{
  "type": "URL",
  "indicator": "https://sip.nomadicguild.com",
  "general": {
    "sections": [
      "general",
      "url_list",
      "http_scans",
      "screenshot"
    ],
    "indicator": "https://sip.nomadicguild.com",
    "type": "url",
    "type_title": "URL",
    "validation": [],
    "base_indicator": {
      "id": 3175196547,
      "indicator": "https://sip.nomadicguild.com",
      "type": "URL",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 11,
      "pulses": [
        {
          "id": "66994bda3e150656cd5ac9dd",
          "name": "Browser Session Hijacking Various MyChart Phishing Scams",
          "description": "Ongoing issues with medical information hijacking. Various medical corporations affected. Tracking, medical, injection process, records retrieval, botnets.",
          "modified": "2024-08-17T16:01:11.866000",
          "created": "2024-07-18T17:07:38.719000",
          "tags": [
            "historical ssl",
            "referrer",
            "domains",
            "august",
            "phishingscams",
            "domains part",
            "domain tracker",
            "roundup",
            "new problems",
            "privacy badger",
            "startpage",
            "self",
            "httponly",
            "samesitenone",
            "http response",
            "final url",
            "ip address",
            "status code",
            "body length",
            "b body",
            "sha256",
            "pragma",
            "mychartlocale",
            "urls",
            "ip detections",
            "country",
            "contacted",
            "files",
            "file type",
            "name file",
            "gmbh",
            "cloudflare",
            "tucows",
            "ii llc",
            "alibaba cloud",
            "computing",
            "sample",
            "media t1091",
            "t1497 may",
            "mitre att",
            "access ta0001",
            "replication",
            "ta0004 process",
            "injection t1055",
            "defense evasion",
            "http requests",
            "get http",
            "request",
            "host",
            "dns resolutions",
            "ip traffic",
            "hashes",
            "tsara brashears",
            "red team",
            "hackers",
            "highly targeted",
            "critical risk",
            "cyberstalking",
            "apple",
            "apple ios",
            "logistics",
            "cyber defense",
            "guloader",
            "hacktool",
            "emotet",
            "phishing",
            "facebook",
            "malware",
            "hiddentear",
            "maze",
            "server",
            "domain status",
            "date",
            "algorithm",
            "google llc",
            "registrar abuse",
            "registrar",
            "record type",
            "ttl value",
            "aaaa",
            "whois lookup",
            "admin country",
            "ca creation",
            "dnssec",
            "markmonitor",
            "siblings",
            "whois lookups",
            "expiration date",
            "registrar iana",
            "creation date",
            "first",
            "united",
            "as15169 google",
            "cname",
            "status",
            "virtool",
            "cryp",
            "as396982 google",
            "search",
            "name servers",
            "win32",
            "remote"
          ],
          "references": [
            "MyChart Phishing Scams",
            "exploit_source IP's: 20.99.186.246 , 40.126.24.147 , 40.126.24.149 , 40.126.24.81 , 40.126.24.82",
            "VirTool:Win32/Obfuscator: 0.googleusercontent.com [hacking]",
            "https://www.anyxxxtube.net/search-porn/tsara-brashears/\t URL\thttp://45.159.189.105/bot/regex |\thttps://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Win64-Trojan/Pakes.Exp",
              "display_name": "Win64-Trojan/Pakes.Exp",
              "target": null
            },
            {
              "id": "Win64:RansomX-gen",
              "display_name": "Win64:RansomX-gen",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1012",
              "name": "Query Registry",
              "display_name": "T1012 - Query Registry"
            },
            {
              "id": "T1018",
              "name": "Remote System Discovery",
              "display_name": "T1018 - Remote System Discovery"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1091",
              "name": "Replication Through Removable Media",
              "display_name": "T1091 - Replication Through Removable Media"
            },
            {
              "id": "T1095",
              "name": "Non-Application Layer Protocol",
              "display_name": "T1095 - Non-Application Layer Protocol"
            },
            {
              "id": "T1120",
              "name": "Peripheral Device Discovery",
              "display_name": "T1120 - Peripheral Device Discovery"
            },
            {
              "id": "T1185",
              "name": "Man in the Browser",
              "display_name": "T1185 - Man in the Browser"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1518",
              "name": "Software Discovery",
              "display_name": "T1518 - Software Discovery"
            },
            {
              "id": "T1562",
              "name": "Impair Defenses",
              "display_name": "T1562 - Impair Defenses"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            }
          ],
          "industries": [
            "Healthcare",
            "Technology"
          ],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 27,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 37,
            "FileHash-SHA1": 33,
            "FileHash-SHA256": 3473,
            "domain": 693,
            "URL": 4384,
            "hostname": 1610,
            "CVE": 2,
            "email": 3
          },
          "indicator_count": 10235,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 231,
          "modified_text": "610 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "655a13e4538e896c00f2077e",
          "name": "Spyware: http://browser.events.data.microsoftstart.cn",
          "description": "This report is generated by MITRE ATT&CK\u2122 and produced by the team at the University of California, San Francisco, and is available on the web, via the Microsoft Research website.\nTulach, 114.114.114.114, spyware, phishing, fraud, malvertizing, password cracker, iPhone unlocker, malicious, media sharing, miscellaneous attacks.",
          "modified": "2023-12-19T13:01:12.394000",
          "created": "2023-11-19T13:55:48.898000",
          "tags": [
            "linkid246338",
            "whois record",
            "ssl certificate",
            "contacted",
            "execution",
            "historical ssl",
            "whois whois",
            "communicating",
            "resolutions",
            "referrer",
            "random",
            "august",
            "lockbit",
            "attack",
            "core",
            "name verdict",
            "falcon sandbox",
            "pattern match",
            "root ca",
            "done adding",
            "catalog file",
            "authority",
            "class",
            "mitre att",
            "script",
            "temp",
            "ascii text",
            "date",
            "unknown",
            "service",
            "generator",
            "critical",
            "error",
            "meta",
            "hybrid",
            "local",
            "click",
            "strings",
            "threat roundup"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1100",
              "name": "Web Shell",
              "display_name": "T1100 - Web Shell"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1560",
              "name": "Archive Collected Data",
              "display_name": "T1560 - Archive Collected Data"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 7,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 34,
            "FileHash-SHA1": 28,
            "FileHash-SHA256": 2526,
            "URL": 3515,
            "domain": 458,
            "hostname": 1092
          },
          "indicator_count": 7653,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 219,
          "modified_text": "852 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "655af35616dbd4781c681948",
          "name": "Spyware: http://browser.events.data.microsoftstart.cn",
          "description": "",
          "modified": "2023-12-19T13:01:12.394000",
          "created": "2023-11-20T05:49:10.586000",
          "tags": [
            "linkid246338",
            "whois record",
            "ssl certificate",
            "contacted",
            "execution",
            "historical ssl",
            "whois whois",
            "communicating",
            "resolutions",
            "referrer",
            "random",
            "august",
            "lockbit",
            "attack",
            "core",
            "name verdict",
            "falcon sandbox",
            "pattern match",
            "root ca",
            "done adding",
            "catalog file",
            "authority",
            "class",
            "mitre att",
            "script",
            "temp",
            "ascii text",
