{
  "type": "URL",
  "indicator": "https://solicita--tumundobhd.replit.app/login.php",
  "general": {
    "sections": [
      "general",
      "url_list",
      "http_scans",
      "screenshot"
    ],
    "indicator": "https://solicita--tumundobhd.replit.app/login.php",
    "type": "url",
    "type_title": "URL",
    "validation": [],
    "base_indicator": {
      "id": 4203976718,
      "indicator": "https://solicita--tumundobhd.replit.app/login.php",
      "type": "URL",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 45,
      "pulses": [
        {
          "id": "69aeda93ec05fb8653adca6d",
          "name": "clone of my pulse. this dmv kit pdfkit.net used the same off logo kit it was one of the few i found in their fcc application   . rpi&macids look for",
          "description": "",
          "modified": "2026-04-08T00:00:45.252000",
          "created": "2026-03-09T14:34:59.072000",
          "tags": [
            "pfft.net"
          ],
          "references": [
            ""
          ],
          "public": 1,
          "adversary": "pi, pdfkit.net",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": "698c75717175e2cc7ff33df2",
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 551,
            "domain": 638,
            "CVE": 114,
            "hostname": 449,
            "email": 28,
            "FileHash-MD5": 145,
            "FileHash-SHA1": 188,
            "FileHash-SHA256": 132,
            "Mutex": 1
          },
          "indicator_count": 2246,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 72,
          "modified_text": "56 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "698d30c03b57c38dff915023",
          "name": "Double Umbrella AS15169/AS21928: This evaluates a critical structural convergence between Google (AS15169) and T-Mobile USA (AS21928) within the global Tier-1 routing backbone",
          "description": "Research credit: msudosos, The research identifies a high-fidelity pattern where traffic from dual origins commingles within a restricted lateral transit hub, allowing for horizontal movement across backbone providers that typically maintain distinct trust boundaries. Specifically, the Content Origin (Umbrella A) originated by Google (AS15169) reaches the core backbone through a high-trust sequence involving Arelion (AS1299), NTT (AS2914), and GTT (AS3257). Simultaneously, the Mobile Origin (Umbrella B) originated by T-Mobile USA (AS21928) enters the backbone via Cogent (AS174) and Lumen (AS3356). The findings designate Lumen (AS3356) as the central lateral hub where traffic pivots horizontally between the \u201cCore Five\u201d partners-including Zayo (AS6461) and Hurricane Electric (AS6939) \u2014before leaking to international sub-transit peers like Sparkle (AS6762) and Telxius (AS12956), finally exiting at global edge points such as PCCW (AS3491) and Tata (AS6453).",
          "modified": "2026-03-29T06:02:00.914000",
          "created": "2026-02-12T01:45:36.128000",
          "tags": [
            "The dynamics of the mudoSOSIntersectalign with sophisticated adv"
          ],
          "references": [
            "as15169"
          ],
          "public": 1,
          "adversary": "Adversary Profile: Salt Typhoon Alignment The architectural gap identified by mudoSO mirrors the act",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 3,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URI": 1,
            "domain": 2661,
            "URL": 6810,
            "hostname": 2147,
            "email": 56,
            "FileHash-SHA256": 2781,
            "CVE": 172,
            "FileHash-MD5": 365,
            "FileHash-SHA1": 344,
            "IPv4": 1,
            "CIDR": 20940
          },
          "indicator_count": 36278,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 75,
          "modified_text": "66 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "698904c316bc7710b967d01d",
          "name": "Rare Tier 1 Persistence - Critical \"Patched\", Non Patched Vulnerabilities Remain bypassing Lockdown Mode",
          "description": "Researcher Note (Feb 08, 2026):\nThis artifact represents a sophisticated Cross-Protocol Mesh. Observations confirm that the Cymt/Nemucod wrapper is being utilized as a delivery vehicle for a Firmware-resident ELF binary (Mirai variant).\nThe persistence is notable for its ability to survive Full DFU Restores and Faraday-isolated states, likely due to JTAG-level interaction with the Power Management IC (Chip 4799). This is not a standard opportunistic infection; it is a targeted provisioning event leveraging IDMSA (Identity Management) bridges and Verizon/Akamai Edge infrastructure.\nThe integration with CalendarKit and Maps for geofenced execution suggests a highly coordinated surveillance objective. Forensic analysts should pay specific attention to the sizeofrawdata_antidbg anomalies, which indicate a focus on bypassing Apple Lockdown Mode and Secure Enclave. \nresearcher credit: msudoSOS",
          "modified": "2026-03-27T09:05:26.285000",
          "created": "2026-02-08T21:48:49.147000",
          "tags": [
            "#supportsitewebsiteabuse #rootcertificatefailure #cryptographicf"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 909,
            "URL": 1779,
            "CVE": 126,
            "domain": 659,
            "email": 23,
            "JA3": 1,
            "FileHash-MD5": 230,
            "FileHash-SHA1": 227,
            "FileHash-SHA256": 934,
            "CIDR": 13
          },
          "indicator_count": 4901,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 76,
          "modified_text": "68 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "698918baac756a084ef67089",
          "name": "151.101.0.22",
          "description": "151.101.0.22",
          "modified": "2026-03-27T00:30:39.055000",
          "created": "2026-02-08T23:13:59.775000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 317,
            "domain": 494,
            "URL": 286,
            "CVE": 78,
            "email": 33,
            "JA3": 1,
            "FileHash-MD5": 10,
            "FileHash-SHA1": 4,
            "FileHash-SHA256": 2
          },
          "indicator_count": 1225,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 75,
          "modified_text": "68 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "698c75717175e2cc7ff33df2",
          "name": "103.203.175.90 - Document and Domain Research Intersect, PDFKIT.NET DMV",
          "description": "http://103.203.175.90:81/fdScript/RootOfEBooks/E%20Book%20collection%20-%202024%20-%20D/CSE%20%20IT%20AIDS%20ML/Raspberry%20Pi%20linux-@Computer_IT_Engineering.pdf\n103.203.175.90",
          "modified": "2026-03-27T00:30:39.055000",
          "created": "2026-02-11T12:26:20.490000",
          "tags": [
            "pfft.net"
          ],
          "references": [
            ""
          ],
          "public": 1,
          "adversary": "pi, pdfkit.net",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 550,
            "domain": 638,
            "CVE": 113,
            "hostname": 445,
            "email": 28,
            "FileHash-MD5": 145,
            "FileHash-SHA1": 136,
            "FileHash-SHA256": 132,
            "Mutex": 1
          },
          "indicator_count": 2188,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 73,
          "modified_text": "68 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "698dbf957154d94be502baea",
          "name": "DugganUSA Feed Harvest - 2026-02-12",
          "description": "Automated multi-source IOC harvest. Sources: openphish: 100, torExit: 500, spamhausDrop: 1483, ja3: 97. Race to 500K! \ud83d\ude80",
          "modified": "2026-03-14T11:07:23.134000",
          "created": "2026-02-12T11:55:01.636000",
          "tags": [
            "dugganusa",
            "automated",
            "feed-harvest",
            "urlhaus",
            "feodo",
            "sslbl",
            "openphish",
            "tor",
            "spamhaus",
            "ja3"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix-feed/v2",
            "https://urlhaus.abuse.ch",
            "https://feodotracker.abuse.ch",
            "https://sslbl.abuse.ch",
            "https://check.torproject.org",
            "https://www.spamhaus.org/drop"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Phishing",
              "display_name": "Phishing",
              "target": null
            },
            {
              "id": "Tor Exit Node",
              "display_name": "Tor Exit Node",
              "target": null
            },
            {
              "id": "Spamhaus DROP",
              "display_name": "Spamhaus DROP",
              "target": null
            },
            {
              "id": "2019-07-27 20:42:54",
              "display_name": "2019-07-27 20:42:54",
              "target": null
            },
            {
              "id": "2019-07-28 00:34:38",
              "display_name": "2019-07-28 00:34:38",
              "target": null
            },
            {
              "id": "2019-05-22 03:22:38",
              "display_name": "2019-05-22 03:22:38",
              "target": null
            },
            {
              "id": "2019-07-28 01:38:22",
              "display_name": "2019-07-28 01:38:22",
              "target": null
            },
            {
              "id": "2021-02-01 18:23:25",
              "display_name": "2021-02-01 18:23:25",
              "target": null
            },
            {
              "id": "2021-03-13 07:33:39",
              "display_name": "2021-03-13 07:33:39",
              "target": null
            },
            {
              "id": "2019-07-27 20:00:57",
              "display_name": "2019-07-27 20:00:57",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1566.002",
              "name": "Spearphishing Link",
              "display_name": "T1566.002 - Spearphishing Link"
            },
            {
              "id": "T1204.002",
              "name": "Malicious File",
              "display_name": "T1204.002 - Malicious File"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 100,
            "CIDR": 1483,
            "JA3": 97
          },
          "indicator_count": 1680,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "81 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "698dbc137123e33733fc82ef",
          "name": "DugganUSA Feed Harvest - 2026-02-12",
          "description": "Automated multi-source IOC harvest. Sources: openphish: 100, torExit: 500, spamhausDrop: 1483, ja3: 97. Race to 500K! \ud83d\ude80",
          "modified": "2026-03-14T11:07:23.134000",
          "created": "2026-02-12T11:40:03.651000",
          "tags": [
            "dugganusa",
            "automated",
            "feed-harvest",
            "urlhaus",
            "feodo",
            "sslbl",
            "openphish",
            "tor",
            "spamhaus",
            "ja3"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix-feed/v2",
            "https://urlhaus.abuse.ch",
            "https://feodotracker.abuse.ch",
            "https://sslbl.abuse.ch",
            "https://check.torproject.org",
            "https://www.spamhaus.org/drop"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Phishing",
              "display_name": "Phishing",
              "target": null
            },
            {
              "id": "Tor Exit Node",
              "display_name": "Tor Exit Node",
              "target": null
            },
            {
              "id": "Spamhaus DROP",
              "display_name": "Spamhaus DROP",
              "target": null
            },
            {
              "id": "2019-07-27 20:42:54",
              "display_name": "2019-07-27 20:42:54",
              "target": null
            },
            {
              "id": "2019-07-28 00:34:38",
              "display_name": "2019-07-28 00:34:38",
              "target": null
            },
            {
              "id": "2019-05-22 03:22:38",
              "display_name": "2019-05-22 03:22:38",
              "target": null
            },
            {
              "id": "2019-07-28 01:38:22",
              "display_name": "2019-07-28 01:38:22",
              "target": null
            },
            {
              "id": "2021-02-01 18:23:25",
              "display_name": "2021-02-01 18:23:25",
              "target": null
            },
            {
              "id": "2021-03-13 07:33:39",
              "display_name": "2021-03-13 07:33:39",
              "target": null
            },
            {
              "id": "2019-07-27 20:00:57",
              "display_name": "2019-07-27 20:00:57",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1566.002",
              "name": "Spearphishing Link",
              "display_name": "T1566.002 - Spearphishing Link"
            },
            {
              "id": "T1204.002",
              "name": "Malicious File",
              "display_name": "T1204.002 - Malicious File"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 100,
            "CIDR": 1483,
            "JA3": 97
          },
          "indicator_count": 1680,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "81 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "698db89bf8fe655fa7b55d27",
          "name": "DugganUSA Feed Harvest - 2026-02-12",
          "description": "Automated multi-source IOC harvest. Sources: openphish: 100, torExit: 500, spamhausDrop: 1483, ja3: 97. Race to 500K! \ud83d\ude80",
          "modified": "2026-03-14T11:07:23.134000",
          "created": "2026-02-12T11:25:15.399000",
          "tags": [
            "dugganusa",
            "automated",
            "feed-harvest",
            "urlhaus",
            "feodo",
            "sslbl",
            "openphish",
            "tor",
            "spamhaus",
            "ja3"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix-feed/v2",
            "https://urlhaus.abuse.ch",
            "https://feodotracker.abuse.ch",
            "https://sslbl.abuse.ch",
            "https://check.torproject.org",
            "https://www.spamhaus.org/drop"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Phishing",
              "display_name": "Phishing",
              "target": null
            },
            {
              "id": "Tor Exit Node",
              "display_name": "Tor Exit Node",
              "target": null
            },
            {
              "id": "Spamhaus DROP",
              "display_name": "Spamhaus DROP",
              "target": null
            },
            {
              "id": "2019-07-27 20:42:54",
              "display_name": "2019-07-27 20:42:54",
              "target": null
            },
            {
              "id": "2019-07-28 00:34:38",
              "display_name": "2019-07-28 00:34:38",
              "target": null
            },
            {
              "id": "2019-05-22 03:22:38",
              "display_name": "2019-05-22 03:22:38",
              "target": null
            },
            {
              "id": "2019-07-28 01:38:22",
              "display_name": "2019-07-28 01:38:22",
              "target": null
            },
            {
              "id": "2021-02-01 18:23:25",
              "display_name": "2021-02-01 18:23:25",
              "target": null
            },
            {
              "id": "2021-03-13 07:33:39",
              "display_name": "2021-03-13 07:33:39",
              "target": null
            },
            {
              "id": "2019-07-27 20:00:57",
              "display_name": "2019-07-27 20:00:57",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1566.002",
              "name": "Spearphishing Link",
              "display_name": "T1566.002 - Spearphishing Link"
            },
            {
              "id": "T1204.002",
              "name": "Malicious File",
              "display_name": "T1204.002 - Malicious File"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 100,
            "CIDR": 1483,
            "JA3": 97
          },
          "indicator_count": 1680,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "81 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "698db214ffdafd6a136c82d3",
          "name": "DugganUSA Feed Harvest - 2026-02-12",
          "description": "Automated multi-source IOC harvest. Sources: openphish: 100, torExit: 500, spamhausDrop: 1483, ja3: 97. Race to 500K! \ud83d\ude80",
          "modified": "2026-03-14T10:28:13.816000",
          "created": "2026-02-12T10:57:24.970000",
          "tags": [
            "dugganusa",
            "automated",
            "feed-harvest",
            "urlhaus",
            "feodo",
            "sslbl",
            "openphish",
            "tor",
            "spamhaus",
            "ja3"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix-feed/v2",
            "https://urlhaus.abuse.ch",
            "https://feodotracker.abuse.ch",
            "https://sslbl.abuse.ch",
            "https://check.torproject.org",
            "https://www.spamhaus.org/drop"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Phishing",
              "display_name": "Phishing",
              "target": null
            },
            {
              "id": "Tor Exit Node",
              "display_name": "Tor Exit Node",
              "target": null
            },
            {
              "id": "Spamhaus DROP",
              "display_name": "Spamhaus DROP",
              "target": null
            },
            {
              "id": "2019-07-27 20:42:54",
              "display_name": "2019-07-27 20:42:54",
              "target": null
            },
            {
              "id": "2019-07-28 00:34:38",
              "display_name": "2019-07-28 00:34:38",
              "target": null
            },
            {
              "id": "2019-05-22 03:22:38",
              "display_name": "2019-05-22 03:22:38",
              "target": null
            },
            {
              "id": "2019-07-28 01:38:22",
              "display_name": "2019-07-28 01:38:22",
              "target": null
            },
            {
              "id": "2021-02-01 18:23:25",
              "display_name": "2021-02-01 18:23:25",
              "target": null
            },
            {
              "id": "2021-03-13 07:33:39",
              "display_name": "2021-03-13 07:33:39",
              "target": null
            },
            {
              "id": "2019-07-27 20:00:57",
