{
  "type": "URL",
  "indicator": "https://swiperjs.com",
  "general": {
    "sections": [
      "general",
      "url_list",
      "http_scans",
      "screenshot"
    ],
    "indicator": "https://swiperjs.com",
    "type": "url",
    "type_title": "URL",
    "validation": [],
    "base_indicator": {
      "id": 3224437945,
      "indicator": "https://swiperjs.com",
      "type": "URL",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 19,
      "pulses": [
        {
          "id": "69b7ac3b32ac89ecba53f3d9",
          "name": "Malicious",
          "description": "",
          "modified": "2026-04-15T08:44:52.171000",
          "created": "2026-03-16T07:07:39.495000",
          "tags": [
            "march",
            "input http",
            "posix shell",
            "ascii text",
            "threat level",
            "summary av",
            "detection",
            "environment",
            "action"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 291,
            "URL": 272,
            "hostname": 296,
            "domain": 293,
            "FileHash-MD5": 90,
            "FileHash-SHA1": 89,
            "CIDR": 3,
            "email": 3,
            "SSLCertFingerprint": 9
          },
          "indicator_count": 1346,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 49,
          "modified_text": "4 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "69b235439d56630943ea31e6",
          "name": "Clone by Q Vashti (excellent systemic analyzer I may add)",
          "description": "",
          "modified": "2026-04-10T22:04:28.607000",
          "created": "2026-03-12T03:38:43.171000",
          "tags": [
            "\u9ed1\u6599",
            "\u5403\u74dc",
            "\u5403\u74dc\u7f51",
            "51\u5403\u74dc",
            "\u9ed1\u6599\u4e0d\u6253\u70ca",
            "\u9ed1\u6599\u5403\u74dc\u7f51",
            "\u70ed\u95e8\u5927\u74dc",
            "\u660e\u661f\u8d44\u8baf",
            "\u7f51\u7ea2\u9ed1\u6599",
            "\u5185\u6db5\u6bb5\u5b50",
            "\u4eca\u65e5\u5403\u74dc",
            "\u5403\u74dc\u65b0\u95fb",
            "\u9ed1\u6599\u66dd\u5149",
            "\u516b\u5366\u65b0\u95fb",
            "\u793e\u4f1a\u70ed\u70b9",
            "\u5403\u74dc\u7fa4\u4f17",
            "\u70ed\u70b9\u4e8b\u4ef6",
            "\u6bcf\u65e5\u5403\u74dc",
            "\u7f51\u7ea2\u5403\u74dc",
            "\u4eca\u65e5\u5927\u74dc",
            "\u5403\u74dc\u7206\u6599",
            "\u5403\u74dc\u4e2d\u5fc3",
            "\u4eca\u65e5\u70ed\u74dc",
            "\u5403\u74dc\u9ed1\u6599",
            "\u9ed1\u6599\u6cc4\u5bc6",
            "\u91cd\u78c5\u9ed1\u6599",
            "\u5403\u74dc\u6cc4\u5bc6",
            "\u4eca\u65e5\u9ed1\u6599",
            "\u6700\u65b0\u9ed1\u6599",
            "\u5403\u74dc\u66dd\u5149",
            "\u5403\u74dc\u8d44\u6e90",
            "\u91cd\u78c5\u5403\u74dc",
            "\u5a31\u4e50\u70ed\u74dc",
            "chrome",
            "cos ai",
            "a serif",
            "sans serif",
            "top10",
            "openclaw",
            "21200",
            "onlyfans",
            "strong",
            "dmca copyright",
            "address google",
            "safe browsing",
            "data upload",
            "extraction",
            "lte all",
            "enter sc",
            "type o",
            "extra",
            "referen https",
            "lte o",
            "type",
            "extr data",
            "include review",
            "exclude sugges",
            "failed",
            "hong kong",
            "passive dns",
            "otx logo",
            "all ipv4",
            "url analysis",
            "urls",
            "files",
            "location hong",
            "value",
            "march",
            "0x1595 function",
            "0x19b5 object",
            "tracker",
            "base64 object",
            "cookie function",
            "mlog",
            "localconst",
            "style function",
            "reverse dns",
            "general full",
            "url https",
            "resource",
            "software",
            "hash",
            "security tls",
            "singapore",
            "asn139341",
            "aceasap ace",
            "ip address",
            "cloudflare",
            "report",
            "whois",
            "as13335",
            "name lookup",
            "website",
            "kong",
            "ssl certificate",
            "http",
            "request chain",
            "nl redirected",
            "http redirect",
            "kb script",
            "protocol h3",
            "security quic",
            "seychelles",
            "asn13335",
            "cloudflarenet",
            "js function",
            "portable descr",
            "internet",
            "iana",
            "iana web",
            "stepgo limited",
            "assigned pa",
            "afrinic",
            "filtered parent",
            "ebene",
            "mahe",
            "stepgo",
            "united",
            "unknown ns",
            "script script",
            "moved",
            "record value",
            "title",
            "0 lte",
            "find s",
            "size",
            "mitre att",
            "ck id",
            "ck matrix",
            "root",
            "hybrid",
            "general",
            "path",
            "click",
            "strings",
            "yrbyd",
            "learn",
            "name tactics",
            "suspicious",
            "informative",
            "command",
            "adversaries",
            "spawns",
            "initial access",
            "lalal.ai",
            "record type",
            "ttl value",
            "thumbprint",
            "ios ping",
            "defense evasion",
            "id name",
            "malicious",
            "t1055.015 list planting",
            "sha1",
            "copy md5",
            "sha256",
            "pattern match",
            "show technique",
            "unknown",
            "accept",
            "date",
            "local",
            "starfield",
            "encrypt",
            "iframe",
            "prometheus intelligence technology",
            "apple",
            "cyber attacks",
            "usptracker.com",
            "android"
          ],
          "references": [
            "https://airline.cmntgoyq.com/  | Prometheus Intelligence Technology",
            "lalal.ai",
            "logstream-mystifying-tharp-7si72pw.cribl.cloud",
            "quantum-staging.emsbk.com",
            "spf.google.com",
            "Amazon.com",
            "mc.yandex.com \u2022 mc.yandex.ru \u2022 yandex.com \u2022 yandex.ru",
            "mc.yandex.com/metrika/ \u2022 mc.yandex.com/watch/99885987/",
            "api-cookie.click",
            "delete-me.bgs.beanie.cloud",
            "bridge-websocket-evolosciuc.devint01.goodleap.com",
            "https://bombing.gwuzafo.cc/",
            "test-ssa.pineapples.dev",
            "sso.dev.applemarketingtools.com",
            "containers-oceanus.palantirsec.com",
            "https://otx.alienvault.com/pulse/69af3fd8db2ede31abda6c14",
            "kadmos.bot \u2022 cutout.bot \u2022 scenebot.com",
            "https://www.lalal.ai/privacy-policy/InvalidOutputFolderErrorQAndroidJniObject",
            "Will sort to identify malware",
            "https://hybrid-analysis.com/sample/9e7bfc9fb60aa3e3f3c5b91f84ebf8b07e35893e1491149420535cd494bb8a32/69b1b467625a11ce330587db"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "Malware",
              "display_name": "Malware",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1069",
              "name": "Permission Groups Discovery",
              "display_name": "T1069 - Permission Groups Discovery"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1204",
              "name": "User Execution",
              "display_name": "T1204 - User Execution"
            },
            {
              "id": "T1480",
              "name": "Execution Guardrails",
              "display_name": "T1480 - Execution Guardrails"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1568",
              "name": "Dynamic Resolution",
              "display_name": "T1568 - Dynamic Resolution"
            },
            {
              "id": "T1583",
              "name": "Acquire Infrastructure",
              "display_name": "T1583 - Acquire Infrastructure"
            },
            {
              "id": "T1583.001",
              "name": "Domains",
              "display_name": "T1583.001 - Domains"
            },
            {
              "id": "T1566.002",
              "name": "Spearphishing Link",
              "display_name": "T1566.002 - Spearphishing Link"
            },
            {
              "id": "T1553.002",
              "name": "Code Signing",
              "display_name": "T1553.002 - Code Signing"
            },
            {
              "id": "T1069.002",
              "name": "Domain Groups",
              "display_name": "T1069.002 - Domain Groups"
            },
            {
              "id": "T1071.004",
              "name": "DNS",
              "display_name": "T1071.004 - DNS"
            },
            {
              "id": "T1568.002",
              "name": "Domain Generation Algorithms",
              "display_name": "T1568.002 - Domain Generation Algorithms"
            },
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1410",
              "name": "Network Traffic Capture or Redirection",
              "display_name": "T1410 - Network Traffic Capture or Redirection"
            },
            {
              "id": "TA0011",
              "name": "Command and Control",
              "display_name": "TA0011 - Command and Control"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1048",
              "name": "Exfiltration Over Alternative Protocol",
              "display_name": "T1048 - Exfiltration Over Alternative Protocol"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1562",
              "name": "Impair Defenses",
              "display_name": "T1562 - Impair Defenses"
            },
            {
              "id": "T1562.001",
              "name": "Disable or Modify Tools",
              "display_name": "T1562.001 - Disable or Modify Tools"
            },
            {
              "id": "T1048.003",
              "name": "Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol",
              "display_name": "T1048.003 - Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol"
            },
            {
              "id": "T1584.005",
              "name": "Botnet",
              "display_name": "T1584.005 - Botnet"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": "69b1f368db0d00947ef729c2",
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 4097,
            "domain": 849,
            "hostname": 2440,
            "FileHash-MD5": 149,
            "FileHash-SHA1": 131,
            "FileHash-SHA256": 955,
            "CIDR": 5,
            "email": 6,
            "SSLCertFingerprint": 8
          },
          "indicator_count": 8640,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 48,
          "modified_text": "8 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "69b1f368db0d00947ef729c2",
          "name": "\u5403\u74dc\u770b\u9ed1\u6599\u5c31\u4e0a - \u9ed1\u6599\u5403\u74dc\u7f51 | \u70ed\u95e8\u4e8b\u4ef6\u7206\u6599\u4e0e\u771f\u76f8",
          "description": "Why is this type of malicious found on a US citizens device? Found in a link extracted from a glitching device.. Palantir\u2019s Prometheus Intelligence Technology tracking and AI at work.\n#tracker #http_redirect #onlyfans_? #bombing #airlines #lalal.ai #openclaw #targeted",
          "modified": "2026-04-10T22:04:28.607000",
          "created": "2026-03-11T22:57:44.584000",
          "tags": [
            "\u9ed1\u6599",
            "\u5403\u74dc",
            "\u5403\u74dc\u7f51",
            "51\u5403\u74dc",
            "\u9ed1\u6599\u4e0d\u6253\u70ca",
            "\u9ed1\u6599\u5403\u74dc\u7f51",
            "\u70ed\u95e8\u5927\u74dc",
            "\u660e\u661f\u8d44\u8baf",
            "\u7f51\u7ea2\u9ed1\u6599",
            "\u5185\u6db5\u6bb5\u5b50",
            "\u4eca\u65e5\u5403\u74dc",
            "\u5403\u74dc\u65b0\u95fb",
            "\u9ed1\u6599\u66dd\u5149",
            "\u516b\u5366\u65b0\u95fb",
            "\u793e\u4f1a\u70ed\u70b9",
            "\u5403\u74dc\u7fa4\u4f17",
            "\u70ed\u70b9\u4e8b\u4ef6",
            "\u6bcf\u65e5\u5403\u74dc",
            "\u7f51\u7ea2\u5403\u74dc",
            "\u4eca\u65e5\u5927\u74dc",
            "\u5403\u74dc\u7206\u6599",
            "\u5403\u74dc\u4e2d\u5fc3",
            "\u4eca\u65e5\u70ed\u74dc",
            "\u5403\u74dc\u9ed1\u6599",
            "\u9ed1\u6599\u6cc4\u5bc6",
            "\u91cd\u78c5\u9ed1\u6599",
            "\u5403\u74dc\u6cc4\u5bc6",
            "\u4eca\u65e5\u9ed1\u6599",
            "\u6700\u65b0\u9ed1\u6599",
            "\u5403\u74dc\u66dd\u5149",
            "\u5403\u74dc\u8d44\u6e90",
            "\u91cd\u78c5\u5403\u74dc",
            "\u5a31\u4e50\u70ed\u74dc",
            "chrome",
            "cos ai",
            "a serif",
            "sans serif",
            "top10",
            "openclaw",
            "21200",
            "onlyfans",
            "strong",
            "dmca copyright",
            "address google",
            "safe browsing",
            "data upload",
            "extraction",
            "lte all",
            "enter sc",
            "type o",
            "extra",
            "referen https",
            "lte o",
            "type",
            "extr data",
            "include review",
            "exclude sugges",
            "failed",
            "hong kong",
            "passive dns",
            "otx logo",
            "all ipv4",
            "url analysis",
            "urls",
            "files",
            "location hong",
            "value",
            "march",
            "0x1595 function",
            "0x19b5 object",
            "tracker",
            "base64 object",
            "cookie function",
            "mlog",
            "localconst",
            "style function",
            "reverse dns",
            "general full",
            "url https",
            "resource",
            "software",
            "hash",
            "security tls",
            "singapore",
            "asn139341",
            "aceasap ace",
            "ip address",
            "cloudflare",
            "report",
            "whois",
            "as13335",
            "name lookup",
            "website",
            "kong",
            "ssl certificate",
            "http",
            "request chain",
            "nl redirected",
            "http redirect",
            "kb script",
            "protocol h3",
            "security quic",
            "seychelles",
            "asn13335",
            "cloudflarenet",
            "js function",
            "portable descr",
            "internet",
            "iana",
            "iana web",
            "stepgo limited",
            "assigned pa",
            "afrinic",
            "filtered parent",
            "ebene",
            "mahe",
            "stepgo",
            "united",
            "unknown ns",
            "script script",
            "moved",
            "record value",
            "title",
            "0 lte",
            "find s",
            "size",
            "mitre att",
            "ck id",
            "ck matrix",
            "root",
            "hybrid",
            "general",
            "path",
            "click",
            "strings",
            "yrbyd",
            "learn",
            "name tactics",
            "suspicious",
            "informative",
            "command",
            "adversaries",
            "spawns",
            "initial access",
            "lalal.ai",
            "record type",
            "ttl value",
            "thumbprint",
            "ios ping",
            "defense evasion",
            "id name",
            "malicious",
            "t1055.015 list planting",
            "sha1",
            "copy md5",
            "sha256",
            "pattern match",
            "show technique",
            "unknown",
            "accept",
            "date",
            "local",
            "starfield",
            "encrypt",
            "iframe",
            "prometheus intelligence technology",
            "apple",
            "cyber attacks",
            "usptracker.com",
            "android"
          ],
          "references": [
            "https://airline.cmntgoyq.com/  | Prometheus Intelligence Technology",
            "lalal.ai",
            "logstream-mystifying-tharp-7si72pw.cribl.cloud",
            "quantum-staging.emsbk.com",
            "spf.google.com",
            "Amazon.com",
            "mc.yandex.com \u2022 mc.yandex.ru \u2022 yandex.com \u2022 yandex.ru",
            "mc.yandex.com/metrika/ \u2022 mc.yandex.com/watch/99885987/",
            "api-cookie.click",
            "delete-me.bgs.beanie.cloud",
            "bridge-websocket-evolosciuc.devint01.goodleap.com",
            "https://bombing.gwuzafo.cc/",
            "test-ssa.pineapples.dev",
            "sso.dev.applemarketingtools.com",
            "containers-oceanus.palantirsec.com",
            "https://otx.alienvault.com/pulse/69af3fd8db2ede31abda6c14",
            "kadmos.bot \u2022 cutout.bot \u2022 scenebot.com",
            "https://www.lalal.ai/privacy-policy/InvalidOutputFolderErrorQAndroidJniObject",
            "Will sort to identify malware",
            "https://hybrid-analysis.com/sample/9e7bfc9fb60aa3e3f3c5b91f84ebf8b07e35893e1491149420535cd494bb8a32/69b1b467625a11ce330587db"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "Malware",
              "display_name": "Malware",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1069",
              "name": "Permission Groups Discovery",
              "display_name": "T1069 - Permission Groups Discovery"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1204",
              "name": "User Execution",
              "display_name": "T1204 - User Execution"
            },
            {
              "id": "T1480",
              "name": "Execution Guardrails",
              "display_name": "T1480 - Execution Guardrails"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1568",
              "name": "Dynamic Resolution",
              "display_name": "T1568 - Dynamic Resolution"
            },
            {
              "id": "T1583",
              "name": "Acquire Infrastructure",
              "display_name": "T1583 - Acquire Infrastructure"
            },
            {
              "id": "T1583.001",
              "name": "Domains",
              "display_name": "T1583.001 - Domains"
            },
            {
              "id": "T1566.002",
              "name": "Spearphishing Link",
              "display_name": "T1566.002 - Spearphishing Link"
            },
            {
              "id": "T1553.002",
              "name": "Code Signing",
              "display_name": "T1553.002 - Code Signing"
            },
            {
              "id": "T1069.002",
              "name": "Domain Groups",
              "display_name": "T1069.002 - Domain Groups"
            },
            {
              "id": "T1071.004",
              "name": "DNS",
              "display_name": "T1071.004 - DNS"
            },
            {
              "id": "T1568.002",
              "name": "Domain Generation Algorithms",
              "display_name": "T1568.002 - Domain Generation Algorithms"
            },
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1410",
              "name": "Network Traffic Capture or Redirection",
              "display_name": "T1410 - Network Traffic Capture or Redirection"
            },
            {
              "id": "TA0011",
              "name": "Command and Control",
              "display_name": "TA0011 - Command and Control"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1048",
              "name": "Exfiltration Over Alternative Protocol",
              "display_name": "T1048 - Exfiltration Over Alternative Protocol"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1562",
              "name": "Impair Defenses",
              "display_name": "T1562 - Impair Defenses"
            },
            {
              "id": "T1562.001",
              "name": "Disable or Modify Tools",
              "display_name": "T1562.001 - Disable or Modify Tools"
            },
            {
              "id": "T1048.003",
              "name": "Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol",
              "display_name": "T1048.003 - Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol"
            },
            {
              "id": "T1584.005",
              "name": "Botnet",
              "display_name": "T1584.005 - Botnet"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Q.Vashti",
            "id": "337942",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 4097,
            "domain": 849,
            "hostname": 2440,
            "FileHash-MD5": 149,
            "FileHash-SHA1": 131,
            "FileHash-SHA256": 955,
            "CIDR": 5,
            "email": 6,
            "SSLCertFingerprint": 8
          },
          "indicator_count": 8640,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 138,
          "modified_text": "8 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "69aa41b0d714318bf8937184",
          "name": "W.Vashti .Net obfuscator clone",
          "description": "",
          "modified": "2026-04-04T00:06:41.423000",
          "created": "2026-03-06T02:53:36.216000",
          "tags": [
            "no expiration",
            "domain",
            "name",
            "control flow",
            "dlls",
            "method parent",
            "declarative",
            "ms build",
            "core",
            "msie",
            "windows nt",
            "wow64",
            "slcc2",
            "media center",
            "read c",
            "dock",
            "write",
            "execution",
            "capture",
            "endgame",
            "united",
            "moved",
            "ip address",
            "record value",
            "gate software",
            "newnham house",
            "expiration date",
            "urls",
            "url add",
            "http",
            "related nids",
            "files location",
            "flag united",
            "present aug",
            "present sep",
            "present nov",
            "present oct",
            "name servers",
            "emails",
            "present dec",
            "meta",
            "passive dns",
            "next associated",
            "ipv4",
            "url analysis",
            "files",
            "cookie",
            "subscribe",
            "unsubscribe",
            "s paris",
            "englewood",
            "state",
            "skip",
            "espaol",
            "summary",
            "filing history",
            "ireland",
            "title",
            "united states",
            "certificate",
            "colorado",
            "ipv4 add",
            "america flag",
            "showing",
            "pulse submit",
            "size",
            "pattern match",
            "mitre att",
            "ck id",
            "path",
            "hybrid",
            "general",
            "local",
            "iframe",
            "click",
            "strings",
            "cece",
            "mult",
            "learn",
            "name tactics",
            "suspicious",
            "informative",
            "command",
            "adversaries",
            "spawns",
            "t1590 gather",
            "victim network",
            "flag",
            "windir",
            "openurl c",
            "prefetch2",
            "analysis",
            "tor analysis",
            "dns requests",
            "domain address",
            "contacted hosts",
            "sha1",
            "sha256",
            "njmk",
            "kwruymy",
            "mime",
            "submitted",
            "process details",
            "calls",
            "apis",
            "reads",
            "defense evasion",
            "model",
            "getprocaddress",
            "show technique",
            "ck matrix",
            "access type",
            "value",
            "api call",
            "open",
            "august",
            "format",
            "typeof symbol",
            "typeof s",
            "typeof c",
            "function",
            "symbol",
            "comenabled",
            "image path",
            "ndex",
            "ndroleextdll",
            "f0f0f0",
            "ff4b55",
            "stop",
            "span",
            "show process",
            "binary file",
            "file",
            "network traffic",
            "encrypt",
            "date",
            "found",
            "ssl certificate",
            "creation date",
            "hostname add",
            "pulse pulses",
            "files ip",
            "address domain",
            "data upload",
            "extraction",
            "ge6 mira",
            "failed",
            "ascii text",
            "development att",
            "hostname",
            "files domain",
            "files related",
            "pulses otx",
            "pulses",
            "unknown aaaa",
            "unknown ns",
            "united states",
            "urls show",
            "date checked",
            "url hostname",
            "server response",
            "google safe",
            "results may",
            "a domains",
            "search",
            "germany unknown",
            "win32",
            "lowfi",
            "chrome",
            "susp",
            "trojan",
            "backdoor",
            "twitter",
            "virtool",
            "worm",
            "exploit",
            "trojandropper",
            "win32upatre dec",
            "mtb dec",
            "reverse dns",
            "body",
            "location united",
            "asn as14618",
            "less whois",
            "files show",
            "date hash",
            "avast avg",
            "initial access",
            "javascript",
            "root",
            "enterprise",
            "form",
            "desktop",
            "command decode",
            "suricata ipv4",
            "spycloud",
            "robots",
            "bots",
            "chatbot",
            "bot network",
            "spy",
            "mixb",
            "a2fryx",
            "therahand",
            "typosquating"
          ],
          "references": [
            "https://www.red-gate.com/products/smartassembly",
            "spycloud.com \u2022 content.spycloud.com \u2022 email.spycloud.com\t hostname\tengage.spycloud.com \u2022 hello.spycloud.com \u2022portal.spycloud.com \u2022 https://email.spycloud",
            "https://email.spycloud.com/NzEzLVdJUC03MzcAAAGe67eM-W3qxAlVkEvZwfw1dWuwRdm0zVU5aMyOzUe2IkxAY3hDe8RfT27HnjgkvTk-uqIy6K0=",
            "https://spycloud.com/solutions/\t\u2022 104.18.26.108 ELF:Mirai-GH\\ [Trj] \u2022 Unix.Dropper.Mirai-7135870-0",
            "dasima-containers.palantirfoundry.com \u2022 blitzrobots.com",
            "https://blog.endgames.com/ \u2022 wg41xm05b3.endgamesystems.com",
            "https://www.coloradosos.gov/biz/BusinessEntityDetail.do?quitButtonDestination=BusinessEntityResults&nameTyp=ENT&masterFileId=20221473927&entityId2=20221473927&fileId=20251525819&srchTyp=ENTITY",
            "www.onyx-ware.com \u2022 http://pages.endgames.com/ \u2022  http://www.endgamesystems.com/",
            "https://hybrid-analysis.com/sample/9a1e0d38b691f1d22a92cff65ec0439b428170ac39a4493c7ecb06d5585f56a3/68a4adea30f7fafee90aefd3",
            "Malicious: http://developers.cloudfiare.com/support/troubleshooting/http-status-",
            "Typosquating: developers.cloudfiare.com \u2022 cloudfiare.com"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Unix.Dropper.Mirai-7135870-0",
              "display_name": "Unix.Dropper.Mirai-7135870-0",
              "target": null
            },
            {
              "id": "ELF:Mirai-GH\\ [Trj]",
              "display_name": "ELF:Mirai-GH\\ [Trj]",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1090",
              "name": "Proxy",
              "display_name": "T1090 - Proxy"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1127",
              "name": "Trusted Developer Utilities Proxy Execution",
              "display_name": "T1127 - Trusted Developer Utilities Proxy Execution"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1560",
              "name": "Archive Collected Data",
              "display_name": "T1560 - Archive Collected Data"
            },
            {
              "id": "T1053",
              "name": "Scheduled Task/Job",
              "display_name": "T1053 - Scheduled Task/Job"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1056",
              "name": "Input Capture",
              "display_name": "T1056 - Input Capture"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1119",
              "name": "Automated Collection",
              "display_name": "T1119 - Automated Collection"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1143",
              "name": "Hidden Window",