            "date",
            "unknown",
            "service",
            "generator",
            "critical",
            "error",
            "meta",
            "hybrid",
            "local",
            "click",
            "strings",
            "threat roundup"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1100",
              "name": "Web Shell",
              "display_name": "T1100 - Web Shell"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1560",
              "name": "Archive Collected Data",
              "display_name": "T1560 - Archive Collected Data"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": "655a13e4538e896c00f2077e",
          "export_count": 15,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 34,
            "FileHash-SHA1": 28,
            "FileHash-SHA256": 2526,
            "URL": 3515,
            "domain": 458,
            "hostname": 1092
          },
          "indicator_count": 7653,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 224,
          "modified_text": "852 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6570a975e2a76dd4ddaec80a",
          "name": "Remote Access attack | Agent Tesla | C2 | BatLoader | C2 | Dridex",
          "description": "",
          "modified": "2023-12-06T17:03:49.269000",
          "created": "2023-12-06T17:03:49.269000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 16,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "CVE": 8,
            "FileHash-SHA256": 2173,
            "domain": 584,
            "hostname": 1707,
            "URL": 4145,
            "FileHash-SHA1": 545,
            "FileHash-MD5": 1071
          },
          "indicator_count": 10233,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 111,
          "modified_text": "865 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "656a97db9134b17c1f6d845b",
          "name": "DeepScan:Generic.Ransom.GandCrab5",
          "description": "",
          "modified": "2023-12-02T02:35:07.890000",
          "created": "2023-12-02T02:35:07.890000",
          "tags": [
            "cisco umbrella",
            "site",
            "safe site",
            "detection list",
            "blacklist",
            "million",
            "malicious url",
            "maltiverse",
            "heuristic",
            "redirme",
            "exploit",
            "malware",
            "team",
            "microsoft",
            "urlhttps",
            "blacklist https",
            "noname057",
            "threat report",
            "ip summary",
            "url summary",
            "summary",
            "sample",
            "samples",
            "hacktool",
            "arkeistealer",
            "mail spammer",
            "united",
            "germany",
            "opencandy",
            "proxy",
            "firehol",
            "alexa top",
            "phishing site",
            "malicious site",
            "malware site",
            "alexa",
            "phishing",
            "iframe",
            "downldr",
            "agent",
            "presenoker",
            "riskware",
            "unsafe",
            "artemis",
            "bank",
            "cve201711882",
            "tag count",
            "cyber threat",
            "httponly",
            "samesitenone",
            "http response",
            "final url",
            "ip address",
            "status code",
            "body length",
            "kb body",
            "sha256",
            "headers",
            "pragma",
            "contacted urls",
            "ssl certificate",
            "whois record",
            "xmodeargs",
            "whois whois",
            "xdpid1203",
            "xpubid10839",
            "september",
            "tsara brashears",
            "collection",
            "emotet",
            "malicious",
            "critical",
            "copy",
            "installer",
            "banker",
            "keylogger",
            "heur",
            "filerepmetagen",
            "suspected",
            "adware",
            "acint",
            "nircmd",
            "swrort",
            "systweak",
            "behav",
            "crack",
            "tiggre",
            "genkryptik",
            "filetour",
            "cleaner",
            "conduit",
            "wacatac",
            "trojanspy",
            "webtoolbar"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "TrojanSpy",
              "display_name": "TrojanSpy",
              "target": null
            },
            {
              "id": "WebToolbar",
              "display_name": "WebToolbar",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": "6541df216e018a0bce63e2a3",
          "export_count": 8,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 2559,
            "CVE": 6,
            "FileHash-MD5": 582,
            "FileHash-SHA1": 353,
            "FileHash-SHA256": 3232,
            "hostname": 826,
            "domain": 206,
            "URI": 1
          },
          "indicator_count": 7765,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 227,
          "modified_text": "869 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6541df216e018a0bce63e2a3",
          "name": "DeepScan:Generic.Ransom.GandCrab5",
          "description": "Malicious redirect. OWA? Dreaded Canary cookie? I don't know yet. Link affects individuals, corporations and edu's. \n\n{*https://mail.greycroft.com/owa/redir.aspx?SURL=a0oI1dvGGkFYUoACVEbN8REVrmfS6H0MhUvXdexgmertl7bBVhrTCGgAdAB0AHAAcwA6AC8ALwB3AHcAdwAuAHAAcgBvAGQAdQBjAHQAaAB1AG4AdAAuAGMAbwBtAC8AdABlAGMAaAAvAGEAbgBpAG0AYQB0AGkAYwA.&URL=https://www.producthunt.com/tech/animatic\n*Redirects to: https://login.microsoftonline.com/jsdisabled}\n(AUTO POPULATED: A full list of findings from the Maltiverse Research Team on Malware and Exploit, as compiled by the National Security Agency (NSA), has been published on the website of Microsoft's website.)",
          "modified": "2023-12-01T04:05:20.963000",
          "created": "2023-11-01T05:16:17.835000",
          "tags": [
            "cisco umbrella",
            "site",
            "safe site",
            "detection list",
            "blacklist",
            "million",
            "malicious url",
            "maltiverse",
            "heuristic",
            "redirme",
            "exploit",
            "malware",
            "team",
            "microsoft",
            "urlhttps",
            "blacklist https",
            "noname057",
            "threat report",
            "ip summary",
            "url summary",
            "summary",
            "sample",
            "samples",
            "hacktool",
            "arkeistealer",
            "mail spammer",
            "united",
            "germany",
            "opencandy",
            "proxy",
            "firehol",
            "alexa top",
            "phishing site",
            "malicious site",
            "malware site",
            "alexa",
            "phishing",
            "iframe",
            "downldr",
            "agent",
            "presenoker",
            "riskware",
            "unsafe",
            "artemis",
            "bank",
            "cve201711882",
            "tag count",
            "cyber threat",
            "httponly",
            "samesitenone",
            "http response",
            "final url",
            "ip address",
            "status code",
            "body length",
            "kb body",
            "sha256",
            "headers",
            "pragma",
            "contacted urls",
            "ssl certificate",
            "whois record",
            "xmodeargs",
            "whois whois",
            "xdpid1203",
            "xpubid10839",
            "september",
            "tsara brashears",
            "collection",
            "emotet",
            "malicious",
            "critical",
            "copy",
            "installer",
            "banker",
            "keylogger",
            "heur",
            "filerepmetagen",
            "suspected",
            "adware",
            "acint",
            "nircmd",
            "swrort",
            "systweak",
            "behav",
            "crack",
            "tiggre",
            "genkryptik",
            "filetour",
            "cleaner",
            "conduit",
            "wacatac",
            "trojanspy",
            "webtoolbar"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "TrojanSpy",
              "display_name": "TrojanSpy",
              "target": null
            },
            {
              "id": "WebToolbar",
              "display_name": "WebToolbar",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 23,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 2559,
            "CVE": 6,
            "FileHash-MD5": 582,
            "FileHash-SHA1": 353,
            "FileHash-SHA256": 3232,
            "hostname": 826,
            "domain": 206,
            "URI": 1
          },
          "indicator_count": 7765,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 221,
          "modified_text": "870 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6541e08c81e836438946bbbf",
          "name": "TrojanSpy",
