{
  "type": "URL",
  "indicator": "https://sotavpn.shop/",
  "general": {
    "sections": [
      "general",
      "url_list",
      "http_scans",
      "screenshot"
    ],
    "indicator": "https://sotavpn.shop/",
    "type": "url",
    "type_title": "URL",
    "validation": [],
    "base_indicator": {
      "id": 4162002916,
      "indicator": "https://sotavpn.shop/",
      "type": "URL",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 50,
      "pulses": [
        {
          "id": "691b8869e00b107fa20d9482",
          "name": "ThreatFix",
          "description": "ThreatFix is an effort to publish various details about ransomware variants and ransomware threat actors. ThreatFix advisories include recently and historically observed tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) to help organizations protect against ransomware.",
          "modified": "2026-01-23T11:01:07.175000",
          "created": "2025-11-17T20:41:11.797000",
          "tags": [
            "",
            "ransomware",
            "malware"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "",
              "display_name": "",
              "target": null
            }
          ],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 8,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "zlepos384",
            "id": "103244",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 8010,
            "FileHash-SHA1": 7922,
            "FileHash-SHA256": 8893,
            "URL": 57004,
            "domain": 36018,
            "hostname": 96473
          },
          "indicator_count": 214320,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 44,
          "modified_text": "131 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6940da7bdf2d8820aa512eeb",
          "name": "ThreatFox Hunt: Unknown malware IOCs - 2025-12-16",
          "description": "Automated ThreatFox hunt for Unknown malware indicators. 82 IOCs collected. Pattern 49 automated intelligence streaming. Reference: https://analytics.dugganusa.com",
          "modified": "2026-01-15T04:02:04.203000",
          "created": "2025-12-16T04:05:15.894000",
          "tags": [
            "unknown-malware",
            "threatfox",
            "automated-hunt",
            "pattern-49",
            "dugganusa"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 41,
            "domain": 21
          },
          "indicator_count": 62,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "139 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6940cc6a934a78b87aa1c698",
          "name": "ThreatFox Hunt: Unknown malware IOCs - 2025-12-16",
          "description": "Automated ThreatFox hunt for Unknown malware indicators. 82 IOCs collected. Pattern 49 automated intelligence streaming. Reference: https://analytics.dugganusa.com",
          "modified": "2026-01-15T03:02:44.177000",
          "created": "2025-12-16T03:05:14.945000",
          "tags": [
            "unknown-malware",
            "threatfox",
            "automated-hunt",
            "pattern-49",
            "dugganusa"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 41,
            "domain": 21
          },
          "indicator_count": 62,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "139 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6940b04e45348b7d765601f9",
          "name": "ThreatFox Hunt: Unknown malware IOCs - 2025-12-16",
          "description": "Automated ThreatFox hunt for Unknown malware indicators. 83 IOCs collected. Pattern 49 automated intelligence streaming. Reference: https://analytics.dugganusa.com",
          "modified": "2026-01-15T01:02:47.757000",
          "created": "2025-12-16T01:05:18.326000",
          "tags": [
            "unknown-malware",
            "threatfox",
            "automated-hunt",
            "pattern-49",
            "dugganusa"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 42,
            "domain": 21
          },
          "indicator_count": 63,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "139 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6940942a20d6f2297254f032",
          "name": "ThreatFox Hunt: Unknown malware IOCs - 2025-12-15",
          "description": "Automated ThreatFox hunt for Unknown malware indicators. 84 IOCs collected. Pattern 49 automated intelligence streaming. Reference: https://analytics.dugganusa.com",
          "modified": "2026-01-14T23:02:12.860000",
          "created": "2025-12-15T23:05:14.974000",
          "tags": [
            "unknown-malware",
            "threatfox",
            "automated-hunt",
            "pattern-49",
            "dugganusa"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 42,
            "domain": 21
          },
          "indicator_count": 63,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "139 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6940861cf4fc04cf328f7574",
          "name": "ThreatFox Hunt: Unknown malware IOCs - 2025-12-15",
          "description": "Automated ThreatFox hunt for Unknown malware indicators. 84 IOCs collected. Pattern 49 automated intelligence streaming. Reference: https://analytics.dugganusa.com",
          "modified": "2026-01-14T22:00:56.245000",
          "created": "2025-12-15T22:05:16.666000",
          "tags": [
            "unknown-malware",
            "threatfox",
            "automated-hunt",
            "pattern-49",
            "dugganusa"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 42,
            "domain": 21
          },
          "indicator_count": 63,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "140 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6940781f7f7aeec6359f750f",
          "name": "ThreatFox Hunt: Unknown malware IOCs - 2025-12-15",
          "description": "Automated ThreatFox hunt for Unknown malware indicators. 84 IOCs collected. Pattern 49 automated intelligence streaming. Reference: https://analytics.dugganusa.com",
          "modified": "2026-01-14T21:05:02.119000",
          "created": "2025-12-15T21:05:35.904000",
          "tags": [
            "unknown-malware",
            "threatfox",
            "automated-hunt",
            "pattern-49",
            "dugganusa"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 42,
            "domain": 21
          },
          "indicator_count": 63,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "140 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "693fb32fdcfa1b3ba2565caa",
          "name": "ThreatFox Hunt: Unknown malware IOCs - 2025-12-15",