              "display_name": "T1143 - Hidden Window"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1069",
              "name": "Permission Groups Discovery",
              "display_name": "T1069 - Permission Groups Discovery"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1480",
              "name": "Execution Guardrails",
              "display_name": "T1480 - Execution Guardrails"
            },
            {
              "id": "T1568",
              "name": "Dynamic Resolution",
              "display_name": "T1568 - Dynamic Resolution"
            },
            {
              "id": "T1583",
              "name": "Acquire Infrastructure",
              "display_name": "T1583 - Acquire Infrastructure"
            },
            {
              "id": "T1590",
              "name": "Gather Victim Network Information",
              "display_name": "T1590 - Gather Victim Network Information"
            },
            {
              "id": "T1113",
              "name": "Screen Capture",
              "display_name": "T1113 - Screen Capture"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1583.001",
              "name": "Domains",
              "display_name": "T1583.001 - Domains"
            },
            {
              "id": "T1553.002",
              "name": "Code Signing",
              "display_name": "T1553.002 - Code Signing"
            },
            {
              "id": "T1069.002",
              "name": "Domain Groups",
              "display_name": "T1069.002 - Domain Groups"
            },
            {
              "id": "T1568.002",
              "name": "Domain Generation Algorithms",
              "display_name": "T1568.002 - Domain Generation Algorithms"
            },
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1071.004",
              "name": "DNS",
              "display_name": "T1071.004 - DNS"
            },
            {
              "id": "T1003",
              "name": "OS Credential Dumping",
              "display_name": "T1003 - OS Credential Dumping"
            },
            {
              "id": "T1007",
              "name": "System Service Discovery",
              "display_name": "T1007 - System Service Discovery"
            },
            {
              "id": "T1010",
              "name": "Application Window Discovery",
              "display_name": "T1010 - Application Window Discovery"
            },
            {
              "id": "T1012",
              "name": "Query Registry",
              "display_name": "T1012 - Query Registry"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1068",
              "name": "Exploitation for Privilege Escalation",
              "display_name": "T1068 - Exploitation for Privilege Escalation"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1546",
              "name": "Event Triggered Execution",
              "display_name": "T1546 - Event Triggered Execution"
            },
            {
              "id": "T1562",
              "name": "Impair Defenses",
              "display_name": "T1562 - Impair Defenses"
            },
            {
              "id": "T1614",
              "name": "System Location Discovery",
              "display_name": "T1614 - System Location Discovery"
            },
            {
              "id": "T1122",
              "name": "Component Object Model Hijacking",
              "display_name": "T1122 - Component Object Model Hijacking"
            },
            {
              "id": "T1415",
              "name": "URL Scheme Hijacking",
              "display_name": "T1415 - URL Scheme Hijacking"
            },
            {
              "id": "T1416",
              "name": "URI Hijacking",
              "display_name": "T1416 - URI Hijacking"
            },
            {
              "id": "T1059.007",
              "name": "JavaScript",
              "display_name": "T1059.007 - JavaScript"
            },
            {
              "id": "T1584.005",
              "name": "Botnet",
              "display_name": "T1584.005 - Botnet"
            },
            {
              "id": "T1189",
              "name": "Drive-by Compromise",
              "display_name": "T1189 - Drive-by Compromise"
            },
            {
              "id": "T1204",
              "name": "User Execution",
              "display_name": "T1204 - User Execution"
            },
            {
              "id": "T1562.001",
              "name": "Disable or Modify Tools",
              "display_name": "T1562.001 - Disable or Modify Tools"
            },
            {
              "id": "T1116",
              "name": "Code Signing",
              "display_name": "T1116 - Code Signing"
            },
            {
              "id": "T1546.015",
              "name": "Component Object Model Hijacking",
              "display_name": "T1546.015 - Component Object Model Hijacking"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1014",
              "name": "Rootkit",
              "display_name": "T1014 - Rootkit"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": "6952d4fc6910b0b866746d8a",
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 341,
            "FileHash-SHA1": 343,
            "FileHash-SHA256": 1332,
            "domain": 1062,
            "hostname": 1969,
            "URL": 5700,
            "email": 10,
            "SSLCertFingerprint": 21,
            "CVE": 1
          },
          "indicator_count": 10779,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 49,
          "modified_text": "15 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "69c795bb826e6067f37ea127",
          "name": "'3'  clone by credit: krishivpatel",
          "description": "",
          "modified": "2026-03-28T08:47:55.537000",
          "created": "2026-03-28T08:47:55.537000",
          "tags": [
            "record type",
            "ttl value",
            "algorithm",
            "data",
            "v3 serial",
            "number",
            "cus olet",
            "encrypt cnr3",
            "validity",
            "subject public",
            "key info",
            "key algorithm",
            "dns replication",
            "date",
            "type name",
            "text",
            "mailpass mixed",
            "redacted for",
            "privacy tech",
            "postal code",
            "server",
            "registrar abuse",
            "code",
            "domain id",
            "iana id",
            "admin country",
            "script urls",
            "a domains",
            "search",
            "status",
            "x fw",
            "record value",
            "for privacy",
            "title",
            "body",
            "unknown",
            "encrypt",
            "log id",
            "gmtn",
            "tls web",
            "ca issuers",
            "timestamp",
            "b715",
            "b59bn timestamp",
            "cc50689e0a",
            "scan endpoints",
            "false",
            "digicert tls",
            "rsa sha256",
            "full name",
            "digicert inc",
            "organization",
            "massachusetts",
            "cambridge",
            "as54113",
            "united",
            "trojan",
            "passive dns",
            "showing",
            "entries",
            "win32",
            "flywheel",
            "sea x",
            "accept",
            "twitter",
            "ransom",
            "meta",
            "urls",
            "all scoreblue",
            "url http",
            "pulse pulses",
            "http",
            "ip address",
            "related nids",
            "files location",
            "nxdomain",
            "whitelisted",
            "cname",
            "aaaa",
            "gandi sas",
            "creation date",
            "emails",
            "avast avg",
            "ipv4",
            "files",
            "location united",
            "ascii text",
            "pattern match",
            "png image",
            "rgba",
            "suricata stream",
            "command decode",
            "size",
            "sha1",
            "mitre att",
            "et tor",
            "hybrid",
            "general",
            "local",
            "click",
            "strings",
            "4624",
            "glox",
            "ck id",
            "suspicious",
            "learn",
            "command",
            "name tactics",
            "informative",
            "ck techniques",
            "development att",
            "adversaries",
            "historical ssl",
            "referrer",
            "copy",
            "typosquat infra",
            "tracker",
            "jekyll",
            "hide",
            "norad tracking",
            "speakez securus",
            "nuance china",
            "phishing",
            "facebook",
            "hiddentear",
            "metro",
            "malware",
            "malicious",
            "skynet",
            "revil",
            "pykspa",
            "next",
            "as44273 host",
            "as7018 att",
            "domain related",
            "hosting",
            "name servers",
            "west domains",
            "asnone germany",
            "singapore",
            "as21499 host",
            "as20940",
            "germany",
            "object",
            "found",
            "domain",
            "files domain",
            "files related",
            "pulses otx",
            "pulses",
            "tags",
            "related tags",
            "win32 exe",
            "pe32",
            "intel",
            "ms windows",
            "win32 dynamic",
            "link library",
            "win16 ne",
            "delphi generic",
            "icons library",
            "pe32 linker",
            "info header",
            "name md5",
            "overlay",
            "dos exe",
            "moved",
            "gmt server",
            "centos",
            "domains",
            "dynadot inc",
            "contacted",
            "ip detections",
            "country",
            "de execution",
            "parents",
            "file type",
            "pulse submit",
            "url analysis",
            "win32heur mar",
            "dynamicloader",
            "medium",
            "qaeaav12",
            "windows",
            "high",
            "show",
            "qbeipbdii",
            "inetsim http",
            "powershell",
            "drweb",
            "write",
            "default",
            "module load",
            "t1129",
            "post http",
            "dock",
            "june",
            "delphi",
            "read c",
            "renos",
            "trojan downloader",
            "social engineering",
            "dns",
            "fraud",
            "cybercrime",
            "stalking",
            "tracking",
            "apple",
            "apple ios",
            "samsung",
            "danger"
          ],
          "references": [
            "https://the initiative.org | Initiative Co.org | chelsea@theinitiativeco.org",
            "Antivirus Detections:: Win.Downloader.103202-1 ,  #LowFiEnableDTContinueAfterUnpacking",
            "IDS Detections: Long Fake wget 3.0 User-Agent Detected Win32.Renos/Artro Trojan Checkin M1 Win32/Renos Checkin 3",
            "IDS Detections: W32/TrojanDownloader.Renos CnC Activity Suspicious User-Agent Malware related Windows wget network_http",
            "Alerts: cape_detected_threat antidebug_devices antivm_generic_disk enumerates_physical_drives deletes_executed_files",
            "Alerts: deletes_self suricata_alert dynamic_function_loading powershell_download powershell_request stealth_window",
            "Alerts: injection_rwx network_cnc_http antidebug_setunhandledexceptionfilter stealth_timeout uses_windows_utilities",
            "https://applemusic-spotlight.myunidays.com/US/en-US?",
            "applemusic-spotlight.myunidays.com | nr-data.net [Apple Private Data Collection] Sabey Data Center",
            "http://borowski-duncan.com/?user-agent=mozilla/5.0+(windows+nt+10.0;+win64;+x64)+applewebkit/537.36+(khtml,+like+gecko)+chrome/86.0.424",
            "http://imap.brooklyngeneration.org/__media__/js/netsoltrademark.php?d=www.fap18pgals.eu/brazilian-porn/",
            "A Jefferson County, Co Police 'advocate' referred target to a group that 'couldn't' to provide services. Referred to The Bench. Unwilling to help",
            "Victim gets a 'social' engineering' call taking every bit of information about victim and case.",
            "She was cleared for treatment; then declined citing a brain injury. Most of 'BB' clients have a TBI",
            "Victim was then given numbers to workers compensation doctors who didn't speak English",
            "Law Firm drops her and asks her who she really is? Victim was assaulted for her phone and other",
            "Victim doesn't fault Police who didn't show intent. Detective did close case, assailant  ID issues",
            "Was told by advocate that his description matches the male in vehicle following her for months.",
            "Be did wear a gator making it improbable for positive identification",
            "She was assaulted for phone 6 weeks after being intentional,y driven off highway",
            "Higher SCI sustained. Positive ID. Driver allowed to walk. Positive License Plate and description of driver with criminal intent.",
            "In the USA she is denied treatment for new injuries to spine causing deep decline. This is crazy.",
            "A series of strange female detectives enter. All corrupt fails. If victim was in prison fight she'd be treated w/guards outside of hospital room door."
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1568",
              "name": "Dynamic Resolution",
              "display_name": "T1568 - Dynamic Resolution"
            },
            {
              "id": "T1583",
              "name": "Acquire Infrastructure",
              "display_name": "T1583 - Acquire Infrastructure"
            },
            {
              "id": "T1071.004",
              "name": "DNS",
              "display_name": "T1071.004 - DNS"
            },
            {
              "id": "T1568.002",
              "name": "Domain Generation Algorithms",
              "display_name": "T1568.002 - Domain Generation Algorithms"
            },
            {
              "id": "T1583.001",
              "name": "Domains",
              "display_name": "T1583.001 - Domains"
            },
            {
              "id": "T1553.002",
              "name": "Code Signing",
              "display_name": "T1553.002 - Code Signing"
            },
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1036.004",
              "name": "Masquerade Task or Service",
              "display_name": "T1036.004 - Masquerade Task or Service"
            },
            {
              "id": "T1031",
              "name": "Modify Existing Service",
              "display_name": "T1031 - Modify Existing Service"
            },
            {
              "id": "T1023",
              "name": "Shortcut Modification",
              "display_name": "T1023 - Shortcut Modification"
            },
            {
              "id": "T1045",
              "name": "Software Packing",
              "display_name": "T1045 - Software Packing"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1060",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1060 - Registry Run Keys / Startup Folder"
            },
            {
              "id": "T1070",
              "name": "Indicator Removal on Host",
              "display_name": "T1070 - Indicator Removal on Host"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1143",
              "name": "Hidden Window",
              "display_name": "T1143 - Hidden Window"
            },
            {
              "id": "T1583.005",
              "name": "Botnet",
              "display_name": "T1583.005 - Botnet"
            },
            {
              "id": "T1584",
              "name": "Compromise Infrastructure",
              "display_name": "T1584 - Compromise Infrastructure"
            },
            {
              "id": "T1122",
              "name": "Component Object Model Hijacking",
              "display_name": "T1122 - Component Object Model Hijacking"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": "66cc6e2c6c5bb617fa7fa892",
          "export_count": 3,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "email": 6,
            "domain": 782,
            "hostname": 530,
            "FileHash-SHA1": 382,
            "FileHash-SHA256": 1572,
            "URL": 847,
            "FileHash-MD5": 386,
            "SSLCertFingerprint": 12
          },
          "indicator_count": 4517,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 48,
          "modified_text": "22 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6952d4fc6910b0b866746d8a",
          "name": ".NET Obfuscator, Error Reporting, DLL Merging | SmartAssembly | Spycloud",
          "description": "*Mirai | Currently being used maliciously. Mirai botnet work in place. Obfuscation, call redirection, evasion , chatbots, spyware , cal retrieval , typosquating , and other tactics used against victim.   Red hats being unethical is expected.. This team is attacking in this instance. Screen Capture 24/7. Malicious media +++ from Englewood, Co. \n\nWhen used ethically SmartAssembly protects your code and Intellectual Property with powerful obfuscation features, and provides error reports when your application crashes in the wild, as well as a range of other tools for database management and data management.\n#palantir #foundry #denver #englewood #colorado #spycloud #mirai #botnet",
          "modified": "2026-01-28T18:03:54.589000",
          "created": "2025-12-29T19:22:36.103000",
          "tags": [
            "no expiration",
            "domain",
            "name",
            "control flow",
            "dlls",
            "method parent",
            "declarative",
            "ms build",
            "core",
            "msie",
            "windows nt",
            "wow64",
            "slcc2",
            "media center",
            "read c",
            "dock",
            "write",
            "execution",
            "capture",
            "endgame",
            "united",
            "moved",
            "ip address",
            "record value",
            "gate software",
            "newnham house",
            "expiration date",
            "urls",
            "url add",
            "http",
            "related nids",
            "files location",
            "flag united",
            "present aug",
            "present sep",
            "present nov",
            "present oct",
            "name servers",
            "emails",
            "present dec",
            "meta",
            "passive dns",
            "next associated",
            "ipv4",
            "url analysis",
            "files",
            "cookie",
            "subscribe",
            "unsubscribe",
            "s paris",
            "englewood",
            "state",
            "skip",
            "espaol",
            "summary",
            "filing history",
            "ireland",
            "title",
            "united states",
            "certificate",
            "colorado",
            "ipv4 add",
            "america flag",
            "showing",
            "pulse submit",
            "size",
            "pattern match",
            "mitre att",
            "ck id",
            "path",
            "hybrid",
            "general",
            "local",
            "iframe",
            "click",
            "strings",
            "cece",
            "mult",
            "learn",
            "name tactics",
            "suspicious",
            "informative",
            "command",
            "adversaries",
            "spawns",
            "t1590 gather",
            "victim network",
            "flag",
            "windir",
            "openurl c",
            "prefetch2",
            "analysis",
            "tor analysis",
            "dns requests",
            "domain address",
            "contacted hosts",
            "sha1",
            "sha256",
            "njmk",
            "kwruymy",
            "mime",
            "submitted",
            "process details",
            "calls",
            "apis",
            "reads",
            "defense evasion",
            "model",
            "getprocaddress",
            "show technique",
            "ck matrix",
            "access type",
            "value",
            "api call",
            "open",
            "august",
            "format",
            "typeof symbol",
            "typeof s",
            "typeof c",
            "function",
            "symbol",
            "comenabled",
            "image path",
            "ndex",
            "ndroleextdll",
            "f0f0f0",
            "ff4b55",
            "stop",
            "span",
            "show process",
            "binary file",
            "file",
            "network traffic",
            "encrypt",
            "date",
            "found",
            "ssl certificate",
            "creation date",
            "hostname add",
            "pulse pulses",
            "files ip",
            "address domain",
            "data upload",
            "extraction",
            "ge6 mira",
            "failed",
            "ascii text",
            "development att",
            "hostname",
            "files domain",
            "files related",
            "pulses otx",
            "pulses",
            "unknown aaaa",
            "unknown ns",
            "united states",
            "urls show",
            "date checked",
            "url hostname",
            "server response",
            "google safe",
            "results may",
            "a domains",
            "search",
            "germany unknown",
            "win32",
            "lowfi",
            "chrome",
            "susp",
            "trojan",
            "backdoor",
            "twitter",
            "virtool",
            "worm",
            "exploit",
            "trojandropper",
            "win32upatre dec",
            "mtb dec",
            "reverse dns",
            "body",
            "location united",
            "asn as14618",
            "less whois",
            "files show",
            "date hash",
            "avast avg",
            "initial access",
            "javascript",
            "root",
            "enterprise",
            "form",
            "desktop",
            "command decode",
            "suricata ipv4",
            "spycloud",
            "robots",
            "bots",
            "chatbot",
            "bot network",
            "spy",
            "mixb",
            "a2fryx",
            "therahand",
            "typosquating"
          ],
          "references": [
            "https://www.red-gate.com/products/smartassembly",
            "spycloud.com \u2022 content.spycloud.com \u2022 email.spycloud.com\t hostname\tengage.spycloud.com \u2022 hello.spycloud.com \u2022portal.spycloud.com \u2022 https://email.spycloud",
            "https://email.spycloud.com/NzEzLVdJUC03MzcAAAGe67eM-W3qxAlVkEvZwfw1dWuwRdm0zVU5aMyOzUe2IkxAY3hDe8RfT27HnjgkvTk-uqIy6K0=",
            "https://spycloud.com/solutions/\t\u2022 104.18.26.108 ELF:Mirai-GH\\ [Trj] \u2022 Unix.Dropper.Mirai-7135870-0",
            "dasima-containers.palantirfoundry.com \u2022 blitzrobots.com",
            "https://blog.endgames.com/ \u2022 wg41xm05b3.endgamesystems.com",
            "https://www.coloradosos.gov/biz/BusinessEntityDetail.do?quitButtonDestination=BusinessEntityResults&nameTyp=ENT&masterFileId=20221473927&entityId2=20221473927&fileId=20251525819&srchTyp=ENTITY",
            "www.onyx-ware.com \u2022 http://pages.endgames.com/ \u2022  http://www.endgamesystems.com/",
            "https://hybrid-analysis.com/sample/9a1e0d38b691f1d22a92cff65ec0439b428170ac39a4493c7ecb06d5585f56a3/68a4adea30f7fafee90aefd3",
            "Malicious: http://developers.cloudfiare.com/support/troubleshooting/http-status-",
            "Typosquating: developers.cloudfiare.com \u2022 cloudfiare.com"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Unix.Dropper.Mirai-7135870-0",
              "display_name": "Unix.Dropper.Mirai-7135870-0",
              "target": null
            },
            {
              "id": "ELF:Mirai-GH\\ [Trj]",
              "display_name": "ELF:Mirai-GH\\ [Trj]",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1090",
              "name": "Proxy",
              "display_name": "T1090 - Proxy"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1127",
              "name": "Trusted Developer Utilities Proxy Execution",
              "display_name": "T1127 - Trusted Developer Utilities Proxy Execution"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1560",
              "name": "Archive Collected Data",
              "display_name": "T1560 - Archive Collected Data"
            },
            {
              "id": "T1053",
              "name": "Scheduled Task/Job",
              "display_name": "T1053 - Scheduled Task/Job"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1056",
              "name": "Input Capture",
              "display_name": "T1056 - Input Capture"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1119",
              "name": "Automated Collection",
              "display_name": "T1119 - Automated Collection"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1143",
              "name": "Hidden Window",
              "display_name": "T1143 - Hidden Window"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1069",
              "name": "Permission Groups Discovery",
              "display_name": "T1069 - Permission Groups Discovery"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1480",
              "name": "Execution Guardrails",
              "display_name": "T1480 - Execution Guardrails"
            },
            {
              "id": "T1568",
              "name": "Dynamic Resolution",
              "display_name": "T1568 - Dynamic Resolution"
            },
            {
              "id": "T1583",
              "name": "Acquire Infrastructure",
              "display_name": "T1583 - Acquire Infrastructure"
            },
            {
              "id": "T1590",
              "name": "Gather Victim Network Information",
              "display_name": "T1590 - Gather Victim Network Information"
            },
            {
              "id": "T1113",
              "name": "Screen Capture",
              "display_name": "T1113 - Screen Capture"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1583.001",
              "name": "Domains",
              "display_name": "T1583.001 - Domains"
            },
            {
              "id": "T1553.002",
              "name": "Code Signing",
              "display_name": "T1553.002 - Code Signing"
            },
            {
              "id": "T1069.002",
              "name": "Domain Groups",
              "display_name": "T1069.002 - Domain Groups"
            },
            {
              "id": "T1568.002",
              "name": "Domain Generation Algorithms",
              "display_name": "T1568.002 - Domain Generation Algorithms"
            },
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1071.004",
              "name": "DNS",
              "display_name": "T1071.004 - DNS"
            },
            {
              "id": "T1003",
              "name": "OS Credential Dumping",
              "display_name": "T1003 - OS Credential Dumping"
            },
            {
              "id": "T1007",
              "name": "System Service Discovery",
              "display_name": "T1007 - System Service Discovery"
            },
            {
              "id": "T1010",
              "name": "Application Window Discovery",
              "display_name": "T1010 - Application Window Discovery"
            },
            {
              "id": "T1012",
              "name": "Query Registry",
              "display_name": "T1012 - Query Registry"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1068",
              "name": "Exploitation for Privilege Escalation",
              "display_name": "T1068 - Exploitation for Privilege Escalation"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1546",
              "name": "Event Triggered Execution",
              "display_name": "T1546 - Event Triggered Execution"
            },
            {
              "id": "T1562",
              "name": "Impair Defenses",
              "display_name": "T1562 - Impair Defenses"
            },
            {
              "id": "T1614",
              "name": "System Location Discovery",
              "display_name": "T1614 - System Location Discovery"
            },
            {
              "id": "T1122",
              "name": "Component Object Model Hijacking",
              "display_name": "T1122 - Component Object Model Hijacking"
            },
            {
              "id": "T1415",
              "name": "URL Scheme Hijacking",
              "display_name": "T1415 - URL Scheme Hijacking"
            },
            {
              "id": "T1416",
              "name": "URI Hijacking",
              "display_name": "T1416 - URI Hijacking"
            },
            {
              "id": "T1059.007",
              "name": "JavaScript",
              "display_name": "T1059.007 - JavaScript"
            },
            {