          "description": "Malicious redirect.  Targets individual.\n{*https://mail.greycroft.com/owa/redir.aspx?SURL=a0oI1dvGGkFYUoACVEbN8REVrmfS6H0MhUvXdexgmertl7bBVhrTCGgAdAB0AHAAcwA6AC8ALwB3AHcAdwAuAHAAcgBvAGQAdQBjAHQAaAB1AG4AdAAuAGMAbwBtAC8AdABlAGMAaAAvAGEAbgBpAG0AYQB0AGkAYwA.&URL=https://www.producthunt.com/tech/animatic\n*Redirects to: https://login.microsoftonline.com/jsdisabled}\n(AUTO POPULATED: A full list of findings from the Maltiverse Research Team on Malware and Exploit, as compiled by the National Security Agency (NSA), has been published on the website of Microsoft's website.)",
          "modified": "2023-12-01T04:05:20.963000",
          "created": "2023-11-01T05:22:20.519000",
          "tags": [
            "cisco umbrella",
            "site",
            "safe site",
            "detection list",
            "blacklist",
            "million",
            "malicious url",
            "maltiverse",
            "heuristic",
            "redirme",
            "exploit",
            "malware",
            "team",
            "microsoft",
            "urlhttps",
            "blacklist https",
            "noname057",
            "threat report",
            "ip summary",
            "url summary",
            "summary",
            "sample",
            "samples",
            "hacktool",
            "arkeistealer",
            "mail spammer",
            "united",
            "germany",
            "opencandy",
            "proxy",
            "firehol",
            "alexa top",
            "phishing site",
            "malicious site",
            "malware site",
            "alexa",
            "phishing",
            "iframe",
            "downldr",
            "agent",
            "presenoker",
            "riskware",
            "unsafe",
            "artemis",
            "bank",
            "cve201711882",
            "tag count",
            "cyber threat",
            "httponly",
            "samesitenone",
            "http response",
            "final url",
            "ip address",
            "status code",
            "body length",
            "kb body",
            "sha256",
            "headers",
            "pragma",
            "contacted urls",
            "ssl certificate",
            "whois record",
            "xmodeargs",
            "whois whois",
            "xdpid1203",
            "xpubid10839",
            "september",
            "tsara brashears",
            "collection",
            "emotet",
            "malicious",
            "critical",
            "copy",
            "installer",
            "banker",
            "keylogger",
            "heur",
            "filerepmetagen",
            "suspected",
            "adware",
            "acint",
            "nircmd",
            "swrort",
            "systweak",
            "behav",
            "crack",
            "tiggre",
            "genkryptik",
            "filetour",
            "cleaner",
            "conduit",
            "wacatac",
            "trojanspy",
            "webtoolbar"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "TrojanSpy",
              "display_name": "TrojanSpy",
              "target": null
            },
            {
              "id": "WebToolbar",
              "display_name": "WebToolbar",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 27,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 2559,
            "CVE": 6,
            "FileHash-MD5": 582,
            "FileHash-SHA1": 353,
            "FileHash-SHA256": 3232,
            "hostname": 826,
            "domain": 206,
            "URI": 1
          },
          "indicator_count": 7765,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 221,
          "modified_text": "870 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6543350c86e1299dc78bfa90",
          "name": "this dick",
          "description": "",
          "modified": "2023-12-01T04:05:20.963000",
          "created": "2023-11-02T05:35:08.226000",
          "tags": [
            "cisco umbrella",
            "site",
            "safe site",
            "detection list",
            "blacklist",
            "million",
            "malicious url",
            "maltiverse",
            "heuristic",
            "redirme",
            "exploit",
            "malware",
            "team",
            "microsoft",
            "urlhttps",
            "blacklist https",
            "noname057",
            "threat report",
            "ip summary",
            "url summary",
            "summary",
            "sample",
            "samples",
            "hacktool",
            "arkeistealer",
            "mail spammer",
            "united",
            "germany",
            "opencandy",
            "proxy",
            "firehol",
            "alexa top",
            "phishing site",
            "malicious site",
            "malware site",
            "alexa",
            "phishing",
            "iframe",
            "downldr",
            "agent",
            "presenoker",
            "riskware",
            "unsafe",
            "artemis",
            "bank",
            "cve201711882",
            "tag count",
            "cyber threat",
            "httponly",
            "samesitenone",
            "http response",
            "final url",
            "ip address",
            "status code",
            "body length",
            "kb body",
            "sha256",
            "headers",
            "pragma",
            "contacted urls",
            "ssl certificate",
            "whois record",
            "xmodeargs",
            "whois whois",
            "xdpid1203",
            "xpubid10839",
            "september",
            "tsara brashears",
            "collection",
            "emotet",
            "malicious",
            "critical",
            "copy",
            "installer",
            "banker",
            "keylogger",
            "heur",
            "filerepmetagen",
            "suspected",
            "adware",
            "acint",
            "nircmd",
            "swrort",
            "systweak",
            "behav",
            "crack",
            "tiggre",
            "genkryptik",
            "filetour",
            "cleaner",
            "conduit",
            "wacatac",
            "trojanspy",
            "webtoolbar"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "TrojanSpy",
              "display_name": "TrojanSpy",
              "target": null
            },
            {
              "id": "WebToolbar",
              "display_name": "WebToolbar",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": "6541df216e018a0bce63e2a3",
          "export_count": 21,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Nicholus33",
            "id": "76046",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 2559,
            "CVE": 6,
            "FileHash-MD5": 582,
            "FileHash-SHA1": 353,
            "FileHash-SHA256": 3232,
            "hostname": 826,
            "domain": 207,
            "URI": 1
          },
          "indicator_count": 7766,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 2,
          "modified_text": "870 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6545a25d60272bac5827f2fc",
          "name": "TrojanSpy",
          "description": "",
          "modified": "2023-12-01T04:05:20.963000",
          "created": "2023-11-04T01:46:05.174000",
          "tags": [
            "cisco umbrella",
            "site",
            "safe site",
            "detection list",
            "blacklist",
            "million",
            "malicious url",
            "maltiverse",
            "heuristic",
            "redirme",
            "exploit",
            "malware",
            "team",
            "microsoft",
            "urlhttps",
            "blacklist https",
            "noname057",
            "threat report",
            "ip summary",
            "url summary",
            "summary",
            "sample",
            "samples",
            "hacktool",
            "arkeistealer",
            "mail spammer",
            "united",
            "germany",
            "opencandy",
            "proxy",
            "firehol",
            "alexa top",
            "phishing site",
            "malicious site",
            "malware site",
            "alexa",
            "phishing",
            "iframe",
            "downldr",
            "agent",
            "presenoker",
            "riskware",
            "unsafe",
            "artemis",
            "bank",
            "cve201711882",
            "tag count",
            "cyber threat",
            "httponly",
            "samesitenone",
            "http response",
            "final url",
            "ip address",
            "status code",
            "body length",
            "kb body",
            "sha256",
            "headers",
            "pragma",
            "contacted urls",
            "ssl certificate",
            "whois record",
            "xmodeargs",
            "whois whois",
            "xdpid1203",
            "xpubid10839",
            "september",
            "tsara brashears",
            "collection",
            "emotet",
            "malicious",
            "critical",
            "copy",
            "installer",
            "banker",
            "keylogger",
            "heur",
            "filerepmetagen",
            "suspected",
            "adware",
            "acint",
            "nircmd",
            "swrort",
            "systweak",
            "behav",
            "crack",
            "tiggre",
            "genkryptik",
            "filetour",
            "cleaner",
            "conduit",
            "wacatac",
            "trojanspy",