          "description": "Automated ThreatFox hunt for Unknown malware indicators. 49 IOCs collected. Pattern 49 automated intelligence streaming. Reference: https://analytics.dugganusa.com",
          "modified": "2026-01-14T07:02:35.106000",
          "created": "2025-12-15T07:05:19.762000",
          "tags": [
            "unknown-malware",
            "threatfox",
            "automated-hunt",
            "pattern-49",
            "dugganusa"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 21,
            "domain": 3,
            "hostname": 1
          },
          "indicator_count": 25,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "140 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "693eab71f5e5a6f11f64ad92",
          "name": "OSINT Volley 2025-12-14 - Cobalt Strike/ClearFake/Unknown malware",
          "description": "Automated OSINT sweep from ThreatFox. Top malware: Cobalt Strike(196), ClearFake(146), Unknown malware(32), Quasar RAT(31), DeimosC2(27). Source: abuse.ch ThreatFox API. Pattern 54: sweep\u2192volley automation.",
          "modified": "2026-01-13T12:00:06.383000",
          "created": "2025-12-14T12:20:01.601000",
          "tags": [
            "osint-volley",
            "threatfox",
            "automated",
            "cobalt-strike",
            "clearfake",
            "unknown-malware"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 111,
            "URL": 14,
            "domain": 10,
            "FileHash-SHA256": 1
          },
          "indicator_count": 136,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "141 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "693e9d624fa39e41bfc7e311",
          "name": "OSINT Volley 2025-12-14 - Cobalt Strike/ClearFake/Unknown malware",
          "description": "Automated OSINT sweep from ThreatFox. Top malware: Cobalt Strike(194), ClearFake(146), Unknown malware(35), Quasar RAT(30), DeimosC2(27). Source: abuse.ch ThreatFox API. Pattern 54: sweep\u2192volley automation.",
          "modified": "2026-01-13T11:02:44.341000",
          "created": "2025-12-14T11:20:02.174000",
          "tags": [
            "osint-volley",
            "threatfox",
            "automated",
            "cobalt-strike",
            "clearfake",
            "unknown-malware"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 101,
            "domain": 11,
            "URL": 11,
            "FileHash-SHA256": 1
          },
          "indicator_count": 124,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "141 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "693e8f563bf45e9781c8f077",
          "name": "OSINT Volley 2025-12-14 - Cobalt Strike/ClearFake/Unknown malware",
          "description": "Automated OSINT sweep from ThreatFox. Top malware: Cobalt Strike(193), ClearFake(146), Unknown malware(31), Quasar RAT(29), DeimosC2(27). Source: abuse.ch ThreatFox API. Pattern 54: sweep\u2192volley automation.",
          "modified": "2026-01-13T10:05:29.602000",
          "created": "2025-12-14T10:20:06.535000",
          "tags": [
            "osint-volley",
            "threatfox",
            "automated",
            "cobalt-strike",
            "clearfake",
            "unknown-malware"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 95,
            "domain": 11,
            "URL": 11,
            "FileHash-SHA256": 1
          },
          "indicator_count": 118,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "141 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "693e81415c5fe80081daa9e9",
          "name": "OSINT Volley 2025-12-14 - Cobalt Strike/ClearFake/Unknown malware",
          "description": "Automated OSINT sweep from ThreatFox. Top malware: Cobalt Strike(193), ClearFake(147), Unknown malware(31), Quasar RAT(29), DeimosC2(27). Source: abuse.ch ThreatFox API. Pattern 54: sweep\u2192volley automation.",
          "modified": "2026-01-13T09:01:11.785000",
          "created": "2025-12-14T09:20:01.446000",
          "tags": [
            "osint-volley",
            "threatfox",
            "automated",
            "cobalt-strike",
            "clearfake",
            "unknown-malware"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 3,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 89,
            "domain": 11,
            "URL": 11,
            "FileHash-SHA256": 1
          },
          "indicator_count": 112,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "141 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "693e7332b331c42eaabdb77b",
          "name": "OSINT Volley 2025-12-14 - Cobalt Strike/ClearFake/Unknown malware",
          "description": "Automated OSINT sweep from ThreatFox. Top malware: Cobalt Strike(194), ClearFake(149), Unknown malware(31), Quasar RAT(29), DeimosC2(27). Source: abuse.ch ThreatFox API. Pattern 54: sweep\u2192volley automation.",
          "modified": "2026-01-13T08:01:04.151000",
          "created": "2025-12-14T08:20:02.078000",
          "tags": [
            "osint-volley",
            "threatfox",
            "automated",
            "cobalt-strike",
            "clearfake",
            "unknown-malware"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 3,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 83,
            "domain": 11,
            "URL": 11,
            "FileHash-SHA256": 1
          },
          "indicator_count": 106,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "141 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "693e652278e89e65295ee669",
          "name": "OSINT Volley 2025-12-14 - Cobalt Strike/ClearFake/Unknown malware",
          "description": "Automated OSINT sweep from ThreatFox. Top malware: Cobalt Strike(207), ClearFake(149), Unknown malware(30), Quasar RAT(29), DeimosC2(27). Source: abuse.ch ThreatFox API. Pattern 54: sweep\u2192volley automation.",
          "modified": "2026-01-13T07:01:02.072000",
          "created": "2025-12-14T07:20:02.284000",
          "tags": [
            "osint-volley",
            "threatfox",
            "automated",
            "cobalt-strike",
            "clearfake",
            "unknown-malware"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 3,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 76,
            "domain": 10,
            "URL": 6,
            "FileHash-SHA256": 1
          },
          "indicator_count": 93,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "141 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "693e5711aaefa031697a677c",
          "name": "OSINT Volley 2025-12-14 - Cobalt Strike/ClearFake/Unknown malware",