              "id": "T1584.005",
              "name": "Botnet",
              "display_name": "T1584.005 - Botnet"
            },
            {
              "id": "T1189",
              "name": "Drive-by Compromise",
              "display_name": "T1189 - Drive-by Compromise"
            },
            {
              "id": "T1204",
              "name": "User Execution",
              "display_name": "T1204 - User Execution"
            },
            {
              "id": "T1562.001",
              "name": "Disable or Modify Tools",
              "display_name": "T1562.001 - Disable or Modify Tools"
            },
            {
              "id": "T1116",
              "name": "Code Signing",
              "display_name": "T1116 - Code Signing"
            },
            {
              "id": "T1546.015",
              "name": "Component Object Model Hijacking",
              "display_name": "T1546.015 - Component Object Model Hijacking"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1014",
              "name": "Rootkit",
              "display_name": "T1014 - Rootkit"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 3,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Q.Vashti",
            "id": "337942",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 341,
            "FileHash-SHA1": 343,
            "FileHash-SHA256": 1332,
            "domain": 1062,
            "hostname": 1967,
            "URL": 5699,
            "email": 10,
            "SSLCertFingerprint": 21,
            "CVE": 1
          },
          "indicator_count": 10776,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 138,
          "modified_text": "81 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "69519fa818f84531ce6becc9",
          "name": "Cart.Guru Malware Hosting - Malware Packed _Pegasus Espionage Detected (Positive)",
          "description": "I really love using this tool (LevelBlue -OTX) In all reality this information would have been sent to the government. CISA , NSA, Homeland Security, Citizens Lab, Canada based international organization would have been involved years ago. Where does this information goes. Citizens Lab would has been attempting to track 1000\u2019s of affected Pegasus targets. OTX detected and tagged Pegasus. I suspected it. This is from a Palantir Malware Hosting Honey Pot. \n\nWhen Pegasus was discovered in the wild , credited to those who found what the real team (T8) found, Citizens Lab then conducted tests in 2021\non the cell phone of Jamal Khashoggi, a Saudi dissident journalist. Pegasus is a kill list. \n\nVictims need help. There are a few people even on this platform that are on this list. Unless it\u2019s the US government who has ordered these actions, I don\u2019t know what is going on. The targets are not only innocent, some are crime victims, some are going mad. AT&T corporate easily confirms LevelBlue is legitimate.",
          "modified": "2026-01-27T21:02:45.343000",
          "created": "2025-12-28T21:22:48.383000",
          "tags": [
            "united",
            "servers",
            "moved",
            "ip address",
            "record value",
            "encrypt",
            "present jul",
            "present jun",
            "trojandropper",
            "passive dns",
            "ipv4 add",
            "urls",
            "files",
            "virtool",
            "united states",
            "dynamicloader",
            "directui",
            "element",
            "classinfobase",
            "write c",
            "medium",
            "yara rule",
            "msvisualbasic60",
            "high",
            "hwndelement",
            "explorer",
            "write",
            "movie",
            "insert",
            "program",
            "python",
            "http traffic",
            "trojan generic",
            "search",
            "cnc activity",
            "delphi",
            "win32",
            "launcher",
            "pony",
            "fareit",
            "malware",
            "push",
            "msie",
            "windows nt",
            "generic",
            "checkin",
            "post",
            "yara detections",
            "rxr",
            "inject",
            "memcommit",
            "cryptexportkey",
            "invalid pointer",
            "regsetvalueexa",
            "solutions ltd",
            "read c",
            "regdword",
            "mozilla",
            "persistence",
            "execution",
            "android",
            "unknown",
            "learn",
            "suspicious",
            "informative",
            "adversaries",
            "ck id",
            "name tactics",
            "command",
            "initial access",
            "defense evasion",
            "spawns",
            "t1590 gather",
            "flag",
            "click",
            "windir",
            "openurl c",
            "prefetch2",
            "analysis",
            "tor analysis",
            "dns requests",
            "domain address",
            "pattern match",
            "mitre att",
            "ck matrix",
            "href",
            "ascii text",
            "starfield",
            "hybrid",
            "general",
            "local",
            "path",
            "iframe",
            "palantir",
            "present nov",
            "present oct",
            "status",
            "present apr",
            "present dec",
            "cryp",
            "date",
            "trojan",
            "title",
            "name servers",
            "windows",
            "t1060",
            "disables proxy",
            "dock",
            "pegasus",
            "rootkit",
            "backdoor",
            "susp",
            "win32qqpass feb",
            "worm",
            "msr win32",
            "win64",
            "process32nextw",
            "findwindowa",
            "file execution",
            "writeconsolea",
            "procexpl",
            "file v2",
            "document",
            "document file",
            "v2 document",
            "lost",
            "tools",
            "pecompact",
            "media",
            "autorun",
            "service",
            "post http",
            "delete",
            "alerts",
            "emotet",
            "rkt",
            "autorun",
            "worm",
            "plugins",
            "title error",
            "body doctype",
            "html public",
            "w3cdtd html",
            "html head",
            "domain",
            "expiration date",
            "hostname add",
            "pulse pulses",
            "contacted hosts",
            "sha1",
            "sha256",
            "show technique",
            "strings",
            "t1480 execution",
            "signing defense",
            "script urls",
            "a domains",
            "unknown ns",
            "texas flyover",
            "script domains",
            "script script",
            "meta",
            "window",
            "process details",
            "contacted"
          ],
          "references": [
            "Cart.Guru",
            "Yara Detections: Delphi",
            "Chekin -Fareit/Pony Downloader Checkin 2 \u2022 Generic - POST To gate.php with no referer",
            "MSIL/Injector.RXR Variant CnC Activity Trojanr Generic - POST To gate.php with no referer",
            "HTTP traffic on port 443 (POST)",
            "IDS Detections Observed Suspicious UA (NSIS_Inetc (Mozilla)) Observed DNS Query",
            "Alerts: crime_win_cutwail_stage2  infostealer_browser infostealer_cookies recon_programs",
            "Alerts: banker_zeus_url procmem_yara suricata_alert infostealer_ftp dynamic_function_loading reads_self network_cnc_http",
            "Alerts: network_icmp persistence_autorun deletes_executed_files modifies_certificates",
            "Alerts: ransomware_dropped_files dumped_buffer network_cnc_http network_http",
            "Alerts: network_http_post allocates_rwx antisandbox_sleep antivm_disk_size creates_exe",
            "Alerts: exe_appdata antivm_network_adapters network_downloader_exe privilege_luid_check",
            "Alerts: checks_debugger generates_crypto_key modifies_proxy_wpad",
            "Yara Detections:  Nullsoft_NSIS    ...",
            "Win32:Evo-gen\\ [Susp] http://downwingbuttons.site/7/huge.dat",
            "Small: Win32:Malware-gen (Small) Yara Detections stack_string \u2022 Domains Contacted: amazon.com",
            "Small_Yara:   IP\u2019s Contacted  176.32.103.205  205.251.242.103",
            "Small_Alerts: persistence_autorun disables_proxy removes_zoneid_ads allocates_rwx",
            "Small _Alerts: antisandbox_foregroundwindows suspicious_process stealth_window packer_entropy",
            "Emotet IDS Detections: Win32/Emotet CnC Checkin Response",
            "Emotet Yara: Yara Detections ConventionEngine_Term_Desktop ,  ConventionEngine_Term_Users"
          ],
          "public": 1,
          "adversary": "Palantir Pegasus",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "RXR",
              "display_name": "RXR",
              "target": null
            },
            {
              "id": "Pony",
              "display_name": "Pony",
              "target": null
            },
            {
              "id": "VirTool:Win32/Obfuscator",
              "display_name": "VirTool:Win32/Obfuscator",
              "target": "/malware/VirTool:Win32/Obfuscator"
            },
            {
              "id": "Trojan:Win32/Bagsu!rfn",
              "display_name": "Trojan:Win32/Bagsu!rfn",
              "target": "/malware/Trojan:Win32/Bagsu!rfn"
            },
            {
              "id": "#LowFiEnableDTContinueAfterUnpacking",
              "display_name": "#LowFiEnableDTContinueAfterUnpacking",
              "target": null
            },
            {
              "id": "Win32:MalOb-BX\\ [Cryp]",
              "display_name": "Win32:MalOb-BX\\ [Cryp]",
              "target": null
            },
            {
              "id": "TrojanDownloader:Win32/Cutwail",
              "display_name": "TrojanDownloader:Win32/Cutwail",
              "target": "/malware/TrojanDownloader:Win32/Cutwail"
            },
            {
              "id": "#Lowfi:Win32/SandboxProductId",
              "display_name": "#Lowfi:Win32/SandboxProductId",
              "target": "/malware/#Lowfi:Win32/SandboxProductId"
            },
            {
              "id": "Win32:Backdoor",
              "display_name": "Win32:Backdoor",
              "target": null
            },
            {
              "id": "Tofsee",
              "display_name": "Tofsee",
              "target": null
            },
            {
              "id": "Win32:Evo-gen\\ [Susp]",
              "display_name": "Win32:Evo-gen\\ [Susp]",
              "target": null
            },
            {
              "id": "ALF:Trojan:MSIL/BlackFus.C",
              "display_name": "ALF:Trojan:MSIL/BlackFus.C",
              "target": null
            },
            {
              "id": "Win32:Malware",
              "display_name": "Win32:Malware",
              "target": null
            },
            {
              "id": "TrojanProxy:Win32/Ceutv.A",
              "display_name": "TrojanProxy:Win32/Ceutv.A",
              "target": "/malware/TrojanProxy:Win32/Ceutv.A"
            },
            {
              "id": "VirTool:Win32/Obfuscator.AHU",
              "display_name": "VirTool:Win32/Obfuscator.AHU",
              "target": "/malware/VirTool:Win32/Obfuscator.AHU"
            },
            {
              "id": "ShellCode",
              "display_name": "ShellCode",
              "target": null
            },
            {
              "id": "Win32:Rootkit",
              "display_name": "Win32:Rootkit",
              "target": null
            },
            {
              "id": "VB Flash",
              "display_name": "VB Flash",
              "target": null
            },
            {
              "id": "Worm:Win32/Autorun",
              "display_name": "Worm:Win32/Autorun",
              "target": "/malware/Worm:Win32/Autorun"
            },
            {
              "id": "Win.Packed.Razy-6847895-0",
              "display_name": "Win.Packed.Razy-6847895-0",
              "target": null
            },
            {
              "id": "Backdoor:Win32/Plugx.N!",
              "display_name": "Backdoor:Win32/Plugx.N!",
              "target": "/malware/Backdoor:Win32/Plugx.N!"
            },
            {
              "id": "Win.Dropper.QQpass-7194329-0",
              "display_name": "Win.Dropper.QQpass-7194329-0",
              "target": null
            },
            {
              "id": "Trojan:Win32/QQpass",
              "display_name": "Trojan:Win32/QQpass",
              "target": "/malware/Trojan:Win32/QQpass"
            },
            {
              "id": "Win32:Agent",
              "display_name": "Win32:Agent",
              "target": null
            },
            {
              "id": "Win.Trojan.Agent",
              "display_name": "Win.Trojan.Agent",
              "target": null
            },
            {
              "id": "Win.Trojan.Emotet-7545664-0",
              "display_name": "Win.Trojan.Emotet-7545664-0",
              "target": null
            },
            {
              "id": "Pegasus - MOB-S0005",
              "display_name": "Pegasus - MOB-S0005",
              "target": null
            },
            {
              "id": "Pegasus",
              "display_name": "Pegasus",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1045",
              "name": "Software Packing",
              "display_name": "T1045 - Software Packing"
            },
            {
              "id": "T1119",
              "name": "Automated Collection",
              "display_name": "T1119 - Automated Collection"
            },
            {
              "id": "T1040",
              "name": "Network Sniffing",
              "display_name": "T1040 - Network Sniffing"
            },
            {
              "id": "T1053",
              "name": "Scheduled Task/Job",
              "display_name": "T1053 - Scheduled Task/Job"
            },
            {
              "id": "T1060",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1060 - Registry Run Keys / Startup Folder"
            },
            {
              "id": "T1070",
              "name": "Indicator Removal on Host",
              "display_name": "T1070 - Indicator Removal on Host"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1112",
              "name": "Modify Registry",
              "display_name": "T1112 - Modify Registry"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1069",
              "name": "Permission Groups Discovery",
              "display_name": "T1069 - Permission Groups Discovery"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1480",
              "name": "Execution Guardrails",
              "display_name": "T1480 - Execution Guardrails"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1562",
              "name": "Impair Defenses",
              "display_name": "T1562 - Impair Defenses"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1568",
              "name": "Dynamic Resolution",
              "display_name": "T1568 - Dynamic Resolution"
            },
            {
              "id": "T1583",
              "name": "Acquire Infrastructure",
              "display_name": "T1583 - Acquire Infrastructure"
            },
            {
              "id": "T1590",
              "name": "Gather Victim Network Information",
              "display_name": "T1590 - Gather Victim Network Information"
            },
            {
              "id": "T1562.001",
              "name": "Disable or Modify Tools",
              "display_name": "T1562.001 - Disable or Modify Tools"
            },
            {
              "id": "T1553.002",
              "name": "Code Signing",
              "display_name": "T1553.002 - Code Signing"
            },
            {
              "id": "T1069.002",
              "name": "Domain Groups",
              "display_name": "T1069.002 - Domain Groups"
            },
            {
              "id": "T1071.004",
              "name": "DNS",
              "display_name": "T1071.004 - DNS"
            },
            {
              "id": "T1568.002",
              "name": "Domain Generation Algorithms",
              "display_name": "T1568.002 - Domain Generation Algorithms"
            },
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1584.005",
              "name": "Botnet",
              "display_name": "T1584.005 - Botnet"
            },
            {
              "id": "T1096",
              "name": "NTFS File Attributes",
              "display_name": "T1096 - NTFS File Attributes"
            },
            {
              "id": "T1143",
              "name": "Hidden Window",
              "display_name": "T1143 - Hidden Window"
            },
            {
              "id": "T1014",
              "name": "Rootkit",
              "display_name": "T1014 - Rootkit"
            },
            {
              "id": "T1054",
              "name": "Indicator Blocking",
              "display_name": "T1054 - Indicator Blocking"
            },
            {
              "id": "T1089",
              "name": "Disabling Security Tools",
              "display_name": "T1089 - Disabling Security Tools"
            },
            {
              "id": "T1091",
              "name": "Replication Through Removable Media",
              "display_name": "T1091 - Replication Through Removable Media"
            },
            {
              "id": "T1158",
              "name": "Hidden Files and Directories",
              "display_name": "T1158 - Hidden Files and Directories"
            },
            {
              "id": "T1031",
              "name": "Modify Existing Service",
              "display_name": "T1031 - Modify Existing Service"
            },
            {
              "id": "T1113",
              "name": "Screen Capture",
              "display_name": "T1113 - Screen Capture"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 19,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Q.Vashti",
            "id": "337942",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 2362,
            "domain": 449,
            "hostname": 710,
            "email": 6,
            "FileHash-MD5": 260,
            "FileHash-SHA1": 201,
            "FileHash-SHA256": 333,
            "SSLCertFingerprint": 27
          },
          "indicator_count": 4348,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 140,
          "modified_text": "81 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "69519fa81048ad057eb9beaa",
          "name": "Cart.Guru Malware Hosting - Malware Packed _Pegasus Espionage Detected (Positive)",
          "description": "I really love using this tool (LevelBlue -OTX) In all reality this information would have been sent to the government. CISA , NSA, Homeland Security, Citizens Lab, Canada based international organization would have been involved years ago. | \nWhere does this information goes. Citizens Lab would has been attempting to track 1000\u2019s of affected Pegasus targets. OTX detected and tagged Pegasus. I suspected it. This is from a Palantir Malware Hosting Honey Pot. \n\nWhen Pegasus was discovered in the wild , credited to those who found what the real team (T8) found, Citizens Lab then conducted tests in 2021\non the cell phone of Jamal Khashoggi, a Saudi dissident journalist. Pegasus is a kill list. \n\nVictims need help. There are a few people even on this platform that are on this list. Unless it\u2019s the US government who has ordered these actions, I don\u2019t know what is going on. The targets are not only innocent, some are crime victims, some are going mad. AT&T corporate easily confirms LevelBlue is legitimate.",
          "modified": "2026-01-27T21:02:45.343000",
          "created": "2025-12-28T21:22:48.595000",
          "tags": [
            "united",
            "servers",
            "moved",
            "ip address",
            "record value",
            "encrypt",
            "present jul",
            "present jun",
            "trojandropper",
            "passive dns",
            "ipv4 add",
            "urls",
            "files",
            "virtool",
            "united states",
            "dynamicloader",
            "directui",
            "element",
            "classinfobase",
            "write c",
            "medium",
            "yara rule",
            "msvisualbasic60",
            "high",
            "hwndelement",
            "explorer",
            "write",
            "movie",
            "insert",
            "program",
            "python",
            "http traffic",
            "trojan generic",
            "search",
            "cnc activity",
            "delphi",
            "win32",
            "launcher",
            "pony",
            "fareit",
            "malware",
            "push",
            "msie",
            "windows nt",
            "generic",
            "checkin",
            "post",
            "yara detections",
            "rxr",
            "inject",
            "memcommit",
            "cryptexportkey",
            "invalid pointer",
            "regsetvalueexa",
            "solutions ltd",
            "read c",
            "regdword",
            "mozilla",
            "persistence",
            "execution",
            "android",
            "unknown",
            "learn",
            "suspicious",
            "informative",
            "adversaries",
            "ck id",
            "name tactics",
            "command",
            "initial access",
            "defense evasion",
            "spawns",
            "t1590 gather",
            "flag",
            "click",
            "windir",
            "openurl c",
            "prefetch2",
            "analysis",
            "tor analysis",
            "dns requests",
            "domain address",
            "pattern match",
            "mitre att",
            "ck matrix",
            "href",
            "ascii text",
            "starfield",
            "hybrid",
            "general",
            "local",
            "path",
            "iframe",
            "palantir",
            "present nov",
            "present oct",
            "status",
            "present apr",
            "present dec",
            "cryp",
            "date",
            "trojan",
            "title",
            "name servers",
            "windows",
            "t1060",
            "disables proxy",
            "dock",
            "pegasus",
            "rootkit",
            "backdoor",
            "susp",
            "win32qqpass feb",
            "worm",
            "msr win32",
            "win64",
            "process32nextw",
            "findwindowa",
            "file execution",
            "writeconsolea",
            "procexpl",
            "file v2",
            "document",
            "document file",
            "v2 document",
            "lost",
            "tools",
            "pecompact",
            "media",
            "autorun",
            "service",
            "post http",
            "delete",
            "alerts",
            "emotet",
            "rkt",
            "autorun",
            "worm",
            "plugins",
            "title error",
            "body doctype",
            "html public",
            "w3cdtd html",
            "html head",
            "domain",
            "expiration date",
            "hostname add",
            "pulse pulses",
            "contacted hosts",
            "sha1",
            "sha256",
            "show technique",
            "strings",
            "t1480 execution",
            "signing defense",
            "script urls",
            "a domains",
            "unknown ns",
            "texas flyover",
            "script domains",
            "script script",
            "meta",
            "window",
            "process details",
            "contacted"
          ],
          "references": [
            "Cart.Guru",
            "Yara Detections: Delphi",
            "Chekin -Fareit/Pony Downloader Checkin 2 \u2022 Generic - POST To gate.php with no referer",
            "MSIL/Injector.RXR Variant CnC Activity Trojanr Generic - POST To gate.php with no referer",
            "HTTP traffic on port 443 (POST)",
            "IDS Detections Observed Suspicious UA (NSIS_Inetc (Mozilla)) Observed DNS Query",
            "Alerts: crime_win_cutwail_stage2  infostealer_browser infostealer_cookies recon_programs",
            "Alerts: banker_zeus_url procmem_yara suricata_alert infostealer_ftp dynamic_function_loading reads_self network_cnc_http",
            "Alerts: network_icmp persistence_autorun deletes_executed_files modifies_certificates",
            "Alerts: ransomware_dropped_files dumped_buffer network_cnc_http network_http",
            "Alerts: network_http_post allocates_rwx antisandbox_sleep antivm_disk_size creates_exe",
            "Alerts: exe_appdata antivm_network_adapters network_downloader_exe privilege_luid_check",
            "Alerts: checks_debugger generates_crypto_key modifies_proxy_wpad",
            "Yara Detections:  Nullsoft_NSIS    ...",
            "Win32:Evo-gen\\ [Susp] http://downwingbuttons.site/7/huge.dat",
            "Small: Win32:Malware-gen (Small) Yara Detections stack_string \u2022 Domains Contacted: amazon.com",
            "Small_Yara:   IP\u2019s Contacted  176.32.103.205  205.251.242.103",
            "Small_Alerts: persistence_autorun disables_proxy removes_zoneid_ads allocates_rwx",
            "Small _Alerts: antisandbox_foregroundwindows suspicious_process stealth_window packer_entropy",
            "Emotet IDS Detections: Win32/Emotet CnC Checkin Response",
            "Emotet Yara: Yara Detections ConventionEngine_Term_Desktop ,  ConventionEngine_Term_Users"
          ],
          "public": 1,
          "adversary": "Palantir Pegasus",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "RXR",
              "display_name": "RXR",
              "target": null
            },
            {
              "id": "Pony",
              "display_name": "Pony",
              "target": null
            },
            {
              "id": "VirTool:Win32/Obfuscator",
              "display_name": "VirTool:Win32/Obfuscator",
              "target": "/malware/VirTool:Win32/Obfuscator"
            },
            {
              "id": "Trojan:Win32/Bagsu!rfn",
              "display_name": "Trojan:Win32/Bagsu!rfn",
              "target": "/malware/Trojan:Win32/Bagsu!rfn"
            },
            {
              "id": "#LowFiEnableDTContinueAfterUnpacking",
              "display_name": "#LowFiEnableDTContinueAfterUnpacking",
              "target": null
            },
            {
              "id": "Win32:MalOb-BX\\ [Cryp]",
              "display_name": "Win32:MalOb-BX\\ [Cryp]",
              "target": null
            },
            {
              "id": "TrojanDownloader:Win32/Cutwail",
              "display_name": "TrojanDownloader:Win32/Cutwail",
              "target": "/malware/TrojanDownloader:Win32/Cutwail"
            },
            {
              "id": "#Lowfi:Win32/SandboxProductId",
              "display_name": "#Lowfi:Win32/SandboxProductId",
              "target": "/malware/#Lowfi:Win32/SandboxProductId"
            },
            {
              "id": "Win32:Backdoor",
              "display_name": "Win32:Backdoor",
              "target": null
            },
            {
              "id": "Tofsee",
              "display_name": "Tofsee",
              "target": null
            },
            {
              "id": "Win32:Evo-gen\\ [Susp]",
              "display_name": "Win32:Evo-gen\\ [Susp]",
              "target": null
            },
            {
              "id": "ALF:Trojan:MSIL/BlackFus.C",
              "display_name": "ALF:Trojan:MSIL/BlackFus.C",
              "target": null
            },
            {
              "id": "Win32:Malware",
              "display_name": "Win32:Malware",
              "target": null
            },
            {
              "id": "TrojanProxy:Win32/Ceutv.A",
              "display_name": "TrojanProxy:Win32/Ceutv.A",
              "target": "/malware/TrojanProxy:Win32/Ceutv.A"
            },
            {
              "id": "VirTool:Win32/Obfuscator.AHU",
              "display_name": "VirTool:Win32/Obfuscator.AHU",
              "target": "/malware/VirTool:Win32/Obfuscator.AHU"
            },
            {
              "id": "ShellCode",
              "display_name": "ShellCode",
              "target": null
            },
            {
              "id": "Win32:Rootkit",
              "display_name": "Win32:Rootkit",
              "target": null
            },
            {
              "id": "VB Flash",
              "display_name": "VB Flash",
              "target": null
            },
            {
              "id": "Worm:Win32/Autorun",
              "display_name": "Worm:Win32/Autorun",
              "target": "/malware/Worm:Win32/Autorun"
            },
            {
              "id": "Win.Packed.Razy-6847895-0",
              "display_name": "Win.Packed.Razy-6847895-0",
              "target": null
            },
            {
              "id": "Backdoor:Win32/Plugx.N!",
              "display_name": "Backdoor:Win32/Plugx.N!",
              "target": "/malware/Backdoor:Win32/Plugx.N!"