            "webtoolbar"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "TrojanSpy",
              "display_name": "TrojanSpy",
              "target": null
            },
            {
              "id": "WebToolbar",
              "display_name": "WebToolbar",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": "6541e08c81e836438946bbbf",
          "export_count": 26,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 2559,
            "CVE": 6,
            "FileHash-MD5": 582,
            "FileHash-SHA1": 353,
            "FileHash-SHA256": 3232,
            "hostname": 826,
            "domain": 206,
            "URI": 1
          },
          "indicator_count": 7765,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 228,
          "modified_text": "870 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "652c33c45c1f1566c4b8c6a2",
          "name": "Remote Access attack | Agent Tesla | C2 | BatLoader | C2 | Dridex",
          "description": "https://login.live.com/oauth20_remoteconnect.srf\nInvalid CRDS Token\nI suffered quite an attack on my devices. My personal experience, phone service changed, embedding., privilege escalation adversaries,  remote probe, obvious unauthorized microsoft usage multiple logins. embedded  phone service apps, injected, unknown apps, dumping. connect/shared/ tethered to other clouds, apps devices, decrypted phone., cookies turned off after attack, no Google, other search engine access, passwords compromised malicious Google sorry index w/Azorult. I am targeted. Usual suspects\nPrior: 'D241 connect test was successful messages'. Wifi and cellular issues.\nAftermath, Zombie devices. C2. Calls don't connect, keyloggers, etc",
          "modified": "2023-11-14T17:01:45.019000",
          "created": "2023-10-15T18:47:32.354000",
          "tags": [
            "whois record",
            "historical ssl",
            "ssl certificate",
            "communicating",
            "referrer",
            "united",
            "mail spammer",
            "detection list",
            "ip address",
            "blacklist",
            "possiblecerber",
            "outlook",
            "covid19",
            "artemis",
            "unsafe",
            "cisco umbrella",
            "site",
            "safe site",
            "phishing site",
            "malicious site",
            "malware",
            "malware site",
            "alexa top",
            "million",
            "phishingms",
            "exploit",
            "live",
            "blacklist https",
            "javascript",
            "http response",
            "final url",
            "serving ip",
            "address",
            "status code",
            "body length",
            "kb body",
            "sha256",
            "headers",
            "p3p cp",
            "pragma",
            "whois whois",
            "contacted",
            "threat network",
            "pe resource",
            "uatrue url",
            "typepv",
            "probe",
            "execution",
            "core",
            "emotet",
            "remcos",
            "nokoyawa",
            "asyncrat",
            "heur",
            "anonymizer",
            "firehol",
            "trojanx",
            "agent",
            "riskware",
            "trojan",
            "binder",
            "small",
            "downloader",
            "hupigon",
            "crypt",
            "cobalt strike",
            "union",
            "team",
            "agent tesla",
            "malicious",
            "fakealert",
            "dbatloader",
            "stealer",
            "nanocore rat",
            "formbook",
            "dropper",
            "dridex",
            "hawkeye",
            "netwire",
            "download",
            "opencandy",
            "bladabindi",
            "phishing",
            "bank",
            "alexa",
            "trojanspy",
            "maltiverse",
            "uatrue",
            "processorx86",
            "langen",
            "generic malware",
            "fakedout threat",
            "ip summary",
            "url summary",
            "summary",
            "sample",
            "samples",
            "injected",
            "mitre",
            "attack",
            "cybercrime",
            "Suspicious.Save",
            "dns server",
            "scanning ip's",
            "Backdoor.Remcos",
            "Threats200220200050",
            "IOC_19052020",
            "behaves like emotet"
          ],
          "references": [
            "https://login.live.com/oauth20_remoteconnect.srf"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America",
            "France"
          ],
          "malware_families": [
            {
              "id": "TrojanSpy",
              "display_name": "TrojanSpy",
              "target": null
            },
            {
              "id": "Maltiverse",
              "display_name": "Maltiverse",
              "target": null
            },
            {
              "id": "Dridex",
              "display_name": "Dridex",
              "target": null
            },
            {
              "id": "Agent Tesla - S0331",
              "display_name": "Agent Tesla - S0331",
              "target": null
            },
            {
              "id": "HawkEye Keylogger",
              "display_name": "HawkEye Keylogger",
              "target": null
            },
            {
              "id": "Suspicious.Save",
              "display_name": "Suspicious.Save",
              "target": null
            },
            {
              "id": "Application.Generic",
              "display_name": "Application.Generic",
              "target": null
            },
            {
              "id": "Backdoor.RemoteManipulator",
              "display_name": "Backdoor.RemoteManipulator",
              "target": null
            },
            {
              "id": "Gen:Heur.Ransom.HiddenTears",
              "display_name": "Gen:Heur.Ransom.HiddenTears",
              "target": null
            },
            {
              "id": "XOR.DDoS",
              "display_name": "XOR.DDoS",
              "target": null
            },
            {
              "id": "Backdoor.Remcos",
              "display_name": "Backdoor.Remcos",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "TA0037",
              "name": "Command and Control",
              "display_name": "TA0037 - Command and Control"
            },
            {
              "id": "T1068",
              "name": "Exploitation for Privilege Escalation",
              "display_name": "T1068 - Exploitation for Privilege Escalation"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1593.002",
              "name": "Search Engines",
              "display_name": "T1593.002 - Search Engines"
            },
            {
              "id": "T1449",
              "name": "Exploit SS7 to Redirect Phone Calls/SMS",
              "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 34,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 1071,
            "FileHash-SHA1": 545,
            "FileHash-SHA256": 2173,
            "domain": 584,
            "hostname": 1707,
            "URL": 4145,
            "CVE": 8
          },
          "indicator_count": 10233,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 228,
          "modified_text": "887 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "653f1c989df5416bd0ff3d38",
          "name": "Remote Access attack | Agent Tesla | C2 | BatLoader | C2 | Dridex",
          "description": "",
          "modified": "2023-11-14T17:01:45.019000",
          "created": "2023-10-30T03:01:44.846000",
          "tags": [
            "whois record",
            "historical ssl",
            "ssl certificate",
            "communicating",
            "referrer",
            "united",
            "mail spammer",
            "detection list",
            "ip address",
            "blacklist",
            "possiblecerber",
            "outlook",
            "covid19",
            "artemis",
            "unsafe",
            "cisco umbrella",
            "site",
            "safe site",
            "phishing site",
            "malicious site",
            "malware",
            "malware site",
            "alexa top",
            "million",
            "phishingms",
            "exploit",
            "live",
            "blacklist https",
            "javascript",
            "http response",
            "final url",
            "serving ip",
            "address",
            "status code",
            "body length",
            "kb body",
            "sha256",
            "headers",
            "p3p cp",
            "pragma",
            "whois whois",
            "contacted",
            "threat network",
            "pe resource",
            "uatrue url",
            "typepv",
            "probe",
            "execution",
            "core",
            "emotet",
            "remcos",
            "nokoyawa",
            "asyncrat",
            "heur",
            "anonymizer",
            "firehol",
            "trojanx",
            "agent",
            "riskware",
            "trojan",
            "binder",
            "small",
            "downloader",
            "hupigon",
            "crypt",
            "cobalt strike",
            "union",
            "team",
            "agent tesla",
            "malicious",
            "fakealert",
