel",
          "display_name": "T1041 - Exfiltration Over C2 Channel"
        },
        {
          "id": "TA0011",
          "name": "Command and Control",
          "display_name": "TA0011 - Command and Control"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1059.002",
          "name": "AppleScript",
          "display_name": "T1059.002 - AppleScript"
        },
        {
          "id": "T1491",
          "name": "Defacement",
          "display_name": "T1491 - Defacement"
        },
        {
          "id": "T1410",
          "name": "Network Traffic Capture or Redirection",
          "display_name": "T1410 - Network Traffic Capture or Redirection"
        },
        {
          "id": "T1185",
          "name": "Man in the Browser",
          "display_name": "T1185 - Man in the Browser"
        },
        {
          "id": "T1594",
          "name": "Search Victim-Owned Websites",
          "display_name": "T1594 - Search Victim-Owned Websites"
        },
        {
          "id": "T1593.002",
          "name": "Search Engines",
          "display_name": "T1593.002 - Search Engines"
        },
        {
          "id": "T1574.008",
          "name": "Path Interception by Search Order Hijacking",
          "display_name": "T1574.008 - Path Interception by Search Order Hijacking"
        },
        {
          "id": "T1114",
          "name": "Email Collection",
          "display_name": "T1114 - Email Collection"
        },
        {
          "id": "T1114.002",
          "name": "Remote Email Collection",
          "display_name": "T1114.002 - Remote Email Collection"
        },
        {
          "id": "TA0009",
          "name": "Collection",
          "display_name": "TA0009 - Collection"
        },
        {
          "id": "T1457",
          "name": "Malicious Media Content",
          "display_name": "T1457 - Malicious Media Content"
        },
        {
          "id": "T1587.001",
          "name": "Malware",
          "display_name": "T1587.001 - Malware"
        },
        {
          "id": "T1608.001",
          "name": "Upload Malware",
          "display_name": "T1608.001 - Upload Malware"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 35,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 231,
        "FileHash-SHA256": 3121,
        "URL": 4225,
        "domain": 1725,
        "hostname": 1416,
        "FileHash-SHA1": 225,
        "CVE": 2,
        "email": 3
      },
      "indicator_count": 10948,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 224,
      "modified_text": "844 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "65a48ab7cd0bd218b17ccf6c",
      "name": "Botnet Command and Control Server | Malware",
      "description": "",
      "modified": "2024-02-06T20:02:52.205000",
      "created": "2024-01-15T01:30:31.655000",
      "tags": [
        "passive dns",
        "urls",
        "scan endpoints",
        "all octoseek",
        "url http",
        "pulse pulses",
        "http",
        "ip address",
        "related nids",
        "files location",
        "http response",
        "final url",
        "status code",
        "body",
        "httponly",
        "ssl certificate",
        "historical ssl",
        "whois record",
        "parent referrer",
        "whois whois",
        "communicating",
        "contacted",
        "contacted urls",
        "bundled",
        "pe resource",
        "dropped",
        "army",
        "machinename",
        "execution",
        "referrer",
        "malware distribution site",
        "phishing dropbox",
        "evasive",
        "banker",
        "dde",
        "dridex",
        "exploit",
        "dyre",
        "dyreza",
        "ransomware",
        "mydoom",
        "backdoor",
        "svg",
        "phising",
        "locky",
        "e-mail provider phishing",
        "spear phishing",
        "retefe",
        "defacement",
        "phishing development bank of singapore",
        "banjori",
        "suppobox",
        "zeus",
        "pony",
        "solar",
        "ransomware locky distribution site",
        "nymaim",
        "shade",
        "troldesh",
        "tvrat",
        "zbot",
        "elocky",
        "wisdomeyes",
        "kryptic",
        "sinkhole",
        "exploit",
        "worm",
        "backdoor",
        "injector",
        "botnet command and control server",
        "unknown",
        "domain",
        "creation date",
        "search",
        "date",
        "hostname",
        "next",
        "all search",
        "otx octoseek",
        "united",
        "as13335",
        "ipv4",
        "pulse submit",
        "url analysis",
        "iocs",
        "ioc search",
        "new ioc",
        "teams api",
        "contact",
        "files",
        "nxdomain",
        "win32",
        "meta",
        "wabot",
        "gmt contenttype",
        "dnssec",
        "name",
        "win32 exe",
        "detections file",
        "file size",
        "kb file",
        "domains",
        "registrar",
        "markmonitor inc",
        "status",
        "susp",
        "expiration date",
        "name servers",
        "domain related",
        "entries",
        "johnnsabey",
        "m. brian sabey",
        "mark sabey",
        "sabey data center",
        "utah",
        "http method",
        "http requests",
        "connect http",
        "get dns",
        "resolutions",
        "ip traffic",
        "problems",
        "alienvault part",
        "kgs0",
        "kls0",
        "schema abuse",
        "sneaky server",
        "iframe",
        "apple",
        "data collection"
      ],
      "references": [
        "http://security.didici.cc/cve"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "virus.virlock/nabucur",
          "display_name": "virus.virlock/nabucur",
          "target": null
        },
        {
          "id": "Virut",
          "display_name": "Virut",
          "target": null
        },
        {
          "id": "MyDoom",
          "display_name": "MyDoom",
          "target": null
        },
        {
          "id": "Locky",
          "display_name": "Locky",
          "target": null
        },
        {
          "id": "Defacement",
          "display_name": "Defacement",
          "target": null
        },
        {
          "id": "Banjori",
          "display_name": "Banjori",
          "target": null
        },