            },
            {
              "id": "Win.Dropper.QQpass-7194329-0",
              "display_name": "Win.Dropper.QQpass-7194329-0",
              "target": null
            },
            {
              "id": "Trojan:Win32/QQpass",
              "display_name": "Trojan:Win32/QQpass",
              "target": "/malware/Trojan:Win32/QQpass"
            },
            {
              "id": "Win32:Agent",
              "display_name": "Win32:Agent",
              "target": null
            },
            {
              "id": "Win.Trojan.Agent",
              "display_name": "Win.Trojan.Agent",
              "target": null
            },
            {
              "id": "Win.Trojan.Emotet-7545664-0",
              "display_name": "Win.Trojan.Emotet-7545664-0",
              "target": null
            },
            {
              "id": "Pegasus - MOB-S0005",
              "display_name": "Pegasus - MOB-S0005",
              "target": null
            },
            {
              "id": "Pegasus",
              "display_name": "Pegasus",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1045",
              "name": "Software Packing",
              "display_name": "T1045 - Software Packing"
            },
            {
              "id": "T1119",
              "name": "Automated Collection",
              "display_name": "T1119 - Automated Collection"
            },
            {
              "id": "T1040",
              "name": "Network Sniffing",
              "display_name": "T1040 - Network Sniffing"
            },
            {
              "id": "T1053",
              "name": "Scheduled Task/Job",
              "display_name": "T1053 - Scheduled Task/Job"
            },
            {
              "id": "T1060",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1060 - Registry Run Keys / Startup Folder"
            },
            {
              "id": "T1070",
              "name": "Indicator Removal on Host",
              "display_name": "T1070 - Indicator Removal on Host"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1112",
              "name": "Modify Registry",
              "display_name": "T1112 - Modify Registry"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1069",
              "name": "Permission Groups Discovery",
              "display_name": "T1069 - Permission Groups Discovery"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1480",
              "name": "Execution Guardrails",
              "display_name": "T1480 - Execution Guardrails"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1562",
              "name": "Impair Defenses",
              "display_name": "T1562 - Impair Defenses"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1568",
              "name": "Dynamic Resolution",
              "display_name": "T1568 - Dynamic Resolution"
            },
            {
              "id": "T1583",
              "name": "Acquire Infrastructure",
              "display_name": "T1583 - Acquire Infrastructure"
            },
            {
              "id": "T1590",
              "name": "Gather Victim Network Information",
              "display_name": "T1590 - Gather Victim Network Information"
            },
            {
              "id": "T1562.001",
              "name": "Disable or Modify Tools",
              "display_name": "T1562.001 - Disable or Modify Tools"
            },
            {
              "id": "T1553.002",
              "name": "Code Signing",
              "display_name": "T1553.002 - Code Signing"
            },
            {
              "id": "T1069.002",
              "name": "Domain Groups",
              "display_name": "T1069.002 - Domain Groups"
            },
            {
              "id": "T1071.004",
              "name": "DNS",
              "display_name": "T1071.004 - DNS"
            },
            {
              "id": "T1568.002",
              "name": "Domain Generation Algorithms",
              "display_name": "T1568.002 - Domain Generation Algorithms"
            },
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1584.005",
              "name": "Botnet",
              "display_name": "T1584.005 - Botnet"
            },
            {
              "id": "T1096",
              "name": "NTFS File Attributes",
              "display_name": "T1096 - NTFS File Attributes"
            },
            {
              "id": "T1143",
              "name": "Hidden Window",
              "display_name": "T1143 - Hidden Window"
            },
            {
              "id": "T1014",
              "name": "Rootkit",
              "display_name": "T1014 - Rootkit"
            },
            {
              "id": "T1054",
              "name": "Indicator Blocking",
              "display_name": "T1054 - Indicator Blocking"
            },
            {
              "id": "T1089",
              "name": "Disabling Security Tools",
              "display_name": "T1089 - Disabling Security Tools"
            },
            {
              "id": "T1091",
              "name": "Replication Through Removable Media",
              "display_name": "T1091 - Replication Through Removable Media"
            },
            {
              "id": "T1158",
              "name": "Hidden Files and Directories",
              "display_name": "T1158 - Hidden Files and Directories"
            },
            {
              "id": "T1031",
              "name": "Modify Existing Service",
              "display_name": "T1031 - Modify Existing Service"
            },
            {
              "id": "T1113",
              "name": "Screen Capture",
              "display_name": "T1113 - Screen Capture"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 18,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 1,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Q.Vashti",
            "id": "337942",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 2362,
            "domain": 449,
            "hostname": 710,
            "email": 6,
            "FileHash-MD5": 260,
            "FileHash-SHA1": 201,
            "FileHash-SHA256": 333,
            "SSLCertFingerprint": 27
          },
          "indicator_count": 4348,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 140,
          "modified_text": "81 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6892e73b32af18aa302df0dc",
          "name": "Part 1.5",
          "description": "Dark web media \u2022 Political news \u2022 Malvertizing\nlocate \u2022\ntrack [stalk] \u2022 record calls \u2022 control media [youtube , etc] http://t.name?n[++i]=e:this.removeEventListener\t\t\nJeeng &\nPowebox [ accidentally left out in original post pulse]",
          "modified": "2025-09-05T04:03:06.929000",
          "created": "2025-08-06T05:25:15.369000",
          "tags": [
            "chromeua",
            "optout",
            "object",
            "path",
            "value",
            "access type",
            "setval",
            "windir",
            "localappdata",
            "null",
            "win64",
            "error",
            "generator",
            "close",
            "roboto",
            "date",
            "format",
            "light",
            "span",
            "template",
            "void",
            "android",
            "body",
            "trident",
            "mexico",
            "sonic",
            "black",
            "critical",
            "desktop",
            "dark",
            "meta",
            "this",
            "june",
            "hybrid",
            "apache",
            "write",
            "crypto",
            "autodetect",
            "face",
            "courier",
            "gigi",
            "impact",
            "shadow",
            "click",
            "strings",
            "cray",
            "smwg",
            "eret",
            "footer",
            "infinity",
            "window",
            "canvas",
            "legend",
            "nuke",
            "lion",
            "4629",
            "ahav",
            "olsa",
            "false",
            "learn",
            "command",
            "ck id",
            "name tactics",
            "suspicious",
            "informative",
            "spawns",
            "defense evasion",
            "t1480 execution",
            "file defense",
            "copy md5",
            "copy sha1",
            "copy sha256",
            "sha1",
            "sha256",
            "script",
            "mitre att",
            "pattern match",
            "show technique",
            "iframe",
            "refresh",
            "august",
            "general",
            "local",
            "tools",
            "demo",
            "look",
            "verify",
            "restart",
            "url http",
            "small",
            "pulses url",
            "tellyoun",
            "showing",
            "entries",
            "url https",
            "indicator role",
            "title added",
            "active related",
            "type indicator",
            "role title",
            "added active",
            "related pulses",
            "cc08",
            "f06a6b",
            "sfurl",
            "filehashsha256",
            "types",
            "indicators show",
            "search",
            "pulses",
            "filehashsha1",
            "adversaries",
            "found",
            "webp image",
            "ascii text",
            "riff",
            "size",
            "encrypt",
            "legacy",
            "filehashmd5",
            "united",
            "flag",
            "server",
            "markmonitor",
            "name server",
            "llc name",
            "overview dns",
            "requests domain",
            "country",
            "win32",
            "av detections",
            "ids detections",
            "yara detections",
            "alerts",
            "analysis date",
            "file score",
            "medium risk",
            "yara",
            "detections",
            "malware",
            "copy",
            "show",
            "icmp traffic",
            "packing t1045",
            "t1045",
            "pdb path",
            "pe resource",
            "extraction",
            "data upload",
            "enter sc",
            "type",
            "extra data",
            "please",
            "failed",
            "review",
            "exclude data",
            "included review",
            "ic data",
            "suggeste",
            "stop",
            "type onow",
            "domain",
            "passive dns",
            "urls",
            "files related",
            "pulses none",
            "related tags",
            "none google",
            "safe browsing",
            "sc data",
            "extr amanuav",
            "review included",
            "manualy",
            "sugges excluded",
            "filehash",
            "md5 add",
            "pulse pulses",
            "url add",
            "http",
            "hostname",
            "files domain",
            "pulses otx",
            "virustotal",
            "hsmi192547107",
            "pulses hostname",
            "r dec",
            "customer dec",
            "iski dec",
            "decision dec",
            "va dec",
            "bitcoin",
            "bitcoin dec",
            "petra",
            "torstatus dec",
            "paul dec",
            "sodesc",
            "planet dec",
            "emilia",
            "heroin dec",
            "difference dec",
            "palantir dec",
            "loraxlive dec",
            "chaturbate dec",
            "sandra",
            "free dec",
            "marvel dec",
            "benjis dec",
            "fresh dec",
            "sodesc dec",
            "srdirport",
            "srhostname",
            "link dec",
            "types of",
            "italy",
            "china",
            "australia",
            "france",
            "turkey",
            "discovery",
            "information",
            "ck ids",
            "t1005",
            "local system",
            "t1007",
            "system service",
            "part",
            "track",
            "locate",
            "political",
            "civil society",
            "news",
            "created",
            "hours ago",
            "report spam",
            "t1555",
            "password",
            "t1560",
            "collected data",
            "t1573",
            "channel",
            "t1574",
            "execution flow",
            "scan",
            "iocs",
            "t1497",
            "u0lhmq",
            "mtawmq",
            "t1480",
            "guardrails",
            "t1486",
            "data encrypted",
            "learn more",
            "unsubscribe aug",
            "protocol",
            "t1074",
            "staged",
            "t1083",
            "t1102",
            "web service",
            "t1105",
            "tool transfer",
            "t1140",
            "data engineer",
            "candidate",
            "tlsv1",
            "odigicert inc",
            "stcalifornia",
            "lsan jose",
            "oadobe systems",
            "incorporated",
            "cndigicert sha2",
            "push",
            "next",
            "high",
            "write c",
            "ireland as16509",
            "delete",
            "dirty",
            "tags",
            "t1012",
            "flow endpoint",
            "security scan",
            "t1106",
            "copyright",
            "levelblue"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1005",
              "name": "Data from Local System",
              "display_name": "T1005 - Data from Local System"
            },
            {
              "id": "T1007",
              "name": "System Service Discovery",
              "display_name": "T1007 - System Service Discovery"
            },
            {
              "id": "T1012",
              "name": "Query Registry",
              "display_name": "T1012 - Query Registry"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1033",
              "name": "System Owner/User Discovery",
              "display_name": "T1033 - System Owner/User Discovery"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1074",
              "name": "Data Staged",
              "display_name": "T1074 - Data Staged"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1102",
              "name": "Web Service",
              "display_name": "T1102 - Web Service"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1112",
              "name": "Modify Registry",
              "display_name": "T1112 - Modify Registry"
            },
            {
              "id": "T1120",
              "name": "Peripheral Device Discovery",
              "display_name": "T1120 - Peripheral Device Discovery"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1132",
              "name": "Data Encoding",
              "display_name": "T1132 - Data Encoding"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1480",
              "name": "Execution Guardrails",
              "display_name": "T1480 - Execution Guardrails"
            },
            {
              "id": "T1486",
              "name": "Data Encrypted for Impact",
              "display_name": "T1486 - Data Encrypted for Impact"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1555",
              "name": "Credentials from Password Stores",
              "display_name": "T1555 - Credentials from Password Stores"
            },
            {
              "id": "T1560",
              "name": "Archive Collected Data",
              "display_name": "T1560 - Archive Collected Data"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            },
            {
              "id": "T1574",
              "name": "Hijack Execution Flow",
              "display_name": "T1574 - Hijack Execution Flow"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1562",
              "name": "Impair Defenses",
              "display_name": "T1562 - Impair Defenses"
            },
            {
              "id": "T1568",
              "name": "Dynamic Resolution",
              "display_name": "T1568 - Dynamic Resolution"
            },
            {
              "id": "T1583",
              "name": "Acquire Infrastructure",
              "display_name": "T1583 - Acquire Infrastructure"
            },
            {
              "id": "T1045",
              "name": "Software Packing",
              "display_name": "T1045 - Software Packing"
            },
            {
              "id": "T1018",
              "name": "Remote System Discovery",
              "display_name": "T1018 - Remote System Discovery"
            },
            {
              "id": "T1041",
              "name": "Exfiltration Over C2 Channel",
              "display_name": "T1041 - Exfiltration Over C2 Channel"
            },
            {
              "id": "T1114",
              "name": "Email Collection",
              "display_name": "T1114 - Email Collection"
            },
            {
              "id": "T1063",
              "name": "Security Software Discovery",
              "display_name": "T1063 - Security Software Discovery"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 18,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Q.Vashti",
            "id": "337942",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 608,
            "FileHash-SHA1": 433,
            "FileHash-SHA256": 3663,
            "URL": 17104,
            "domain": 1316,
            "email": 39,
            "hostname": 4208,
            "SSLCertFingerprint": 17
          },
          "indicator_count": 27388,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 139,
          "modified_text": "226 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "684b932fcbcc577471a28c8a",
          "name": "Imaging Center Malware, Virus other manipulations",
          "description": "IMO Serious!  Virus, Trojans, potential cams? PHI , PII access. Super concerning potential manipulation , imaging, reports., records, billing\nis manipulated.\nMore research necessary.\nTrue potential for manipulation \nof x-ray , ct scan dosing.\nExcessive Adult content:\ncdn1-thumbs.pornhost.com | \ncdn28.eporncam.com | \t\ncdn35.thotporn.tv | \ncdnst7.pornburst.xxx | \nmcdns.vrporn.com |\nURL\nhttps://c845a1577e.mjedge.net/contents/videos_screenshots/3979000/3979719/preview.jpg&tbnid=rLNgRtn9SIlcgM&vet=10CAwQ1JoKKARqFwoTCIjlsv7v0Y0DFQAAAAAdAAAAABAH..i&imgrefurl=https:/it.vikiporn.com/videos/3979719/horror-porn-the-dark-side-of-the-woods/&docid=tVU1jbsRquWQLM&w=1920&h=1080&itg=1&q=horror porn&ved=0CAwQ1JoKKARqFwoTCIjlsv7v0Y0DFQAAAAAdAAAAABAH |\nhttps://cdn1-thumbs.pornhost.com/0/2/0235809321/001_150_112.jpg | \n\u2022 Den:Variant.Application.Bundler.Ludus.1\n\u2022 PUABundler:Win32/YandexBundled\n\u2022 Adware.Win32.DownWare.cl\n\u2022 pua:Win32/Catalina\n\u2022W32.AIDetectMalware\n* Why is my OTX account blocked from features",
          "modified": "2025-07-13T02:05:19.612000",
          "created": "2025-06-13T02:55:42.562000",
          "tags": [
            "united",
            "asn16509",
            "amazon02",
            "frankfurt",
            "main",
            "germany",
            "asn60068",
            "cdn77 datacamp",
            "limited",
            "browsing",
            "reverse dns",
            "protocol h2",
            "security tls",
            "general full",
            "url https",
            "resource",
            "hash",
            "software",
            "dalles",
            "june",
            "de indicators",
            "domains",
            "hashes",
            "verified",
            "ecdsa",
            "linux x8664",
            "khtml",
            "gecko",
            "aes256gcm",
            "veryhigh",
            "patch",
            "accept",
            "encrypt",
            "cookie",
            "sticky",
            "aaaa",
            "cname",
            "ttl value",
            "algorithm",
            "key identifier",
            "v3 serial",
            "number",
            "cus olet",
            "encrypt cne5",
            "validity",
            "subject public",
            "key info",
            "key algorithm",
            "record type",
            "thumbprint"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 27,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Q.Vashti",
            "id": "337942",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 836,
            "hostname": 1001,
            "domain": 193,
            "URL": 3007,
            "FileHash-MD5": 83,
            "FileHash-SHA1": 42,
            "CIDR": 5
          },
          "indicator_count": 5167,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 137,
          "modified_text": "280 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6836497513b6637e7e6f39d2",
          "name": "Exploited Host",
          "description": "",
          "modified": "2025-06-26T22:03:25.914000",
          "created": "2025-05-27T23:23:33.814000",
          "tags": [
            "cname",
            "aaaa",
            "record type",
            "ttl value",
            "ascii text",
            "sha1",
            "copy md5",
            "copy sha1",
            "copy sha256",
            "size",
            "sha256",
            "united",
            "pattern match",
            "mitre att",
            "date",
            "path",
            "encrypt",
            "starfield",
            "hybrid",
            "general",
            "local",
            "click",
            "strings",
            "4624",
            "records",
            "amazon02",
            "us ie",
            "dns ns",
            "dns a",
            "dns mx",
            "command decode",
            "ck id",
            "show technique",
            "ck matrix",
            "filehashsha1",
            "filehashsha256",
            "filehashmd5",
            "search",
            "type indicator",
            "role title",
            "added active",
            "related pulses",
            "showing",
            "entries",
            "pulses",
            "url https",
            "ipv4",
            "ccus asnas33070",
            "role",
            "value a",
            "sec ch",
            "ch ua",
            "ua full",
            "ua platform",
            "ua bitness",
            "ua arch",
            "version sec",
            "mobile sec",
            "model sec",
            "version list"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1480",
              "name": "Execution Guardrails",
              "display_name": "T1480 - Execution Guardrails"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1562",
              "name": "Impair Defenses",
              "display_name": "T1562 - Impair Defenses"
            },
            {
              "id": "T1568",
              "name": "Dynamic Resolution",
              "display_name": "T1568 - Dynamic Resolution"
            },
            {
              "id": "T1583",
              "name": "Acquire Infrastructure",
              "display_name": "T1583 - Acquire Infrastructure"
            },
            {
              "id": "T1590",
              "name": "Gather Victim Network Information",
              "display_name": "T1590 - Gather Victim Network Information"
            },
            {
              "id": "T1113",
              "name": "Screen Capture",
              "display_name": "T1113 - Screen Capture"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 13,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Q.Vashti",
            "id": "337942",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 70,
            "FileHash-MD5": 225,
            "FileHash-SHA1": 232,
            "FileHash-SHA256": 1004,
            "domain": 138,
            "hostname": 74,
            "SSLCertFingerprint": 19,
            "email": 1
          },
          "indicator_count": 1763,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 139,
          "modified_text": "296 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "66cc6e2c6c5bb617fa7fa892",
          "name": "3",
          "description": "",
          "modified": "2024-08-27T03:05:18.727000",
          "created": "2024-08-26T11:59:40.174000",
          "tags": [
            "record type",
            "ttl value",
            "algorithm",
            "data",
            "v3 serial",
            "number",
            "cus olet",
            "encrypt cnr3",
            "validity",
            "subject public",
            "key info",
            "key algorithm",
            "dns replication",
            "date",
            "type name",
            "text",
            "mailpass mixed",
            "redacted for",
            "privacy tech",
            "postal code",
            "server",
            "registrar abuse",
            "code",
            "domain id",
            "iana id",
            "admin country",
            "script urls",
            "a domains",
            "search",
            "status",
            "x fw",
            "record value",
            "for privacy",
            "title",
            "body",
            "unknown",
            "encrypt",
            "log id",
            "gmtn",
            "tls web",
            "ca issuers",
            "timestamp",
            "b715",
            "b59bn timestamp",
            "cc50689e0a",
            "scan endpoints",
            "false",
            "digicert tls",
            "rsa sha256",
            "full name",
            "digicert inc",
            "organization",
            "massachusetts",
            "cambridge",
            "as54113",
            "united",
            "trojan",
            "passive dns",
            "showing",
            "entries",
            "win32",
            "flywheel",
            "sea x",
            "accept",
            "twitter",
            "ransom",
            "meta",
            "urls",
            "all scoreblue",
            "url http",
            "pulse pulses",
            "http",
            "ip address",
            "related nids",
            "files location",
            "nxdomain",
            "whitelisted",
            "cname",
            "aaaa",
            "gandi sas",
            "creation date",
            "emails",
            "avast avg",
            "ipv4",
            "files",
            "location united",
            "ascii text",
            "pattern match",
            "png image",
            "rgba",
            "suricata stream",
            "command decode",
            "size",
            "sha1",
            "mitre att",
            "et tor",
            "hybrid",
            "general",
            "local",
            "click",
            "strings",
            "4624",
            "glox",
            "ck id",
            "suspicious",
            "learn",
            "command",
            "name tactics",
            "informative",
            "ck techniques",
            "development att",
            "adversaries",
            "historical ssl",
            "referrer",
            "copy",
            "typosquat infra",
            "tracker",
            "jekyll",
            "hide",
            "norad tracking",
            "speakez securus",
            "nuance china",
            "phishing",
            "facebook",
            "hiddentear",
            "metro",
            "malware",
            "malicious",
            "skynet",
            "revil",
            "pykspa",
            "next",
            "as44273 host",
            "as7018 att",
            "domain related",
            "hosting",
            "name servers",
            "west domains",
            "asnone germany",
            "singapore",
            "as21499 host",
            "as20940",
            "germany",
            "object",
            "found",
            "domain",
            "files domain",
            "files related",
            "pulses otx",
            "pulses",
            "tags",
            "related tags",
            "win32 exe",
            "pe32",
            "intel",
            "ms windows",
            "win32 dynamic",
            "link library",
            "win16 ne",
            "delphi generic",
            "icons library",
            "pe32 linker",
            "info header",
            "name md5",
            "overlay",
            "dos exe",
            "moved",
            "gmt server",
            "centos",
            "domains",
            "dynadot inc",
            "contacted",
            "ip detections",
            "country",
            "de execution",
            "parents",
            "file type",
            "pulse submit",
            "url analysis",
            "win32heur mar",
            "dynamicloader",
            "medium",
            "qaeaav12",
            "windows",
            "high",
            "show",
            "qbeipbdii",
            "inetsim http",
            "powershell",
            "drweb",
            "write",
            "default",
            "module load",
            "t1129",
            "post http",
            "dock",
            "june",
            "delphi",
            "read c",
            "renos",
            "trojan downloader",
            "social engineering",
            "dns",
            "fraud",
            "cybercrime",
            "stalking",
            "tracking",
            "apple",
            "apple ios",
            "samsung",
            "danger"
          ],
          "references": [
            "https://the initiative.org | Initiative Co.org | chelsea@theinitiativeco.org",
            "Antivirus Detections:: Win.Downloader.103202-1 ,  #LowFiEnableDTContinueAfterUnpacking",
            "IDS Detections: Long Fake wget 3.0 User-Agent Detected Win32.Renos/Artro Trojan Checkin M1 Win32/Renos Checkin 3",
            "IDS Detections: W32/TrojanDownloader.Renos CnC Activity Suspicious User-Agent Malware related Windows wget network_http",
            "Alerts: cape_detected_threat antidebug_devices antivm_generic_disk enumerates_physical_drives deletes_executed_files",
            "Alerts: deletes_self suricata_alert dynamic_function_loading powershell_download powershell_request stealth_window",
            "Alerts: injection_rwx network_cnc_http antidebug_setunhandledexceptionfilter stealth_timeout uses_windows_utilities",
            "https://applemusic-spotlight.myunidays.com/US/en-US?",
            "applemusic-spotlight.myunidays.com | nr-data.net [Apple Private Data Collection] Sabey Data Center",
            "http://borowski-duncan.com/?user-agent=mozilla/5.0+(windows+nt+10.0;+win64;+x64)+applewebkit/537.36+(khtml,+like+gecko)+chrome/86.0.424",
            "http://imap.brooklyngeneration.org/__media__/js/netsoltrademark.php?d=www.fap18pgals.eu/brazilian-porn/",
            "A Jefferson County, Co Police 'advocate' referred target to a group that 'couldn't' to provide services. Referred to The Bench. Unwilling to help",
            "Victim gets a 'social' engineering' call taking every bit of information about victim and case.",
            "She was cleared for treatment; then declined citing a brain injury. Most of 'BB' clients have a TBI",
            "Victim was then given numbers to workers compensation doctors who didn't speak English",
            "Law Firm drops her and asks her who she really is? Victim was assaulted for her phone and other",
            "Victim doesn't fault Police who didn't show intent. Detective did close case, assailant  ID issues",
            "Was told by advocate that his description matches the male in vehicle following her for months.",
            "Be did wear a gator making it improbable for positive identification",
            "She was assaulted for phone 6 weeks after being intentional,y driven off highway",
            "Higher SCI sustained. Positive ID. Driver allowed to walk. Positive License Plate and description of driver with criminal intent.",
            "In the USA she is denied treatment for new injuries to spine causing deep decline. This is crazy.",
            "A series of strange female detectives enter. All corrupt fails. If victim was in prison fight she'd be treated w/guards outside of hospital room door."