            "dbatloader",
            "stealer",
            "nanocore rat",
            "formbook",
            "dropper",
            "dridex",
            "hawkeye",
            "netwire",
            "download",
            "opencandy",
            "bladabindi",
            "phishing",
            "bank",
            "alexa",
            "trojanspy",
            "maltiverse",
            "uatrue",
            "processorx86",
            "langen",
            "generic malware",
            "fakedout threat",
            "ip summary",
            "url summary",
            "summary",
            "sample",
            "samples",
            "injected",
            "mitre",
            "attack",
            "cybercrime",
            "Suspicious.Save",
            "dns server",
            "scanning ip's",
            "Backdoor.Remcos",
            "Threats200220200050",
            "IOC_19052020",
            "behaves like emotet"
          ],
          "references": [
            "https://login.live.com/oauth20_remoteconnect.srf"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America",
            "France"
          ],
          "malware_families": [
            {
              "id": "TrojanSpy",
              "display_name": "TrojanSpy",
              "target": null
            },
            {
              "id": "Maltiverse",
              "display_name": "Maltiverse",
              "target": null
            },
            {
              "id": "Dridex",
              "display_name": "Dridex",
              "target": null
            },
            {
              "id": "Agent Tesla - S0331",
              "display_name": "Agent Tesla - S0331",
              "target": null
            },
            {
              "id": "HawkEye Keylogger",
              "display_name": "HawkEye Keylogger",
              "target": null
            },
            {
              "id": "Suspicious.Save",
              "display_name": "Suspicious.Save",
              "target": null
            },
            {
              "id": "Application.Generic",
              "display_name": "Application.Generic",
              "target": null
            },
            {
              "id": "Backdoor.RemoteManipulator",
              "display_name": "Backdoor.RemoteManipulator",
              "target": null
            },
            {
              "id": "Gen:Heur.Ransom.HiddenTears",
              "display_name": "Gen:Heur.Ransom.HiddenTears",
              "target": null
            },
            {
              "id": "XOR.DDoS",
              "display_name": "XOR.DDoS",
              "target": null
            },
            {
              "id": "Backdoor.Remcos",
              "display_name": "Backdoor.Remcos",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "TA0037",
              "name": "Command and Control",
              "display_name": "TA0037 - Command and Control"
            },
            {
              "id": "T1068",
              "name": "Exploitation for Privilege Escalation",
              "display_name": "T1068 - Exploitation for Privilege Escalation"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1593.002",
              "name": "Search Engines",
              "display_name": "T1593.002 - Search Engines"
            },
            {
              "id": "T1449",
              "name": "Exploit SS7 to Redirect Phone Calls/SMS",
              "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": "652c33c45c1f1566c4b8c6a2",
          "export_count": 22,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 1071,
            "FileHash-SHA1": 545,
            "FileHash-SHA256": 2173,
            "domain": 584,
            "hostname": 1707,
            "URL": 4145,
            "CVE": 8
          },
          "indicator_count": 10233,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 219,
          "modified_text": "887 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "https://www.anyxxxtube.net/search-porn/tsara-brashears/\t URL\thttp://45.159.189.105/bot/regex |\thttps://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian",
        "VirTool:Win32/Obfuscator: 0.googleusercontent.com [hacking]",
        "https://login.live.com/oauth20_remoteconnect.srf",
        "MyChart Phishing Scams",
        "exploit_source IP's: 20.99.186.246 , 40.126.24.147 , 40.126.24.149 , 40.126.24.81 , 40.126.24.82"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 0
        },
        "other": {
          "adversary": [],
          "malware_families": [
            "Agent tesla - s0331",
            "Webtoolbar",
            "Win64:ransomx-gen",
            "Win64-trojan/pakes.exp",
            "Hawkeye keylogger",
            "Application.generic",
            "Maltiverse",
            "Xor.ddos",
            "Trojanspy",
            "Gen:heur.ransom.hiddentears",
            "Backdoor.remcos",
            "Dridex",
            "Suspicious.save",
            "Backdoor.remotemanipulator"
          ],
          "industries": [
            "Technology",
            "Healthcare"
          ],
          "unique_indicators": 33519
        }
      }
    },
    "false_positive": [],
    "alexa": "http://www.alexa.com/siteinfo/nomadicguild.com",
    "whois": "http://whois.domaintools.com/nomadicguild.com",
    "domain": "nomadicguild.com",
    "hostname": "sip.nomadicguild.com"
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 11,
  "pulses": [
    {
      "id": "66994bda3e150656cd5ac9dd",
      "name": "Browser Session Hijacking Various MyChart Phishing Scams",
      "description": "Ongoing issues with medical information hijacking. Various medical corporations affected. Tracking, medical, injection process, records retrieval, botnets.",
      "modified": "2024-08-17T16:01:11.866000",
      "created": "2024-07-18T17:07:38.719000",
      "tags": [
        "historical ssl",
        "referrer",
        "domains",
        "august",
        "phishingscams",
        "domains part",
        "domain tracker",
        "roundup",
        "new problems",
        "privacy badger",
        "startpage",
        "self",
        "httponly",
        "samesitenone",
        "http response",
        "final url",
        "ip address",
        "status code",
        "body length",
        "b body",
        "sha256",
        "pragma",
        "mychartlocale",
        "urls",
        "ip detections",
        "country",
        "contacted",
        "files",
        "file type",
        "name file",
        "gmbh",
        "cloudflare",
        "tucows",
        "ii llc",
        "alibaba cloud",
        "computing",
        "sample",
        "media t1091",
        "t1497 may",
        "mitre att",
        "access ta0001",
        "replication",
        "ta0004 process",
        "injection t1055",
        "defense evasion",
        "http requests",
        "get http",
        "request",
        "host",
        "dns resolutions",
        "ip traffic",
        "hashes",
        "tsara brashears",
        "red team",
        "hackers",
        "highly targeted",
        "critical risk",
        "cyberstalking",
        "apple",
        "apple ios",
        "logistics",
        "cyber defense",
        "guloader",
        "hacktool",
        "emotet",
        "phishing",
        "facebook",
        "malware",
        "hiddentear",
        "maze",
        "server",
        "domain status",
        "date",
        "algorithm",
        "google llc",
        "registrar abuse",
        "registrar",
        "record type",
        "ttl value",
        "aaaa",
        "whois lookup",
        "admin country",
        "ca creation",
        "dnssec",
        "markmonitor",
        "siblings",
        "whois lookups",
        "expiration date",
        "registrar iana",
        "creation date",
        "first",
        "united",
        "as15169 google",
        "cname",
        "status",
        "virtool",
        "cryp",
        "as396982 google",
        "search",
        "name servers",
        "win32",
        "remote"
      ],
      "references": [
        "MyChart Phishing Scams",
        "exploit_source IP's: 20.99.186.246 , 40.126.24.147 , 40.126.24.149 , 40.126.24.81 , 40.126.24.82",
        "VirTool:Win32/Obfuscator: 0.googleusercontent.com [hacking]",
        "https://www.anyxxxtube.net/search-porn/tsara-brashears/\t URL\thttp://45.159.189.105/bot/regex |\thttps://www.pornhub.com/gifs/search?search=tsara+lynn+brashears+lesbian"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Win64-Trojan/Pakes.Exp",
          "display_name": "Win64-Trojan/Pakes.Exp",
          "target": null
        },
        {
          "id": "Win64:RansomX-gen",
          "display_name": "Win64:RansomX-gen",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1012",
          "name": "Query Registry",
          "display_name": "T1012 - Query Registry"
        },
        {
          "id": "T1018",
          "name": "Remote System Discovery",
          "display_name": "T1018 - Remote System Discovery"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1036",
          "name": "Masquerading",
          "display_name": "T1036 - Masquerading"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1083",
          "name": "File and Directory Discovery",
          "display_name": "T1083 - File and Directory Discovery"
        },
        {
          "id": "T1091",
          "name": "Replication Through Removable Media",
          "display_name": "T1091 - Replication Through Removable Media"