          "description": "Automated OSINT sweep from ThreatFox. Top malware: Cobalt Strike(207), ClearFake(150), Unknown malware(30), Quasar RAT(29), DeimosC2(27). Source: abuse.ch ThreatFox API. Pattern 54: sweep\u2192volley automation.",
          "modified": "2026-01-13T06:02:38.934000",
          "created": "2025-12-14T06:20:01.415000",
          "tags": [
            "osint-volley",
            "threatfox",
            "automated",
            "cobalt-strike",
            "clearfake",
            "unknown-malware"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 3,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 69,
            "domain": 5,
            "URL": 5,
            "FileHash-SHA256": 1
          },
          "indicator_count": 80,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "141 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "693e3af12efc4823a3b0b0fd",
          "name": "OSINT Volley 2025-12-14 - Cobalt Strike/ClearFake/Unknown malware",
          "description": "Automated OSINT sweep from ThreatFox. Top malware: Cobalt Strike(231), ClearFake(150), Unknown malware(36), Quasar RAT(29), DeimosC2(27). Source: abuse.ch ThreatFox API. Pattern 54: sweep\u2192volley automation.",
          "modified": "2026-01-13T04:01:05.192000",
          "created": "2025-12-14T04:20:01.546000",
          "tags": [
            "osint-volley",
            "threatfox",
            "automated",
            "cobalt-strike",
            "clearfake",
            "unknown-malware"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 4,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 55,
            "domain": 5,
            "URL": 2
          },
          "indicator_count": 62,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "141 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "693e2ce2358f69ba705da59b",
          "name": "OSINT Volley 2025-12-14 - Cobalt Strike/ClearFake/Unknown malware",
          "description": "Automated OSINT sweep from ThreatFox. Top malware: Cobalt Strike(228), ClearFake(150), Unknown malware(36), Meterpreter(36), Quasar RAT(29). Source: abuse.ch ThreatFox API. Pattern 54: sweep\u2192volley automation.",
          "modified": "2026-01-13T03:04:43.902000",
          "created": "2025-12-14T03:20:02.611000",
          "tags": [
            "osint-volley",
            "threatfox",
            "automated",
            "cobalt-strike",
            "clearfake",
            "unknown-malware"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 4,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 49,
            "domain": 5,
            "URL": 2
          },
          "indicator_count": 56,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "141 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "693e1ed11983bb19f30aa373",
          "name": "OSINT Volley 2025-12-14 - Cobalt Strike/ClearFake/Unknown malware",
          "description": "Automated OSINT sweep from ThreatFox. Top malware: Cobalt Strike(226), ClearFake(150), Unknown malware(36), Meterpreter(36), Quasar RAT(29). Source: abuse.ch ThreatFox API. Pattern 54: sweep\u2192volley automation.",
          "modified": "2026-01-13T02:04:32.094000",
          "created": "2025-12-14T02:20:01.989000",
          "tags": [
            "osint-volley",
            "threatfox",
            "automated",
            "cobalt-strike",
            "clearfake",
            "unknown-malware"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 5,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 41,
            "URL": 2,
            "domain": 2
          },
          "indicator_count": 45,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "141 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "693e10c144c7c915ce95111b",
          "name": "OSINT Volley 2025-12-14 - Cobalt Strike/ClearFake/Meterpreter",
          "description": "Automated OSINT sweep from ThreatFox. Top malware: Cobalt Strike(226), ClearFake(150), Meterpreter(36), Unknown malware(35), Quasar RAT(29). Source: abuse.ch ThreatFox API. Pattern 54: sweep\u2192volley automation.",
          "modified": "2026-01-13T01:02:59.421000",
          "created": "2025-12-14T01:20:01.862000",
          "tags": [
            "osint-volley",
            "threatfox",
            "automated",
            "cobalt-strike",
            "clearfake",
            "meterpreter"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 35,
            "domain": 2,
            "URL": 1
          },
          "indicator_count": 38,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "141 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "693df4a250a25c30ea45a20c",
          "name": "OSINT Volley 2025-12-13 - Cobalt Strike/ClearFake/Unknown malware",
          "description": "Automated OSINT sweep from ThreatFox. Top malware: Cobalt Strike(226), ClearFake(150), Unknown malware(35), Meterpreter(35), Quasar RAT(29). Source: abuse.ch ThreatFox API. Pattern 54: sweep\u2192volley automation.",
          "modified": "2026-01-12T23:00:15.739000",
          "created": "2025-12-13T23:20:02.453000",
          "tags": [
            "osint-volley",
            "threatfox",
            "automated",
            "cobalt-strike",
            "clearfake",
            "unknown-malware"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 23,
            "domain": 2,
            "URL": 1
          },
          "indicator_count": 26,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "141 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "693de6927d333ea1e40e8d36",
          "name": "OSINT Volley 2025-12-13 - Cobalt Strike/ClearFake/Meterpreter",
          "description": "Automated OSINT sweep from ThreatFox. Top malware: Cobalt Strike(202), ClearFake(149), Meterpreter(35), Quasar RAT(28), DeimosC2(27). Source: abuse.ch ThreatFox API. Pattern 54: sweep\u2192volley automation.",
          "modified": "2026-01-12T22:01:57.329000",
          "created": "2025-12-13T22:20:02.858000",
          "tags": [
            "osint-volley",
            "threatfox",
            "automated",
            "cobalt-strike",
            "clearfake",
            "meterpreter"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 15,
            "URL": 1,
            "domain": 1
          },
          "indicator_count": 17,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "142 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "693dd881d780f794864fa9a4",
          "name": "OSINT Volley 2025-12-13 - Cobalt Strike/ClearFake/Meterpreter",