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1568",
              "name": "Dynamic Resolution",
              "display_name": "T1568 - Dynamic Resolution"
            },
            {
              "id": "T1583",
              "name": "Acquire Infrastructure",
              "display_name": "T1583 - Acquire Infrastructure"
            },
            {
              "id": "T1071.004",
              "name": "DNS",
              "display_name": "T1071.004 - DNS"
            },
            {
              "id": "T1568.002",
              "name": "Domain Generation Algorithms",
              "display_name": "T1568.002 - Domain Generation Algorithms"
            },
            {
              "id": "T1583.001",
              "name": "Domains",
              "display_name": "T1583.001 - Domains"
            },
            {
              "id": "T1553.002",
              "name": "Code Signing",
              "display_name": "T1553.002 - Code Signing"
            },
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1036.004",
              "name": "Masquerade Task or Service",
              "display_name": "T1036.004 - Masquerade Task or Service"
            },
            {
              "id": "T1031",
              "name": "Modify Existing Service",
              "display_name": "T1031 - Modify Existing Service"
            },
            {
              "id": "T1023",
              "name": "Shortcut Modification",
              "display_name": "T1023 - Shortcut Modification"
            },
            {
              "id": "T1045",
              "name": "Software Packing",
              "display_name": "T1045 - Software Packing"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1060",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1060 - Registry Run Keys / Startup Folder"
            },
            {
              "id": "T1070",
              "name": "Indicator Removal on Host",
              "display_name": "T1070 - Indicator Removal on Host"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1143",
              "name": "Hidden Window",
              "display_name": "T1143 - Hidden Window"
            },
            {
              "id": "T1583.005",
              "name": "Botnet",
              "display_name": "T1583.005 - Botnet"
            },
            {
              "id": "T1584",
              "name": "Compromise Infrastructure",
              "display_name": "T1584 - Compromise Infrastructure"
            },
            {
              "id": "T1122",
              "name": "Component Object Model Hijacking",
              "display_name": "T1122 - Component Object Model Hijacking"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": "66a5c2445cf4bbf984e98861",
          "export_count": 14,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Krishivpatel",
            "id": "292085",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "email": 6,
            "domain": 782,
            "hostname": 530,
            "FileHash-SHA1": 382,
            "FileHash-SHA256": 1572,
            "URL": 847,
            "FileHash-MD5": 386,
            "SSLCertFingerprint": 12
          },
          "indicator_count": 4517,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 29,
          "modified_text": "600 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "66a5c2445cf4bbf984e98861",
          "name": "Social Engineering Crime Victims into Tracking Botnets | Fraud",
          "description": "Social Engineering 'S' Assault Victims into Tracking Botnets. This goes against basic human rights. An organization named 'The Blue Bench' referred victim to The Initiative for advocacy. She was social engineered, severely compromised and sent diverted from 'The Blue Bench' Colorado. They denied treatment for assault victim in 2022, while The Initiative ' Brian Sabey's stuff, tracked and hijacked phone and location, conversations.\nAuto-populated: \"Last HTTPS certificate\" is the last one to be issued on the internet, according to the website, and it is believed to have been signed by a member of the US government.",
          "modified": "2024-08-27T03:05:18.727000",
          "created": "2024-07-28T04:00:04.773000",
          "tags": [
            "record type",
            "ttl value",
            "algorithm",
            "data",
            "v3 serial",
            "number",
            "cus olet",
            "encrypt cnr3",
            "validity",
            "subject public",
            "key info",
            "key algorithm",
            "dns replication",
            "date",
            "type name",
            "text",
            "mailpass mixed",
            "redacted for",
            "privacy tech",
            "postal code",
            "server",
            "registrar abuse",
            "code",
            "domain id",
            "iana id",
            "admin country",
            "script urls",
            "a domains",
            "search",
            "status",
            "x fw",
            "record value",
            "for privacy",
            "title",
            "body",
            "unknown",
            "encrypt",
            "log id",
            "gmtn",
            "tls web",
            "ca issuers",
            "timestamp",
            "b715",
            "b59bn timestamp",
            "cc50689e0a",
            "scan endpoints",
            "false",
            "digicert tls",
            "rsa sha256",
            "full name",
            "digicert inc",
            "organization",
            "massachusetts",
            "cambridge",
            "as54113",
            "united",
            "trojan",
            "passive dns",
            "showing",
            "entries",
            "win32",
            "flywheel",
            "sea x",
            "accept",
            "twitter",
            "ransom",
            "meta",
            "urls",
            "all scoreblue",
            "url http",
            "pulse pulses",
            "http",
            "ip address",
            "related nids",
            "files location",
            "nxdomain",
            "whitelisted",
            "cname",
            "aaaa",
            "gandi sas",
            "creation date",
            "emails",
            "avast avg",
            "ipv4",
            "files",
            "location united",
            "ascii text",
            "pattern match",
            "png image",
            "rgba",
            "suricata stream",
            "command decode",
            "size",
            "sha1",
            "mitre att",
            "et tor",
            "hybrid",
            "general",
            "local",
            "click",
            "strings",
            "4624",
            "glox",
            "ck id",
            "suspicious",
            "learn",
            "command",
            "name tactics",
            "informative",
            "ck techniques",
            "development att",
            "adversaries",
            "historical ssl",
            "referrer",
            "copy",
            "typosquat infra",
            "tracker",
            "jekyll",
            "hide",
            "norad tracking",
            "speakez securus",
            "nuance china",
            "phishing",
            "facebook",
            "hiddentear",
            "metro",
            "malware",
            "malicious",
            "skynet",
            "revil",
            "pykspa",
            "next",
            "as44273 host",
            "as7018 att",
            "domain related",
            "hosting",
            "name servers",
            "west domains",
            "asnone germany",
            "singapore",
            "as21499 host",
            "as20940",
            "germany",
            "object",
            "found",
            "domain",
            "files domain",
            "files related",
            "pulses otx",
            "pulses",
            "tags",
            "related tags",
            "win32 exe",
            "pe32",
            "intel",
            "ms windows",
            "win32 dynamic",
            "link library",
            "win16 ne",
            "delphi generic",
            "icons library",
            "pe32 linker",
            "info header",
            "name md5",
            "overlay",
            "dos exe",
            "moved",
            "gmt server",
            "centos",
            "domains",
            "dynadot inc",
            "contacted",
            "ip detections",
            "country",
            "de execution",
            "parents",
            "file type",
            "pulse submit",
            "url analysis",
            "win32heur mar",
            "dynamicloader",
            "medium",
            "qaeaav12",
            "windows",
            "high",
            "show",
            "qbeipbdii",
            "inetsim http",
            "powershell",
            "drweb",
            "write",
            "default",
            "module load",
            "t1129",
            "post http",
            "dock",
            "june",
            "delphi",
            "read c",
            "renos",
            "trojan downloader",
            "social engineering",
            "dns",
            "fraud",
            "cybercrime",
            "stalking",
            "tracking",
            "apple",
            "apple ios",
            "samsung",
            "danger"
          ],
          "references": [
            "https://the initiative.org | Initiative Co.org | chelsea@theinitiativeco.org",
            "Antivirus Detections:: Win.Downloader.103202-1 ,  #LowFiEnableDTContinueAfterUnpacking",
            "IDS Detections: Long Fake wget 3.0 User-Agent Detected Win32.Renos/Artro Trojan Checkin M1 Win32/Renos Checkin 3",
            "IDS Detections: W32/TrojanDownloader.Renos CnC Activity Suspicious User-Agent Malware related Windows wget network_http",
            "Alerts: cape_detected_threat antidebug_devices antivm_generic_disk enumerates_physical_drives deletes_executed_files",
            "Alerts: deletes_self suricata_alert dynamic_function_loading powershell_download powershell_request stealth_window",
            "Alerts: injection_rwx network_cnc_http antidebug_setunhandledexceptionfilter stealth_timeout uses_windows_utilities",
            "https://applemusic-spotlight.myunidays.com/US/en-US?",
            "applemusic-spotlight.myunidays.com | nr-data.net [Apple Private Data Collection] Sabey Data Center",
            "http://borowski-duncan.com/?user-agent=mozilla/5.0+(windows+nt+10.0;+win64;+x64)+applewebkit/537.36+(khtml,+like+gecko)+chrome/86.0.424",
            "http://imap.brooklyngeneration.org/__media__/js/netsoltrademark.php?d=www.fap18pgals.eu/brazilian-porn/",
            "A Jefferson County, Co Police 'advocate' referred target to a group that 'couldn't' to provide services. Referred to The Bench. Unwilling to help",
            "Victim gets a 'social' engineering' call taking every bit of information about victim and case.",
            "She was cleared for treatment; then declined citing a brain injury. Most of 'BB' clients have a TBI",
            "Victim was then given numbers to workers compensation doctors who didn't speak English",
            "Law Firm drops her and asks her who she really is? Victim was assaulted for her phone and other",
            "Victim doesn't fault Police who didn't show intent. Detective did close case, assailant  ID issues",
            "Was told by advocate that his description matches the male in vehicle following her for months.",
            "Be did wear a gator making it improbable for positive identification",
            "She was assaulted for phone 6 weeks after being intentional,y driven off highway",
            "Higher SCI sustained. Positive ID. Driver allowed to walk. Positive License Plate and description of driver with criminal intent.",
            "In the USA she is denied treatment for new injuries to spine causing deep decline. This is crazy.",
            "A series of strange female detectives enter. All corrupt fails. If victim was in prison fight she'd be treated w/guards outside of hospital room door."
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1568",
              "name": "Dynamic Resolution",
              "display_name": "T1568 - Dynamic Resolution"
            },
            {
              "id": "T1583",
              "name": "Acquire Infrastructure",
              "display_name": "T1583 - Acquire Infrastructure"
            },
            {
              "id": "T1071.004",
              "name": "DNS",
              "display_name": "T1071.004 - DNS"
            },
            {
              "id": "T1568.002",
              "name": "Domain Generation Algorithms",
              "display_name": "T1568.002 - Domain Generation Algorithms"
            },
            {
              "id": "T1583.001",
              "name": "Domains",
              "display_name": "T1583.001 - Domains"
            },
            {
              "id": "T1553.002",
              "name": "Code Signing",
              "display_name": "T1553.002 - Code Signing"
            },
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1036.004",
              "name": "Masquerade Task or Service",
              "display_name": "T1036.004 - Masquerade Task or Service"
            },
            {
              "id": "T1031",
              "name": "Modify Existing Service",
              "display_name": "T1031 - Modify Existing Service"
            },
            {
              "id": "T1023",
              "name": "Shortcut Modification",
              "display_name": "T1023 - Shortcut Modification"
            },
            {
              "id": "T1045",
              "name": "Software Packing",
              "display_name": "T1045 - Software Packing"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1060",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1060 - Registry Run Keys / Startup Folder"
            },
            {
              "id": "T1070",
              "name": "Indicator Removal on Host",
              "display_name": "T1070 - Indicator Removal on Host"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1143",
              "name": "Hidden Window",
              "display_name": "T1143 - Hidden Window"
            },
            {
              "id": "T1583.005",
              "name": "Botnet",
              "display_name": "T1583.005 - Botnet"
            },
            {
              "id": "T1584",
              "name": "Compromise Infrastructure",
              "display_name": "T1584 - Compromise Infrastructure"
            },
            {
              "id": "T1122",
              "name": "Component Object Model Hijacking",
              "display_name": "T1122 - Component Object Model Hijacking"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 20,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "email": 6,
            "domain": 782,
            "hostname": 530,
            "FileHash-SHA1": 382,
            "FileHash-SHA256": 1572,
            "URL": 847,
            "FileHash-MD5": 386,
            "SSLCertFingerprint": 12
          },
          "indicator_count": 4517,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 225,
          "modified_text": "600 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "65708425f2199b7275c3a6a7",
          "name": "discordsound.com",
          "description": "",
          "modified": "2023-12-06T14:24:36.976000",
          "created": "2023-12-06T14:24:36.976000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 386,
            "FileHash-SHA256": 1115,
            "domain": 198,
            "URL": 735,
            "CIDR": 10,
            "FileHash-MD5": 27,
            "FileHash-SHA1": 9
          },
          "indicator_count": 2480,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "865 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6570807c9521659aacb5668a",
          "name": "gainpower.org ~ Voting Rights Non-profit",
          "description": "",
          "modified": "2023-12-06T14:09:00.527000",
          "created": "2023-12-06T14:09:00.527000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 1159,
            "hostname": 816,
            "domain": 263,
            "URL": 2550,
            "CIDR": 5,
            "FileHash-MD5": 45,
            "FileHash-SHA1": 3
          },
          "indicator_count": 4841,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "865 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "624dbf64e7682b3bf049129c",
          "name": "Malware-USA",
          "description": "Shopseg Sistemas, a company specialising in software and equipamentos for supermercados, wedi dweud eu s\u00f4n i'n \u00f4l.",
          "modified": "2022-05-06T16:01:29.122000",
          "created": "2022-04-06T16:27:16.842000",
          "tags": [
            "dataaos",
            "100px00",
            "dataaosfade",
            "100px0",
            "dataaoszoom",
            "dataaosflip",
            "woff2",
            "fontface",
            "sans",
            "u0259",
            "u1e001eff",
            "u2020",
            "u20a020ab",
            "u20ad20cf",
            "u2113",
            "u2c602c7f",
            "reduceright",
            "number",
            "string",
            "gtl5jtn10ss",
            "regexp",
            "error",
            "r300",
            "copyright",
            "dafunction",
            "gafunction",
            "uint8array",
            "date",
            "path",
            "void",
            "const",
            "click",
            "select",
            "scroll",
            "mobile",
            "template",
            "template url",
            "license",
            "easy selector",
            "easy event",
            "easy",
            "back",
            "typeof e",
            "typeof t",
            "this",
            "main",
            "swiper",
            "button",
            "most",
            "mit license",
            "android",
            "win32",
            "null",
            "dblock",
            "email form",
            "validation",
            "action",
            "formdata",
            "api url",
            "typeof define",
            "typeof module",
            "gplv3",
            "metafizzy",
            "math",
            "plyr",
            "typeof symbol",
            "typeerror",
            "tnull",
            "cnull",
            "typeof",
            "inject",
            "playbook",
            "name",
            "getconfig",
            "default",
            "area",
            "event",
            "shadowroot",
            "boolean",
            "window",
            "trident",
            "body",
            "ofunction",
            "symbol",
            "mfunction",
            "sfunction",
            "quando",
            "quem",
            "fundada em",
            "informtica",
            "sistemas",
            "segurana",
            "softwares",
            "supermercados",
            "lojas",
            "restaurantes",
            "padarias"
          ],
          "references": [
            "http://www.shopsegsistemas.com.br/",
            "http://www.shopsegsistemas.com.br/assets/vendor/aos/aos.js",
            "http://www.shopsegsistemas.com.br/assets/vendor/bootstrap/js/bootstrap.bundle.min.js",
            "http://www.shopsegsistemas.com.br/assets/vendor/glightbox/js/glightbox.min.js",
            "http://www.shopsegsistemas.com.br/assets/vendor/isotope-layout/isotope.pkgd.min.js",
            "http://www.shopsegsistemas.com.br/assets/vendor/php-email-form/validate.js",
            "http://www.shopsegsistemas.com.br/assets/vendor/swiper/swiper-bundle.min.js",
            "http://www.shopsegsistemas.com.br/assets/js/main.js",
            "https://www.googletagmanager.com/gtag/js?id=G-TL5JTN10SS",
            "https://fonts.googleapis.com/css?family=Open+Sans:300,300i,400,400i,600,600i,700,700i%7CRaleway:300,300i,400,400i,500,500i,600,600i,700,700i%7CPoppins:300,300i,400,400i,500,500i,600,600i,700,700i",
            "http://www.shopsegsistemas.com.br/assets/vendor/aos/aos.css",
            "https://www.google.com/maps/embed?pb=!1m18!1m12!1m3!1d3730.503584706544!2d-41.67284568552043!3d-20.770905270369408!2m3!1f0!2f0!3f0!3m2!1i1024!2i768!4f13.1!3m3!1m2!1s0xbb93dcc0beb01f%3A0x97397d38847b3692!2sShopSeg%20Sistemas!5e0!3m2!1spt-BR!2sbr!4v1636561779046!5m2!1spt-BR!2sbr",
            "xfe-IP-50.116.87.164-stix2-2.0-export.json"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "ReduceRight",
              "display_name": "ReduceRight",
              "target": null
            },
            {
              "id": "Quando",
              "display_name": "Quando",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1498",
              "name": "Network Denial of Service",
              "display_name": "T1498 - Network Denial of Service"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 4,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "adjadex1@gmail.com",
            "id": "187163",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 254,
            "URL": 815,
            "FileHash-SHA256": 168,
            "domain": 174
          },
          "indicator_count": 1411,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 69,
          "modified_text": "1444 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "624dbf641e6a04169629e662",
          "name": "Malware-USA",
          "description": "Shopseg Sistemas, a company specialising in software and equipamentos for supermercados, wedi dweud eu s\u00f4n i'n \u00f4l.",
          "modified": "2022-05-06T16:01:29.122000",
          "created": "2022-04-06T16:27:16.093000",
          "tags": [
            "dataaos",
            "100px00",
            "dataaosfade",
            "100px0",
            "dataaoszoom",
            "dataaosflip",
            "woff2",
            "fontface",
            "sans",
            "u0259",
            "u1e001eff",
            "u2020",
            "u20a020ab",
            "u20ad20cf",
            "u2113",
            "u2c602c7f",
            "reduceright",
            "number",
            "string",
            "gtl5jtn10ss",
            "regexp",
            "error",
            "r300",
            "copyright",
            "dafunction",
            "gafunction",
            "uint8array",
            "date",
            "path",
            "void",
            "const",
            "click",
            "select",
            "scroll",
            "mobile",
            "template",
            "template url",
            "license",
            "easy selector",
            "easy event",
            "easy",
            "back",
            "typeof e",
            "typeof t",
            "this",
            "main",
            "swiper",
            "button",
            "most",
            "mit license",
            "android",
            "win32",
            "null",
            "dblock",
            "email form",
            "validation",
            "action",
            "formdata",
            "api url",
            "typeof define",
            "typeof module",
            "gplv3",
            "metafizzy",
            "math",
            "plyr",
            "typeof symbol",
            "typeerror",
            "tnull",
            "cnull",
            "typeof",
            "inject",
            "playbook",
            "name",
            "getconfig",
            "default",
            "area",
            "event",
            "shadowroot",
            "boolean",
            "window",
            "trident",
            "body",
            "ofunction",
            "symbol",
            "mfunction",
            "sfunction",
            "quando",
            "quem",
            "fundada em",
            "informtica",
            "sistemas",
            "segurana",
            "softwares",
            "supermercados",
            "lojas",
            "restaurantes",
            "padarias"
          ],
          "references": [
            "http://www.shopsegsistemas.com.br/",
            "http://www.shopsegsistemas.com.br/assets/vendor/aos/aos.js",
            "http://www.shopsegsistemas.com.br/assets/vendor/bootstrap/js/bootstrap.bundle.min.js",
            "http://www.shopsegsistemas.com.br/assets/vendor/glightbox/js/glightbox.min.js",
            "http://www.shopsegsistemas.com.br/assets/vendor/isotope-layout/isotope.pkgd.min.js",
            "http://www.shopsegsistemas.com.br/assets/vendor/php-email-form/validate.js",
            "http://www.shopsegsistemas.com.br/assets/vendor/swiper/swiper-bundle.min.js",
            "http://www.shopsegsistemas.com.br/assets/js/main.js",
            "https://www.googletagmanager.com/gtag/js?id=G-TL5JTN10SS",
            "https://fonts.googleapis.com/css?family=Open+Sans:300,300i,400,400i,600,600i,700,700i%7CRaleway:300,300i,400,400i,500,500i,600,600i,700,700i%7CPoppins:300,300i,400,400i,500,500i,600,600i,700,700i",
            "http://www.shopsegsistemas.com.br/assets/vendor/aos/aos.css",
            "https://www.google.com/maps/embed?pb=!1m18!1m12!1m3!1d3730.503584706544!2d-41.67284568552043!3d-20.770905270369408!2m3!1f0!2f0!3f0!3m2!1i1024!2i768!4f13.1!3m3!1m2!1s0xbb93dcc0beb01f%3A0x97397d38847b3692!2sShopSeg%20Sistemas!5e0!3m2!1spt-BR!2sbr!4v1636561779046!5m2!1spt-BR!2sbr",
            "xfe-IP-50.116.87.164-stix2-2.0-export.json"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "ReduceRight",
              "display_name": "ReduceRight",
              "target": null
            },
            {
              "id": "Quando",
              "display_name": "Quando",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1498",
              "name": "Network Denial of Service",
              "display_name": "T1498 - Network Denial of Service"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 4,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "adjadex1@gmail.com",
            "id": "187163",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 254,