              "display_name": "2019-07-27 20:00:57",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1566.002",
              "name": "Spearphishing Link",
              "display_name": "T1566.002 - Spearphishing Link"
            },
            {
              "id": "T1204.002",
              "name": "Malicious File",
              "display_name": "T1204.002 - Malicious File"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 100,
            "CIDR": 1483,
            "JA3": 97
          },
          "indicator_count": 1680,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "81 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "698dae1c8759b3a8a8f73702",
          "name": "DugganUSA Feed Harvest - 2026-02-12",
          "description": "Automated multi-source IOC harvest. Sources: openphish: 100, torExit: 500, spamhausDrop: 1483, ja3: 97. Race to 500K! \ud83d\ude80",
          "modified": "2026-03-14T10:28:13.816000",
          "created": "2026-02-12T10:40:28.705000",
          "tags": [
            "dugganusa",
            "automated",
            "feed-harvest",
            "urlhaus",
            "feodo",
            "sslbl",
            "openphish",
            "tor",
            "spamhaus",
            "ja3"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix-feed/v2",
            "https://urlhaus.abuse.ch",
            "https://feodotracker.abuse.ch",
            "https://sslbl.abuse.ch",
            "https://check.torproject.org",
            "https://www.spamhaus.org/drop"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Phishing",
              "display_name": "Phishing",
              "target": null
            },
            {
              "id": "Tor Exit Node",
              "display_name": "Tor Exit Node",
              "target": null
            },
            {
              "id": "Spamhaus DROP",
              "display_name": "Spamhaus DROP",
              "target": null
            },
            {
              "id": "2019-07-27 20:42:54",
              "display_name": "2019-07-27 20:42:54",
              "target": null
            },
            {
              "id": "2019-07-28 00:34:38",
              "display_name": "2019-07-28 00:34:38",
              "target": null
            },
            {
              "id": "2019-05-22 03:22:38",
              "display_name": "2019-05-22 03:22:38",
              "target": null
            },
            {
              "id": "2019-07-28 01:38:22",
              "display_name": "2019-07-28 01:38:22",
              "target": null
            },
            {
              "id": "2021-02-01 18:23:25",
              "display_name": "2021-02-01 18:23:25",
              "target": null
            },
            {
              "id": "2021-03-13 07:33:39",
              "display_name": "2021-03-13 07:33:39",
              "target": null
            },
            {
              "id": "2019-07-27 20:00:57",
              "display_name": "2019-07-27 20:00:57",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1566.002",
              "name": "Spearphishing Link",
              "display_name": "T1566.002 - Spearphishing Link"
            },
            {
              "id": "T1204.002",
              "name": "Malicious File",
              "display_name": "T1204.002 - Malicious File"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 100,
            "CIDR": 1483,
            "JA3": 97
          },
          "indicator_count": 1680,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "81 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "698da6f97b2901285342301b",
          "name": "DugganUSA Feed Harvest - 2026-02-12",
          "description": "Automated multi-source IOC harvest. Sources: openphish: 100, torExit: 500, spamhausDrop: 1483, ja3: 97. Race to 500K! \ud83d\ude80",
          "modified": "2026-03-14T10:28:13.816000",
          "created": "2026-02-12T10:10:01.566000",
          "tags": [
            "dugganusa",
            "automated",
            "feed-harvest",
            "urlhaus",
            "feodo",
            "sslbl",
            "openphish",
            "tor",
            "spamhaus",
            "ja3"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix-feed/v2",
            "https://urlhaus.abuse.ch",
            "https://feodotracker.abuse.ch",
            "https://sslbl.abuse.ch",
            "https://check.torproject.org",
            "https://www.spamhaus.org/drop"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Phishing",
              "display_name": "Phishing",
              "target": null
            },
            {
              "id": "Tor Exit Node",
              "display_name": "Tor Exit Node",
              "target": null
            },
            {
              "id": "Spamhaus DROP",
              "display_name": "Spamhaus DROP",
              "target": null
            },
            {
              "id": "2019-07-27 20:42:54",
              "display_name": "2019-07-27 20:42:54",
              "target": null
            },
            {
              "id": "2019-07-28 00:34:38",
              "display_name": "2019-07-28 00:34:38",
              "target": null
            },
            {
              "id": "2019-05-22 03:22:38",
              "display_name": "2019-05-22 03:22:38",
              "target": null
            },
            {
              "id": "2019-07-28 01:38:22",
              "display_name": "2019-07-28 01:38:22",
              "target": null
            },
            {
              "id": "2021-02-01 18:23:25",
              "display_name": "2021-02-01 18:23:25",
              "target": null
            },
            {
              "id": "2021-03-13 07:33:39",
              "display_name": "2021-03-13 07:33:39",
              "target": null
            },
            {
              "id": "2019-07-27 20:00:57",
              "display_name": "2019-07-27 20:00:57",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1566.002",
              "name": "Spearphishing Link",
              "display_name": "T1566.002 - Spearphishing Link"
            },
            {
              "id": "T1204.002",
              "name": "Malicious File",
              "display_name": "T1204.002 - Malicious File"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 100,
            "CIDR": 1483,
            "JA3": 97
          },
          "indicator_count": 1680,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "81 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "698d98fa1dda1670306ce011",
          "name": "DugganUSA Feed Harvest - 2026-02-12",
          "description": "Automated multi-source IOC harvest. Sources: openphish: 100, torExit: 500, spamhausDrop: 1483, ja3: 97. Race to 500K! \ud83d\ude80",
          "modified": "2026-03-14T09:00:56.720000",
          "created": "2026-02-12T09:10:18.826000",
          "tags": [
            "dugganusa",
            "automated",
            "feed-harvest",
            "urlhaus",
            "feodo",
            "sslbl",
            "openphish",
            "tor",
            "spamhaus",
            "ja3"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix-feed/v2",
            "https://urlhaus.abuse.ch",
            "https://feodotracker.abuse.ch",
            "https://sslbl.abuse.ch",
            "https://check.torproject.org",
            "https://www.spamhaus.org/drop"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Phishing",
              "display_name": "Phishing",
              "target": null
            },
            {
              "id": "Tor Exit Node",
              "display_name": "Tor Exit Node",
              "target": null
            },
            {
              "id": "Spamhaus DROP",
              "display_name": "Spamhaus DROP",
              "target": null
            },
            {
              "id": "2019-07-27 20:42:54",
              "display_name": "2019-07-27 20:42:54",
              "target": null
            },
            {
              "id": "2019-07-28 00:34:38",
              "display_name": "2019-07-28 00:34:38",
              "target": null
            },
            {
              "id": "2019-05-22 03:22:38",
              "display_name": "2019-05-22 03:22:38",
              "target": null
            },
            {
              "id": "2019-07-28 01:38:22",
              "display_name": "2019-07-28 01:38:22",
              "target": null
            },
            {
              "id": "2021-02-01 18:23:25",
              "display_name": "2021-02-01 18:23:25",
              "target": null
            },
            {
              "id": "2021-03-13 07:33:39",
              "display_name": "2021-03-13 07:33:39",
              "target": null
            },
            {
              "id": "2019-07-27 20:00:57",
              "display_name": "2019-07-27 20:00:57",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1566.002",
              "name": "Spearphishing Link",
              "display_name": "T1566.002 - Spearphishing Link"
            },
            {
              "id": "T1204.002",
              "name": "Malicious File",
              "display_name": "T1204.002 - Malicious File"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 100,
            "CIDR": 1483,
            "JA3": 97
          },
          "indicator_count": 1680,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "81 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "698d9c7f32af67581c79e235",
          "name": "DugganUSA Feed Harvest - 2026-02-12",
          "description": "Automated multi-source IOC harvest. Sources: openphish: 100, torExit: 500, spamhausDrop: 1483, ja3: 97. Race to 500K! \ud83d\ude80",
          "modified": "2026-03-14T09:00:56.720000",
          "created": "2026-02-12T09:25:19.519000",
          "tags": [
            "dugganusa",
            "automated",
            "feed-harvest",
            "urlhaus",
            "feodo",
            "sslbl",
            "openphish",
            "tor",
            "spamhaus",
            "ja3"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix-feed/v2",
            "https://urlhaus.abuse.ch",
            "https://feodotracker.abuse.ch",
            "https://sslbl.abuse.ch",
            "https://check.torproject.org",
            "https://www.spamhaus.org/drop"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Phishing",
              "display_name": "Phishing",
              "target": null
            },
            {
              "id": "Tor Exit Node",
              "display_name": "Tor Exit Node",
              "target": null
            },
            {
              "id": "Spamhaus DROP",
              "display_name": "Spamhaus DROP",
              "target": null
            },
            {
              "id": "2019-07-27 20:42:54",
              "display_name": "2019-07-27 20:42:54",
              "target": null
            },
            {
              "id": "2019-07-28 00:34:38",
              "display_name": "2019-07-28 00:34:38",
              "target": null
            },
            {
              "id": "2019-05-22 03:22:38",
              "display_name": "2019-05-22 03:22:38",
              "target": null
            },
            {
              "id": "2019-07-28 01:38:22",
              "display_name": "2019-07-28 01:38:22",
              "target": null
            },
            {
              "id": "2021-02-01 18:23:25",
              "display_name": "2021-02-01 18:23:25",
              "target": null
            },
            {
              "id": "2021-03-13 07:33:39",
              "display_name": "2021-03-13 07:33:39",
              "target": null
            },
            {
              "id": "2019-07-27 20:00:57",
              "display_name": "2019-07-27 20:00:57",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1566.002",
              "name": "Spearphishing Link",
              "display_name": "T1566.002 - Spearphishing Link"
            },
            {
              "id": "T1204.002",
              "name": "Malicious File",
              "display_name": "T1204.002 - Malicious File"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 100,
            "CIDR": 1483,
            "JA3": 97
          },
          "indicator_count": 1680,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "81 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "698da37687b6fcdf7e2d8cfa",
          "name": "DugganUSA Feed Harvest - 2026-02-12",
          "description": "Automated multi-source IOC harvest. Sources: openphish: 100, torExit: 500, spamhausDrop: 1483, ja3: 97. Race to 500K! \ud83d\ude80",
          "modified": "2026-03-14T09:00:56.720000",
          "created": "2026-02-12T09:55:02.394000",
          "tags": [
            "dugganusa",
            "automated",
            "feed-harvest",
            "urlhaus",
            "feodo",
            "sslbl",
            "openphish",
            "tor",
            "spamhaus",
            "ja3"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix-feed/v2",
            "https://urlhaus.abuse.ch",
            "https://feodotracker.abuse.ch",
            "https://sslbl.abuse.ch",
            "https://check.torproject.org",
            "https://www.spamhaus.org/drop"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Phishing",
              "display_name": "Phishing",
              "target": null
            },
            {
              "id": "Tor Exit Node",
              "display_name": "Tor Exit Node",
              "target": null
            },
            {
              "id": "Spamhaus DROP",
              "display_name": "Spamhaus DROP",
              "target": null
            },
            {
              "id": "2019-07-27 20:42:54",
              "display_name": "2019-07-27 20:42:54",
              "target": null
            },
            {
              "id": "2019-07-28 00:34:38",
              "display_name": "2019-07-28 00:34:38",
              "target": null
            },
            {
              "id": "2019-05-22 03:22:38",
              "display_name": "2019-05-22 03:22:38",
              "target": null
            },
            {
              "id": "2019-07-28 01:38:22",
              "display_name": "2019-07-28 01:38:22",
              "target": null
            },
            {
              "id": "2021-02-01 18:23:25",
              "display_name": "2021-02-01 18:23:25",
              "target": null
            },
            {
              "id": "2021-03-13 07:33:39",
              "display_name": "2021-03-13 07:33:39",
              "target": null
            },
            {
              "id": "2019-07-27 20:00:57",
              "display_name": "2019-07-27 20:00:57",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1566.002",
              "name": "Spearphishing Link",
              "display_name": "T1566.002 - Spearphishing Link"
            },
            {
              "id": "T1204.002",
              "name": "Malicious File",
              "display_name": "T1204.002 - Malicious File"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 100,
            "CIDR": 1483,
            "JA3": 97
          },
          "indicator_count": 1680,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "81 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "698d9565a1b009715da258b0",
          "name": "DugganUSA Feed Harvest - 2026-02-12",
          "description": "Automated multi-source IOC harvest. Sources: openphish: 100, torExit: 500, spamhausDrop: 1483, ja3: 97. Race to 500K! \ud83d\ude80",
          "modified": "2026-03-14T08:19:54.086000",
          "created": "2026-02-12T08:55:01.275000",
          "tags": [
            "dugganusa",
            "automated",
            "feed-harvest",
            "urlhaus",
            "feodo",
            "sslbl",
            "openphish",
            "tor",
            "spamhaus",
            "ja3"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix-feed/v2",
            "https://urlhaus.abuse.ch",
            "https://feodotracker.abuse.ch",
            "https://sslbl.abuse.ch",
            "https://check.torproject.org",
            "https://www.spamhaus.org/drop"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Phishing",
              "display_name": "Phishing",
              "target": null
            },
            {
              "id": "Tor Exit Node",
              "display_name": "Tor Exit Node",
              "target": null
            },
            {
              "id": "Spamhaus DROP",
              "display_name": "Spamhaus DROP",
              "target": null
            },
            {
              "id": "2019-07-27 20:42:54",
              "display_name": "2019-07-27 20:42:54",
              "target": null
            },
            {
              "id": "2019-07-28 00:34:38",
              "display_name": "2019-07-28 00:34:38",
              "target": null
            },
            {
              "id": "2019-05-22 03:22:38",
              "display_name": "2019-05-22 03:22:38",
              "target": null
            },
            {
              "id": "2019-07-28 01:38:22",
              "display_name": "2019-07-28 01:38:22",
              "target": null
            },
            {
              "id": "2021-02-01 18:23:25",
              "display_name": "2021-02-01 18:23:25",
              "target": null
            },
            {
              "id": "2021-03-13 07:33:39",
              "display_name": "2021-03-13 07:33:39",
              "target": null
            },
            {
              "id": "2019-07-27 20:00:57",
              "display_name": "2019-07-27 20:00:57",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1566.002",
              "name": "Spearphishing Link",
              "display_name": "T1566.002 - Spearphishing Link"
            },
            {
              "id": "T1204.002",
              "name": "Malicious File",
              "display_name": "T1204.002 - Malicious File"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 100,
            "CIDR": 1483,
            "JA3": 97
          },
          "indicator_count": 1680,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "81 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "698d91ebc132a4ed01e2e816",
          "name": "DugganUSA Feed Harvest - 2026-02-12",
          "description": "Automated multi-source IOC harvest. Sources: openphish: 100, torExit: 500, spamhausDrop: 1483, ja3: 97. Race to 500K! \ud83d\ude80",