          "description": "Automated OSINT sweep from ThreatFox. Top malware: Cobalt Strike(202), ClearFake(150), Meterpreter(35), Quasar RAT(28), Unknown malware(27). Source: abuse.ch ThreatFox API. Pattern 54: sweep\u2192volley automation.",
          "modified": "2026-01-12T21:02:35.560000",
          "created": "2025-12-13T21:20:01.840000",
          "tags": [
            "osint-volley",
            "threatfox",
            "automated",
            "cobalt-strike",
            "clearfake",
            "meterpreter"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 9,
            "URL": 1,
            "domain": 1
          },
          "indicator_count": 11,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "142 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "693f174ed371663fd493276c",
          "name": "PreCog Sweep - 2025-12-14 20h",
          "description": "Novel threat indicators detected by PreCog Sweep Engine",
          "modified": "2025-12-14T20:00:14.559000",
          "created": "2025-12-14T20:00:14.559000",
          "tags": [
            "precog",
            "automated",
            "novel-ioc",
            "c2",
            "malware"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix/master",
            "https://github.com/pduggusa/dugganusa-research"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 349,
            "URL": 19,
            "domain": 55
          },
          "indicator_count": 423,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "171 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "693f14f73d5a9045e49379f5",
          "name": "PreCog Sweep - 2025-12-14 19h",
          "description": "Novel threat indicators detected by PreCog Sweep Engine",
          "modified": "2025-12-14T19:50:15.243000",
          "created": "2025-12-14T19:50:15.243000",
          "tags": [
            "precog",
            "automated",
            "novel-ioc",
            "c2",
            "malware"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix/master",
            "https://github.com/pduggusa/dugganusa-research"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 348,
            "URL": 19,
            "domain": 55
          },
          "indicator_count": 422,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "171 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "693f129dd384eb3cbe9ca641",
          "name": "PreCog Sweep - 2025-12-14 19h",
          "description": "Novel threat indicators detected by PreCog Sweep Engine",
          "modified": "2025-12-14T19:40:13.942000",
          "created": "2025-12-14T19:40:13.942000",
          "tags": [
            "precog",
            "automated",
            "novel-ioc",
            "c2",
            "malware"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix/master",
            "https://github.com/pduggusa/dugganusa-research"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 353,
            "URL": 15,
            "domain": 55
          },
          "indicator_count": 423,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "171 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "693f10489e745491bd532355",
          "name": "PreCog Sweep - 2025-12-14 19h",
          "description": "Novel threat indicators detected by PreCog Sweep Engine",
          "modified": "2025-12-14T19:30:16.002000",
          "created": "2025-12-14T19:30:16.002000",
          "tags": [
            "precog",
            "automated",
            "novel-ioc",
            "c2",
            "malware"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix/master",
            "https://github.com/pduggusa/dugganusa-research"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 353,
            "URL": 15,
            "domain": 55
          },
          "indicator_count": 423,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "171 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "693f0dee7c852451393ffe66",
          "name": "PreCog Sweep - 2025-12-14 19h",
          "description": "Novel threat indicators detected by PreCog Sweep Engine",
          "modified": "2025-12-14T19:20:14.916000",
          "created": "2025-12-14T19:20:14.916000",
          "tags": [
            "precog",
            "automated",
            "novel-ioc",
            "c2",
            "malware"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix/master",
            "https://github.com/pduggusa/dugganusa-research"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 352,
            "URL": 15,
            "domain": 55
          },
          "indicator_count": 422,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "171 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "693f0b965e52de53886b8485",
          "name": "PreCog Sweep - 2025-12-14 19h",
          "description": "Novel threat indicators detected by PreCog Sweep Engine",
          "modified": "2025-12-14T19:10:14.448000",
          "created": "2025-12-14T19:10:14.448000",
          "tags": [
            "precog",
            "automated",
            "novel-ioc",
            "c2",
            "malware"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix/master",
            "https://github.com/pduggusa/dugganusa-research"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 351,
            "URL": 15,
            "domain": 55
          },
          "indicator_count": 421,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "171 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "693f093f1e9eac7939467b9c",
          "name": "PreCog Sweep - 2025-12-14 19h",
          "description": "Novel threat indicators detected by PreCog Sweep Engine",
          "modified": "2025-12-14T19:00:15.482000",
          "created": "2025-12-14T19:00:15.482000",
          "tags": [
            "precog",
            "automated",
            "novel-ioc",
            "c2",
            "malware"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix/master",
            "https://github.com/pduggusa/dugganusa-research"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 350,
            "URL": 14,
            "domain": 55
          },
          "indicator_count": 419,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "171 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "693f06e5a9e60f2118d6458f",
          "name": "PreCog Sweep - 2025-12-14 18h",
          "description": "Novel threat indicators detected by PreCog Sweep Engine",
          "modified": "2025-12-14T18:50:13.966000",
          "created": "2025-12-14T18:50:13.966000",
          "tags": [
            "precog",
            "automated",
            "novel-ioc",
            "c2",