            "URL": 815,
            "FileHash-SHA256": 168,
            "domain": 174
          },
          "indicator_count": 1411,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 69,
          "modified_text": "1444 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "62323398a50e309cfbf08e4c",
          "name": "discordsound.com",
          "description": "",
          "modified": "2022-04-15T00:03:47.669000",
          "created": "2022-03-16T18:59:36.078000",
          "tags": [
            "WannaCry"
          ],
          "references": [
            "discordsound.com.pdf"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "Win.Ransomware.WannaCry-9856297-0",
              "display_name": "Win.Ransomware.WannaCry-9856297-0",
              "target": null
            }
          ],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 6,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Kailula4",
            "id": "131997",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 386,
            "URL": 735,
            "domain": 198,
            "FileHash-SHA256": 1115,
            "CIDR": 10,
            "FileHash-MD5": 27,
            "FileHash-SHA1": 9
          },
          "indicator_count": 2480,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 408,
          "modified_text": "1465 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "622271b1360810e486ae6510",
          "name": "gainpower.org ~ Voting Rights Non-profit",
          "description": "",
          "modified": "2022-04-03T00:00:55.161000",
          "created": "2022-03-04T20:08:17.351000",
          "tags": [],
          "references": [
            "gainpower.org.pdf"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "NGO"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 6,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Kailula4",
            "id": "131997",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 816,
            "URL": 2550,
            "domain": 263,
            "FileHash-SHA256": 1159,
            "CIDR": 5,
            "FileHash-MD5": 45,
            "FileHash-SHA1": 3
          },
          "indicator_count": 4841,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 407,
          "modified_text": "1477 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "spycloud.com \u2022 content.spycloud.com \u2022 email.spycloud.com\t hostname\tengage.spycloud.com \u2022 hello.spycloud.com \u2022portal.spycloud.com \u2022 https://email.spycloud",
        "https://airline.cmntgoyq.com/  | Prometheus Intelligence Technology",
        "Yara Detections: Delphi",
        "Was told by advocate that his description matches the male in vehicle following her for months.",
        "https://otx.alienvault.com/pulse/69af3fd8db2ede31abda6c14",
        "IDS Detections: Long Fake wget 3.0 User-Agent Detected Win32.Renos/Artro Trojan Checkin M1 Win32/Renos Checkin 3",
        "Small: Win32:Malware-gen (Small) Yara Detections stack_string \u2022 Domains Contacted: amazon.com",
        "www.onyx-ware.com \u2022 http://pages.endgames.com/ \u2022  http://www.endgamesystems.com/",
        "Will sort to identify malware",
        "Emotet IDS Detections: Win32/Emotet CnC Checkin Response",
        "https://www.googletagmanager.com/gtag/js?id=G-TL5JTN10SS",
        "Alerts: cape_detected_threat antidebug_devices antivm_generic_disk enumerates_physical_drives deletes_executed_files",
        "containers-oceanus.palantirsec.com",
        "spf.google.com",
        "Alerts: network_icmp persistence_autorun deletes_executed_files modifies_certificates",
        "http://www.shopsegsistemas.com.br/assets/vendor/aos/aos.css",
        "https://www.google.com/maps/embed?pb=!1m18!1m12!1m3!1d3730.503584706544!2d-41.67284568552043!3d-20.770905270369408!2m3!1f0!2f0!3f0!3m2!1i1024!2i768!4f13.1!3m3!1m2!1s0xbb93dcc0beb01f%3A0x97397d38847b3692!2sShopSeg%20Sistemas!5e0!3m2!1spt-BR!2sbr!4v1636561779046!5m2!1spt-BR!2sbr",
        "https://blog.endgames.com/ \u2022 wg41xm05b3.endgamesystems.com",
        "http://www.shopsegsistemas.com.br/assets/vendor/aos/aos.js",
        "https://spycloud.com/solutions/\t\u2022 104.18.26.108 ELF:Mirai-GH\\ [Trj] \u2022 Unix.Dropper.Mirai-7135870-0",
        "https://applemusic-spotlight.myunidays.com/US/en-US?",
        "http://www.shopsegsistemas.com.br/",
        "https://fonts.googleapis.com/css?family=Open+Sans:300,300i,400,400i,600,600i,700,700i%7CRaleway:300,300i,400,400i,500,500i,600,600i,700,700i%7CPoppins:300,300i,400,400i,500,500i,600,600i,700,700i",
        "Be did wear a gator making it improbable for positive identification",
        "http://borowski-duncan.com/?user-agent=mozilla/5.0+(windows+nt+10.0;+win64;+x64)+applewebkit/537.36+(khtml,+like+gecko)+chrome/86.0.424",
        "She was cleared for treatment; then declined citing a brain injury. Most of 'BB' clients have a TBI",
        "Alerts: exe_appdata antivm_network_adapters network_downloader_exe privilege_luid_check",
        "IDS Detections: W32/TrojanDownloader.Renos CnC Activity Suspicious User-Agent Malware related Windows wget network_http",
        "HTTP traffic on port 443 (POST)",
        "Alerts: crime_win_cutwail_stage2  infostealer_browser infostealer_cookies recon_programs",
        "Amazon.com",
        "http://www.shopsegsistemas.com.br/assets/vendor/glightbox/js/glightbox.min.js",
        "Victim was then given numbers to workers compensation doctors who didn't speak English",
        "Malicious: http://developers.cloudfiare.com/support/troubleshooting/http-status-",
        "gainpower.org.pdf",
        "http://www.shopsegsistemas.com.br/assets/vendor/swiper/swiper-bundle.min.js",
        "She was assaulted for phone 6 weeks after being intentional,y driven off highway",
        "https://www.lalal.ai/privacy-policy/InvalidOutputFolderErrorQAndroidJniObject",
        "xfe-IP-50.116.87.164-stix2-2.0-export.json",
        "Higher SCI sustained. Positive ID. Driver allowed to walk. Positive License Plate and description of driver with criminal intent.",
        "https://hybrid-analysis.com/sample/9e7bfc9fb60aa3e3f3c5b91f84ebf8b07e35893e1491149420535cd494bb8a32/69b1b467625a11ce330587db",
        "sso.dev.applemarketingtools.com",
        "Small _Alerts: antisandbox_foregroundwindows suspicious_process stealth_window packer_entropy",
        "Alerts: injection_rwx network_cnc_http antidebug_setunhandledexceptionfilter stealth_timeout uses_windows_utilities",
        "https://email.spycloud.com/NzEzLVdJUC03MzcAAAGe67eM-W3qxAlVkEvZwfw1dWuwRdm0zVU5aMyOzUe2IkxAY3hDe8RfT27HnjgkvTk-uqIy6K0=",
        "bridge-websocket-evolosciuc.devint01.goodleap.com",
        "mc.yandex.com \u2022 mc.yandex.ru \u2022 yandex.com \u2022 yandex.ru",
        "A series of strange female detectives enter. All corrupt fails. If victim was in prison fight she'd be treated w/guards outside of hospital room door.",
        "IDS Detections Observed Suspicious UA (NSIS_Inetc (Mozilla)) Observed DNS Query",
        "Yara Detections:  Nullsoft_NSIS    ...",
        "https://www.coloradosos.gov/biz/BusinessEntityDetail.do?quitButtonDestination=BusinessEntityResults&nameTyp=ENT&masterFileId=20221473927&entityId2=20221473927&fileId=20251525819&srchTyp=ENTITY",
        "https://hybrid-analysis.com/sample/9a1e0d38b691f1d22a92cff65ec0439b428170ac39a4493c7ecb06d5585f56a3/68a4adea30f7fafee90aefd3",
        "Chekin -Fareit/Pony Downloader Checkin 2 \u2022 Generic - POST To gate.php with no referer",
        "Cart.Guru",
        "Win32:Evo-gen\\ [Susp] http://downwingbuttons.site/7/huge.dat",
        "Victim doesn't fault Police who didn't show intent. Detective did close case, assailant  ID issues",
        "Emotet Yara: Yara Detections ConventionEngine_Term_Desktop ,  ConventionEngine_Term_Users",
        "http://www.shopsegsistemas.com.br/assets/vendor/php-email-form/validate.js",
        "http://imap.brooklyngeneration.org/__media__/js/netsoltrademark.php?d=www.fap18pgals.eu/brazilian-porn/",
        "Typosquating: developers.cloudfiare.com \u2022 cloudfiare.com",
        "http://www.shopsegsistemas.com.br/assets/vendor/isotope-layout/isotope.pkgd.min.js",
        "MSIL/Injector.RXR Variant CnC Activity Trojanr Generic - POST To gate.php with no referer",
        "http://www.shopsegsistemas.com.br/assets/vendor/bootstrap/js/bootstrap.bundle.min.js",
        "quantum-staging.emsbk.com",
        "api-cookie.click",
        "delete-me.bgs.beanie.cloud",
        "Small_Yara:   IP\u2019s Contacted  176.32.103.205  205.251.242.103",
        "Alerts: banker_zeus_url procmem_yara suricata_alert infostealer_ftp dynamic_function_loading reads_self network_cnc_http",
        "https://www.red-gate.com/products/smartassembly",
        "http://www.shopsegsistemas.com.br/assets/js/main.js",
        "discordsound.com.pdf",
        "Alerts: checks_debugger generates_crypto_key modifies_proxy_wpad",
        "Alerts: ransomware_dropped_files dumped_buffer network_cnc_http network_http",
        "Law Firm drops her and asks her who she really is? Victim was assaulted for her phone and other",
        "test-ssa.pineapples.dev",
        "Alerts: network_http_post allocates_rwx antisandbox_sleep antivm_disk_size creates_exe",
        "https://the initiative.org | Initiative Co.org | chelsea@theinitiativeco.org",
        "applemusic-spotlight.myunidays.com | nr-data.net [Apple Private Data Collection] Sabey Data Center",
        "A Jefferson County, Co Police 'advocate' referred target to a group that 'couldn't' to provide services. Referred to The Bench. Unwilling to help",
        "logstream-mystifying-tharp-7si72pw.cribl.cloud",
        "mc.yandex.com/metrika/ \u2022 mc.yandex.com/watch/99885987/",
        "kadmos.bot \u2022 cutout.bot \u2022 scenebot.com",
        "lalal.ai",
        "Victim gets a 'social' engineering' call taking every bit of information about victim and case.",
        "Antivirus Detections:: Win.Downloader.103202-1 ,  #LowFiEnableDTContinueAfterUnpacking",
        "https://bombing.gwuzafo.cc/",
        "Small_Alerts: persistence_autorun disables_proxy removes_zoneid_ads allocates_rwx",
        "In the USA she is denied treatment for new injuries to spine causing deep decline. This is crazy.",
        "dasima-containers.palantirfoundry.com \u2022 blitzrobots.com",
        "Alerts: deletes_self suricata_alert dynamic_function_loading powershell_download powershell_request stealth_window"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 0
        },
        "other": {
          "adversary": [
            "Palantir Pegasus"
          ],
          "malware_families": [
            "Elf:mirai-gh\\ [trj]",
            "Virtool:win32/obfuscator.ahu",
            "Win.trojan.agent",
            "Win32:evo-gen\\ [susp]",
            "#lowfienabledtcontinueafterunpacking",
            "Trojan:win32/bagsu!rfn",
            "Unix.dropper.mirai-7135870-0",
            "Quando",
            "Trojandownloader:win32/cutwail",
            "Win32:malob-bx\\ [cryp]",
            "Rxr",
            "Tofsee",
            "Win32:malware",
            "Vb flash",
            "Win.ransomware.wannacry-9856297-0",
            "#lowfi:win32/sandboxproductid",
            "Win32:rootkit",
            "Win32:agent",
            "Malware",
            "Virtool:win32/obfuscator",
            "Pegasus",
            "Win.trojan.emotet-7545664-0",
            "Pony",
            "Trojan:win32/qqpass",
            "Pegasus - mob-s0005",
            "Backdoor:win32/plugx.n!",
            "Win.dropper.qqpass-7194329-0",
            "Win32:backdoor",
            "Reduceright",
            "Alf:trojan:msil/blackfus.c",
            "Shellcode",
            "Trojanproxy:win32/ceutv.a",
            "Win.packed.razy-6847895-0",
            "Worm:win32/autorun"
          ],
          "industries": [
            "Ngo"
          ],
          "unique_indicators": 71023
        }
      }
    },
    "false_positive": [],
    "alexa": "http://www.alexa.com/siteinfo/swiperjs.com",
    "whois": "http://whois.domaintools.com/swiperjs.com",
    "domain": "swiperjs.com",
    "hostname": "Unavailable"
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 19,
  "pulses": [
    {
      "id": "69b7ac3b32ac89ecba53f3d9",
      "name": "Malicious",
      "description": "",
      "modified": "2026-04-15T08:44:52.171000",
      "created": "2026-03-16T07:07:39.495000",
      "tags": [
        "march",
        "input http",
        "posix shell",
        "ascii text",
        "threat level",
        "summary av",
        "detection",
        "environment",
        "action"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 291,
        "URL": 272,
        "hostname": 296,
        "domain": 293,
        "FileHash-MD5": 90,
        "FileHash-SHA1": 89,
        "CIDR": 3,
        "email": 3,
        "SSLCertFingerprint": 9
      },
      "indicator_count": 1346,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 49,
      "modified_text": "4 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "69b235439d56630943ea31e6",
      "name": "Clone by Q Vashti (excellent systemic analyzer I may add)",
      "description": "",
      "modified": "2026-04-10T22:04:28.607000",
      "created": "2026-03-12T03:38:43.171000",
      "tags": [
        "\u9ed1\u6599",
        "\u5403\u74dc",
        "\u5403\u74dc\u7f51",
        "51\u5403\u74dc",
        "\u9ed1\u6599\u4e0d\u6253\u70ca",
        "\u9ed1\u6599\u5403\u74dc\u7f51",
        "\u70ed\u95e8\u5927\u74dc",
        "\u660e\u661f\u8d44\u8baf",
        "\u7f51\u7ea2\u9ed1\u6599",
        "\u5185\u6db5\u6bb5\u5b50",
        "\u4eca\u65e5\u5403\u74dc",
        "\u5403\u74dc\u65b0\u95fb",
        "\u9ed1\u6599\u66dd\u5149",
        "\u516b\u5366\u65b0\u95fb",
        "\u793e\u4f1a\u70ed\u70b9",
        "\u5403\u74dc\u7fa4\u4f17",
        "\u70ed\u70b9\u4e8b\u4ef6",
        "\u6bcf\u65e5\u5403\u74dc",
        "\u7f51\u7ea2\u5403\u74dc",
        "\u4eca\u65e5\u5927\u74dc",
        "\u5403\u74dc\u7206\u6599",
        "\u5403\u74dc\u4e2d\u5fc3",
        "\u4eca\u65e5\u70ed\u74dc",
        "\u5403\u74dc\u9ed1\u6599",
        "\u9ed1\u6599\u6cc4\u5bc6",
        "\u91cd\u78c5\u9ed1\u6599",
        "\u5403\u74dc\u6cc4\u5bc6",
        "\u4eca\u65e5\u9ed1\u6599",
        "\u6700\u65b0\u9ed1\u6599",
        "\u5403\u74dc\u66dd\u5149",
        "\u5403\u74dc\u8d44\u6e90",
        "\u91cd\u78c5\u5403\u74dc",
        "\u5a31\u4e50\u70ed\u74dc",
        "chrome",
        "cos ai",
        "a serif",
        "sans serif",
        "top10",
        "openclaw",
        "21200",
        "onlyfans",
        "strong",
        "dmca copyright",
        "address google",
        "safe browsing",
        "data upload",
        "extraction",
        "lte all",
        "enter sc",
        "type o",
        "extra",
        "referen https",
        "lte o",
        "type",
        "extr data",
        "include review",
        "exclude sugges",
        "failed",
        "hong kong",
        "passive dns",
        "otx logo",
        "all ipv4",
        "url analysis",
        "urls",
        "files",
        "location hong",
        "value",
        "march",
        "0x1595 function",
        "0x19b5 object",
        "tracker",
        "base64 object",
        "cookie function",
        "mlog",
        "localconst",
        "style function",
        "reverse dns",
        "general full",
        "url https",
        "resource",
        "software",
        "hash",
        "security tls",
        "singapore",
        "asn139341",
        "aceasap ace",
        "ip address",
        "cloudflare",
        "report",
        "whois",
        "as13335",
        "name lookup",
        "website",
        "kong",
        "ssl certificate",
        "http",
        "request chain",
        "nl redirected",
        "http redirect",
        "kb script",
        "protocol h3",
        "security quic",
        "seychelles",
        "asn13335",
        "cloudflarenet",
        "js function",
        "portable descr",
        "internet",
        "iana",
        "iana web",
        "stepgo limited",
        "assigned pa",
        "afrinic",
        "filtered parent",
        "ebene",
        "mahe",
        "stepgo",
        "united",
        "unknown ns",
        "script script",
        "moved",
        "record value",
        "title",
        "0 lte",
        "find s",
        "size",
        "mitre att",
        "ck id",
        "ck matrix",
        "root",
        "hybrid",
        "general",
        "path",
        "click",
        "strings",
        "yrbyd",
        "learn",
        "name tactics",
        "suspicious",
        "informative",
        "command",
        "adversaries",
        "spawns",
        "initial access",
        "lalal.ai",
        "record type",
        "ttl value",
        "thumbprint",
        "ios ping",
        "defense evasion",
        "id name",
        "malicious",
        "t1055.015 list planting",
        "sha1",
        "copy md5",
        "sha256",
        "pattern match",
        "show technique",
        "unknown",
        "accept",
        "date",
        "local",
        "starfield",
        "encrypt",
        "iframe",
        "prometheus intelligence technology",
        "apple",
        "cyber attacks",
        "usptracker.com",
        "android"
      ],
      "references": [
        "https://airline.cmntgoyq.com/  | Prometheus Intelligence Technology",
        "lalal.ai",
        "logstream-mystifying-tharp-7si72pw.cribl.cloud",
        "quantum-staging.emsbk.com",
        "spf.google.com",
        "Amazon.com",
        "mc.yandex.com \u2022 mc.yandex.ru \u2022 yandex.com \u2022 yandex.ru",
        "mc.yandex.com/metrika/ \u2022 mc.yandex.com/watch/99885987/",
        "api-cookie.click",
        "delete-me.bgs.beanie.cloud",
        "bridge-websocket-evolosciuc.devint01.goodleap.com",
        "https://bombing.gwuzafo.cc/",
        "test-ssa.pineapples.dev",
        "sso.dev.applemarketingtools.com",
        "containers-oceanus.palantirsec.com",
        "https://otx.alienvault.com/pulse/69af3fd8db2ede31abda6c14",
        "kadmos.bot \u2022 cutout.bot \u2022 scenebot.com",
        "https://www.lalal.ai/privacy-policy/InvalidOutputFolderErrorQAndroidJniObject",
        "Will sort to identify malware",
        "https://hybrid-analysis.com/sample/9e7bfc9fb60aa3e3f3c5b91f84ebf8b07e35893e1491149420535cd494bb8a32/69b1b467625a11ce330587db"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "Malware",
          "display_name": "Malware",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1069",
          "name": "Permission Groups Discovery",
          "display_name": "T1069 - Permission Groups Discovery"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1204",
          "name": "User Execution",
          "display_name": "T1204 - User Execution"
        },
        {
          "id": "T1480",
          "name": "Execution Guardrails",
          "display_name": "T1480 - Execution Guardrails"
        },
        {
          "id": "T1553",
          "name": "Subvert Trust Controls",
          "display_name": "T1553 - Subvert Trust Controls"
        },
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        },
        {
          "id": "T1568",
          "name": "Dynamic Resolution",
          "display_name": "T1568 - Dynamic Resolution"
        },
        {
          "id": "T1583",
          "name": "Acquire Infrastructure",
          "display_name": "T1583 - Acquire Infrastructure"
        },
        {
          "id": "T1583.001",
          "name": "Domains",
          "display_name": "T1583.001 - Domains"
        },
        {
          "id": "T1566.002",
          "name": "Spearphishing Link",
          "display_name": "T1566.002 - Spearphishing Link"
        },
        {
          "id": "T1553.002",
          "name": "Code Signing",
          "display_name": "T1553.002 - Code Signing"
        },
        {
          "id": "T1069.002",
          "name": "Domain Groups",
          "display_name": "T1069.002 - Domain Groups"
        },
        {
          "id": "T1071.004",
          "name": "DNS",
          "display_name": "T1071.004 - DNS"
        },
        {
          "id": "T1568.002",
          "name": "Domain Generation Algorithms",
          "display_name": "T1568.002 - Domain Generation Algorithms"
        },
        {
          "id": "T1071.001",
          "name": "Web Protocols",
          "display_name": "T1071.001 - Web Protocols"
        },
        {
          "id": "T1410",
          "name": "Network Traffic Capture or Redirection",
          "display_name": "T1410 - Network Traffic Capture or Redirection"
        },
        {
          "id": "TA0011",
          "name": "Command and Control",
          "display_name": "TA0011 - Command and Control"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1048",
          "name": "Exfiltration Over Alternative Protocol",
          "display_name": "T1048 - Exfiltration Over Alternative Protocol"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1083",
          "name": "File and Directory Discovery",
          "display_name": "T1083 - File and Directory Discovery"
        },
        {
          "id": "T1562",
          "name": "Impair Defenses",
          "display_name": "T1562 - Impair Defenses"
        },
        {
          "id": "T1562.001",
          "name": "Disable or Modify Tools",
          "display_name": "T1562.001 - Disable or Modify Tools"
        },
        {
          "id": "T1048.003",
          "name": "Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol",
          "display_name": "T1048.003 - Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol"
        },
        {
          "id": "T1584.005",
          "name": "Botnet",
          "display_name": "T1584.005 - Botnet"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": "69b1f368db0d00947ef729c2",
      "export_count": 1,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 4097,
        "domain": 849,
        "hostname": 2440,
        "FileHash-MD5": 149,
        "FileHash-SHA1": 131,
        "FileHash-SHA256": 955,
        "CIDR": 5,
        "email": 6,
        "SSLCertFingerprint": 8
      },
      "indicator_count": 8640,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 48,
      "modified_text": "8 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "69b1f368db0d00947ef729c2",
      "name": "\u5403\u74dc\u770b\u9ed1\u6599\u5c31\u4e0a - \u9ed1\u6599\u5403\u74dc\u7f51 | \u70ed\u95e8\u4e8b\u4ef6\u7206\u6599\u4e0e\u771f\u76f8",
      "description": "Why is this type of malicious found on a US citizens device? Found in a link extracted from a glitching device.. Palantir\u2019s Prometheus Intelligence Technology tracking and AI at work.\n#tracker #http_redirect #onlyfans_? #bombing #airlines #lalal.ai #openclaw #targeted",
      "modified": "2026-04-10T22:04:28.607000",
      "created": "2026-03-11T22:57:44.584000",
      "tags": [
        "\u9ed1\u6599",
        "\u5403\u74dc",
        "\u5403\u74dc\u7f51",
        "51\u5403\u74dc",
        "\u9ed1\u6599\u4e0d\u6253\u70ca",
        "\u9ed1\u6599\u5403\u74dc\u7f51",
        "\u70ed\u95e8\u5927\u74dc",
        "\u660e\u661f\u8d44\u8baf",
        "\u7f51\u7ea2\u9ed1\u6599",
        "\u5185\u6db5\u6bb5\u5b50",
        "\u4eca\u65e5\u5403\u74dc",
        "\u5403\u74dc\u65b0\u95fb",
        "\u9ed1\u6599\u66dd\u5149",
        "\u516b\u5366\u65b0\u95fb",
        "\u793e\u4f1a\u70ed\u70b9",
        "\u5403\u74dc\u7fa4\u4f17",
        "\u70ed\u70b9\u4e8b\u4ef6",
        "\u6bcf\u65e5\u5403\u74dc",
        "\u7f51\u7ea2\u5403\u74dc",
        "\u4eca\u65e5\u5927\u74dc",
        "\u5403\u74dc\u7206\u6599",
        "\u5403\u74dc\u4e2d\u5fc3",
        "\u4eca\u65e5\u70ed\u74dc",
        "\u5403\u74dc\u9ed1\u6599",
        "\u9ed1\u6599\u6cc4\u5bc6",
        "\u91cd\u78c5\u9ed1\u6599",
        "\u5403\u74dc\u6cc4\u5bc6",
        "\u4eca\u65e5\u9ed1\u6599",
        "\u6700\u65b0\u9ed1\u6599",
        "\u5403\u74dc\u66dd\u5149",
        "\u5403\u74dc\u8d44\u6e90",
        "\u91cd\u78c5\u5403\u74dc",
        "\u5a31\u4e50\u70ed\u74dc",
        "chrome",
        "cos ai",
        "a serif",
        "sans serif",
        "top10",
        "openclaw",
        "21200",
        "onlyfans",
        "strong",
        "dmca copyright",
        "address google",
        "safe browsing",
        "data upload",
        "extraction",
        "lte all",
        "enter sc",
        "type o",
        "extra",
        "referen https",
        "lte o",
        "type",
        "extr data",
        "include review",
        "exclude sugges",
        "failed",
        "hong kong",
        "passive dns",
        "otx logo",
        "all ipv4",
        "url analysis",
        "urls",
        "files",
        "location hong",
        "value",
        "march",
        "0x1595 function",
        "0x19b5 object",
        "tracker",
        "base64 object",
        "cookie function",
        "mlog",
        "localconst",
        "style function",
        "reverse dns",
        "general full",
        "url https",
        "resource",
        "software",
        "hash",
        "security tls",
        "singapore",
        "asn139341",
        "aceasap ace",
        "ip address",
        "cloudflare",
        "report",
        "whois",
        "as13335",
        "name lookup",
        "website",
        "kong",
        "ssl certificate",
        "http",
        "request chain",
        "nl redirected",
        "http redirect",
        "kb script",
        "protocol h3",
        "security quic",
        "seychelles",
        "asn13335",
        "cloudflarenet",
        "js function",
        "portable descr",
        "internet",
        "iana",
        "iana web",
        "stepgo limited",
        "assigned pa",
        "afrinic",
        "filtered parent",
        "ebene",
        "mahe",
        "stepgo",
        "united",
        "unknown ns",
        "script script",
        "moved",
        "record value",
        "title",
        "0 lte",
        "find s",
        "size",
        "mitre att",
        "ck id",
        "ck matrix",
        "root",