        {
          "id": "Trojan.AvsEtecer",
          "display_name": "Trojan.AvsEtecer",
          "target": null
        },
        {
          "id": "SuppoBox",
          "display_name": "SuppoBox",
          "target": null
        },
        {
          "id": "ZeuS",
          "display_name": "ZeuS",
          "target": null
        },
        {
          "id": "Pony",
          "display_name": "Pony",
          "target": null
        },
        {
          "id": "Solar",
          "display_name": "Solar",
          "target": null
        },
        {
          "id": "Nymaim",
          "display_name": "Nymaim",
          "target": null
        },
        {
          "id": "TV RAT",
          "display_name": "TV RAT",
          "target": null
        },
        {
          "id": "Zbot",
          "display_name": "Zbot",
          "target": null
        },
        {
          "id": "Dyre",
          "display_name": "Dyre",
          "target": null
        },
        {
          "id": "ELocky",
          "display_name": "ELocky",
          "target": null
        },
        {
          "id": "Dridex",
          "display_name": "Dridex",
          "target": null
        },
        {
          "id": "Locky (Decryptor)",
          "display_name": "Locky (Decryptor)",
          "target": null
        },
        {
          "id": "Ransomware",
          "display_name": "Ransomware",
          "target": null
        },
        {
          "id": "Trojan.WisdomEyes.16070401.9500",
          "display_name": "Trojan.WisdomEyes.16070401.9500",
          "target": null
        },
        {
          "id": "Gen:Variant.Strictor",
          "display_name": "Gen:Variant.Strictor",
          "target": null
        },
        {
          "id": "Adware.BrowseFox",
          "display_name": "Adware.BrowseFox",
          "target": null
        },
        {
          "id": "W32.eHeur",
          "display_name": "W32.eHeur",
          "target": null
        },
        {
          "id": "MSIL_Kryptik.P.gen",
          "display_name": "MSIL_Kryptik.P.gen",
          "target": null
        },
        {
          "id": "pykspa_v2_fake",
          "display_name": "pykspa_v2_fake",
          "target": null
        },
        {
          "id": "Worm:Win32/Pykspa",
          "display_name": "Worm:Win32/Pykspa",
          "target": "/malware/Worm:Win32/Pykspa"
        },
        {
          "id": "Pykspa",
          "display_name": "Pykspa",
          "target": null
        },
        {
          "id": "TEL:Exploit:Win32/Sinkers",
          "display_name": "TEL:Exploit:Win32/Sinkers",
          "target": null
        },
        {
          "id": "Sabey",
          "display_name": "Sabey",
          "target": null
        },
        {
          "id": "HallRender",
          "display_name": "HallRender",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1583.005",
          "name": "Botnet",
          "display_name": "T1583.005 - Botnet"
        },
        {
          "id": "T1001",
          "name": "Data Obfuscation",
          "display_name": "T1001 - Data Obfuscation"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1449",
          "name": "Exploit SS7 to Redirect Phone Calls/SMS",
          "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
        },
        {
          "id": "T1041",
          "name": "Exfiltration Over C2 Channel",
          "display_name": "T1041 - Exfiltration Over C2 Channel"
        },
        {
          "id": "TA0011",
          "name": "Command and Control",
          "display_name": "TA0011 - Command and Control"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1059.002",
          "name": "AppleScript",
          "display_name": "T1059.002 - AppleScript"
        },
        {
          "id": "T1491",
          "name": "Defacement",
          "display_name": "T1491 - Defacement"
        },
        {
          "id": "T1410",
          "name": "Network Traffic Capture or Redirection",
          "display_name": "T1410 - Network Traffic Capture or Redirection"
        },
        {
          "id": "T1185",
          "name": "Man in the Browser",
          "display_name": "T1185 - Man in the Browser"
        },
        {
          "id": "T1594",
          "name": "Search Victim-Owned Websites",
          "display_name": "T1594 - Search Victim-Owned Websites"
        },
        {
          "id": "T1593.002",
          "name": "Search Engines",
          "display_name": "T1593.002 - Search Engines"
        },
        {
          "id": "T1574.008",
          "name": "Path Interception by Search Order Hijacking",
          "display_name": "T1574.008 - Path Interception by Search Order Hijacking"
        },
        {
          "id": "T1114",
          "name": "Email Collection",
          "display_name": "T1114 - Email Collection"
        },
        {
          "id": "T1114.002",
          "name": "Remote Email Collection",
          "display_name": "T1114.002 - Remote Email Collection"
        },
        {
          "id": "TA0009",
          "name": "Collection",
          "display_name": "TA0009 - Collection"
        },
        {
          "id": "T1457",
          "name": "Malicious Media Content",
          "display_name": "T1457 - Malicious Media Content"
        },
        {
          "id": "T1587.001",
          "name": "Malware",
          "display_name": "T1587.001 - Malware"
        },
        {
          "id": "T1608.001",
          "name": "Upload Malware",
          "display_name": "T1608.001 - Upload Malware"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": "659b0fd1ac7cb4d83834db1f",
      "export_count": 25,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "scoreblue",
        "id": "254100",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 231,
        "FileHash-SHA256": 3121,
        "URL": 4225,
        "domain": 1725,
        "hostname": 1416,
        "FileHash-SHA1": 225,
        "CVE": 2,
        "email": 3
      },
      "indicator_count": 10948,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 231,
      "modified_text": "844 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "https://resonantcavity.com/voloco/",
    "type": "URL"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "https://resonantcavity.com/voloco/",
    "type": "URL",
    "found": false,
    "verdict": "clean",
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780235534.5645137
}