            "malware"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix/master",
            "https://github.com/pduggusa/dugganusa-research"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 349,
            "URL": 14,
            "domain": 55
          },
          "indicator_count": 418,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "171 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "693f048f4190e9b7a338f7dc",
          "name": "PreCog Sweep - 2025-12-14 18h",
          "description": "Novel threat indicators detected by PreCog Sweep Engine",
          "modified": "2025-12-14T18:40:15.060000",
          "created": "2025-12-14T18:40:15.060000",
          "tags": [
            "precog",
            "automated",
            "novel-ioc",
            "c2",
            "malware"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix/master",
            "https://github.com/pduggusa/dugganusa-research"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 351,
            "URL": 14,
            "domain": 55
          },
          "indicator_count": 420,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "171 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "693f0237e2c343043abf45cb",
          "name": "PreCog Sweep - 2025-12-14 18h",
          "description": "Novel threat indicators detected by PreCog Sweep Engine",
          "modified": "2025-12-14T18:30:15.971000",
          "created": "2025-12-14T18:30:15.971000",
          "tags": [
            "precog",
            "automated",
            "novel-ioc",
            "c2",
            "malware"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix/master",
            "https://github.com/pduggusa/dugganusa-research"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 351,
            "URL": 14,
            "domain": 55
          },
          "indicator_count": 420,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "171 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "693effde1d3d45d2fb806dab",
          "name": "PreCog Sweep - 2025-12-14 18h",
          "description": "Novel threat indicators detected by PreCog Sweep Engine",
          "modified": "2025-12-14T18:20:14.697000",
          "created": "2025-12-14T18:20:14.697000",
          "tags": [
            "precog",
            "automated",
            "novel-ioc",
            "c2",
            "malware"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix/master",
            "https://github.com/pduggusa/dugganusa-research"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 351,
            "URL": 14,
            "domain": 55
          },
          "indicator_count": 420,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "171 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "693efd87952f0110ca966b81",
          "name": "PreCog Sweep - 2025-12-14 18h",
          "description": "Novel threat indicators detected by PreCog Sweep Engine",
          "modified": "2025-12-14T18:10:15.467000",
          "created": "2025-12-14T18:10:15.467000",
          "tags": [
            "precog",
            "automated",
            "novel-ioc",
            "c2",
            "malware"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix/master",
            "https://github.com/pduggusa/dugganusa-research"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 351,
            "URL": 14,
            "domain": 55
          },
          "indicator_count": 420,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "171 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "693efb30fdb70578cd333a45",
          "name": "PreCog Sweep - 2025-12-14 18h",
          "description": "Novel threat indicators detected by PreCog Sweep Engine",
          "modified": "2025-12-14T18:00:16.214000",
          "created": "2025-12-14T18:00:16.214000",
          "tags": [
            "precog",
            "automated",
            "novel-ioc",
            "c2",
            "malware"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix/master",
            "https://github.com/pduggusa/dugganusa-research"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 352,
            "URL": 15,
            "domain": 55
          },
          "indicator_count": 422,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "171 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "693ef8d7730e17b3ece26943",
          "name": "PreCog Sweep - 2025-12-14 17h",
          "description": "Novel threat indicators detected by PreCog Sweep Engine",
          "modified": "2025-12-14T17:50:15.011000",
          "created": "2025-12-14T17:50:15.011000",
          "tags": [
            "precog",
            "automated",
            "novel-ioc",
            "c2",
            "malware"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix/master",
            "https://github.com/pduggusa/dugganusa-research"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 352,
            "URL": 15,
            "domain": 55
          },
          "indicator_count": 422,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "171 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "693ef67f67fd7e57677ad6cf",
          "name": "PreCog Sweep - 2025-12-14 17h",
          "description": "Novel threat indicators detected by PreCog Sweep Engine",
          "modified": "2025-12-14T17:40:15.008000",
          "created": "2025-12-14T17:40:15.008000",
          "tags": [
            "precog",
            "automated",
            "novel-ioc",
            "c2",
            "malware"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix/master",
            "https://github.com/pduggusa/dugganusa-research"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 353,
            "URL": 15,
            "domain": 55
          },
          "indicator_count": 423,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "171 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "693ef4262bde9376dfed4bdc",
          "name": "PreCog Sweep - 2025-12-14 17h",
          "description": "Novel threat indicators detected by PreCog Sweep Engine",
          "modified": "2025-12-14T17:30:14.649000",
          "created": "2025-12-14T17:30:14.649000",
          "tags": [
            "precog",
            "automated",
            "novel-ioc",
            "c2",
            "malware"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix/master",
            "https://github.com/pduggusa/dugganusa-research"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 353,
            "URL": 15,
            "domain": 55
          },
          "indicator_count": 423,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "171 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "693ef1ce17cfd5ff4eeff90c",