        "hybrid",
        "general",
        "path",
        "click",
        "strings",
        "yrbyd",
        "learn",
        "name tactics",
        "suspicious",
        "informative",
        "command",
        "adversaries",
        "spawns",
        "initial access",
        "lalal.ai",
        "record type",
        "ttl value",
        "thumbprint",
        "ios ping",
        "defense evasion",
        "id name",
        "malicious",
        "t1055.015 list planting",
        "sha1",
        "copy md5",
        "sha256",
        "pattern match",
        "show technique",
        "unknown",
        "accept",
        "date",
        "local",
        "starfield",
        "encrypt",
        "iframe",
        "prometheus intelligence technology",
        "apple",
        "cyber attacks",
        "usptracker.com",
        "android"
      ],
      "references": [
        "https://airline.cmntgoyq.com/  | Prometheus Intelligence Technology",
        "lalal.ai",
        "logstream-mystifying-tharp-7si72pw.cribl.cloud",
        "quantum-staging.emsbk.com",
        "spf.google.com",
        "Amazon.com",
        "mc.yandex.com \u2022 mc.yandex.ru \u2022 yandex.com \u2022 yandex.ru",
        "mc.yandex.com/metrika/ \u2022 mc.yandex.com/watch/99885987/",
        "api-cookie.click",
        "delete-me.bgs.beanie.cloud",
        "bridge-websocket-evolosciuc.devint01.goodleap.com",
        "https://bombing.gwuzafo.cc/",
        "test-ssa.pineapples.dev",
        "sso.dev.applemarketingtools.com",
        "containers-oceanus.palantirsec.com",
        "https://otx.alienvault.com/pulse/69af3fd8db2ede31abda6c14",
        "kadmos.bot \u2022 cutout.bot \u2022 scenebot.com",
        "https://www.lalal.ai/privacy-policy/InvalidOutputFolderErrorQAndroidJniObject",
        "Will sort to identify malware",
        "https://hybrid-analysis.com/sample/9e7bfc9fb60aa3e3f3c5b91f84ebf8b07e35893e1491149420535cd494bb8a32/69b1b467625a11ce330587db"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "Malware",
          "display_name": "Malware",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1069",
          "name": "Permission Groups Discovery",
          "display_name": "T1069 - Permission Groups Discovery"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1204",
          "name": "User Execution",
          "display_name": "T1204 - User Execution"
        },
        {
          "id": "T1480",
          "name": "Execution Guardrails",
          "display_name": "T1480 - Execution Guardrails"
        },
        {
          "id": "T1553",
          "name": "Subvert Trust Controls",
          "display_name": "T1553 - Subvert Trust Controls"
        },
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        },
        {
          "id": "T1568",
          "name": "Dynamic Resolution",
          "display_name": "T1568 - Dynamic Resolution"
        },
        {
          "id": "T1583",
          "name": "Acquire Infrastructure",
          "display_name": "T1583 - Acquire Infrastructure"
        },
        {
          "id": "T1583.001",
          "name": "Domains",
          "display_name": "T1583.001 - Domains"
        },
        {
          "id": "T1566.002",
          "name": "Spearphishing Link",
          "display_name": "T1566.002 - Spearphishing Link"
        },
        {
          "id": "T1553.002",
          "name": "Code Signing",
          "display_name": "T1553.002 - Code Signing"
        },
        {
          "id": "T1069.002",
          "name": "Domain Groups",
          "display_name": "T1069.002 - Domain Groups"
        },
        {
          "id": "T1071.004",
          "name": "DNS",
          "display_name": "T1071.004 - DNS"
        },
        {
          "id": "T1568.002",
          "name": "Domain Generation Algorithms",
          "display_name": "T1568.002 - Domain Generation Algorithms"
        },
        {
          "id": "T1071.001",
          "name": "Web Protocols",
          "display_name": "T1071.001 - Web Protocols"
        },
        {
          "id": "T1410",
          "name": "Network Traffic Capture or Redirection",
          "display_name": "T1410 - Network Traffic Capture or Redirection"
        },
        {
          "id": "TA0011",
          "name": "Command and Control",
          "display_name": "TA0011 - Command and Control"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1048",
          "name": "Exfiltration Over Alternative Protocol",
          "display_name": "T1048 - Exfiltration Over Alternative Protocol"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1083",
          "name": "File and Directory Discovery",
          "display_name": "T1083 - File and Directory Discovery"
        },
        {
          "id": "T1562",
          "name": "Impair Defenses",
          "display_name": "T1562 - Impair Defenses"
        },
        {
          "id": "T1562.001",
          "name": "Disable or Modify Tools",
          "display_name": "T1562.001 - Disable or Modify Tools"
        },
        {
          "id": "T1048.003",
          "name": "Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol",
          "display_name": "T1048.003 - Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol"
        },
        {
          "id": "T1584.005",
          "name": "Botnet",
          "display_name": "T1584.005 - Botnet"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 1,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Q.Vashti",
        "id": "337942",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 4097,
        "domain": 849,
        "hostname": 2440,
        "FileHash-MD5": 149,
        "FileHash-SHA1": 131,
        "FileHash-SHA256": 955,
        "CIDR": 5,
        "email": 6,
        "SSLCertFingerprint": 8
      },
      "indicator_count": 8640,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 138,
      "modified_text": "8 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "69aa41b0d714318bf8937184",
      "name": "W.Vashti .Net obfuscator clone",
      "description": "",
      "modified": "2026-04-04T00:06:41.423000",
      "created": "2026-03-06T02:53:36.216000",
      "tags": [
        "no expiration",
        "domain",
        "name",
        "control flow",
        "dlls",
        "method parent",
        "declarative",
        "ms build",
        "core",
        "msie",
        "windows nt",
        "wow64",
        "slcc2",
        "media center",
        "read c",
        "dock",
        "write",
        "execution",
        "capture",
        "endgame",
        "united",
        "moved",
        "ip address",
        "record value",
        "gate software",
        "newnham house",
        "expiration date",
        "urls",
        "url add",
        "http",
        "related nids",
        "files location",
        "flag united",
        "present aug",
        "present sep",
        "present nov",
        "present oct",
        "name servers",
        "emails",
        "present dec",
        "meta",
        "passive dns",
        "next associated",
        "ipv4",
        "url analysis",
        "files",
        "cookie",
        "subscribe",
        "unsubscribe",
        "s paris",
        "englewood",
        "state",
        "skip",
        "espaol",
        "summary",
        "filing history",
        "ireland",
        "title",
        "united states",
        "certificate",
        "colorado",
        "ipv4 add",
        "america flag",
        "showing",
        "pulse submit",
        "size",
        "pattern match",
        "mitre att",
        "ck id",
        "path",
        "hybrid",
        "general",
        "local",
        "iframe",
        "click",
        "strings",
        "cece",
        "mult",
        "learn",
        "name tactics",
        "suspicious",
        "informative",
        "command",
        "adversaries",
        "spawns",
        "t1590 gather",
        "victim network",
        "flag",
        "windir",
        "openurl c",
        "prefetch2",
        "analysis",
        "tor analysis",
        "dns requests",
        "domain address",
        "contacted hosts",
        "sha1",
        "sha256",
        "njmk",
        "kwruymy",
        "mime",
        "submitted",
        "process details",
        "calls",
        "apis",
        "reads",
        "defense evasion",
        "model",
        "getprocaddress",
        "show technique",
        "ck matrix",
        "access type",
        "value",
        "api call",
        "open",
        "august",
        "format",
        "typeof symbol",
        "typeof s",
        "typeof c",
        "function",
        "symbol",
        "comenabled",
        "image path",
        "ndex",
        "ndroleextdll",
        "f0f0f0",
        "ff4b55",
        "stop",
        "span",
        "show process",
        "binary file",
        "file",
        "network traffic",
        "encrypt",
        "date",
        "found",
        "ssl certificate",
        "creation date",
        "hostname add",
        "pulse pulses",
        "files ip",
        "address domain",
        "data upload",
        "extraction",
        "ge6 mira",
        "failed",
        "ascii text",
        "development att",
        "hostname",
        "files domain",
        "files related",
        "pulses otx",
        "pulses",
        "unknown aaaa",
        "unknown ns",
        "united states",
        "urls show",
        "date checked",
        "url hostname",
        "server response",
        "google safe",
        "results may",
        "a domains",
        "search",
        "germany unknown",
        "win32",
        "lowfi",
        "chrome",
        "susp",
        "trojan",
        "backdoor",
        "twitter",
        "virtool",
        "worm",
        "exploit",
        "trojandropper",
        "win32upatre dec",
        "mtb dec",
        "reverse dns",
        "body",
        "location united",
        "asn as14618",
        "less whois",
        "files show",
        "date hash",
        "avast avg",
        "initial access",
        "javascript",
        "root",
        "enterprise",
        "form",
        "desktop",
        "command decode",
        "suricata ipv4",
        "spycloud",
        "robots",
        "bots",
        "chatbot",
        "bot network",
        "spy",
        "mixb",
        "a2fryx",
        "therahand",
        "typosquating"
      ],
      "references": [
        "https://www.red-gate.com/products/smartassembly",
        "spycloud.com \u2022 content.spycloud.com \u2022 email.spycloud.com\t hostname\tengage.spycloud.com \u2022 hello.spycloud.com \u2022portal.spycloud.com \u2022 https://email.spycloud",
        "https://email.spycloud.com/NzEzLVdJUC03MzcAAAGe67eM-W3qxAlVkEvZwfw1dWuwRdm0zVU5aMyOzUe2IkxAY3hDe8RfT27HnjgkvTk-uqIy6K0=",
        "https://spycloud.com/solutions/\t\u2022 104.18.26.108 ELF:Mirai-GH\\ [Trj] \u2022 Unix.Dropper.Mirai-7135870-0",
        "dasima-containers.palantirfoundry.com \u2022 blitzrobots.com",
        "https://blog.endgames.com/ \u2022 wg41xm05b3.endgamesystems.com",
        "https://www.coloradosos.gov/biz/BusinessEntityDetail.do?quitButtonDestination=BusinessEntityResults&nameTyp=ENT&masterFileId=20221473927&entityId2=20221473927&fileId=20251525819&srchTyp=ENTITY",
        "www.onyx-ware.com \u2022 http://pages.endgames.com/ \u2022  http://www.endgamesystems.com/",
        "https://hybrid-analysis.com/sample/9a1e0d38b691f1d22a92cff65ec0439b428170ac39a4493c7ecb06d5585f56a3/68a4adea30f7fafee90aefd3",
        "Malicious: http://developers.cloudfiare.com/support/troubleshooting/http-status-",
        "Typosquating: developers.cloudfiare.com \u2022 cloudfiare.com"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Unix.Dropper.Mirai-7135870-0",
          "display_name": "Unix.Dropper.Mirai-7135870-0",
          "target": null
        },
        {
          "id": "ELF:Mirai-GH\\ [Trj]",
          "display_name": "ELF:Mirai-GH\\ [Trj]",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1090",
          "name": "Proxy",
          "display_name": "T1090 - Proxy"
        },
        {
          "id": "T1553",
          "name": "Subvert Trust Controls",
          "display_name": "T1553 - Subvert Trust Controls"
        },
        {
          "id": "T1127",
          "name": "Trusted Developer Utilities Proxy Execution",
          "display_name": "T1127 - Trusted Developer Utilities Proxy Execution"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1560",
          "name": "Archive Collected Data",
          "display_name": "T1560 - Archive Collected Data"
        },
        {
          "id": "T1053",
          "name": "Scheduled Task/Job",
          "display_name": "T1053 - Scheduled Task/Job"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1056",
          "name": "Input Capture",
          "display_name": "T1056 - Input Capture"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1119",
          "name": "Automated Collection",
          "display_name": "T1119 - Automated Collection"
        },
        {
          "id": "T1129",
          "name": "Shared Modules",
          "display_name": "T1129 - Shared Modules"
        },
        {
          "id": "T1143",
          "name": "Hidden Window",
          "display_name": "T1143 - Hidden Window"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1069",
          "name": "Permission Groups Discovery",
          "display_name": "T1069 - Permission Groups Discovery"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1083",
          "name": "File and Directory Discovery",
          "display_name": "T1083 - File and Directory Discovery"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1480",
          "name": "Execution Guardrails",
          "display_name": "T1480 - Execution Guardrails"
        },
        {
          "id": "T1568",
          "name": "Dynamic Resolution",
          "display_name": "T1568 - Dynamic Resolution"
        },
        {
          "id": "T1583",
          "name": "Acquire Infrastructure",
          "display_name": "T1583 - Acquire Infrastructure"
        },
        {
          "id": "T1590",
          "name": "Gather Victim Network Information",
          "display_name": "T1590 - Gather Victim Network Information"
        },
        {
          "id": "T1113",
          "name": "Screen Capture",
          "display_name": "T1113 - Screen Capture"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1583.001",
          "name": "Domains",
          "display_name": "T1583.001 - Domains"
        },
        {
          "id": "T1553.002",
          "name": "Code Signing",
          "display_name": "T1553.002 - Code Signing"
        },
        {
          "id": "T1069.002",
          "name": "Domain Groups",
          "display_name": "T1069.002 - Domain Groups"
        },
        {
          "id": "T1568.002",
          "name": "Domain Generation Algorithms",
          "display_name": "T1568.002 - Domain Generation Algorithms"
        },
        {
          "id": "T1071.001",
          "name": "Web Protocols",
          "display_name": "T1071.001 - Web Protocols"
        },
        {
          "id": "T1071.004",
          "name": "DNS",
          "display_name": "T1071.004 - DNS"
        },
        {
          "id": "T1003",
          "name": "OS Credential Dumping",
          "display_name": "T1003 - OS Credential Dumping"
        },
        {
          "id": "T1007",
          "name": "System Service Discovery",
          "display_name": "T1007 - System Service Discovery"
        },
        {
          "id": "T1010",
          "name": "Application Window Discovery",
          "display_name": "T1010 - Application Window Discovery"
        },
        {
          "id": "T1012",
          "name": "Query Registry",
          "display_name": "T1012 - Query Registry"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1068",
          "name": "Exploitation for Privilege Escalation",
          "display_name": "T1068 - Exploitation for Privilege Escalation"
        },
        {
          "id": "T1106",
          "name": "Native API",
          "display_name": "T1106 - Native API"
        },
        {
          "id": "T1497",
          "name": "Virtualization/Sandbox Evasion",
          "display_name": "T1497 - Virtualization/Sandbox Evasion"
        },
        {
          "id": "T1546",
          "name": "Event Triggered Execution",
          "display_name": "T1546 - Event Triggered Execution"
        },
        {
          "id": "T1562",
          "name": "Impair Defenses",
          "display_name": "T1562 - Impair Defenses"
        },
        {
          "id": "T1614",
          "name": "System Location Discovery",
          "display_name": "T1614 - System Location Discovery"
        },
        {
          "id": "T1122",
          "name": "Component Object Model Hijacking",
          "display_name": "T1122 - Component Object Model Hijacking"
        },
        {
          "id": "T1415",
          "name": "URL Scheme Hijacking",
          "display_name": "T1415 - URL Scheme Hijacking"
        },
        {
          "id": "T1416",
          "name": "URI Hijacking",
          "display_name": "T1416 - URI Hijacking"
        },
        {
          "id": "T1059.007",
          "name": "JavaScript",
          "display_name": "T1059.007 - JavaScript"
        },
        {
          "id": "T1584.005",
          "name": "Botnet",
          "display_name": "T1584.005 - Botnet"
        },
        {
          "id": "T1189",
          "name": "Drive-by Compromise",
          "display_name": "T1189 - Drive-by Compromise"
        },
        {
          "id": "T1204",
          "name": "User Execution",
          "display_name": "T1204 - User Execution"
        },
        {
          "id": "T1562.001",
          "name": "Disable or Modify Tools",
          "display_name": "T1562.001 - Disable or Modify Tools"
        },
        {
          "id": "T1116",
          "name": "Code Signing",
          "display_name": "T1116 - Code Signing"
        },
        {
          "id": "T1546.015",
          "name": "Component Object Model Hijacking",
          "display_name": "T1546.015 - Component Object Model Hijacking"
        },
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        },
        {
          "id": "T1014",
          "name": "Rootkit",
          "display_name": "T1014 - Rootkit"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": "6952d4fc6910b0b866746d8a",
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 341,
        "FileHash-SHA1": 343,
        "FileHash-SHA256": 1332,
        "domain": 1062,
        "hostname": 1969,
        "URL": 5700,
        "email": 10,
        "SSLCertFingerprint": 21,
        "CVE": 1
      },
      "indicator_count": 10779,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 49,
      "modified_text": "15 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "69c795bb826e6067f37ea127",
      "name": "'3'  clone by credit: krishivpatel",
      "description": "",
      "modified": "2026-03-28T08:47:55.537000",
      "created": "2026-03-28T08:47:55.537000",
      "tags": [
        "record type",
        "ttl value",
        "algorithm",
        "data",
        "v3 serial",
        "number",
        "cus olet",
        "encrypt cnr3",
        "validity",
        "subject public",
        "key info",
        "key algorithm",
        "dns replication",
        "date",
        "type name",
        "text",
        "mailpass mixed",
        "redacted for",
        "privacy tech",
        "postal code",
        "server",
        "registrar abuse",
        "code",
        "domain id",
        "iana id",
        "admin country",
        "script urls",
        "a domains",
        "search",
        "status",
        "x fw",
        "record value",
        "for privacy",
        "title",
        "body",
        "unknown",
        "encrypt",
        "log id",
        "gmtn",
        "tls web",
        "ca issuers",
        "timestamp",
        "b715",
        "b59bn timestamp",
        "cc50689e0a",
        "scan endpoints",
        "false",
        "digicert tls",
        "rsa sha256",
        "full name",
        "digicert inc",
        "organization",
        "massachusetts",
        "cambridge",
        "as54113",
        "united",
        "trojan",
        "passive dns",
        "showing",
        "entries",
        "win32",
        "flywheel",
        "sea x",
        "accept",
        "twitter",
        "ransom",
        "meta",
        "urls",
        "all scoreblue",
        "url http",
        "pulse pulses",
        "http",
        "ip address",
        "related nids",
        "files location",
        "nxdomain",
        "whitelisted",
        "cname",
        "aaaa",
        "gandi sas",
        "creation date",
        "emails",
        "avast avg",
        "ipv4",
        "files",
        "location united",
        "ascii text",
        "pattern match",
        "png image",
        "rgba",
        "suricata stream",
        "command decode",
        "size",
        "sha1",
        "mitre att",
        "et tor",
        "hybrid",
        "general",
        "local",
        "click",
        "strings",
        "4624",
        "glox",
        "ck id",
        "suspicious",
        "learn",
        "command",
        "name tactics",
        "informative",
        "ck techniques",
        "development att",
        "adversaries",
        "historical ssl",
        "referrer",
        "copy",
        "typosquat infra",
        "tracker",
        "jekyll",
        "hide",
        "norad tracking",
        "speakez securus",
        "nuance china",
        "phishing",
        "facebook",
        "hiddentear",
        "metro",
        "malware",
        "malicious",
        "skynet",
        "revil",
        "pykspa",
        "next",
        "as44273 host",
        "as7018 att",
        "domain related",
        "hosting",
        "name servers",
        "west domains",
        "asnone germany",
        "singapore",
        "as21499 host",
        "as20940",
        "germany",
        "object",
        "found",
        "domain",
        "files domain",
        "files related",
        "pulses otx",
        "pulses",
        "tags",
        "related tags",
        "win32 exe",
        "pe32",
        "intel",
        "ms windows",
        "win32 dynamic",
        "link library",
        "win16 ne",
        "delphi generic",
        "icons library",
        "pe32 linker",
        "info header",
        "name md5",
        "overlay",
        "dos exe",
        "moved",
        "gmt server",
        "centos",
        "domains",
        "dynadot inc",
        "contacted",
        "ip detections",
        "country",
        "de execution",
        "parents",
        "file type",
        "pulse submit",
        "url analysis",
        "win32heur mar",
        "dynamicloader",
        "medium",
        "qaeaav12",
        "windows",
        "high",
        "show",
        "qbeipbdii",
        "inetsim http",
        "powershell",
        "drweb",
        "write",
        "default",
        "module load",
        "t1129",
        "post http",
        "dock",
        "june",
        "delphi",
        "read c",
        "renos",
        "trojan downloader",
        "social engineering",
        "dns",
        "fraud",
        "cybercrime",
        "stalking",
        "tracking",
        "apple",
        "apple ios",
        "samsung",
        "danger"
      ],
      "references": [
        "https://the initiative.org | Initiative Co.org | chelsea@theinitiativeco.org",
        "Antivirus Detections:: Win.Downloader.103202-1 ,  #LowFiEnableDTContinueAfterUnpacking",
        "IDS Detections: Long Fake wget 3.0 User-Agent Detected Win32.Renos/Artro Trojan Checkin M1 Win32/Renos Checkin 3",
        "IDS Detections: W32/TrojanDownloader.Renos CnC Activity Suspicious User-Agent Malware related Windows wget network_http",
        "Alerts: cape_detected_threat antidebug_devices antivm_generic_disk enumerates_physical_drives deletes_executed_files",
        "Alerts: deletes_self suricata_alert dynamic_function_loading powershell_download powershell_request stealth_window",
        "Alerts: injection_rwx network_cnc_http antidebug_setunhandledexceptionfilter stealth_timeout uses_windows_utilities",
        "https://applemusic-spotlight.myunidays.com/US/en-US?",
        "applemusic-spotlight.myunidays.com | nr-data.net [Apple Private Data Collection] Sabey Data Center",
        "http://borowski-duncan.com/?user-agent=mozilla/5.0+(windows+nt+10.0;+win64;+x64)+applewebkit/537.36+(khtml,+like+gecko)+chrome/86.0.424",
        "http://imap.brooklyngeneration.org/__media__/js/netsoltrademark.php?d=www.fap18pgals.eu/brazilian-porn/",
        "A Jefferson County, Co Police 'advocate' referred target to a group that 'couldn't' to provide services. Referred to The Bench. Unwilling to help",
        "Victim gets a 'social' engineering' call taking every bit of information about victim and case.",
        "She was cleared for treatment; then declined citing a brain injury. Most of 'BB' clients have a TBI",
        "Victim was then given numbers to workers compensation doctors who didn't speak English",
        "Law Firm drops her and asks her who she really is? Victim was assaulted for her phone and other",
        "Victim doesn't fault Police who didn't show intent. Detective did close case, assailant  ID issues",
        "Was told by advocate that his description matches the male in vehicle following her for months.",
        "Be did wear a gator making it improbable for positive identification",
        "She was assaulted for phone 6 weeks after being intentional,y driven off highway",
        "Higher SCI sustained. Positive ID. Driver allowed to walk. Positive License Plate and description of driver with criminal intent.",
        "In the USA she is denied treatment for new injuries to spine causing deep decline. This is crazy.",
        "A series of strange female detectives enter. All corrupt fails. If victim was in prison fight she'd be treated w/guards outside of hospital room door."