          "modified": "2026-03-14T08:19:54.086000",
          "created": "2026-02-12T08:40:11.649000",
          "tags": [
            "dugganusa",
            "automated",
            "feed-harvest",
            "urlhaus",
            "feodo",
            "sslbl",
            "openphish",
            "tor",
            "spamhaus",
            "ja3"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix-feed/v2",
            "https://urlhaus.abuse.ch",
            "https://feodotracker.abuse.ch",
            "https://sslbl.abuse.ch",
            "https://check.torproject.org",
            "https://www.spamhaus.org/drop"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Phishing",
              "display_name": "Phishing",
              "target": null
            },
            {
              "id": "Tor Exit Node",
              "display_name": "Tor Exit Node",
              "target": null
            },
            {
              "id": "Spamhaus DROP",
              "display_name": "Spamhaus DROP",
              "target": null
            },
            {
              "id": "2019-07-27 20:42:54",
              "display_name": "2019-07-27 20:42:54",
              "target": null
            },
            {
              "id": "2019-07-28 00:34:38",
              "display_name": "2019-07-28 00:34:38",
              "target": null
            },
            {
              "id": "2019-05-22 03:22:38",
              "display_name": "2019-05-22 03:22:38",
              "target": null
            },
            {
              "id": "2019-07-28 01:38:22",
              "display_name": "2019-07-28 01:38:22",
              "target": null
            },
            {
              "id": "2021-02-01 18:23:25",
              "display_name": "2021-02-01 18:23:25",
              "target": null
            },
            {
              "id": "2021-03-13 07:33:39",
              "display_name": "2021-03-13 07:33:39",
              "target": null
            },
            {
              "id": "2019-07-27 20:00:57",
              "display_name": "2019-07-27 20:00:57",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1566.002",
              "name": "Spearphishing Link",
              "display_name": "T1566.002 - Spearphishing Link"
            },
            {
              "id": "T1204.002",
              "name": "Malicious File",
              "display_name": "T1204.002 - Malicious File"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 100,
            "CIDR": 1483,
            "JA3": 97
          },
          "indicator_count": 1680,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 198,
          "modified_text": "81 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "698d8e6d2b59e43904700c50",
          "name": "DugganUSA Feed Harvest - 2026-02-12",
          "description": "Automated multi-source IOC harvest. Sources: openphish: 100, torExit: 500, spamhausDrop: 1483, ja3: 97. Race to 500K! \ud83d\ude80",
          "modified": "2026-03-14T08:19:54.086000",
          "created": "2026-02-12T08:25:17.391000",
          "tags": [
            "dugganusa",
            "automated",
            "feed-harvest",
            "urlhaus",
            "feodo",
            "sslbl",
            "openphish",
            "tor",
            "spamhaus",
            "ja3"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix-feed/v2",
            "https://urlhaus.abuse.ch",
            "https://feodotracker.abuse.ch",
            "https://sslbl.abuse.ch",
            "https://check.torproject.org",
            "https://www.spamhaus.org/drop"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Phishing",
              "display_name": "Phishing",
              "target": null
            },
            {
              "id": "Tor Exit Node",
              "display_name": "Tor Exit Node",
              "target": null
            },
            {
              "id": "Spamhaus DROP",
              "display_name": "Spamhaus DROP",
              "target": null
            },
            {
              "id": "2019-07-27 20:42:54",
              "display_name": "2019-07-27 20:42:54",
              "target": null
            },
            {
              "id": "2019-07-28 00:34:38",
              "display_name": "2019-07-28 00:34:38",
              "target": null
            },
            {
              "id": "2019-05-22 03:22:38",
              "display_name": "2019-05-22 03:22:38",
              "target": null
            },
            {
              "id": "2019-07-28 01:38:22",
              "display_name": "2019-07-28 01:38:22",
              "target": null
            },
            {
              "id": "2021-02-01 18:23:25",
              "display_name": "2021-02-01 18:23:25",
              "target": null
            },
            {
              "id": "2021-03-13 07:33:39",
              "display_name": "2021-03-13 07:33:39",
              "target": null
            },
            {
              "id": "2019-07-27 20:00:57",
              "display_name": "2019-07-27 20:00:57",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1566.002",
              "name": "Spearphishing Link",
              "display_name": "T1566.002 - Spearphishing Link"
            },
            {
              "id": "T1204.002",
              "name": "Malicious File",
              "display_name": "T1204.002 - Malicious File"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 100,
            "CIDR": 1483,
            "JA3": 97
          },
          "indicator_count": 1680,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 198,
          "modified_text": "81 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "698d8aee737637c97d2e2350",
          "name": "DugganUSA Feed Harvest - 2026-02-12",
          "description": "Automated multi-source IOC harvest. Sources: openphish: 100, torExit: 500, spamhausDrop: 1483, ja3: 97. Race to 500K! \ud83d\ude80",
          "modified": "2026-03-14T08:19:54.086000",
          "created": "2026-02-12T08:10:22.351000",
          "tags": [
            "dugganusa",
            "automated",
            "feed-harvest",
            "urlhaus",
            "feodo",
            "sslbl",
            "openphish",
            "tor",
            "spamhaus",
            "ja3"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix-feed/v2",
            "https://urlhaus.abuse.ch",
            "https://feodotracker.abuse.ch",
            "https://sslbl.abuse.ch",
            "https://check.torproject.org",
            "https://www.spamhaus.org/drop"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Phishing",
              "display_name": "Phishing",
              "target": null
            },
            {
              "id": "Tor Exit Node",
              "display_name": "Tor Exit Node",
              "target": null
            },
            {
              "id": "Spamhaus DROP",
              "display_name": "Spamhaus DROP",
              "target": null
            },
            {
              "id": "2019-07-27 20:42:54",
              "display_name": "2019-07-27 20:42:54",
              "target": null
            },
            {
              "id": "2019-07-28 00:34:38",
              "display_name": "2019-07-28 00:34:38",
              "target": null
            },
            {
              "id": "2019-05-22 03:22:38",
              "display_name": "2019-05-22 03:22:38",
              "target": null
            },
            {
              "id": "2019-07-28 01:38:22",
              "display_name": "2019-07-28 01:38:22",
              "target": null
            },
            {
              "id": "2021-02-01 18:23:25",
              "display_name": "2021-02-01 18:23:25",
              "target": null
            },
            {
              "id": "2021-03-13 07:33:39",
              "display_name": "2021-03-13 07:33:39",
              "target": null
            },
            {
              "id": "2019-07-27 20:00:57",
              "display_name": "2019-07-27 20:00:57",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1566.002",
              "name": "Spearphishing Link",
              "display_name": "T1566.002 - Spearphishing Link"
            },
            {
              "id": "T1204.002",
              "name": "Malicious File",
              "display_name": "T1204.002 - Malicious File"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 100,
            "CIDR": 1483,
            "JA3": 97
          },
          "indicator_count": 1680,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 198,
          "modified_text": "81 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "698d875699a18e59f69a4583",
          "name": "DugganUSA Feed Harvest - 2026-02-12",
          "description": "Automated multi-source IOC harvest. Sources: openphish: 100, torExit: 500, spamhausDrop: 1483, ja3: 97. Race to 500K! \ud83d\ude80",
          "modified": "2026-03-14T07:04:31.872000",
          "created": "2026-02-12T07:55:01.995000",
          "tags": [
            "dugganusa",
            "automated",
            "feed-harvest",
            "urlhaus",
            "feodo",
            "sslbl",
            "openphish",
            "tor",
            "spamhaus",
            "ja3"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix-feed/v2",
            "https://urlhaus.abuse.ch",
            "https://feodotracker.abuse.ch",
            "https://sslbl.abuse.ch",
            "https://check.torproject.org",
            "https://www.spamhaus.org/drop"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Phishing",
              "display_name": "Phishing",
              "target": null
            },
            {
              "id": "Tor Exit Node",
              "display_name": "Tor Exit Node",
              "target": null
            },
            {
              "id": "Spamhaus DROP",
              "display_name": "Spamhaus DROP",
              "target": null
            },
            {
              "id": "2019-07-27 20:42:54",
              "display_name": "2019-07-27 20:42:54",
              "target": null
            },
            {
              "id": "2019-07-28 00:34:38",
              "display_name": "2019-07-28 00:34:38",
              "target": null
            },
            {
              "id": "2019-05-22 03:22:38",
              "display_name": "2019-05-22 03:22:38",
              "target": null
            },
            {
              "id": "2019-07-28 01:38:22",
              "display_name": "2019-07-28 01:38:22",
              "target": null
            },
            {
              "id": "2021-02-01 18:23:25",
              "display_name": "2021-02-01 18:23:25",
              "target": null
            },
            {
              "id": "2021-03-13 07:33:39",
              "display_name": "2021-03-13 07:33:39",
              "target": null
            },
            {
              "id": "2019-07-27 20:00:57",
              "display_name": "2019-07-27 20:00:57",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1566.002",
              "name": "Spearphishing Link",
              "display_name": "T1566.002 - Spearphishing Link"
            },
            {
              "id": "T1204.002",
              "name": "Malicious File",
              "display_name": "T1204.002 - Malicious File"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 100,
            "CIDR": 1483,
            "JA3": 97
          },
          "indicator_count": 1680,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 198,
          "modified_text": "81 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "698d83d1261606be0c28aa6f",
          "name": "DugganUSA Feed Harvest - 2026-02-12",
          "description": "Automated multi-source IOC harvest. Sources: openphish: 100, torExit: 500, spamhausDrop: 1483, ja3: 97. Race to 500K! \ud83d\ude80",
          "modified": "2026-03-14T07:04:31.872000",
          "created": "2026-02-12T07:40:01.385000",
          "tags": [
            "dugganusa",
            "automated",
            "feed-harvest",
            "urlhaus",
            "feodo",
            "sslbl",
            "openphish",
            "tor",
            "spamhaus",
            "ja3"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix-feed/v2",
            "https://urlhaus.abuse.ch",
            "https://feodotracker.abuse.ch",
            "https://sslbl.abuse.ch",
            "https://check.torproject.org",
            "https://www.spamhaus.org/drop"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Phishing",
              "display_name": "Phishing",
              "target": null
            },
            {
              "id": "Tor Exit Node",
              "display_name": "Tor Exit Node",
              "target": null
            },
            {
              "id": "Spamhaus DROP",
              "display_name": "Spamhaus DROP",
              "target": null
            },
            {
              "id": "2019-07-27 20:42:54",
              "display_name": "2019-07-27 20:42:54",
              "target": null
            },
            {
              "id": "2019-07-28 00:34:38",
              "display_name": "2019-07-28 00:34:38",
              "target": null
            },
            {
              "id": "2019-05-22 03:22:38",
              "display_name": "2019-05-22 03:22:38",
              "target": null
            },
            {
              "id": "2019-07-28 01:38:22",
              "display_name": "2019-07-28 01:38:22",
              "target": null
            },
            {
              "id": "2021-02-01 18:23:25",
              "display_name": "2021-02-01 18:23:25",
              "target": null
            },
            {
              "id": "2021-03-13 07:33:39",
              "display_name": "2021-03-13 07:33:39",
              "target": null
            },
            {
              "id": "2019-07-27 20:00:57",
              "display_name": "2019-07-27 20:00:57",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1566.002",
              "name": "Spearphishing Link",
              "display_name": "T1566.002 - Spearphishing Link"
            },
            {
              "id": "T1204.002",
              "name": "Malicious File",
              "display_name": "T1204.002 - Malicious File"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 100,
            "CIDR": 1483,
            "JA3": 97
          },
          "indicator_count": 1680,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 198,
          "modified_text": "81 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "698d806b9ee8b3625b2eed09",
          "name": "DugganUSA Feed Harvest - 2026-02-12",
          "description": "Automated multi-source IOC harvest. Sources: openphish: 100, torExit: 500, spamhausDrop: 1483, ja3: 97. Race to 500K! \ud83d\ude80",
          "modified": "2026-03-14T07:04:31.872000",
          "created": "2026-02-12T07:25:31.248000",
          "tags": [
            "dugganusa",
            "automated",
            "feed-harvest",
            "urlhaus",
            "feodo",
            "sslbl",
            "openphish",
            "tor",
            "spamhaus",
            "ja3"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix-feed/v2",
            "https://urlhaus.abuse.ch",
            "https://feodotracker.abuse.ch",
            "https://sslbl.abuse.ch",
            "https://check.torproject.org",
            "https://www.spamhaus.org/drop"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Phishing",
              "display_name": "Phishing",
              "target": null
            },
            {
              "id": "Tor Exit Node",
              "display_name": "Tor Exit Node",
              "target": null
            },
            {
              "id": "Spamhaus DROP",
              "display_name": "Spamhaus DROP",
              "target": null
            },
            {
              "id": "2019-07-27 20:42:54",
              "display_name": "2019-07-27 20:42:54",
              "target": null
            },
            {
              "id": "2019-07-28 00:34:38",
              "display_name": "2019-07-28 00:34:38",
              "target": null
            },
            {
              "id": "2019-05-22 03:22:38",
              "display_name": "2019-05-22 03:22:38",
              "target": null
            },
            {
              "id": "2019-07-28 01:38:22",
              "display_name": "2019-07-28 01:38:22",
              "target": null
            },
            {
              "id": "2021-02-01 18:23:25",
              "display_name": "2021-02-01 18:23:25",
              "target": null
            },
            {
              "id": "2021-03-13 07:33:39",
              "display_name": "2021-03-13 07:33:39",
              "target": null
            },
            {
              "id": "2019-07-27 20:00:57",
              "display_name": "2019-07-27 20:00:57",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1566.002",
              "name": "Spearphishing Link",
              "display_name": "T1566.002 - Spearphishing Link"
            },
            {
              "id": "T1204.002",
              "name": "Malicious File",
              "display_name": "T1204.002 - Malicious File"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 100,
            "CIDR": 1483,
            "JA3": 97
          },
          "indicator_count": 1680,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 198,
          "modified_text": "81 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "698d7cda18da17ac6bf3309e",
          "name": "DugganUSA Feed Harvest - 2026-02-12",
          "description": "Automated multi-source IOC harvest. Sources: openphish: 100, torExit: 500, spamhausDrop: 1483, ja3: 97. Race to 500K! \ud83d\ude80",
          "modified": "2026-03-14T07:04:31.872000",
          "created": "2026-02-12T07:10:18.189000",
          "tags": [
            "dugganusa",
            "automated",
            "feed-harvest",
            "urlhaus",
            "feodo",
            "sslbl",
            "openphish",
            "tor",
            "spamhaus",
            "ja3"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix-feed/v2",
            "https://urlhaus.abuse.ch",
            "https://feodotracker.abuse.ch",
            "https://sslbl.abuse.ch",
            "https://check.torproject.org",
            "https://www.spamhaus.org/drop"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Phishing",
              "display_name": "Phishing",