        },
        {
          "id": "T1095",
          "name": "Non-Application Layer Protocol",
          "display_name": "T1095 - Non-Application Layer Protocol"
        },
        {
          "id": "T1120",
          "name": "Peripheral Device Discovery",
          "display_name": "T1120 - Peripheral Device Discovery"
        },
        {
          "id": "T1185",
          "name": "Man in the Browser",
          "display_name": "T1185 - Man in the Browser"
        },
        {
          "id": "T1497",
          "name": "Virtualization/Sandbox Evasion",
          "display_name": "T1497 - Virtualization/Sandbox Evasion"
        },
        {
          "id": "T1518",
          "name": "Software Discovery",
          "display_name": "T1518 - Software Discovery"
        },
        {
          "id": "T1562",
          "name": "Impair Defenses",
          "display_name": "T1562 - Impair Defenses"
        },
        {
          "id": "T1573",
          "name": "Encrypted Channel",
          "display_name": "T1573 - Encrypted Channel"
        }
      ],
      "industries": [
        "Healthcare",
        "Technology"
      ],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 27,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "scoreblue",
        "id": "254100",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 37,
        "FileHash-SHA1": 33,
        "FileHash-SHA256": 3473,
        "domain": 693,
        "URL": 4384,
        "hostname": 1610,
        "CVE": 2,
        "email": 3
      },
      "indicator_count": 10235,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 231,
      "modified_text": "610 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "655a13e4538e896c00f2077e",
      "name": "Spyware: http://browser.events.data.microsoftstart.cn",
      "description": "This report is generated by MITRE ATT&CK\u2122 and produced by the team at the University of California, San Francisco, and is available on the web, via the Microsoft Research website.\nTulach, 114.114.114.114, spyware, phishing, fraud, malvertizing, password cracker, iPhone unlocker, malicious, media sharing, miscellaneous attacks.",
      "modified": "2023-12-19T13:01:12.394000",
      "created": "2023-11-19T13:55:48.898000",
      "tags": [
        "linkid246338",
        "whois record",
        "ssl certificate",
        "contacted",
        "execution",
        "historical ssl",
        "whois whois",
        "communicating",
        "resolutions",
        "referrer",
        "random",
        "august",
        "lockbit",
        "attack",
        "core",
        "name verdict",
        "falcon sandbox",
        "pattern match",
        "root ca",
        "done adding",
        "catalog file",
        "authority",
        "class",
        "mitre att",
        "script",
        "temp",
        "ascii text",
        "date",
        "unknown",
        "service",
        "generator",
        "critical",
        "error",
        "meta",
        "hybrid",
        "local",
        "click",
        "strings",
        "threat roundup"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1100",
          "name": "Web Shell",
          "display_name": "T1100 - Web Shell"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1560",
          "name": "Archive Collected Data",
          "display_name": "T1560 - Archive Collected Data"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 7,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 34,
        "FileHash-SHA1": 28,
        "FileHash-SHA256": 2526,
        "URL": 3515,
        "domain": 458,
        "hostname": 1092
      },
      "indicator_count": 7653,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 219,
      "modified_text": "852 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "655af35616dbd4781c681948",
      "name": "Spyware: http://browser.events.data.microsoftstart.cn",
      "description": "",
      "modified": "2023-12-19T13:01:12.394000",
      "created": "2023-11-20T05:49:10.586000",
      "tags": [
        "linkid246338",
        "whois record",
        "ssl certificate",
        "contacted",
        "execution",
        "historical ssl",
        "whois whois",
        "communicating",
        "resolutions",
        "referrer",
        "random",
        "august",
        "lockbit",
        "attack",
        "core",
        "name verdict",
        "falcon sandbox",
        "pattern match",
        "root ca",
        "done adding",
        "catalog file",
        "authority",
        "class",
        "mitre att",
        "script",
        "temp",
        "ascii text",
        "date",
        "unknown",
        "service",
        "generator",
        "critical",
        "error",
        "meta",
        "hybrid",
        "local",
        "click",
        "strings",
        "threat roundup"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1100",
          "name": "Web Shell",
          "display_name": "T1100 - Web Shell"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1560",
          "name": "Archive Collected Data",
          "display_name": "T1560 - Archive Collected Data"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": "655a13e4538e896c00f2077e",
      "export_count": 15,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "scoreblue",
        "id": "254100",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 34,
        "FileHash-SHA1": 28,
        "FileHash-SHA256": 2526,
        "URL": 3515,
        "domain": 458,
        "hostname": 1092
      },
      "indicator_count": 7653,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 224,
      "modified_text": "852 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6570a975e2a76dd4ddaec80a",
      "name": "Remote Access attack | Agent Tesla | C2 | BatLoader | C2 | Dridex",
      "description": "",
      "modified": "2023-12-06T17:03:49.269000",
      "created": "2023-12-06T17:03:49.269000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 16,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "CVE": 8,
        "FileHash-SHA256": 2173,
        "domain": 584,
        "hostname": 1707,
        "URL": 4145,
        "FileHash-SHA1": 545,
        "FileHash-MD5": 1071
      },
      "indicator_count": 10233,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 111,
      "modified_text": "865 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "656a97db9134b17c1f6d845b",
      "name": "DeepScan:Generic.Ransom.GandCrab5",
      "description": "",
      "modified": "2023-12-02T02:35:07.890000",
      "created": "2023-12-02T02:35:07.890000",
      "tags": [
        "cisco umbrella",
        "site",
        "safe site",
        "detection list",
        "blacklist",
        "million",
        "malicious url",
        "maltiverse",
        "heuristic",
        "redirme",
        "exploit",
        "malware",
        "team",
        "microsoft",
        "urlhttps",
        "blacklist https",
        "noname057",
        "threat report",
        "ip summary",
        "url summary",
        "summary",
        "sample",
        "samples",
        "hacktool",
        "arkeistealer",
        "mail spammer",
        "united",
        "germany",
        "opencandy",
        "proxy",
        "firehol",
        "alexa top",
        "phishing site",
        "malicious site",
        "malware site",
        "alexa",
        "phishing",
        "iframe",
        "downldr",
        "agent",
        "presenoker",
        "riskware",
        "unsafe",
        "artemis",
        "bank",
        "cve201711882",
        "tag count",
        "cyber threat",
        "httponly",
        "samesitenone",
        "http response",
        "final url",
        "ip address",
        "status code",
        "body length",
        "kb body",
        "sha256",
        "headers",
        "pragma",
        "contacted urls",
        "ssl certificate",
        "whois record",
        "xmodeargs",
        "whois whois",
        "xdpid1203",
        "xpubid10839",
        "september",
        "tsara brashears",
        "collection",
        "emotet",
        "malicious",
        "critical",
        "copy",
        "installer",
        "banker",
        "keylogger",
        "heur",
        "filerepmetagen",
        "suspected",
        "adware",
        "acint",
        "nircmd",
        "swrort",
        "systweak",
        "behav",
        "crack",
        "tiggre",
        "genkryptik",
        "filetour",
        "cleaner",
        "conduit",
        "wacatac",
        "trojanspy",
        "webtoolbar"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "TrojanSpy",
          "display_name": "TrojanSpy",
          "target": null
        },
        {
          "id": "WebToolbar",
          "display_name": "WebToolbar",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": "6541df216e018a0bce63e2a3",
      "export_count": 8,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "scoreblue",
        "id": "254100",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 2559,
        "CVE": 6,
        "FileHash-MD5": 582,
        "FileHash-SHA1": 353,
        "FileHash-SHA256": 3232,
        "hostname": 826,
        "domain": 206,
        "URI": 1
      },
      "indicator_count": 7765,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 227,
      "modified_text": "869 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6541df216e018a0bce63e2a3",
      "name": "DeepScan:Generic.Ransom.GandCrab5",