          "name": "PreCog Sweep - 2025-12-14 17h",
          "description": "Novel threat indicators detected by PreCog Sweep Engine",
          "modified": "2025-12-14T17:20:14.349000",
          "created": "2025-12-14T17:20:14.349000",
          "tags": [
            "precog",
            "automated",
            "novel-ioc",
            "c2",
            "malware"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix/master",
            "https://github.com/pduggusa/dugganusa-research"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 353,
            "URL": 15,
            "domain": 55
          },
          "indicator_count": 423,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "171 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "693eef7601554cd4c9a45ac4",
          "name": "PreCog Sweep - 2025-12-14 17h",
          "description": "Novel threat indicators detected by PreCog Sweep Engine",
          "modified": "2025-12-14T17:10:14.426000",
          "created": "2025-12-14T17:10:14.426000",
          "tags": [
            "precog",
            "automated",
            "novel-ioc",
            "c2",
            "malware"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix/master",
            "https://github.com/pduggusa/dugganusa-research"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 353,
            "URL": 15,
            "domain": 55
          },
          "indicator_count": 423,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "171 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "693eed1f142cea3fe260eb14",
          "name": "PreCog Sweep - 2025-12-14 17h",
          "description": "Novel threat indicators detected by PreCog Sweep Engine",
          "modified": "2025-12-14T17:00:15.130000",
          "created": "2025-12-14T17:00:15.130000",
          "tags": [
            "precog",
            "automated",
            "novel-ioc",
            "c2",
            "malware"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix/master",
            "https://github.com/pduggusa/dugganusa-research"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 353,
            "URL": 15,
            "domain": 55
          },
          "indicator_count": 423,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "171 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "693eeac559c1ad86f82298e0",
          "name": "PreCog Sweep - 2025-12-14 16h",
          "description": "Novel threat indicators detected by PreCog Sweep Engine",
          "modified": "2025-12-14T16:50:13.782000",
          "created": "2025-12-14T16:50:13.782000",
          "tags": [
            "precog",
            "automated",
            "novel-ioc",
            "c2",
            "malware"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix/master",
            "https://github.com/pduggusa/dugganusa-research"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 348,
            "URL": 15,
            "domain": 55
          },
          "indicator_count": 418,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "171 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "693ee86d07f7174997235c4f",
          "name": "PreCog Sweep - 2025-12-14 16h",
          "description": "Novel threat indicators detected by PreCog Sweep Engine",
          "modified": "2025-12-14T16:40:13.584000",
          "created": "2025-12-14T16:40:13.584000",
          "tags": [
            "precog",
            "automated",
            "novel-ioc",
            "c2",
            "malware"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix/master",
            "https://github.com/pduggusa/dugganusa-research"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 341,
            "URL": 15,
            "domain": 55
          },
          "indicator_count": 411,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "171 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "693ee6166f8315b876bde668",
          "name": "PreCog Sweep - 2025-12-14 16h",
          "description": "Novel threat indicators detected by PreCog Sweep Engine",
          "modified": "2025-12-14T16:30:14.290000",
          "created": "2025-12-14T16:30:14.290000",
          "tags": [
            "precog",
            "automated",
            "novel-ioc",
            "c2",
            "malware"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix/master",
            "https://github.com/pduggusa/dugganusa-research"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 315,
            "URL": 15,
            "domain": 56
          },
          "indicator_count": 386,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "171 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "693ee3bfff05d86149f147c8",
          "name": "PreCog Sweep - 2025-12-14 16h",
          "description": "Novel threat indicators detected by PreCog Sweep Engine",
          "modified": "2025-12-14T16:20:15.079000",
          "created": "2025-12-14T16:20:15.079000",
          "tags": [
            "precog",
            "automated",
            "novel-ioc",
            "c2",
            "malware"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix/master",
            "https://github.com/pduggusa/dugganusa-research"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 296,
            "URL": 15,
            "domain": 56
          },
          "indicator_count": 367,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "171 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "693ee1666564c3eb1870f853",
          "name": "PreCog Sweep - 2025-12-14 16h",
          "description": "Novel threat indicators detected by PreCog Sweep Engine",
          "modified": "2025-12-14T16:10:14.153000",
          "created": "2025-12-14T16:10:14.153000",
          "tags": [
            "precog",
            "automated",
            "novel-ioc",
            "c2",
            "malware"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix/master",
            "https://github.com/pduggusa/dugganusa-research"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 295,
            "URL": 15,
            "domain": 56
          },
          "indicator_count": 366,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "171 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "693edf0ff3157e2fe0329db8",
          "name": "PreCog Sweep - 2025-12-14 16h",
          "description": "Novel threat indicators detected by PreCog Sweep Engine",
          "modified": "2025-12-14T16:00:15.472000",
          "created": "2025-12-14T16:00:15.472000",