              "target": null
            },
            {
              "id": "Tor Exit Node",
              "display_name": "Tor Exit Node",
              "target": null
            },
            {
              "id": "Spamhaus DROP",
              "display_name": "Spamhaus DROP",
              "target": null
            },
            {
              "id": "2019-07-27 20:42:54",
              "display_name": "2019-07-27 20:42:54",
              "target": null
            },
            {
              "id": "2019-07-28 00:34:38",
              "display_name": "2019-07-28 00:34:38",
              "target": null
            },
            {
              "id": "2019-05-22 03:22:38",
              "display_name": "2019-05-22 03:22:38",
              "target": null
            },
            {
              "id": "2019-07-28 01:38:22",
              "display_name": "2019-07-28 01:38:22",
              "target": null
            },
            {
              "id": "2021-02-01 18:23:25",
              "display_name": "2021-02-01 18:23:25",
              "target": null
            },
            {
              "id": "2021-03-13 07:33:39",
              "display_name": "2021-03-13 07:33:39",
              "target": null
            },
            {
              "id": "2019-07-27 20:00:57",
              "display_name": "2019-07-27 20:00:57",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1566.002",
              "name": "Spearphishing Link",
              "display_name": "T1566.002 - Spearphishing Link"
            },
            {
              "id": "T1204.002",
              "name": "Malicious File",
              "display_name": "T1204.002 - Malicious File"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 100,
            "CIDR": 1483,
            "JA3": 97
          },
          "indicator_count": 1680,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 198,
          "modified_text": "81 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "698d7945b15c16dec35ffe81",
          "name": "DugganUSA Feed Harvest - 2026-02-12",
          "description": "Automated multi-source IOC harvest. Sources: openphish: 100, torExit: 500, spamhausDrop: 1483, ja3: 97. Race to 500K! \ud83d\ude80",
          "modified": "2026-03-14T06:22:39.531000",
          "created": "2026-02-12T06:55:01.640000",
          "tags": [
            "dugganusa",
            "automated",
            "feed-harvest",
            "urlhaus",
            "feodo",
            "sslbl",
            "openphish",
            "tor",
            "spamhaus",
            "ja3"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix-feed/v2",
            "https://urlhaus.abuse.ch",
            "https://feodotracker.abuse.ch",
            "https://sslbl.abuse.ch",
            "https://check.torproject.org",
            "https://www.spamhaus.org/drop"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Phishing",
              "display_name": "Phishing",
              "target": null
            },
            {
              "id": "Tor Exit Node",
              "display_name": "Tor Exit Node",
              "target": null
            },
            {
              "id": "Spamhaus DROP",
              "display_name": "Spamhaus DROP",
              "target": null
            },
            {
              "id": "2019-07-27 20:42:54",
              "display_name": "2019-07-27 20:42:54",
              "target": null
            },
            {
              "id": "2019-07-28 00:34:38",
              "display_name": "2019-07-28 00:34:38",
              "target": null
            },
            {
              "id": "2019-05-22 03:22:38",
              "display_name": "2019-05-22 03:22:38",
              "target": null
            },
            {
              "id": "2019-07-28 01:38:22",
              "display_name": "2019-07-28 01:38:22",
              "target": null
            },
            {
              "id": "2021-02-01 18:23:25",
              "display_name": "2021-02-01 18:23:25",
              "target": null
            },
            {
              "id": "2021-03-13 07:33:39",
              "display_name": "2021-03-13 07:33:39",
              "target": null
            },
            {
              "id": "2019-07-27 20:00:57",
              "display_name": "2019-07-27 20:00:57",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1566.002",
              "name": "Spearphishing Link",
              "display_name": "T1566.002 - Spearphishing Link"
            },
            {
              "id": "T1204.002",
              "name": "Malicious File",
              "display_name": "T1204.002 - Malicious File"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 100,
            "CIDR": 1483,
            "JA3": 97
          },
          "indicator_count": 1680,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 198,
          "modified_text": "81 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "698d75d44da4e8db1c227078",
          "name": "DugganUSA Feed Harvest - 2026-02-12",
          "description": "Automated multi-source IOC harvest. Sources: openphish: 100, torExit: 500, spamhausDrop: 1483, ja3: 97. Race to 500K! \ud83d\ude80",
          "modified": "2026-03-14T06:22:39.531000",
          "created": "2026-02-12T06:40:19.998000",
          "tags": [
            "dugganusa",
            "automated",
            "feed-harvest",
            "urlhaus",
            "feodo",
            "sslbl",
            "openphish",
            "tor",
            "spamhaus",
            "ja3"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix-feed/v2",
            "https://urlhaus.abuse.ch",
            "https://feodotracker.abuse.ch",
            "https://sslbl.abuse.ch",
            "https://check.torproject.org",
            "https://www.spamhaus.org/drop"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Phishing",
              "display_name": "Phishing",
              "target": null
            },
            {
              "id": "Tor Exit Node",
              "display_name": "Tor Exit Node",
              "target": null
            },
            {
              "id": "Spamhaus DROP",
              "display_name": "Spamhaus DROP",
              "target": null
            },
            {
              "id": "2019-07-27 20:42:54",
              "display_name": "2019-07-27 20:42:54",
              "target": null
            },
            {
              "id": "2019-07-28 00:34:38",
              "display_name": "2019-07-28 00:34:38",
              "target": null
            },
            {
              "id": "2019-05-22 03:22:38",
              "display_name": "2019-05-22 03:22:38",
              "target": null
            },
            {
              "id": "2019-07-28 01:38:22",
              "display_name": "2019-07-28 01:38:22",
              "target": null
            },
            {
              "id": "2021-02-01 18:23:25",
              "display_name": "2021-02-01 18:23:25",
              "target": null
            },
            {
              "id": "2021-03-13 07:33:39",
              "display_name": "2021-03-13 07:33:39",
              "target": null
            },
            {
              "id": "2019-07-27 20:00:57",
              "display_name": "2019-07-27 20:00:57",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1566.002",
              "name": "Spearphishing Link",
              "display_name": "T1566.002 - Spearphishing Link"
            },
            {
              "id": "T1204.002",
              "name": "Malicious File",
              "display_name": "T1204.002 - Malicious File"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 100,
            "CIDR": 1483,
            "JA3": 97
          },
          "indicator_count": 1680,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 198,
          "modified_text": "81 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "698d67be255970bb29a56d09",
          "name": "DugganUSA Feed Harvest - 2026-02-12",
          "description": "Automated multi-source IOC harvest. Sources: openphish: 100, torExit: 500, spamhausDrop: 1483, ja3: 97. Race to 500K! \ud83d\ude80",
          "modified": "2026-03-14T05:02:16.629000",
          "created": "2026-02-12T05:40:14.441000",
          "tags": [
            "dugganusa",
            "automated",
            "feed-harvest",
            "urlhaus",
            "feodo",
            "sslbl",
            "openphish",
            "tor",
            "spamhaus",
            "ja3"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix-feed/v2",
            "https://urlhaus.abuse.ch",
            "https://feodotracker.abuse.ch",
            "https://sslbl.abuse.ch",
            "https://check.torproject.org",
            "https://www.spamhaus.org/drop"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Phishing",
              "display_name": "Phishing",
              "target": null
            },
            {
              "id": "Tor Exit Node",
              "display_name": "Tor Exit Node",
              "target": null
            },
            {
              "id": "Spamhaus DROP",
              "display_name": "Spamhaus DROP",
              "target": null
            },
            {
              "id": "2019-07-27 20:42:54",
              "display_name": "2019-07-27 20:42:54",
              "target": null
            },
            {
              "id": "2019-07-28 00:34:38",
              "display_name": "2019-07-28 00:34:38",
              "target": null
            },
            {
              "id": "2019-05-22 03:22:38",
              "display_name": "2019-05-22 03:22:38",
              "target": null
            },
            {
              "id": "2019-07-28 01:38:22",
              "display_name": "2019-07-28 01:38:22",
              "target": null
            },
            {
              "id": "2021-02-01 18:23:25",
              "display_name": "2021-02-01 18:23:25",
              "target": null
            },
            {
              "id": "2021-03-13 07:33:39",
              "display_name": "2021-03-13 07:33:39",
              "target": null
            },
            {
              "id": "2019-07-27 20:00:57",
              "display_name": "2019-07-27 20:00:57",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1566.002",
              "name": "Spearphishing Link",
              "display_name": "T1566.002 - Spearphishing Link"
            },
            {
              "id": "T1204.002",
              "name": "Malicious File",
              "display_name": "T1204.002 - Malicious File"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 100,
            "CIDR": 1483,
            "JA3": 97
          },
          "indicator_count": 1680,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 198,
          "modified_text": "81 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "698d60a9722aac31245793db",
          "name": "DugganUSA Feed Harvest - 2026-02-12",
          "description": "Automated multi-source IOC harvest. Sources: openphish: 100, torExit: 500, spamhausDrop: 1483, ja3: 97. Race to 500K! \ud83d\ude80",
          "modified": "2026-03-14T05:02:16.629000",
          "created": "2026-02-12T05:10:01.231000",
          "tags": [
            "dugganusa",
            "automated",
            "feed-harvest",
            "urlhaus",
            "feodo",
            "sslbl",
            "openphish",
            "tor",
            "spamhaus",
            "ja3"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix-feed/v2",
            "https://urlhaus.abuse.ch",
            "https://feodotracker.abuse.ch",
            "https://sslbl.abuse.ch",
            "https://check.torproject.org",
            "https://www.spamhaus.org/drop"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Phishing",
              "display_name": "Phishing",
              "target": null
            },
            {
              "id": "Tor Exit Node",
              "display_name": "Tor Exit Node",
              "target": null
            },
            {
              "id": "Spamhaus DROP",
              "display_name": "Spamhaus DROP",
              "target": null
            },
            {
              "id": "2019-07-27 20:42:54",
              "display_name": "2019-07-27 20:42:54",
              "target": null
            },
            {
              "id": "2019-07-28 00:34:38",
              "display_name": "2019-07-28 00:34:38",
              "target": null
            },
            {
              "id": "2019-05-22 03:22:38",
              "display_name": "2019-05-22 03:22:38",
              "target": null
            },
            {
              "id": "2019-07-28 01:38:22",
              "display_name": "2019-07-28 01:38:22",
              "target": null
            },
            {
              "id": "2021-02-01 18:23:25",
              "display_name": "2021-02-01 18:23:25",
              "target": null
            },
            {
              "id": "2021-03-13 07:33:39",
              "display_name": "2021-03-13 07:33:39",
              "target": null
            },
            {
              "id": "2019-07-27 20:00:57",
              "display_name": "2019-07-27 20:00:57",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1566.002",
              "name": "Spearphishing Link",
              "display_name": "T1566.002 - Spearphishing Link"
            },
            {
              "id": "T1204.002",
              "name": "Malicious File",
              "display_name": "T1204.002 - Malicious File"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 100,
            "CIDR": 1483,
            "JA3": 97
          },
          "indicator_count": 1680,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 199,
          "modified_text": "81 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "698d5d255cfafd8a4bd90a01",
          "name": "DugganUSA Feed Harvest - 2026-02-12",
          "description": "Automated multi-source IOC harvest. Sources: openphish: 100, torExit: 500, spamhausDrop: 1483, ja3: 97. Race to 500K! \ud83d\ude80",
          "modified": "2026-03-14T04:06:00.296000",
          "created": "2026-02-12T04:55:01.198000",
          "tags": [
            "dugganusa",
            "automated",
            "feed-harvest",
            "urlhaus",
            "feodo",
            "sslbl",
            "openphish",
            "tor",
            "spamhaus",
            "ja3"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix-feed/v2",
            "https://urlhaus.abuse.ch",
            "https://feodotracker.abuse.ch",
            "https://sslbl.abuse.ch",
            "https://check.torproject.org",
            "https://www.spamhaus.org/drop"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Phishing",
              "display_name": "Phishing",
              "target": null
            },
            {
              "id": "Tor Exit Node",
              "display_name": "Tor Exit Node",
              "target": null
            },
            {
              "id": "Spamhaus DROP",
              "display_name": "Spamhaus DROP",
              "target": null
            },
            {
              "id": "2019-07-27 20:42:54",
              "display_name": "2019-07-27 20:42:54",
              "target": null
            },
            {
              "id": "2019-07-28 00:34:38",
              "display_name": "2019-07-28 00:34:38",
              "target": null
            },
            {
              "id": "2019-05-22 03:22:38",
              "display_name": "2019-05-22 03:22:38",
              "target": null
            },
            {
              "id": "2019-07-28 01:38:22",
              "display_name": "2019-07-28 01:38:22",
              "target": null
            },
            {
              "id": "2021-02-01 18:23:25",
              "display_name": "2021-02-01 18:23:25",
              "target": null
            },
            {
              "id": "2021-03-13 07:33:39",
              "display_name": "2021-03-13 07:33:39",
              "target": null
            },
            {
              "id": "2019-07-27 20:00:57",
              "display_name": "2019-07-27 20:00:57",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1566.002",
              "name": "Spearphishing Link",
              "display_name": "T1566.002 - Spearphishing Link"
            },
            {
              "id": "T1204.002",
              "name": "Malicious File",
              "display_name": "T1204.002 - Malicious File"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 100,
            "CIDR": 1483,
            "JA3": 97
          },
          "indicator_count": 1680,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 199,
          "modified_text": "81 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "698d59a13846141eee892a81",
          "name": "DugganUSA Feed Harvest - 2026-02-12",
          "description": "Automated multi-source IOC harvest. Sources: openphish: 100, torExit: 500, spamhausDrop: 1483, ja3: 97. Race to 500K! \ud83d\ude80",
          "modified": "2026-03-14T04:06:00.296000",
          "created": "2026-02-12T04:40:01.396000",
          "tags": [
            "dugganusa",
            "automated",
            "feed-harvest",
            "urlhaus",
            "feodo",
            "sslbl",
            "openphish",
            "tor",
            "spamhaus",
            "ja3"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix-feed/v2",
            "https://urlhaus.abuse.ch",
            "https://feodotracker.abuse.ch",
            "https://sslbl.abuse.ch",
            "https://check.torproject.org",
            "https://www.spamhaus.org/drop"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Phishing",
              "display_name": "Phishing",
              "target": null
            },
            {
              "id": "Tor Exit Node",
              "display_name": "Tor Exit Node",
              "target": null
            },
            {
              "id": "Spamhaus DROP",
              "display_name": "Spamhaus DROP",
              "target": null
            },
            {
              "id": "2019-07-27 20:42:54",
              "display_name": "2019-07-27 20:42:54",
              "target": null
            },
            {
              "id": "2019-07-28 00:34:38",
              "display_name": "2019-07-28 00:34:38",
              "target": null
            },
            {
              "id": "2019-05-22 03:22:38",