      "description": "Malicious redirect. OWA? Dreaded Canary cookie? I don't know yet. Link affects individuals, corporations and edu's. \n\n{*https://mail.greycroft.com/owa/redir.aspx?SURL=a0oI1dvGGkFYUoACVEbN8REVrmfS6H0MhUvXdexgmertl7bBVhrTCGgAdAB0AHAAcwA6AC8ALwB3AHcAdwAuAHAAcgBvAGQAdQBjAHQAaAB1AG4AdAAuAGMAbwBtAC8AdABlAGMAaAAvAGEAbgBpAG0AYQB0AGkAYwA.&URL=https://www.producthunt.com/tech/animatic\n*Redirects to: https://login.microsoftonline.com/jsdisabled}\n(AUTO POPULATED: A full list of findings from the Maltiverse Research Team on Malware and Exploit, as compiled by the National Security Agency (NSA), has been published on the website of Microsoft's website.)",
      "modified": "2023-12-01T04:05:20.963000",
      "created": "2023-11-01T05:16:17.835000",
      "tags": [
        "cisco umbrella",
        "site",
        "safe site",
        "detection list",
        "blacklist",
        "million",
        "malicious url",
        "maltiverse",
        "heuristic",
        "redirme",
        "exploit",
        "malware",
        "team",
        "microsoft",
        "urlhttps",
        "blacklist https",
        "noname057",
        "threat report",
        "ip summary",
        "url summary",
        "summary",
        "sample",
        "samples",
        "hacktool",
        "arkeistealer",
        "mail spammer",
        "united",
        "germany",
        "opencandy",
        "proxy",
        "firehol",
        "alexa top",
        "phishing site",
        "malicious site",
        "malware site",
        "alexa",
        "phishing",
        "iframe",
        "downldr",
        "agent",
        "presenoker",
        "riskware",
        "unsafe",
        "artemis",
        "bank",
        "cve201711882",
        "tag count",
        "cyber threat",
        "httponly",
        "samesitenone",
        "http response",
        "final url",
        "ip address",
        "status code",
        "body length",
        "kb body",
        "sha256",
        "headers",
        "pragma",
        "contacted urls",
        "ssl certificate",
        "whois record",
        "xmodeargs",
        "whois whois",
        "xdpid1203",
        "xpubid10839",
        "september",
        "tsara brashears",
        "collection",
        "emotet",
        "malicious",
        "critical",
        "copy",
        "installer",
        "banker",
        "keylogger",
        "heur",
        "filerepmetagen",
        "suspected",
        "adware",
        "acint",
        "nircmd",
        "swrort",
        "systweak",
        "behav",
        "crack",
        "tiggre",
        "genkryptik",
        "filetour",
        "cleaner",
        "conduit",
        "wacatac",
        "trojanspy",
        "webtoolbar"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "TrojanSpy",
          "display_name": "TrojanSpy",
          "target": null
        },
        {
          "id": "WebToolbar",
          "display_name": "WebToolbar",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 23,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 2559,
        "CVE": 6,
        "FileHash-MD5": 582,
        "FileHash-SHA1": 353,
        "FileHash-SHA256": 3232,
        "hostname": 826,
        "domain": 206,
        "URI": 1
      },
      "indicator_count": 7765,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 221,
      "modified_text": "870 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6541e08c81e836438946bbbf",
      "name": "TrojanSpy",
      "description": "Malicious redirect.  Targets individual.\n{*https://mail.greycroft.com/owa/redir.aspx?SURL=a0oI1dvGGkFYUoACVEbN8REVrmfS6H0MhUvXdexgmertl7bBVhrTCGgAdAB0AHAAcwA6AC8ALwB3AHcAdwAuAHAAcgBvAGQAdQBjAHQAaAB1AG4AdAAuAGMAbwBtAC8AdABlAGMAaAAvAGEAbgBpAG0AYQB0AGkAYwA.&URL=https://www.producthunt.com/tech/animatic\n*Redirects to: https://login.microsoftonline.com/jsdisabled}\n(AUTO POPULATED: A full list of findings from the Maltiverse Research Team on Malware and Exploit, as compiled by the National Security Agency (NSA), has been published on the website of Microsoft's website.)",
      "modified": "2023-12-01T04:05:20.963000",
      "created": "2023-11-01T05:22:20.519000",
      "tags": [
        "cisco umbrella",
        "site",
        "safe site",
        "detection list",
        "blacklist",
        "million",
        "malicious url",
        "maltiverse",
        "heuristic",
        "redirme",
        "exploit",
        "malware",
        "team",
        "microsoft",
        "urlhttps",
        "blacklist https",
        "noname057",
        "threat report",
        "ip summary",
        "url summary",
        "summary",
        "sample",
        "samples",
        "hacktool",
        "arkeistealer",
        "mail spammer",
        "united",
        "germany",
        "opencandy",
        "proxy",
        "firehol",
        "alexa top",
        "phishing site",
        "malicious site",
        "malware site",
        "alexa",
        "phishing",
        "iframe",
        "downldr",
        "agent",
        "presenoker",
        "riskware",
        "unsafe",
        "artemis",
        "bank",
        "cve201711882",
        "tag count",
        "cyber threat",
        "httponly",
        "samesitenone",
        "http response",
        "final url",
        "ip address",
        "status code",
        "body length",
        "kb body",
        "sha256",
        "headers",
        "pragma",
        "contacted urls",
        "ssl certificate",
        "whois record",
        "xmodeargs",
        "whois whois",
        "xdpid1203",
        "xpubid10839",
        "september",
        "tsara brashears",
        "collection",
        "emotet",
        "malicious",
        "critical",
        "copy",
        "installer",
        "banker",
        "keylogger",
        "heur",
        "filerepmetagen",
        "suspected",
        "adware",
        "acint",
        "nircmd",
        "swrort",
        "systweak",
        "behav",
        "crack",
        "tiggre",
        "genkryptik",
        "filetour",
        "cleaner",
        "conduit",
        "wacatac",
        "trojanspy",
        "webtoolbar"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "TrojanSpy",
          "display_name": "TrojanSpy",
          "target": null
        },
        {
          "id": "WebToolbar",
          "display_name": "WebToolbar",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 27,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 2559,
        "CVE": 6,
        "FileHash-MD5": 582,
        "FileHash-SHA1": 353,
        "FileHash-SHA256": 3232,
        "hostname": 826,
        "domain": 206,
        "URI": 1
      },
      "indicator_count": 7765,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 221,
      "modified_text": "870 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6543350c86e1299dc78bfa90",
      "name": "this dick",
      "description": "",
      "modified": "2023-12-01T04:05:20.963000",
      "created": "2023-11-02T05:35:08.226000",
      "tags": [
        "cisco umbrella",
        "site",
        "safe site",
        "detection list",
        "blacklist",
        "million",
        "malicious url",
        "maltiverse",
        "heuristic",
        "redirme",
        "exploit",
        "malware",
        "team",
        "microsoft",
        "urlhttps",
        "blacklist https",
        "noname057",
        "threat report",
        "ip summary",
        "url summary",
        "summary",
        "sample",
        "samples",
        "hacktool",
        "arkeistealer",
        "mail spammer",
        "united",
        "germany",
        "opencandy",
        "proxy",
        "firehol",
        "alexa top",
        "phishing site",
        "malicious site",
        "malware site",
        "alexa",
        "phishing",
        "iframe",
        "downldr",
        "agent",
        "presenoker",
        "riskware",
        "unsafe",
        "artemis",
        "bank",
        "cve201711882",
        "tag count",
        "cyber threat",
        "httponly",
        "samesitenone",
        "http response",
        "final url",
        "ip address",
        "status code",
        "body length",
        "kb body",
        "sha256",
        "headers",
        "pragma",
        "contacted urls",
        "ssl certificate",
        "whois record",
        "xmodeargs",
        "whois whois",
        "xdpid1203",
        "xpubid10839",
        "september",
        "tsara brashears",
        "collection",
        "emotet",
        "malicious",
        "critical",
        "copy",
        "installer",
        "banker",
        "keylogger",
        "heur",
        "filerepmetagen",
        "suspected",
        "adware",
        "acint",
        "nircmd",
        "swrort",
        "systweak",
        "behav",
        "crack",
        "tiggre",
        "genkryptik",
        "filetour",
        "cleaner",
        "conduit",
        "wacatac",
        "trojanspy",
        "webtoolbar"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "TrojanSpy",
          "display_name": "TrojanSpy",
          "target": null
        },
        {
          "id": "WebToolbar",
          "display_name": "WebToolbar",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": "6541df216e018a0bce63e2a3",
      "export_count": 21,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Nicholus33",
        "id": "76046",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 2559,
        "CVE": 6,
        "FileHash-MD5": 582,