          "tags": [
            "precog",
            "automated",
            "novel-ioc",
            "c2",
            "malware"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix/master",
            "https://github.com/pduggusa/dugganusa-research"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 294,
            "URL": 15,
            "domain": 56
          },
          "indicator_count": 365,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "171 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "693edcb505eda22f10489385",
          "name": "PreCog Sweep - 2025-12-14 15h",
          "description": "Novel threat indicators detected by PreCog Sweep Engine",
          "modified": "2025-12-14T15:50:13.419000",
          "created": "2025-12-14T15:50:13.419000",
          "tags": [
            "precog",
            "automated",
            "novel-ioc",
            "c2",
            "malware"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix/master",
            "https://github.com/pduggusa/dugganusa-research"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 293,
            "URL": 15,
            "domain": 56
          },
          "indicator_count": 364,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "171 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "693eda5e2f5b3dce41787b56",
          "name": "PreCog Sweep - 2025-12-14 15h",
          "description": "Novel threat indicators detected by PreCog Sweep Engine",
          "modified": "2025-12-14T15:40:14.738000",
          "created": "2025-12-14T15:40:14.738000",
          "tags": [
            "precog",
            "automated",
            "novel-ioc",
            "c2",
            "malware"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix/master",
            "https://github.com/pduggusa/dugganusa-research"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 292,
            "URL": 15,
            "domain": 56
          },
          "indicator_count": 363,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "171 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "693ed80695b88665b85bc4e2",
          "name": "PreCog Sweep - 2025-12-14 15h",
          "description": "Novel threat indicators detected by PreCog Sweep Engine",
          "modified": "2025-12-14T15:30:14.325000",
          "created": "2025-12-14T15:30:14.325000",
          "tags": [
            "precog",
            "automated",
            "novel-ioc",
            "c2",
            "malware"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix/master",
            "https://github.com/pduggusa/dugganusa-research"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 291,
            "URL": 15,
            "domain": 56
          },
          "indicator_count": 362,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "171 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "https://github.com/pduggusa/dugganusa-research",
        "https://analytics.dugganusa.com/api/v1/stix/master"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 0
        },
        "other": {
          "adversary": [],
          "malware_families": [
            ""
          ],
          "industries": [],
          "unique_indicators": 108641
        }
      }
    },
    "false_positive": [],
    "alexa": "http://www.alexa.com/siteinfo/sotavpn.shop",
    "whois": "http://whois.domaintools.com/sotavpn.shop",
    "domain": "sotavpn.shop",
    "hostname": "Unavailable"
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 50,
  "pulses": [
    {
      "id": "691b8869e00b107fa20d9482",
      "name": "ThreatFix",
      "description": "ThreatFix is an effort to publish various details about ransomware variants and ransomware threat actors. ThreatFix advisories include recently and historically observed tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) to help organizations protect against ransomware.",
      "modified": "2026-01-23T11:01:07.175000",
      "created": "2025-11-17T20:41:11.797000",
      "tags": [
        "",
        "ransomware",
        "malware"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "",
          "display_name": "",
          "target": null
        }
      ],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 8,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "zlepos384",
        "id": "103244",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 8010,
        "FileHash-SHA1": 7922,
        "FileHash-SHA256": 8893,
        "URL": 57004,
        "domain": 36018,
        "hostname": 96473
      },
      "indicator_count": 214320,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 44,
      "modified_text": "131 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6940da7bdf2d8820aa512eeb",
      "name": "ThreatFox Hunt: Unknown malware IOCs - 2025-12-16",
      "description": "Automated ThreatFox hunt for Unknown malware indicators. 82 IOCs collected. Pattern 49 automated intelligence streaming. Reference: https://analytics.dugganusa.com",
      "modified": "2026-01-15T04:02:04.203000",
      "created": "2025-12-16T04:05:15.894000",
      "tags": [
        "unknown-malware",
        "threatfox",
        "automated-hunt",
        "pattern-49",
        "dugganusa"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 1,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "pduggusa",
        "id": "371400",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 41,
        "domain": 21
      },
      "indicator_count": 62,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 197,
      "modified_text": "139 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6940cc6a934a78b87aa1c698",
      "name": "ThreatFox Hunt: Unknown malware IOCs - 2025-12-16",
      "description": "Automated ThreatFox hunt for Unknown malware indicators. 82 IOCs collected. Pattern 49 automated intelligence streaming. Reference: https://analytics.dugganusa.com",
      "modified": "2026-01-15T03:02:44.177000",
      "created": "2025-12-16T03:05:14.945000",
      "tags": [
        "unknown-malware",
        "threatfox",
        "automated-hunt",
        "pattern-49",
        "dugganusa"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 1,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "pduggusa",
        "id": "371400",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 41,
        "domain": 21
      },
      "indicator_count": 62,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 197,
      "modified_text": "139 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6940b04e45348b7d765601f9",
      "name": "ThreatFox Hunt: Unknown malware IOCs - 2025-12-16",