              "display_name": "2019-05-22 03:22:38",
              "target": null
            },
            {
              "id": "2019-07-28 01:38:22",
              "display_name": "2019-07-28 01:38:22",
              "target": null
            },
            {
              "id": "2021-02-01 18:23:25",
              "display_name": "2021-02-01 18:23:25",
              "target": null
            },
            {
              "id": "2021-03-13 07:33:39",
              "display_name": "2021-03-13 07:33:39",
              "target": null
            },
            {
              "id": "2019-07-27 20:00:57",
              "display_name": "2019-07-27 20:00:57",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1566.002",
              "name": "Spearphishing Link",
              "display_name": "T1566.002 - Spearphishing Link"
            },
            {
              "id": "T1204.002",
              "name": "Malicious File",
              "display_name": "T1204.002 - Malicious File"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 100,
            "CIDR": 1483,
            "JA3": 97
          },
          "indicator_count": 1680,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 199,
          "modified_text": "81 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "698d561eed3fe2b5e7688efd",
          "name": "DugganUSA Feed Harvest - 2026-02-12",
          "description": "Automated multi-source IOC harvest. Sources: openphish: 100, torExit: 500, spamhausDrop: 1483, ja3: 97. Race to 500K! \ud83d\ude80",
          "modified": "2026-03-14T04:06:00.296000",
          "created": "2026-02-12T04:25:02.079000",
          "tags": [
            "dugganusa",
            "automated",
            "feed-harvest",
            "urlhaus",
            "feodo",
            "sslbl",
            "openphish",
            "tor",
            "spamhaus",
            "ja3"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix-feed/v2",
            "https://urlhaus.abuse.ch",
            "https://feodotracker.abuse.ch",
            "https://sslbl.abuse.ch",
            "https://check.torproject.org",
            "https://www.spamhaus.org/drop"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Phishing",
              "display_name": "Phishing",
              "target": null
            },
            {
              "id": "Tor Exit Node",
              "display_name": "Tor Exit Node",
              "target": null
            },
            {
              "id": "Spamhaus DROP",
              "display_name": "Spamhaus DROP",
              "target": null
            },
            {
              "id": "2019-07-27 20:42:54",
              "display_name": "2019-07-27 20:42:54",
              "target": null
            },
            {
              "id": "2019-07-28 00:34:38",
              "display_name": "2019-07-28 00:34:38",
              "target": null
            },
            {
              "id": "2019-05-22 03:22:38",
              "display_name": "2019-05-22 03:22:38",
              "target": null
            },
            {
              "id": "2019-07-28 01:38:22",
              "display_name": "2019-07-28 01:38:22",
              "target": null
            },
            {
              "id": "2021-02-01 18:23:25",
              "display_name": "2021-02-01 18:23:25",
              "target": null
            },
            {
              "id": "2021-03-13 07:33:39",
              "display_name": "2021-03-13 07:33:39",
              "target": null
            },
            {
              "id": "2019-07-27 20:00:57",
              "display_name": "2019-07-27 20:00:57",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1566.002",
              "name": "Spearphishing Link",
              "display_name": "T1566.002 - Spearphishing Link"
            },
            {
              "id": "T1204.002",
              "name": "Malicious File",
              "display_name": "T1204.002 - Malicious File"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 100,
            "CIDR": 1483,
            "JA3": 97
          },
          "indicator_count": 1680,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 200,
          "modified_text": "81 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "698d53d3b54ef3233ae8f4ca",
          "name": "DugganUSA Feed Harvest - 2026-02-12",
          "description": "Automated multi-source IOC harvest. Sources: openphish: 100, torExit: 500, spamhausDrop: 1483, ja3: 97. Race to 500K! \ud83d\ude80",
          "modified": "2026-03-14T04:06:00.296000",
          "created": "2026-02-12T04:15:15.770000",
          "tags": [
            "dugganusa",
            "automated",
            "feed-harvest",
            "urlhaus",
            "feodo",
            "sslbl",
            "openphish",
            "tor",
            "spamhaus",
            "ja3"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix-feed/v2",
            "https://urlhaus.abuse.ch",
            "https://feodotracker.abuse.ch",
            "https://sslbl.abuse.ch",
            "https://check.torproject.org",
            "https://www.spamhaus.org/drop"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Phishing",
              "display_name": "Phishing",
              "target": null
            },
            {
              "id": "Tor Exit Node",
              "display_name": "Tor Exit Node",
              "target": null
            },
            {
              "id": "Spamhaus DROP",
              "display_name": "Spamhaus DROP",
              "target": null
            },
            {
              "id": "2019-07-27 20:42:54",
              "display_name": "2019-07-27 20:42:54",
              "target": null
            },
            {
              "id": "2019-07-28 00:34:38",
              "display_name": "2019-07-28 00:34:38",
              "target": null
            },
            {
              "id": "2019-05-22 03:22:38",
              "display_name": "2019-05-22 03:22:38",
              "target": null
            },
            {
              "id": "2019-07-28 01:38:22",
              "display_name": "2019-07-28 01:38:22",
              "target": null
            },
            {
              "id": "2021-02-01 18:23:25",
              "display_name": "2021-02-01 18:23:25",
              "target": null
            },
            {
              "id": "2021-03-13 07:33:39",
              "display_name": "2021-03-13 07:33:39",
              "target": null
            },
            {
              "id": "2019-07-27 20:00:57",
              "display_name": "2019-07-27 20:00:57",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1566.002",
              "name": "Spearphishing Link",
              "display_name": "T1566.002 - Spearphishing Link"
            },
            {
              "id": "T1204.002",
              "name": "Malicious File",
              "display_name": "T1204.002 - Malicious File"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 100,
            "CIDR": 1483,
            "JA3": 97
          },
          "indicator_count": 1680,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 199,
          "modified_text": "81 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "698d4f1699755e3b9b9c939b",
          "name": "DugganUSA Feed Harvest - 2026-02-12",
          "description": "Automated multi-source IOC harvest. Sources: openphish: 100, torExit: 500, spamhausDrop: 1483, ja3: 97. Race to 500K! \ud83d\ude80",
          "modified": "2026-03-14T03:05:12.350000",
          "created": "2026-02-12T03:55:01.977000",
          "tags": [
            "dugganusa",
            "automated",
            "feed-harvest",
            "urlhaus",
            "feodo",
            "sslbl",
            "openphish",
            "tor",
            "spamhaus",
            "ja3"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix-feed/v2",
            "https://urlhaus.abuse.ch",
            "https://feodotracker.abuse.ch",
            "https://sslbl.abuse.ch",
            "https://check.torproject.org",
            "https://www.spamhaus.org/drop"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Phishing",
              "display_name": "Phishing",
              "target": null
            },
            {
              "id": "Tor Exit Node",
              "display_name": "Tor Exit Node",
              "target": null
            },
            {
              "id": "Spamhaus DROP",
              "display_name": "Spamhaus DROP",
              "target": null
            },
            {
              "id": "2019-07-27 20:42:54",
              "display_name": "2019-07-27 20:42:54",
              "target": null
            },
            {
              "id": "2019-07-28 00:34:38",
              "display_name": "2019-07-28 00:34:38",
              "target": null
            },
            {
              "id": "2019-05-22 03:22:38",
              "display_name": "2019-05-22 03:22:38",
              "target": null
            },
            {
              "id": "2019-07-28 01:38:22",
              "display_name": "2019-07-28 01:38:22",
              "target": null
            },
            {
              "id": "2021-02-01 18:23:25",
              "display_name": "2021-02-01 18:23:25",
              "target": null
            },
            {
              "id": "2021-03-13 07:33:39",
              "display_name": "2021-03-13 07:33:39",
              "target": null
            },
            {
              "id": "2019-07-27 20:00:57",
              "display_name": "2019-07-27 20:00:57",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1566.002",
              "name": "Spearphishing Link",
              "display_name": "T1566.002 - Spearphishing Link"
            },
            {
              "id": "T1204.002",
              "name": "Malicious File",
              "display_name": "T1204.002 - Malicious File"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 100,
            "CIDR": 1483,
            "JA3": 97
          },
          "indicator_count": 1680,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 198,
          "modified_text": "81 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "698d4ba0ebafd2fd1ec0ae10",
          "name": "DugganUSA Feed Harvest - 2026-02-12",
          "description": "Automated multi-source IOC harvest. Sources: openphish: 100, torExit: 500, spamhausDrop: 1483, ja3: 97. Race to 500K! \ud83d\ude80",
          "modified": "2026-03-14T03:05:12.350000",
          "created": "2026-02-12T03:40:16.602000",
          "tags": [
            "dugganusa",
            "automated",
            "feed-harvest",
            "urlhaus",
            "feodo",
            "sslbl",
            "openphish",
            "tor",
            "spamhaus",
            "ja3"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix-feed/v2",
            "https://urlhaus.abuse.ch",
            "https://feodotracker.abuse.ch",
            "https://sslbl.abuse.ch",
            "https://check.torproject.org",
            "https://www.spamhaus.org/drop"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Phishing",
              "display_name": "Phishing",
              "target": null
            },
            {
              "id": "Tor Exit Node",
              "display_name": "Tor Exit Node",
              "target": null
            },
            {
              "id": "Spamhaus DROP",
              "display_name": "Spamhaus DROP",
              "target": null
            },
            {
              "id": "2019-07-27 20:42:54",
              "display_name": "2019-07-27 20:42:54",
              "target": null
            },
            {
              "id": "2019-07-28 00:34:38",
              "display_name": "2019-07-28 00:34:38",
              "target": null
            },
            {
              "id": "2019-05-22 03:22:38",
              "display_name": "2019-05-22 03:22:38",
              "target": null
            },
            {
              "id": "2019-07-28 01:38:22",
              "display_name": "2019-07-28 01:38:22",
              "target": null
            },
            {
              "id": "2021-02-01 18:23:25",
              "display_name": "2021-02-01 18:23:25",
              "target": null
            },
            {
              "id": "2021-03-13 07:33:39",
              "display_name": "2021-03-13 07:33:39",
              "target": null
            },
            {
              "id": "2019-07-27 20:00:57",
              "display_name": "2019-07-27 20:00:57",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1566.002",
              "name": "Spearphishing Link",
              "display_name": "T1566.002 - Spearphishing Link"
            },
            {
              "id": "T1204.002",
              "name": "Malicious File",
              "display_name": "T1204.002 - Malicious File"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 100,
            "CIDR": 1483,
            "JA3": 97
          },
          "indicator_count": 1680,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 198,
          "modified_text": "81 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "698d481eebf4a83627de1208",
          "name": "DugganUSA Feed Harvest - 2026-02-12",
          "description": "Automated multi-source IOC harvest. Sources: openphish: 100, torExit: 500, spamhausDrop: 1483, ja3: 97. Race to 500K! \ud83d\ude80",
          "modified": "2026-03-14T03:05:12.350000",
          "created": "2026-02-12T03:25:18.205000",
          "tags": [
            "dugganusa",
            "automated",
            "feed-harvest",
            "urlhaus",
            "feodo",
            "sslbl",
            "openphish",
            "tor",
            "spamhaus",
            "ja3"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix-feed/v2",
            "https://urlhaus.abuse.ch",
            "https://feodotracker.abuse.ch",
            "https://sslbl.abuse.ch",
            "https://check.torproject.org",
            "https://www.spamhaus.org/drop"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Phishing",
              "display_name": "Phishing",
              "target": null
            },
            {
              "id": "Tor Exit Node",
              "display_name": "Tor Exit Node",
              "target": null
            },
            {
              "id": "Spamhaus DROP",
              "display_name": "Spamhaus DROP",
              "target": null
            },
            {
              "id": "2019-07-27 20:42:54",
              "display_name": "2019-07-27 20:42:54",
              "target": null
            },
            {
              "id": "2019-07-28 00:34:38",
              "display_name": "2019-07-28 00:34:38",
              "target": null
            },
            {
              "id": "2019-05-22 03:22:38",
              "display_name": "2019-05-22 03:22:38",
              "target": null
            },
            {
              "id": "2019-07-28 01:38:22",
              "display_name": "2019-07-28 01:38:22",
              "target": null
            },
            {
              "id": "2021-02-01 18:23:25",
              "display_name": "2021-02-01 18:23:25",
              "target": null
            },
            {
              "id": "2021-03-13 07:33:39",
              "display_name": "2021-03-13 07:33:39",
              "target": null
            },
            {
              "id": "2019-07-27 20:00:57",
              "display_name": "2019-07-27 20:00:57",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1566.002",
              "name": "Spearphishing Link",
              "display_name": "T1566.002 - Spearphishing Link"
            },
            {
              "id": "T1204.002",
              "name": "Malicious File",
              "display_name": "T1204.002 - Malicious File"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 100,
            "CIDR": 1483,
            "JA3": 97
          },
          "indicator_count": 1680,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 198,
          "modified_text": "81 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "698d4489bc3367972f26e578",
          "name": "DugganUSA Feed Harvest - 2026-02-12",
          "description": "Automated multi-source IOC harvest. Sources: openphish: 100, torExit: 500, spamhausDrop: 1483, ja3: 97. Race to 500K! \ud83d\ude80",
          "modified": "2026-03-14T03:05:12.350000",
          "created": "2026-02-12T03:10:01.670000",
          "tags": [
            "dugganusa",
            "automated",
            "feed-harvest",
            "urlhaus",
            "feodo",
            "sslbl",
            "openphish",
            "tor",
            "spamhaus",
            "ja3"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix-feed/v2",
            "https://urlhaus.abuse.ch",
            "https://feodotracker.abuse.ch",
            "https://sslbl.abuse.ch",
            "https://check.torproject.org",
            "https://www.spamhaus.org/drop"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Phishing",
              "display_name": "Phishing",
              "target": null
            },
            {
              "id": "Tor Exit Node",
              "display_name": "Tor Exit Node",
              "target": null
            },
            {
              "id": "Spamhaus DROP",
              "display_name": "Spamhaus DROP",
              "target": null
            },
            {
              "id": "2019-07-27 20:42:54",
              "display_name": "2019-07-27 20:42:54",
              "target": null
            },
            {
              "id": "2019-07-28 00:34:38",
              "display_name": "2019-07-28 00:34:38",
              "target": null
            },
            {
              "id": "2019-05-22 03:22:38",
              "display_name": "2019-05-22 03:22:38",
              "target": null
            },
            {
              "id": "2019-07-28 01:38:22",
              "display_name": "2019-07-28 01:38:22",
              "target": null
            },
            {
              "id": "2021-02-01 18:23:25",
              "display_name": "2021-02-01 18:23:25",
              "target": null
            },
            {
              "id": "2021-03-13 07:33:39",
              "display_name": "2021-03-13 07:33:39",
              "target": null
            },
            {
              "id": "2019-07-27 20:00:57",
              "display_name": "2019-07-27 20:00:57",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1566.002",