        "FileHash-SHA1": 353,
        "FileHash-SHA256": 3232,
        "hostname": 826,
        "domain": 207,
        "URI": 1
      },
      "indicator_count": 7766,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 2,
      "modified_text": "870 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6545a25d60272bac5827f2fc",
      "name": "TrojanSpy",
      "description": "",
      "modified": "2023-12-01T04:05:20.963000",
      "created": "2023-11-04T01:46:05.174000",
      "tags": [
        "cisco umbrella",
        "site",
        "safe site",
        "detection list",
        "blacklist",
        "million",
        "malicious url",
        "maltiverse",
        "heuristic",
        "redirme",
        "exploit",
        "malware",
        "team",
        "microsoft",
        "urlhttps",
        "blacklist https",
        "noname057",
        "threat report",
        "ip summary",
        "url summary",
        "summary",
        "sample",
        "samples",
        "hacktool",
        "arkeistealer",
        "mail spammer",
        "united",
        "germany",
        "opencandy",
        "proxy",
        "firehol",
        "alexa top",
        "phishing site",
        "malicious site",
        "malware site",
        "alexa",
        "phishing",
        "iframe",
        "downldr",
        "agent",
        "presenoker",
        "riskware",
        "unsafe",
        "artemis",
        "bank",
        "cve201711882",
        "tag count",
        "cyber threat",
        "httponly",
        "samesitenone",
        "http response",
        "final url",
        "ip address",
        "status code",
        "body length",
        "kb body",
        "sha256",
        "headers",
        "pragma",
        "contacted urls",
        "ssl certificate",
        "whois record",
        "xmodeargs",
        "whois whois",
        "xdpid1203",
        "xpubid10839",
        "september",
        "tsara brashears",
        "collection",
        "emotet",
        "malicious",
        "critical",
        "copy",
        "installer",
        "banker",
        "keylogger",
        "heur",
        "filerepmetagen",
        "suspected",
        "adware",
        "acint",
        "nircmd",
        "swrort",
        "systweak",
        "behav",
        "crack",
        "tiggre",
        "genkryptik",
        "filetour",
        "cleaner",
        "conduit",
        "wacatac",
        "trojanspy",
        "webtoolbar"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "TrojanSpy",
          "display_name": "TrojanSpy",
          "target": null
        },
        {
          "id": "WebToolbar",
          "display_name": "WebToolbar",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": "6541e08c81e836438946bbbf",
      "export_count": 26,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "scoreblue",
        "id": "254100",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 2559,
        "CVE": 6,
        "FileHash-MD5": 582,
        "FileHash-SHA1": 353,
        "FileHash-SHA256": 3232,
        "hostname": 826,
        "domain": 206,
        "URI": 1
      },
      "indicator_count": 7765,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 228,
      "modified_text": "870 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "652c33c45c1f1566c4b8c6a2",
      "name": "Remote Access attack | Agent Tesla | C2 | BatLoader | C2 | Dridex",
      "description": "https://login.live.com/oauth20_remoteconnect.srf\nInvalid CRDS Token\nI suffered quite an attack on my devices. My personal experience, phone service changed, embedding., privilege escalation adversaries,  remote probe, obvious unauthorized microsoft usage multiple logins. embedded  phone service apps, injected, unknown apps, dumping. connect/shared/ tethered to other clouds, apps devices, decrypted phone., cookies turned off after attack, no Google, other search engine access, passwords compromised malicious Google sorry index w/Azorult. I am targeted. Usual suspects\nPrior: 'D241 connect test was successful messages'. Wifi and cellular issues.\nAftermath, Zombie devices. C2. Calls don't connect, keyloggers, etc",
      "modified": "2023-11-14T17:01:45.019000",
      "created": "2023-10-15T18:47:32.354000",
      "tags": [
        "whois record",
        "historical ssl",
        "ssl certificate",
        "communicating",
        "referrer",
        "united",
        "mail spammer",
        "detection list",
        "ip address",
        "blacklist",
        "possiblecerber",
        "outlook",
        "covid19",
        "artemis",
        "unsafe",
        "cisco umbrella",
        "site",
        "safe site",
        "phishing site",
        "malicious site",
        "malware",
        "malware site",
        "alexa top",
        "million",
        "phishingms",
        "exploit",
        "live",
        "blacklist https",
        "javascript",
        "http response",
        "final url",
        "serving ip",
        "address",
        "status code",
        "body length",
        "kb body",
        "sha256",
        "headers",
        "p3p cp",
        "pragma",
        "whois whois",
        "contacted",
        "threat network",
        "pe resource",
        "uatrue url",
        "typepv",
        "probe",
        "execution",
        "core",
        "emotet",
        "remcos",
        "nokoyawa",
        "asyncrat",
        "heur",
        "anonymizer",
        "firehol",
        "trojanx",
        "agent",
        "riskware",
        "trojan",
        "binder",
        "small",
        "downloader",
        "hupigon",
        "crypt",
        "cobalt strike",
        "union",
        "team",
        "agent tesla",
        "malicious",
        "fakealert",
        "dbatloader",
        "stealer",
        "nanocore rat",
        "formbook",
        "dropper",
        "dridex",
        "hawkeye",
        "netwire",
        "download",
        "opencandy",
        "bladabindi",
        "phishing",
        "bank",
        "alexa",
        "trojanspy",
        "maltiverse",
        "uatrue",
        "processorx86",
        "langen",
        "generic malware",
        "fakedout threat",
        "ip summary",
        "url summary",
        "summary",
        "sample",
        "samples",
        "injected",
        "mitre",
        "attack",
        "cybercrime",
        "Suspicious.Save",
        "dns server",
        "scanning ip's",
        "Backdoor.Remcos",
        "Threats200220200050",
        "IOC_19052020",
        "behaves like emotet"
      ],
      "references": [
        "https://login.live.com/oauth20_remoteconnect.srf"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America",
        "France"
      ],
      "malware_families": [
        {
          "id": "TrojanSpy",
          "display_name": "TrojanSpy",
          "target": null
        },
        {
          "id": "Maltiverse",
          "display_name": "Maltiverse",
          "target": null
        },
        {
          "id": "Dridex",
          "display_name": "Dridex",
          "target": null
        },
        {
          "id": "Agent Tesla - S0331",
          "display_name": "Agent Tesla - S0331",
          "target": null
        },
        {
          "id": "HawkEye Keylogger",
          "display_name": "HawkEye Keylogger",
          "target": null
        },
        {
          "id": "Suspicious.Save",
          "display_name": "Suspicious.Save",
          "target": null
        },
        {
          "id": "Application.Generic",
          "display_name": "Application.Generic",
          "target": null
        },
        {
          "id": "Backdoor.RemoteManipulator",
          "display_name": "Backdoor.RemoteManipulator",
          "target": null
        },
        {
          "id": "Gen:Heur.Ransom.HiddenTears",
          "display_name": "Gen:Heur.Ransom.HiddenTears",
          "target": null
        },
        {
          "id": "XOR.DDoS",
          "display_name": "XOR.DDoS",
          "target": null
        },
        {
          "id": "Backdoor.Remcos",
          "display_name": "Backdoor.Remcos",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "TA0037",
          "name": "Command and Control",
          "display_name": "TA0037 - Command and Control"
        },
        {
          "id": "T1068",
          "name": "Exploitation for Privilege Escalation",
          "display_name": "T1068 - Exploitation for Privilege Escalation"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1593.002",
          "name": "Search Engines",
          "display_name": "T1593.002 - Search Engines"
        },
        {
          "id": "T1449",
          "name": "Exploit SS7 to Redirect Phone Calls/SMS",
          "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 34,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "scoreblue",
        "id": "254100",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 1071,
        "FileHash-SHA1": 545,
        "FileHash-SHA256": 2173,
        "domain": 584,
        "hostname": 1707,
        "URL": 4145,
        "CVE": 8
      },
      "indicator_count": 10233,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 228,
      "modified_text": "887 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "https://sip.nomadicguild.com",
    "type": "URL"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "https://sip.nomadicguild.com",
    "type": "URL",
    "found": false,
    "verdict": "clean",
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1776650457.1842284
}