      "description": "Automated ThreatFox hunt for Unknown malware indicators. 83 IOCs collected. Pattern 49 automated intelligence streaming. Reference: https://analytics.dugganusa.com",
      "modified": "2026-01-15T01:02:47.757000",
      "created": "2025-12-16T01:05:18.326000",
      "tags": [
        "unknown-malware",
        "threatfox",
        "automated-hunt",
        "pattern-49",
        "dugganusa"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "pduggusa",
        "id": "371400",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 42,
        "domain": 21
      },
      "indicator_count": 63,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 197,
      "modified_text": "139 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6940942a20d6f2297254f032",
      "name": "ThreatFox Hunt: Unknown malware IOCs - 2025-12-15",
      "description": "Automated ThreatFox hunt for Unknown malware indicators. 84 IOCs collected. Pattern 49 automated intelligence streaming. Reference: https://analytics.dugganusa.com",
      "modified": "2026-01-14T23:02:12.860000",
      "created": "2025-12-15T23:05:14.974000",
      "tags": [
        "unknown-malware",
        "threatfox",
        "automated-hunt",
        "pattern-49",
        "dugganusa"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "pduggusa",
        "id": "371400",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 42,
        "domain": 21
      },
      "indicator_count": 63,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 197,
      "modified_text": "139 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6940861cf4fc04cf328f7574",
      "name": "ThreatFox Hunt: Unknown malware IOCs - 2025-12-15",
      "description": "Automated ThreatFox hunt for Unknown malware indicators. 84 IOCs collected. Pattern 49 automated intelligence streaming. Reference: https://analytics.dugganusa.com",
      "modified": "2026-01-14T22:00:56.245000",
      "created": "2025-12-15T22:05:16.666000",
      "tags": [
        "unknown-malware",
        "threatfox",
        "automated-hunt",
        "pattern-49",
        "dugganusa"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "pduggusa",
        "id": "371400",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 42,
        "domain": 21
      },
      "indicator_count": 63,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 197,
      "modified_text": "140 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6940781f7f7aeec6359f750f",
      "name": "ThreatFox Hunt: Unknown malware IOCs - 2025-12-15",
      "description": "Automated ThreatFox hunt for Unknown malware indicators. 84 IOCs collected. Pattern 49 automated intelligence streaming. Reference: https://analytics.dugganusa.com",
      "modified": "2026-01-14T21:05:02.119000",
      "created": "2025-12-15T21:05:35.904000",
      "tags": [
        "unknown-malware",
        "threatfox",
        "automated-hunt",
        "pattern-49",
        "dugganusa"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 1,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "pduggusa",
        "id": "371400",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 42,
        "domain": 21
      },
      "indicator_count": 63,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 197,
      "modified_text": "140 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "693fb32fdcfa1b3ba2565caa",
      "name": "ThreatFox Hunt: Unknown malware IOCs - 2025-12-15",
      "description": "Automated ThreatFox hunt for Unknown malware indicators. 49 IOCs collected. Pattern 49 automated intelligence streaming. Reference: https://analytics.dugganusa.com",
      "modified": "2026-01-14T07:02:35.106000",
      "created": "2025-12-15T07:05:19.762000",
      "tags": [
        "unknown-malware",
        "threatfox",
        "automated-hunt",
        "pattern-49",
        "dugganusa"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 1,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "pduggusa",
        "id": "371400",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 21,
        "domain": 3,
        "hostname": 1
      },
      "indicator_count": 25,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 197,
      "modified_text": "140 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "693eab71f5e5a6f11f64ad92",
      "name": "OSINT Volley 2025-12-14 - Cobalt Strike/ClearFake/Unknown malware",
      "description": "Automated OSINT sweep from ThreatFox. Top malware: Cobalt Strike(196), ClearFake(146), Unknown malware(32), Quasar RAT(31), DeimosC2(27). Source: abuse.ch ThreatFox API. Pattern 54: sweep\u2192volley automation.",
      "modified": "2026-01-13T12:00:06.383000",
      "created": "2025-12-14T12:20:01.601000",
      "tags": [
        "osint-volley",
        "threatfox",
        "automated",
        "cobalt-strike",
        "clearfake",
        "unknown-malware"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 1,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "pduggusa",
        "id": "371400",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 111,
        "URL": 14,
        "domain": 10,
        "FileHash-SHA256": 1
      },
      "indicator_count": 136,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 197,
      "modified_text": "141 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "693e9d624fa39e41bfc7e311",
      "name": "OSINT Volley 2025-12-14 - Cobalt Strike/ClearFake/Unknown malware",
      "description": "Automated OSINT sweep from ThreatFox. Top malware: Cobalt Strike(194), ClearFake(146), Unknown malware(35), Quasar RAT(30), DeimosC2(27). Source: abuse.ch ThreatFox API. Pattern 54: sweep\u2192volley automation.",
      "modified": "2026-01-13T11:02:44.341000",
      "created": "2025-12-14T11:20:02.174000",
      "tags": [
        "osint-volley",
        "threatfox",
        "automated",
        "cobalt-strike",
        "clearfake",
        "unknown-malware"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "pduggusa",
        "id": "371400",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 101,
        "domain": 11,
        "URL": 11,
        "FileHash-SHA256": 1
      },
      "indicator_count": 124,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 197,
      "modified_text": "141 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "https://sotavpn.shop/",
    "type": "URL"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "https://sotavpn.shop/",
    "type": "URL",
    "found": false,
    "verdict": "clean",
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780524316.014603
}