              "name": "Spearphishing Link",
              "display_name": "T1566.002 - Spearphishing Link"
            },
            {
              "id": "T1204.002",
              "name": "Malicious File",
              "display_name": "T1204.002 - Malicious File"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 100,
            "CIDR": 1483,
            "JA3": 97
          },
          "indicator_count": 1680,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 198,
          "modified_text": "81 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "698d41053a4460d3e9f8e791",
          "name": "DugganUSA Feed Harvest - 2026-02-12",
          "description": "Automated multi-source IOC harvest. Sources: openphish: 100, torExit: 500, spamhausDrop: 1483, ja3: 97. Race to 500K! \ud83d\ude80",
          "modified": "2026-03-14T02:03:24.450000",
          "created": "2026-02-12T02:55:01.545000",
          "tags": [
            "dugganusa",
            "automated",
            "feed-harvest",
            "urlhaus",
            "feodo",
            "sslbl",
            "openphish",
            "tor",
            "spamhaus",
            "ja3"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix-feed/v2",
            "https://urlhaus.abuse.ch",
            "https://feodotracker.abuse.ch",
            "https://sslbl.abuse.ch",
            "https://check.torproject.org",
            "https://www.spamhaus.org/drop"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Phishing",
              "display_name": "Phishing",
              "target": null
            },
            {
              "id": "Tor Exit Node",
              "display_name": "Tor Exit Node",
              "target": null
            },
            {
              "id": "Spamhaus DROP",
              "display_name": "Spamhaus DROP",
              "target": null
            },
            {
              "id": "2019-07-27 20:42:54",
              "display_name": "2019-07-27 20:42:54",
              "target": null
            },
            {
              "id": "2019-07-28 00:34:38",
              "display_name": "2019-07-28 00:34:38",
              "target": null
            },
            {
              "id": "2019-05-22 03:22:38",
              "display_name": "2019-05-22 03:22:38",
              "target": null
            },
            {
              "id": "2019-07-28 01:38:22",
              "display_name": "2019-07-28 01:38:22",
              "target": null
            },
            {
              "id": "2021-02-01 18:23:25",
              "display_name": "2021-02-01 18:23:25",
              "target": null
            },
            {
              "id": "2021-03-13 07:33:39",
              "display_name": "2021-03-13 07:33:39",
              "target": null
            },
            {
              "id": "2019-07-27 20:00:57",
              "display_name": "2019-07-27 20:00:57",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1566.002",
              "name": "Spearphishing Link",
              "display_name": "T1566.002 - Spearphishing Link"
            },
            {
              "id": "T1204.002",
              "name": "Malicious File",
              "display_name": "T1204.002 - Malicious File"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 100,
            "CIDR": 1483,
            "JA3": 97
          },
          "indicator_count": 1680,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 198,
          "modified_text": "81 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "698d368cd4d61c5a02668b0e",
          "name": "DugganUSA Feed Harvest - 2026-02-12",
          "description": "Automated multi-source IOC harvest. Sources: openphish: 100, torExit: 500, spamhausDrop: 1483, ja3: 97. Race to 500K! \ud83d\ude80",
          "modified": "2026-03-14T02:03:24.450000",
          "created": "2026-02-12T02:10:19.982000",
          "tags": [
            "dugganusa",
            "automated",
            "feed-harvest",
            "urlhaus",
            "feodo",
            "sslbl",
            "openphish",
            "tor",
            "spamhaus",
            "ja3"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix-feed/v2",
            "https://urlhaus.abuse.ch",
            "https://feodotracker.abuse.ch",
            "https://sslbl.abuse.ch",
            "https://check.torproject.org",
            "https://www.spamhaus.org/drop"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Phishing",
              "display_name": "Phishing",
              "target": null
            },
            {
              "id": "Tor Exit Node",
              "display_name": "Tor Exit Node",
              "target": null
            },
            {
              "id": "Spamhaus DROP",
              "display_name": "Spamhaus DROP",
              "target": null
            },
            {
              "id": "2019-07-27 20:42:54",
              "display_name": "2019-07-27 20:42:54",
              "target": null
            },
            {
              "id": "2019-07-28 00:34:38",
              "display_name": "2019-07-28 00:34:38",
              "target": null
            },
            {
              "id": "2019-05-22 03:22:38",
              "display_name": "2019-05-22 03:22:38",
              "target": null
            },
            {
              "id": "2019-07-28 01:38:22",
              "display_name": "2019-07-28 01:38:22",
              "target": null
            },
            {
              "id": "2021-02-01 18:23:25",
              "display_name": "2021-02-01 18:23:25",
              "target": null
            },
            {
              "id": "2021-03-13 07:33:39",
              "display_name": "2021-03-13 07:33:39",
              "target": null
            },
            {
              "id": "2019-07-27 20:00:57",
              "display_name": "2019-07-27 20:00:57",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1566.002",
              "name": "Spearphishing Link",
              "display_name": "T1566.002 - Spearphishing Link"
            },
            {
              "id": "T1204.002",
              "name": "Malicious File",
              "display_name": "T1204.002 - Malicious File"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 100,
            "CIDR": 1483,
            "JA3": 97
          },
          "indicator_count": 1680,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "81 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "698d39fd3ce463731f32c8ba",
          "name": "DugganUSA Feed Harvest - 2026-02-12",
          "description": "Automated multi-source IOC harvest. Sources: openphish: 100, torExit: 500, spamhausDrop: 1483, ja3: 97. Race to 500K! \ud83d\ude80",
          "modified": "2026-03-14T02:03:24.450000",
          "created": "2026-02-12T02:25:01.546000",
          "tags": [
            "dugganusa",
            "automated",
            "feed-harvest",
            "urlhaus",
            "feodo",
            "sslbl",
            "openphish",
            "tor",
            "spamhaus",
            "ja3"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix-feed/v2",
            "https://urlhaus.abuse.ch",
            "https://feodotracker.abuse.ch",
            "https://sslbl.abuse.ch",
            "https://check.torproject.org",
            "https://www.spamhaus.org/drop"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Phishing",
              "display_name": "Phishing",
              "target": null
            },
            {
              "id": "Tor Exit Node",
              "display_name": "Tor Exit Node",
              "target": null
            },
            {
              "id": "Spamhaus DROP",
              "display_name": "Spamhaus DROP",
              "target": null
            },
            {
              "id": "2019-07-27 20:42:54",
              "display_name": "2019-07-27 20:42:54",
              "target": null
            },
            {
              "id": "2019-07-28 00:34:38",
              "display_name": "2019-07-28 00:34:38",
              "target": null
            },
            {
              "id": "2019-05-22 03:22:38",
              "display_name": "2019-05-22 03:22:38",
              "target": null
            },
            {
              "id": "2019-07-28 01:38:22",
              "display_name": "2019-07-28 01:38:22",
              "target": null
            },
            {
              "id": "2021-02-01 18:23:25",
              "display_name": "2021-02-01 18:23:25",
              "target": null
            },
            {
              "id": "2021-03-13 07:33:39",
              "display_name": "2021-03-13 07:33:39",
              "target": null
            },
            {
              "id": "2019-07-27 20:00:57",
              "display_name": "2019-07-27 20:00:57",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1566.002",
              "name": "Spearphishing Link",
              "display_name": "T1566.002 - Spearphishing Link"
            },
            {
              "id": "T1204.002",
              "name": "Malicious File",
              "display_name": "T1204.002 - Malicious File"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 100,
            "CIDR": 1483,
            "JA3": 97
          },
          "indicator_count": 1680,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "81 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "698d3d91d925395cb0692c09",
          "name": "DugganUSA Feed Harvest - 2026-02-12",
          "description": "Automated multi-source IOC harvest. Sources: openphish: 100, torExit: 500, spamhausDrop: 1483, ja3: 97. Race to 500K! \ud83d\ude80",
          "modified": "2026-03-14T02:03:24.450000",
          "created": "2026-02-12T02:40:17.540000",
          "tags": [
            "dugganusa",
            "automated",
            "feed-harvest",
            "urlhaus",
            "feodo",
            "sslbl",
            "openphish",
            "tor",
            "spamhaus",
            "ja3"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix-feed/v2",
            "https://urlhaus.abuse.ch",
            "https://feodotracker.abuse.ch",
            "https://sslbl.abuse.ch",
            "https://check.torproject.org",
            "https://www.spamhaus.org/drop"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Phishing",
              "display_name": "Phishing",
              "target": null
            },
            {
              "id": "Tor Exit Node",
              "display_name": "Tor Exit Node",
              "target": null
            },
            {
              "id": "Spamhaus DROP",
              "display_name": "Spamhaus DROP",
              "target": null
            },
            {
              "id": "2019-07-27 20:42:54",
              "display_name": "2019-07-27 20:42:54",
              "target": null
            },
            {
              "id": "2019-07-28 00:34:38",
              "display_name": "2019-07-28 00:34:38",
              "target": null
            },
            {
              "id": "2019-05-22 03:22:38",
              "display_name": "2019-05-22 03:22:38",
              "target": null
            },
            {
              "id": "2019-07-28 01:38:22",
              "display_name": "2019-07-28 01:38:22",
              "target": null
            },
            {
              "id": "2021-02-01 18:23:25",
              "display_name": "2021-02-01 18:23:25",
              "target": null
            },
            {
              "id": "2021-03-13 07:33:39",
              "display_name": "2021-03-13 07:33:39",
              "target": null
            },
            {
              "id": "2019-07-27 20:00:57",
              "display_name": "2019-07-27 20:00:57",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1566.002",
              "name": "Spearphishing Link",
              "display_name": "T1566.002 - Spearphishing Link"
            },
            {
              "id": "T1204.002",
              "name": "Malicious File",
              "display_name": "T1204.002 - Malicious File"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 100,
            "CIDR": 1483,
            "JA3": 97
          },
          "indicator_count": 1680,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "81 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "698d32fd697d21a8ee3332b8",
          "name": "DugganUSA Feed Harvest - 2026-02-12",
          "description": "Automated multi-source IOC harvest. Sources: openphish: 100, torExit: 500, spamhausDrop: 1483, ja3: 97. Race to 500K! \ud83d\ude80",
          "modified": "2026-03-14T01:15:39.741000",
          "created": "2026-02-12T01:55:09.196000",
          "tags": [
            "dugganusa",
            "automated",
            "feed-harvest",
            "urlhaus",
            "feodo",
            "sslbl",
            "openphish",
            "tor",
            "spamhaus",
            "ja3"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix-feed/v2",
            "https://urlhaus.abuse.ch",
            "https://feodotracker.abuse.ch",
            "https://sslbl.abuse.ch",
            "https://check.torproject.org",
            "https://www.spamhaus.org/drop"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Phishing",
              "display_name": "Phishing",
              "target": null
            },
            {
              "id": "Tor Exit Node",
              "display_name": "Tor Exit Node",
              "target": null
            },
            {
              "id": "Spamhaus DROP",
              "display_name": "Spamhaus DROP",
              "target": null
            },
            {
              "id": "2019-07-27 20:42:54",
              "display_name": "2019-07-27 20:42:54",
              "target": null
            },
            {
              "id": "2019-07-28 00:34:38",
              "display_name": "2019-07-28 00:34:38",
              "target": null
            },
            {
              "id": "2019-05-22 03:22:38",
              "display_name": "2019-05-22 03:22:38",
              "target": null
            },
            {
              "id": "2019-07-28 01:38:22",
              "display_name": "2019-07-28 01:38:22",
              "target": null
            },
            {
              "id": "2021-02-01 18:23:25",
              "display_name": "2021-02-01 18:23:25",
              "target": null
            },
            {
              "id": "2021-03-13 07:33:39",
              "display_name": "2021-03-13 07:33:39",
              "target": null
            },
            {
              "id": "2019-07-27 20:00:57",
              "display_name": "2019-07-27 20:00:57",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1566.002",
              "name": "Spearphishing Link",
              "display_name": "T1566.002 - Spearphishing Link"
            },
            {
              "id": "T1204.002",
              "name": "Malicious File",
              "display_name": "T1204.002 - Malicious File"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 100,
            "CIDR": 1483,
            "JA3": 97
          },
          "indicator_count": 1680,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "81 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "698d2f71f12fde9e2cfef22a",
          "name": "DugganUSA Feed Harvest - 2026-02-12",
          "description": "Automated multi-source IOC harvest. Sources: openphish: 100, torExit: 500, spamhausDrop: 1483, ja3: 97. Race to 500K! \ud83d\ude80",
          "modified": "2026-03-14T01:15:39.741000",
          "created": "2026-02-12T01:40:01.953000",
          "tags": [
            "dugganusa",
            "automated",
            "feed-harvest",
            "urlhaus",
            "feodo",
            "sslbl",
            "openphish",
            "tor",
            "spamhaus",
            "ja3"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix-feed/v2",
            "https://urlhaus.abuse.ch",
            "https://feodotracker.abuse.ch",
            "https://sslbl.abuse.ch",
            "https://check.torproject.org",
            "https://www.spamhaus.org/drop"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Phishing",
              "display_name": "Phishing",
              "target": null
            },
            {
              "id": "Tor Exit Node",
              "display_name": "Tor Exit Node",
              "target": null
            },
            {
              "id": "Spamhaus DROP",
              "display_name": "Spamhaus DROP",
              "target": null
            },
            {
              "id": "2019-07-27 20:42:54",
              "display_name": "2019-07-27 20:42:54",
              "target": null
            },
            {
              "id": "2019-07-28 00:34:38",
              "display_name": "2019-07-28 00:34:38",
              "target": null
            },
            {
              "id": "2019-05-22 03:22:38",
              "display_name": "2019-05-22 03:22:38",
              "target": null
            },
            {
              "id": "2019-07-28 01:38:22",
              "display_name": "2019-07-28 01:38:22",
              "target": null
            },
            {
              "id": "2021-02-01 18:23:25",
              "display_name": "2021-02-01 18:23:25",
              "target": null
            },
            {
              "id": "2021-03-13 07:33:39",
              "display_name": "2021-03-13 07:33:39",
              "target": null
            },
            {
              "id": "2019-07-27 20:00:57",
              "display_name": "2019-07-27 20:00:57",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1566.002",
              "name": "Spearphishing Link",
              "display_name": "T1566.002 - Spearphishing Link"
            },
            {
              "id": "T1204.002",
              "name": "Malicious File",
              "display_name": "T1204.002 - Malicious File"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 100,
            "CIDR": 1483,
            "JA3": 97
          },
          "indicator_count": 1680,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "81 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "698d2beda1a5795b4c8f2de6",
          "name": "DugganUSA Feed Harvest - 2026-02-12",
          "description": "Automated multi-source IOC harvest. Sources: openphish: 100, torExit: 500, spamhausDrop: 1483, ja3: 97. Race to 500K! \ud83d\ude80",
          "modified": "2026-03-14T01:15:39.741000",
          "created": "2026-02-12T01:25:01.385000",
          "tags": [
            "dugganusa",
            "automated",
            "feed-harvest",
            "urlhaus",
            "feodo",
            "sslbl",
            "openphish",
            "tor",
            "spamhaus",
            "ja3"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix-feed/v2",
            "https://urlhaus.abuse.ch",
            "https://feodotracker.abuse.ch",
            "https://sslbl.abuse.ch",
            "https://check.torproject.org",
            "https://www.spamhaus.org/drop"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Phishing",
              "display_name": "Phishing",
              "target": null
            },
            {
              "id": "Tor Exit Node",
              "display_name": "Tor Exit Node",
              "target": null
            },
            {
              "id": "Spamhaus DROP",
              "display_name": "Spamhaus DROP",
              "target": null
            },
            {
              "id": "2019-07-27 20:42:54",
              "display_name": "2019-07-27 20:42:54",
              "target": null
            },
            {
              "id": "2019-07-28 00:34:38",
              "display_name": "2019-07-28 00:34:38",
              "target": null
            },
            {
              "id": "2019-05-22 03:22:38",
              "display_name": "2019-05-22 03:22:38",
              "target": null
            },
            {
              "id": "2019-07-28 01:38:22",
              "display_name": "2019-07-28 01:38:22",
              "target": null
            },
            {
              "id": "2021-02-01 18:23:25",
              "display_name": "2021-02-01 18:23:25",
              "target": null
            },
            {
              "id": "2021-03-13 07:33:39",
              "display_name": "2021-03-13 07:33:39",
              "target": null
            },
            {
              "id": "2019-07-27 20:00:57",
              "display_name": "2019-07-27 20:00:57",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1566.002",
              "name": "Spearphishing Link",
              "display_name": "T1566.002 - Spearphishing Link"
            },
            {
              "id": "T1204.002",
              "name": "Malicious File",
              "display_name": "T1204.002 - Malicious File"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 100,
            "CIDR": 1483,
            "JA3": 97
          },
          "indicator_count": 1680,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "81 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "698d28693bd94f2e488dcc38",
          "name": "DugganUSA Feed Harvest - 2026-02-12",
          "description": "Automated multi-source IOC harvest. Sources: openphish: 100, torExit: 500, spamhausDrop: 1483, ja3: 97. Race to 500K! \ud83d\ude80",
          "modified": "2026-03-14T01:15:39.741000",
          "created": "2026-02-12T01:10:01.711000",
          "tags": [
            "dugganusa",
            "automated",
            "feed-harvest",
            "urlhaus",
            "feodo",
            "sslbl",
            "openphish",
            "tor",
            "spamhaus",
            "ja3"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix-feed/v2",
            "https://urlhaus.abuse.ch",
            "https://feodotracker.abuse.ch",
            "https://sslbl.abuse.ch",
            "https://check.torproject.org",
            "https://www.spamhaus.org/drop"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Phishing",
              "display_name": "Phishing",
              "target": null
            },
            {
              "id": "Tor Exit Node",
              "display_name": "Tor Exit Node",
              "target": null
            },
            {
              "id": "Spamhaus DROP",
              "display_name": "Spamhaus DROP",
              "target": null
            },
            {
              "id": "2019-07-27 20:42:54",
              "display_name": "2019-07-27 20:42:54",
              "target": null
            },
            {
              "id": "2019-07-28 00:34:38",
              "display_name": "2019-07-28 00:34:38",
              "target": null
            },
            {
              "id": "2019-05-22 03:22:38",
              "display_name": "2019-05-22 03:22:38",
              "target": null
            },
            {
              "id": "2019-07-28 01:38:22",
              "display_name": "2019-07-28 01:38:22",
              "target": null
            },
            {
              "id": "2021-02-01 18:23:25",
              "display_name": "2021-02-01 18:23:25",
              "target": null
            },
            {
              "id": "2021-03-13 07:33:39",
              "display_name": "2021-03-13 07:33:39",
              "target": null
            },
            {
              "id": "2019-07-27 20:00:57",
              "display_name": "2019-07-27 20:00:57",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1566.002",
              "name": "Spearphishing Link",
              "display_name": "T1566.002 - Spearphishing Link"
            },
            {
              "id": "T1204.002",
              "name": "Malicious File",
              "display_name": "T1204.002 - Malicious File"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 100,
            "CIDR": 1483,
            "JA3": 97
          },
          "indicator_count": 1680,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "81 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "698d2174684aa78b434a44f7",
          "name": "DugganUSA Feed Harvest - 2026-02-12",
          "description": "Automated multi-source IOC harvest. Sources: openphish: 100, torExit: 500, spamhausDrop: 1483, ja3: 97. Race to 500K! \ud83d\ude80",
          "modified": "2026-03-14T00:35:30.399000",
          "created": "2026-02-12T00:40:20.664000",
          "tags": [
            "dugganusa",
            "automated",
            "feed-harvest",
            "urlhaus",
            "feodo",
            "sslbl",
            "openphish",
            "tor",
            "spamhaus",
            "ja3"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix-feed/v2",
            "https://urlhaus.abuse.ch",
            "https://feodotracker.abuse.ch",
            "https://sslbl.abuse.ch",
            "https://check.torproject.org",
            "https://www.spamhaus.org/drop"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Phishing",
              "display_name": "Phishing",
              "target": null
            },
            {
              "id": "Tor Exit Node",
              "display_name": "Tor Exit Node",
              "target": null
            },
            {
              "id": "Spamhaus DROP",
              "display_name": "Spamhaus DROP",
              "target": null
            },
            {
              "id": "2019-07-27 20:42:54",
              "display_name": "2019-07-27 20:42:54",
              "target": null
            },
            {
              "id": "2019-07-28 00:34:38",
              "display_name": "2019-07-28 00:34:38",
              "target": null
            },
            {
              "id": "2019-05-22 03:22:38",
              "display_name": "2019-05-22 03:22:38",
              "target": null
            },
            {
              "id": "2019-07-28 01:38:22",
              "display_name": "2019-07-28 01:38:22",
              "target": null
            },
            {
              "id": "2021-02-01 18:23:25",
              "display_name": "2021-02-01 18:23:25",
              "target": null
            },
            {
              "id": "2021-03-13 07:33:39",
              "display_name": "2021-03-13 07:33:39",
              "target": null
            },
            {
              "id": "2019-07-27 20:00:57",
              "display_name": "2019-07-27 20:00:57",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1566.002",
              "name": "Spearphishing Link",
              "display_name": "T1566.002 - Spearphishing Link"
            },
            {
              "id": "T1204.002",
              "name": "Malicious File",
              "display_name": "T1204.002 - Malicious File"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 100,
            "CIDR": 1483,
            "JA3": 97
          },
          "indicator_count": 1680,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "81 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "698d1a6aef8ff2e5a944ee1e",
          "name": "DugganUSA Feed Harvest - 2026-02-12",
          "description": "Automated multi-source IOC harvest. Sources: openphish: 100, torExit: 500, spamhausDrop: 1483, ja3: 97. Race to 500K! \ud83d\ude80",
          "modified": "2026-03-14T00:35:30.399000",
          "created": "2026-02-12T00:10:18.033000",
          "tags": [
            "dugganusa",
            "automated",
            "feed-harvest",
            "urlhaus",
            "feodo",
            "sslbl",
            "openphish",
            "tor",
            "spamhaus",
            "ja3"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix-feed/v2",
            "https://urlhaus.abuse.ch",
            "https://feodotracker.abuse.ch",
            "https://sslbl.abuse.ch",
            "https://check.torproject.org",
            "https://www.spamhaus.org/drop"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Phishing",
              "display_name": "Phishing",
              "target": null
            },
            {
              "id": "Tor Exit Node",
              "display_name": "Tor Exit Node",
              "target": null
            },
            {
              "id": "Spamhaus DROP",
              "display_name": "Spamhaus DROP",
              "target": null
            },
            {
              "id": "2019-07-27 20:42:54",
              "display_name": "2019-07-27 20:42:54",
              "target": null
            },
            {
              "id": "2019-07-28 00:34:38",
              "display_name": "2019-07-28 00:34:38",
              "target": null
            },
            {
              "id": "2019-05-22 03:22:38",
              "display_name": "2019-05-22 03:22:38",
              "target": null
            },
            {
              "id": "2019-07-28 01:38:22",
              "display_name": "2019-07-28 01:38:22",
              "target": null
            },
            {
              "id": "2021-02-01 18:23:25",
              "display_name": "2021-02-01 18:23:25",
              "target": null
            },
            {
              "id": "2021-03-13 07:33:39",
              "display_name": "2021-03-13 07:33:39",
              "target": null
            },
            {
              "id": "2019-07-27 20:00:57",
              "display_name": "2019-07-27 20:00:57",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1566.002",
              "name": "Spearphishing Link",
              "display_name": "T1566.002 - Spearphishing Link"
            },
            {
              "id": "T1204.002",
              "name": "Malicious File",
              "display_name": "T1204.002 - Malicious File"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 100,
            "CIDR": 1483,
            "JA3": 97
          },
          "indicator_count": 1680,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "81 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "698d24f642fdc07d012e9670",
          "name": "DugganUSA Feed Harvest - 2026-02-12",
          "description": "Automated multi-source IOC harvest. Sources: openphish: 100, torExit: 500, spamhausDrop: 1483, ja3: 97. Race to 500K! \ud83d\ude80",
          "modified": "2026-03-14T00:35:30.399000",
          "created": "2026-02-12T00:55:18.725000",
          "tags": [
            "dugganusa",
            "automated",
            "feed-harvest",
            "urlhaus",
            "feodo",
            "sslbl",
            "openphish",
            "tor",
            "spamhaus",
            "ja3"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix-feed/v2",
            "https://urlhaus.abuse.ch",
            "https://feodotracker.abuse.ch",
            "https://sslbl.abuse.ch",
            "https://check.torproject.org",
            "https://www.spamhaus.org/drop"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Phishing",
              "display_name": "Phishing",
              "target": null
            },
            {
              "id": "Tor Exit Node",
              "display_name": "Tor Exit Node",
              "target": null
            },
            {
              "id": "Spamhaus DROP",
              "display_name": "Spamhaus DROP",
              "target": null
            },
            {
              "id": "2019-07-27 20:42:54",
              "display_name": "2019-07-27 20:42:54",
              "target": null
            },
            {
              "id": "2019-07-28 00:34:38",
              "display_name": "2019-07-28 00:34:38",
              "target": null
            },
            {
              "id": "2019-05-22 03:22:38",
              "display_name": "2019-05-22 03:22:38",
              "target": null
            },
            {
              "id": "2019-07-28 01:38:22",
              "display_name": "2019-07-28 01:38:22",
              "target": null
            },
            {
              "id": "2021-02-01 18:23:25",
              "display_name": "2021-02-01 18:23:25",
              "target": null
            },
            {
              "id": "2021-03-13 07:33:39",
              "display_name": "2021-03-13 07:33:39",
              "target": null
            },
            {
              "id": "2019-07-27 20:00:57",
              "display_name": "2019-07-27 20:00:57",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1566.002",
              "name": "Spearphishing Link",
              "display_name": "T1566.002 - Spearphishing Link"
            },
            {
              "id": "T1204.002",
              "name": "Malicious File",
              "display_name": "T1204.002 - Malicious File"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 100,
            "CIDR": 1483,
            "JA3": 97
          },
          "indicator_count": 1680,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "81 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "",
        "as15169",
        "https://analytics.dugganusa.com/api/v1/stix-feed/v2",
        "https://sslbl.abuse.ch",
        "https://urlhaus.abuse.ch",
        "https://check.torproject.org",
        "https://www.spamhaus.org/drop",
        "https://feodotracker.abuse.ch"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 0
        },
        "other": {
          "adversary": [
            "pi, pdfkit.net",
            "Adversary Profile: Salt Typhoon Alignment The architectural gap identified by mudoSO mirrors the act"
          ],
          "malware_families": [
            "2019-07-27 20:00:57",
            "2019-05-22 03:22:38",
            "2019-07-28 00:34:38",
            "Tor exit node",
            "2021-02-01 18:23:25",
            "Spamhaus drop",
            "2019-07-27 20:42:54",
            "2019-07-28 01:38:22",
            "2021-03-13 07:33:39",
            "Phishing"
          ],
          "industries": [],
          "unique_indicators": 21174
        }
      }
    },
    "false_positive": [],
    "alexa": "http://www.alexa.com/siteinfo/replit.app",
    "whois": "http://whois.domaintools.com/replit.app",
    "domain": "replit.app",
    "hostname": "solicita--tumundobhd.replit.app"
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 45,
  "pulses": [
    {
      "id": "69aeda93ec05fb8653adca6d",
      "name": "clone of my pulse. this dmv kit pdfkit.net used the same off logo kit it was one of the few i found in their fcc application   . rpi&macids look for",
      "description": "",
      "modified": "2026-04-08T00:00:45.252000",
      "created": "2026-03-09T14:34:59.072000",
      "tags": [
        "pfft.net"
      ],
      "references": [
        ""
      ],
      "public": 1,
      "adversary": "pi, pdfkit.net",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": "698c75717175e2cc7ff33df2",
      "export_count": 1,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 551,
        "domain": 638,
        "CVE": 114,
        "hostname": 449,
        "email": 28,
        "FileHash-MD5": 145,
        "FileHash-SHA1": 188,
        "FileHash-SHA256": 132,
        "Mutex": 1
      },
      "indicator_count": 2246,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 72,
      "modified_text": "56 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "698d30c03b57c38dff915023",
      "name": "Double Umbrella AS15169/AS21928: This evaluates a critical structural convergence between Google (AS15169) and T-Mobile USA (AS21928) within the global Tier-1 routing backbone",
      "description": "Research credit: msudosos, The research identifies a high-fidelity pattern where traffic from dual origins commingles within a restricted lateral transit hub, allowing for horizontal movement across backbone providers that typically maintain distinct trust boundaries. Specifically, the Content Origin (Umbrella A) originated by Google (AS15169) reaches the core backbone through a high-trust sequence involving Arelion (AS1299), NTT (AS2914), and GTT (AS3257). Simultaneously, the Mobile Origin (Umbrella B) originated by T-Mobile USA (AS21928) enters the backbone via Cogent (AS174) and Lumen (AS3356). The findings designate Lumen (AS3356) as the central lateral hub where traffic pivots horizontally between the \u201cCore Five\u201d partners-including Zayo (AS6461) and Hurricane Electric (AS6939) \u2014before leaking to international sub-transit peers like Sparkle (AS6762) and Telxius (AS12956), finally exiting at global edge points such as PCCW (AS3491) and Tata (AS6453).",
      "modified": "2026-03-29T06:02:00.914000",
      "created": "2026-02-12T01:45:36.128000",
      "tags": [
        "The dynamics of the mudoSOSIntersectalign with sophisticated adv"
      ],
      "references": [
        "as15169"
      ],
      "public": 1,
      "adversary": "Adversary Profile: Salt Typhoon Alignment The architectural gap identified by mudoSO mirrors the act",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 3,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URI": 1,
        "domain": 2661,
        "URL": 6810,
        "hostname": 2147,
        "email": 56,
        "FileHash-SHA256": 2781,
        "CVE": 172,
        "FileHash-MD5": 365,
        "FileHash-SHA1": 344,
        "IPv4": 1,
        "CIDR": 20940
      },
      "indicator_count": 36278,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 75,
      "modified_text": "66 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "698904c316bc7710b967d01d",
      "name": "Rare Tier 1 Persistence - Critical \"Patched\", Non Patched Vulnerabilities Remain bypassing Lockdown Mode",
      "description": "Researcher Note (Feb 08, 2026):\nThis artifact represents a sophisticated Cross-Protocol Mesh. Observations confirm that the Cymt/Nemucod wrapper is being utilized as a delivery vehicle for a Firmware-resident ELF binary (Mirai variant).\nThe persistence is notable for its ability to survive Full DFU Restores and Faraday-isolated states, likely due to JTAG-level interaction with the Power Management IC (Chip 4799). This is not a standard opportunistic infection; it is a targeted provisioning event leveraging IDMSA (Identity Management) bridges and Verizon/Akamai Edge infrastructure.\nThe integration with CalendarKit and Maps for geofenced execution suggests a highly coordinated surveillance objective. Forensic analysts should pay specific attention to the sizeofrawdata_antidbg anomalies, which indicate a focus on bypassing Apple Lockdown Mode and Secure Enclave. \nresearcher credit: msudoSOS",
      "modified": "2026-03-27T09:05:26.285000",
      "created": "2026-02-08T21:48:49.147000",
      "tags": [
        "#supportsitewebsiteabuse #rootcertificatefailure #cryptographicf"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 909,
        "URL": 1779,
        "CVE": 126,
        "domain": 659,
        "email": 23,
        "JA3": 1,
        "FileHash-MD5": 230,
        "FileHash-SHA1": 227,
        "FileHash-SHA256": 934,
        "CIDR": 13
      },
      "indicator_count": 4901,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 76,
      "modified_text": "68 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "698918baac756a084ef67089",
      "name": "151.101.0.22",
      "description": "151.101.0.22",
      "modified": "2026-03-27T00:30:39.055000",
      "created": "2026-02-08T23:13:59.775000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 317,
        "domain": 494,
        "URL": 286,
        "CVE": 78,
        "email": 33,
        "JA3": 1,
        "FileHash-MD5": 10,
        "FileHash-SHA1": 4,
        "FileHash-SHA256": 2
      },
      "indicator_count": 1225,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 75,
      "modified_text": "68 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "698c75717175e2cc7ff33df2",
      "name": "103.203.175.90 - Document and Domain Research Intersect, PDFKIT.NET DMV",
      "description": "http://103.203.175.90:81/fdScript/RootOfEBooks/E%20Book%20collection%20-%202024%20-%20D/CSE%20%20IT%20AIDS%20ML/Raspberry%20Pi%20linux-@Computer_IT_Engineering.pdf\n103.203.175.90",
      "modified": "2026-03-27T00:30:39.055000",
      "created": "2026-02-11T12:26:20.490000",
      "tags": [
        "pfft.net"
      ],
      "references": [
        ""
      ],
      "public": 1,
      "adversary": "pi, pdfkit.net",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 550,
        "domain": 638,
        "CVE": 113,
        "hostname": 445,
        "email": 28,
        "FileHash-MD5": 145,
        "FileHash-SHA1": 136,
        "FileHash-SHA256": 132,
        "Mutex": 1
      },
      "indicator_count": 2188,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 73,
      "modified_text": "68 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "698dbf957154d94be502baea",
      "name": "DugganUSA Feed Harvest - 2026-02-12",
      "description": "Automated multi-source IOC harvest. Sources: openphish: 100, torExit: 500, spamhausDrop: 1483, ja3: 97. Race to 500K! \ud83d\ude80",
      "modified": "2026-03-14T11:07:23.134000",
      "created": "2026-02-12T11:55:01.636000",
      "tags": [
        "dugganusa",
        "automated",
        "feed-harvest",
        "urlhaus",
        "feodo",
        "sslbl",
        "openphish",
        "tor",
        "spamhaus",
        "ja3"
      ],
      "references": [
        "https://analytics.dugganusa.com/api/v1/stix-feed/v2",
        "https://urlhaus.abuse.ch",
        "https://feodotracker.abuse.ch",
        "https://sslbl.abuse.ch",
        "https://check.torproject.org",
        "https://www.spamhaus.org/drop"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Phishing",
          "display_name": "Phishing",
          "target": null
        },
        {
          "id": "Tor Exit Node",
          "display_name": "Tor Exit Node",
          "target": null
        },
        {
          "id": "Spamhaus DROP",
          "display_name": "Spamhaus DROP",
          "target": null
        },
        {
          "id": "2019-07-27 20:42:54",
          "display_name": "2019-07-27 20:42:54",
          "target": null
        },
        {
          "id": "2019-07-28 00:34:38",
          "display_name": "2019-07-28 00:34:38",
          "target": null
        },
        {
          "id": "2019-05-22 03:22:38",
          "display_name": "2019-05-22 03:22:38",
          "target": null
        },
        {
          "id": "2019-07-28 01:38:22",
          "display_name": "2019-07-28 01:38:22",
          "target": null
        },
        {
          "id": "2021-02-01 18:23:25",
          "display_name": "2021-02-01 18:23:25",
          "target": null
        },
        {
          "id": "2021-03-13 07:33:39",
          "display_name": "2021-03-13 07:33:39",
          "target": null
        },
        {
          "id": "2019-07-27 20:00:57",
          "display_name": "2019-07-27 20:00:57",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1071.001",
          "name": "Web Protocols",
          "display_name": "T1071.001 - Web Protocols"
        },
        {
          "id": "T1566.002",
          "name": "Spearphishing Link",
          "display_name": "T1566.002 - Spearphishing Link"
        },
        {
          "id": "T1204.002",
          "name": "Malicious File",
          "display_name": "T1204.002 - Malicious File"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "pduggusa",
        "id": "371400",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 100,
        "CIDR": 1483,
        "JA3": 97
      },
      "indicator_count": 1680,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 197,
      "modified_text": "81 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "698dbc137123e33733fc82ef",
      "name": "DugganUSA Feed Harvest - 2026-02-12",
      "description": "Automated multi-source IOC harvest. Sources: openphish: 100, torExit: 500, spamhausDrop: 1483, ja3: 97. Race to 500K! \ud83d\ude80",
      "modified": "2026-03-14T11:07:23.134000",
      "created": "2026-02-12T11:40:03.651000",
      "tags": [
        "dugganusa",
        "automated",
        "feed-harvest",
        "urlhaus",
        "feodo",
        "sslbl",
        "openphish",
        "tor",
        "spamhaus",
        "ja3"
      ],
      "references": [
        "https://analytics.dugganusa.com/api/v1/stix-feed/v2",
        "https://urlhaus.abuse.ch",
        "https://feodotracker.abuse.ch",
        "https://sslbl.abuse.ch",
        "https://check.torproject.org",
        "https://www.spamhaus.org/drop"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Phishing",
          "display_name": "Phishing",
          "target": null
        },
        {
          "id": "Tor Exit Node",
          "display_name": "Tor Exit Node",
          "target": null
        },
        {
          "id": "Spamhaus DROP",
          "display_name": "Spamhaus DROP",
          "target": null
        },
        {
          "id": "2019-07-27 20:42:54",
          "display_name": "2019-07-27 20:42:54",
          "target": null
        },
        {
          "id": "2019-07-28 00:34:38",
          "display_name": "2019-07-28 00:34:38",
          "target": null
        },
        {
          "id": "2019-05-22 03:22:38",
          "display_name": "2019-05-22 03:22:38",
          "target": null
        },
        {
          "id": "2019-07-28 01:38:22",
          "display_name": "2019-07-28 01:38:22",
          "target": null
        },
        {
          "id": "2021-02-01 18:23:25",
          "display_name": "2021-02-01 18:23:25",
          "target": null
        },
        {
          "id": "2021-03-13 07:33:39",
          "display_name": "2021-03-13 07:33:39",
          "target": null
        },
        {
          "id": "2019-07-27 20:00:57",
          "display_name": "2019-07-27 20:00:57",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1071.001",
          "name": "Web Protocols",
          "display_name": "T1071.001 - Web Protocols"
        },
        {
          "id": "T1566.002",
          "name": "Spearphishing Link",
          "display_name": "T1566.002 - Spearphishing Link"
        },
        {
          "id": "T1204.002",
          "name": "Malicious File",
          "display_name": "T1204.002 - Malicious File"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "pduggusa",
        "id": "371400",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 100,
        "CIDR": 1483,
        "JA3": 97
      },
      "indicator_count": 1680,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 197,
      "modified_text": "81 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "698db89bf8fe655fa7b55d27",
      "name": "DugganUSA Feed Harvest - 2026-02-12",
      "description": "Automated multi-source IOC harvest. Sources: openphish: 100, torExit: 500, spamhausDrop: 1483, ja3: 97. Race to 500K! \ud83d\ude80",
      "modified": "2026-03-14T11:07:23.134000",
      "created": "2026-02-12T11:25:15.399000",
      "tags": [
        "dugganusa",
        "automated",
        "feed-harvest",
        "urlhaus",
        "feodo",
        "sslbl",
        "openphish",
        "tor",
        "spamhaus",
        "ja3"
      ],
      "references": [
        "https://analytics.dugganusa.com/api/v1/stix-feed/v2",
        "https://urlhaus.abuse.ch",
        "https://feodotracker.abuse.ch",
        "https://sslbl.abuse.ch",
        "https://check.torproject.org",
        "https://www.spamhaus.org/drop"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Phishing",
          "display_name": "Phishing",
          "target": null
        },
        {
          "id": "Tor Exit Node",
          "display_name": "Tor Exit Node",
          "target": null
        },
        {
          "id": "Spamhaus DROP",
          "display_name": "Spamhaus DROP",
          "target": null
        },
        {
          "id": "2019-07-27 20:42:54",
          "display_name": "2019-07-27 20:42:54",
          "target": null
        },
        {
          "id": "2019-07-28 00:34:38",
          "display_name": "2019-07-28 00:34:38",
          "target": null
        },
        {
          "id": "2019-05-22 03:22:38",
          "display_name": "2019-05-22 03:22:38",
          "target": null
        },
        {
          "id": "2019-07-28 01:38:22",
          "display_name": "2019-07-28 01:38:22",
          "target": null
        },
        {
          "id": "2021-02-01 18:23:25",
          "display_name": "2021-02-01 18:23:25",
          "target": null
        },
        {
          "id": "2021-03-13 07:33:39",
          "display_name": "2021-03-13 07:33:39",
          "target": null
        },
        {
          "id": "2019-07-27 20:00:57",
          "display_name": "2019-07-27 20:00:57",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1071.001",
          "name": "Web Protocols",
          "display_name": "T1071.001 - Web Protocols"
        },
        {
          "id": "T1566.002",
          "name": "Spearphishing Link",
          "display_name": "T1566.002 - Spearphishing Link"
        },
        {
          "id": "T1204.002",
          "name": "Malicious File",
          "display_name": "T1204.002 - Malicious File"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "pduggusa",
        "id": "371400",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 100,
        "CIDR": 1483,
        "JA3": 97
      },
      "indicator_count": 1680,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 197,
      "modified_text": "81 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "698db214ffdafd6a136c82d3",
      "name": "DugganUSA Feed Harvest - 2026-02-12",
      "description": "Automated multi-source IOC harvest. Sources: openphish: 100, torExit: 500, spamhausDrop: 1483, ja3: 97. Race to 500K! \ud83d\ude80",
      "modified": "2026-03-14T10:28:13.816000",
      "created": "2026-02-12T10:57:24.970000",
      "tags": [
        "dugganusa",
        "automated",
        "feed-harvest",
        "urlhaus",
        "feodo",
        "sslbl",
        "openphish",
        "tor",
        "spamhaus",
        "ja3"
      ],
      "references": [
        "https://analytics.dugganusa.com/api/v1/stix-feed/v2",
        "https://urlhaus.abuse.ch",
        "https://feodotracker.abuse.ch",
        "https://sslbl.abuse.ch",
        "https://check.torproject.org",
        "https://www.spamhaus.org/drop"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Phishing",
          "display_name": "Phishing",
          "target": null
        },
        {
          "id": "Tor Exit Node",
          "display_name": "Tor Exit Node",
          "target": null
        },
        {
          "id": "Spamhaus DROP",
          "display_name": "Spamhaus DROP",
          "target": null
        },
        {
          "id": "2019-07-27 20:42:54",
          "display_name": "2019-07-27 20:42:54",
          "target": null
        },
        {
          "id": "2019-07-28 00:34:38",
          "display_name": "2019-07-28 00:34:38",
          "target": null
        },
        {
          "id": "2019-05-22 03:22:38",
          "display_name": "2019-05-22 03:22:38",
          "target": null
        },
        {
          "id": "2019-07-28 01:38:22",
          "display_name": "2019-07-28 01:38:22",
          "target": null
        },
        {
          "id": "2021-02-01 18:23:25",
          "display_name": "2021-02-01 18:23:25",
          "target": null
        },
        {
          "id": "2021-03-13 07:33:39",
          "display_name": "2021-03-13 07:33:39",
          "target": null
        },
        {
          "id": "2019-07-27 20:00:57",
          "display_name": "2019-07-27 20:00:57",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1071.001",
          "name": "Web Protocols",
          "display_name": "T1071.001 - Web Protocols"
        },
        {
          "id": "T1566.002",
          "name": "Spearphishing Link",
          "display_name": "T1566.002 - Spearphishing Link"
        },
        {
          "id": "T1204.002",
          "name": "Malicious File",
          "display_name": "T1204.002 - Malicious File"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "pduggusa",
        "id": "371400",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 100,
        "CIDR": 1483,
        "JA3": 97
      },
      "indicator_count": 1680,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 197,
      "modified_text": "81 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "698dae1c8759b3a8a8f73702",
      "name": "DugganUSA Feed Harvest - 2026-02-12",
      "description": "Automated multi-source IOC harvest. Sources: openphish: 100, torExit: 500, spamhausDrop: 1483, ja3: 97. Race to 500K! \ud83d\ude80",
      "modified": "2026-03-14T10:28:13.816000",
      "created": "2026-02-12T10:40:28.705000",
      "tags": [
        "dugganusa",
        "automated",
        "feed-harvest",
        "urlhaus",
        "feodo",
        "sslbl",
        "openphish",
        "tor",
        "spamhaus",
        "ja3"
      ],
      "references": [
        "https://analytics.dugganusa.com/api/v1/stix-feed/v2",
        "https://urlhaus.abuse.ch",
        "https://feodotracker.abuse.ch",
        "https://sslbl.abuse.ch",
        "https://check.torproject.org",
        "https://www.spamhaus.org/drop"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Phishing",
          "display_name": "Phishing",
          "target": null
        },
        {
          "id": "Tor Exit Node",
          "display_name": "Tor Exit Node",
          "target": null
        },
        {
          "id": "Spamhaus DROP",
          "display_name": "Spamhaus DROP",
          "target": null
        },
        {
          "id": "2019-07-27 20:42:54",
          "display_name": "2019-07-27 20:42:54",
          "target": null
        },
        {
          "id": "2019-07-28 00:34:38",
          "display_name": "2019-07-28 00:34:38",
          "target": null
        },
        {
          "id": "2019-05-22 03:22:38",
          "display_name": "2019-05-22 03:22:38",
          "target": null
        },
        {
          "id": "2019-07-28 01:38:22",
          "display_name": "2019-07-28 01:38:22",
          "target": null
        },
        {
          "id": "2021-02-01 18:23:25",
          "display_name": "2021-02-01 18:23:25",
          "target": null
        },
        {
          "id": "2021-03-13 07:33:39",
          "display_name": "2021-03-13 07:33:39",
          "target": null
        },
        {
          "id": "2019-07-27 20:00:57",
          "display_name": "2019-07-27 20:00:57",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1071.001",
          "name": "Web Protocols",
          "display_name": "T1071.001 - Web Protocols"
        },
        {
          "id": "T1566.002",
          "name": "Spearphishing Link",
          "display_name": "T1566.002 - Spearphishing Link"
        },
        {
          "id": "T1204.002",
          "name": "Malicious File",
          "display_name": "T1204.002 - Malicious File"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "pduggusa",
        "id": "371400",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 100,
        "CIDR": 1483,
        "JA3": 97
      },
      "indicator_count": 1680,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 197,
      "modified_text": "81 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "https://solicita--tumundobhd.replit.app/login.php",
    "type": "URL"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "https://solicita--tumundobhd.replit.app/login.php",
    "type": "URL",
    "found": false,
    "verdict": "clean",
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780499291.2305965
}