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1553",
          "name": "Subvert Trust Controls",
          "display_name": "T1553 - Subvert Trust Controls"
        },
        {
          "id": "T1568",
          "name": "Dynamic Resolution",
          "display_name": "T1568 - Dynamic Resolution"
        },
        {
          "id": "T1583",
          "name": "Acquire Infrastructure",
          "display_name": "T1583 - Acquire Infrastructure"
        },
        {
          "id": "T1071.004",
          "name": "DNS",
          "display_name": "T1071.004 - DNS"
        },
        {
          "id": "T1568.002",
          "name": "Domain Generation Algorithms",
          "display_name": "T1568.002 - Domain Generation Algorithms"
        },
        {
          "id": "T1583.001",
          "name": "Domains",
          "display_name": "T1583.001 - Domains"
        },
        {
          "id": "T1553.002",
          "name": "Code Signing",
          "display_name": "T1553.002 - Code Signing"
        },
        {
          "id": "T1071.001",
          "name": "Web Protocols",
          "display_name": "T1071.001 - Web Protocols"
        },
        {
          "id": "T1036",
          "name": "Masquerading",
          "display_name": "T1036 - Masquerading"
        },
        {
          "id": "T1036.004",
          "name": "Masquerade Task or Service",
          "display_name": "T1036.004 - Masquerade Task or Service"
        },
        {
          "id": "T1031",
          "name": "Modify Existing Service",
          "display_name": "T1031 - Modify Existing Service"
        },
        {
          "id": "T1023",
          "name": "Shortcut Modification",
          "display_name": "T1023 - Shortcut Modification"
        },
        {
          "id": "T1045",
          "name": "Software Packing",
          "display_name": "T1045 - Software Packing"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1060",
          "name": "Registry Run Keys / Startup Folder",
          "display_name": "T1060 - Registry Run Keys / Startup Folder"
        },
        {
          "id": "T1070",
          "name": "Indicator Removal on Host",
          "display_name": "T1070 - Indicator Removal on Host"
        },
        {
          "id": "T1083",
          "name": "File and Directory Discovery",
          "display_name": "T1083 - File and Directory Discovery"
        },
        {
          "id": "T1129",
          "name": "Shared Modules",
          "display_name": "T1129 - Shared Modules"
        },
        {
          "id": "T1143",
          "name": "Hidden Window",
          "display_name": "T1143 - Hidden Window"
        },
        {
          "id": "T1583.005",
          "name": "Botnet",
          "display_name": "T1583.005 - Botnet"
        },
        {
          "id": "T1584",
          "name": "Compromise Infrastructure",
          "display_name": "T1584 - Compromise Infrastructure"
        },
        {
          "id": "T1122",
          "name": "Component Object Model Hijacking",
          "display_name": "T1122 - Component Object Model Hijacking"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": "66cc6e2c6c5bb617fa7fa892",
      "export_count": 3,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "email": 6,
        "domain": 782,
        "hostname": 530,
        "FileHash-SHA1": 382,
        "FileHash-SHA256": 1572,
        "URL": 847,
        "FileHash-MD5": 386,
        "SSLCertFingerprint": 12
      },
      "indicator_count": 4517,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 48,
      "modified_text": "22 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6952d4fc6910b0b866746d8a",
      "name": ".NET Obfuscator, Error Reporting, DLL Merging | SmartAssembly | Spycloud",
      "description": "*Mirai | Currently being used maliciously. Mirai botnet work in place. Obfuscation, call redirection, evasion , chatbots, spyware , cal retrieval , typosquating , and other tactics used against victim.   Red hats being unethical is expected.. This team is attacking in this instance. Screen Capture 24/7. Malicious media +++ from Englewood, Co. \n\nWhen used ethically SmartAssembly protects your code and Intellectual Property with powerful obfuscation features, and provides error reports when your application crashes in the wild, as well as a range of other tools for database management and data management.\n#palantir #foundry #denver #englewood #colorado #spycloud #mirai #botnet",
      "modified": "2026-01-28T18:03:54.589000",
      "created": "2025-12-29T19:22:36.103000",
      "tags": [
        "no expiration",
        "domain",
        "name",
        "control flow",
        "dlls",
        "method parent",
        "declarative",
        "ms build",
        "core",
        "msie",
        "windows nt",
        "wow64",
        "slcc2",
        "media center",
        "read c",
        "dock",
        "write",
        "execution",
        "capture",
        "endgame",
        "united",
        "moved",
        "ip address",
        "record value",
        "gate software",
        "newnham house",
        "expiration date",
        "urls",
        "url add",
        "http",
        "related nids",
        "files location",
        "flag united",
        "present aug",
        "present sep",
        "present nov",
        "present oct",
        "name servers",
        "emails",
        "present dec",
        "meta",
        "passive dns",
        "next associated",
        "ipv4",
        "url analysis",
        "files",
        "cookie",
        "subscribe",
        "unsubscribe",
        "s paris",
        "englewood",
        "state",
        "skip",
        "espaol",
        "summary",
        "filing history",
        "ireland",
        "title",
        "united states",
        "certificate",
        "colorado",
        "ipv4 add",
        "america flag",
        "showing",
        "pulse submit",
        "size",
        "pattern match",
        "mitre att",
        "ck id",
        "path",
        "hybrid",
        "general",
        "local",
        "iframe",
        "click",
        "strings",
        "cece",
        "mult",
        "learn",
        "name tactics",
        "suspicious",
        "informative",
        "command",
        "adversaries",
        "spawns",
        "t1590 gather",
        "victim network",
        "flag",
        "windir",
        "openurl c",
        "prefetch2",
        "analysis",
        "tor analysis",
        "dns requests",
        "domain address",
        "contacted hosts",
        "sha1",
        "sha256",
        "njmk",
        "kwruymy",
        "mime",
        "submitted",
        "process details",
        "calls",
        "apis",
        "reads",
        "defense evasion",
        "model",
        "getprocaddress",
        "show technique",
        "ck matrix",
        "access type",
        "value",
        "api call",
        "open",
        "august",
        "format",
        "typeof symbol",
        "typeof s",
        "typeof c",
        "function",
        "symbol",
        "comenabled",
        "image path",
        "ndex",
        "ndroleextdll",
        "f0f0f0",
        "ff4b55",
        "stop",
        "span",
        "show process",
        "binary file",
        "file",
        "network traffic",
        "encrypt",
        "date",
        "found",
        "ssl certificate",
        "creation date",
        "hostname add",
        "pulse pulses",
        "files ip",
        "address domain",
        "data upload",
        "extraction",
        "ge6 mira",
        "failed",
        "ascii text",
        "development att",
        "hostname",
        "files domain",
        "files related",
        "pulses otx",
        "pulses",
        "unknown aaaa",
        "unknown ns",
        "united states",
        "urls show",
        "date checked",
        "url hostname",
        "server response",
        "google safe",
        "results may",
        "a domains",
        "search",
        "germany unknown",
        "win32",
        "lowfi",
        "chrome",
        "susp",
        "trojan",
        "backdoor",
        "twitter",
        "virtool",
        "worm",
        "exploit",
        "trojandropper",
        "win32upatre dec",
        "mtb dec",
        "reverse dns",
        "body",
        "location united",
        "asn as14618",
        "less whois",
        "files show",
        "date hash",
        "avast avg",
        "initial access",
        "javascript",
        "root",
        "enterprise",
        "form",
        "desktop",
        "command decode",
        "suricata ipv4",
        "spycloud",
        "robots",
        "bots",
        "chatbot",
        "bot network",
        "spy",
        "mixb",
        "a2fryx",
        "therahand",
        "typosquating"
      ],
      "references": [
        "https://www.red-gate.com/products/smartassembly",
        "spycloud.com \u2022 content.spycloud.com \u2022 email.spycloud.com\t hostname\tengage.spycloud.com \u2022 hello.spycloud.com \u2022portal.spycloud.com \u2022 https://email.spycloud",
        "https://email.spycloud.com/NzEzLVdJUC03MzcAAAGe67eM-W3qxAlVkEvZwfw1dWuwRdm0zVU5aMyOzUe2IkxAY3hDe8RfT27HnjgkvTk-uqIy6K0=",
        "https://spycloud.com/solutions/\t\u2022 104.18.26.108 ELF:Mirai-GH\\ [Trj] \u2022 Unix.Dropper.Mirai-7135870-0",
        "dasima-containers.palantirfoundry.com \u2022 blitzrobots.com",
        "https://blog.endgames.com/ \u2022 wg41xm05b3.endgamesystems.com",
        "https://www.coloradosos.gov/biz/BusinessEntityDetail.do?quitButtonDestination=BusinessEntityResults&nameTyp=ENT&masterFileId=20221473927&entityId2=20221473927&fileId=20251525819&srchTyp=ENTITY",
        "www.onyx-ware.com \u2022 http://pages.endgames.com/ \u2022  http://www.endgamesystems.com/",
        "https://hybrid-analysis.com/sample/9a1e0d38b691f1d22a92cff65ec0439b428170ac39a4493c7ecb06d5585f56a3/68a4adea30f7fafee90aefd3",
        "Malicious: http://developers.cloudfiare.com/support/troubleshooting/http-status-",
        "Typosquating: developers.cloudfiare.com \u2022 cloudfiare.com"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Unix.Dropper.Mirai-7135870-0",
          "display_name": "Unix.Dropper.Mirai-7135870-0",
          "target": null
        },
        {
          "id": "ELF:Mirai-GH\\ [Trj]",
          "display_name": "ELF:Mirai-GH\\ [Trj]",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1090",
          "name": "Proxy",
          "display_name": "T1090 - Proxy"
        },
        {
          "id": "T1553",
          "name": "Subvert Trust Controls",
          "display_name": "T1553 - Subvert Trust Controls"
        },
        {
          "id": "T1127",
          "name": "Trusted Developer Utilities Proxy Execution",
          "display_name": "T1127 - Trusted Developer Utilities Proxy Execution"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1560",
          "name": "Archive Collected Data",
          "display_name": "T1560 - Archive Collected Data"
        },
        {
          "id": "T1053",
          "name": "Scheduled Task/Job",
          "display_name": "T1053 - Scheduled Task/Job"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1056",
          "name": "Input Capture",
          "display_name": "T1056 - Input Capture"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1119",
          "name": "Automated Collection",
          "display_name": "T1119 - Automated Collection"
        },
        {
          "id": "T1129",
          "name": "Shared Modules",
          "display_name": "T1129 - Shared Modules"
        },
        {
          "id": "T1143",
          "name": "Hidden Window",
          "display_name": "T1143 - Hidden Window"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1069",
          "name": "Permission Groups Discovery",
          "display_name": "T1069 - Permission Groups Discovery"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1083",
          "name": "File and Directory Discovery",
          "display_name": "T1083 - File and Directory Discovery"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1480",
          "name": "Execution Guardrails",
          "display_name": "T1480 - Execution Guardrails"
        },
        {
          "id": "T1568",
          "name": "Dynamic Resolution",
          "display_name": "T1568 - Dynamic Resolution"
        },
        {
          "id": "T1583",
          "name": "Acquire Infrastructure",
          "display_name": "T1583 - Acquire Infrastructure"
        },
        {
          "id": "T1590",
          "name": "Gather Victim Network Information",
          "display_name": "T1590 - Gather Victim Network Information"
        },
        {
          "id": "T1113",
          "name": "Screen Capture",
          "display_name": "T1113 - Screen Capture"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1583.001",
          "name": "Domains",
          "display_name": "T1583.001 - Domains"
        },
        {
          "id": "T1553.002",
          "name": "Code Signing",
          "display_name": "T1553.002 - Code Signing"
        },
        {
          "id": "T1069.002",
          "name": "Domain Groups",
          "display_name": "T1069.002 - Domain Groups"
        },
        {
          "id": "T1568.002",
          "name": "Domain Generation Algorithms",
          "display_name": "T1568.002 - Domain Generation Algorithms"
        },
        {
          "id": "T1071.001",
          "name": "Web Protocols",
          "display_name": "T1071.001 - Web Protocols"
        },
        {
          "id": "T1071.004",
          "name": "DNS",
          "display_name": "T1071.004 - DNS"
        },
        {
          "id": "T1003",
          "name": "OS Credential Dumping",
          "display_name": "T1003 - OS Credential Dumping"
        },
        {
          "id": "T1007",
          "name": "System Service Discovery",
          "display_name": "T1007 - System Service Discovery"
        },
        {
          "id": "T1010",
          "name": "Application Window Discovery",
          "display_name": "T1010 - Application Window Discovery"
        },
        {
          "id": "T1012",
          "name": "Query Registry",
          "display_name": "T1012 - Query Registry"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1068",
          "name": "Exploitation for Privilege Escalation",
          "display_name": "T1068 - Exploitation for Privilege Escalation"
        },
        {
          "id": "T1106",
          "name": "Native API",
          "display_name": "T1106 - Native API"
        },
        {
          "id": "T1497",
          "name": "Virtualization/Sandbox Evasion",
          "display_name": "T1497 - Virtualization/Sandbox Evasion"
        },
        {
          "id": "T1546",
          "name": "Event Triggered Execution",
          "display_name": "T1546 - Event Triggered Execution"
        },
        {
          "id": "T1562",
          "name": "Impair Defenses",
          "display_name": "T1562 - Impair Defenses"
        },
        {
          "id": "T1614",
          "name": "System Location Discovery",
          "display_name": "T1614 - System Location Discovery"
        },
        {
          "id": "T1122",
          "name": "Component Object Model Hijacking",
          "display_name": "T1122 - Component Object Model Hijacking"
        },
        {
          "id": "T1415",
          "name": "URL Scheme Hijacking",
          "display_name": "T1415 - URL Scheme Hijacking"
        },
        {
          "id": "T1416",
          "name": "URI Hijacking",
          "display_name": "T1416 - URI Hijacking"
        },
        {
          "id": "T1059.007",
          "name": "JavaScript",
          "display_name": "T1059.007 - JavaScript"
        },
        {
          "id": "T1584.005",
          "name": "Botnet",
          "display_name": "T1584.005 - Botnet"
        },
        {
          "id": "T1189",
          "name": "Drive-by Compromise",
          "display_name": "T1189 - Drive-by Compromise"
        },
        {
          "id": "T1204",
          "name": "User Execution",
          "display_name": "T1204 - User Execution"
        },
        {
          "id": "T1562.001",
          "name": "Disable or Modify Tools",
          "display_name": "T1562.001 - Disable or Modify Tools"
        },
        {
          "id": "T1116",
          "name": "Code Signing",
          "display_name": "T1116 - Code Signing"
        },
        {
          "id": "T1546.015",
          "name": "Component Object Model Hijacking",
          "display_name": "T1546.015 - Component Object Model Hijacking"
        },
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        },
        {
          "id": "T1014",
          "name": "Rootkit",
          "display_name": "T1014 - Rootkit"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 3,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Q.Vashti",
        "id": "337942",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 341,
        "FileHash-SHA1": 343,
        "FileHash-SHA256": 1332,
        "domain": 1062,
        "hostname": 1967,
        "URL": 5699,
        "email": 10,
        "SSLCertFingerprint": 21,
        "CVE": 1
      },
      "indicator_count": 10776,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 138,
      "modified_text": "81 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "69519fa818f84531ce6becc9",
      "name": "Cart.Guru Malware Hosting - Malware Packed _Pegasus Espionage Detected (Positive)",
      "description": "I really love using this tool (LevelBlue -OTX) In all reality this information would have been sent to the government. CISA , NSA, Homeland Security, Citizens Lab, Canada based international organization would have been involved years ago. Where does this information goes. Citizens Lab would has been attempting to track 1000\u2019s of affected Pegasus targets. OTX detected and tagged Pegasus. I suspected it. This is from a Palantir Malware Hosting Honey Pot. \n\nWhen Pegasus was discovered in the wild , credited to those who found what the real team (T8) found, Citizens Lab then conducted tests in 2021\non the cell phone of Jamal Khashoggi, a Saudi dissident journalist. Pegasus is a kill list. \n\nVictims need help. There are a few people even on this platform that are on this list. Unless it\u2019s the US government who has ordered these actions, I don\u2019t know what is going on. The targets are not only innocent, some are crime victims, some are going mad. AT&T corporate easily confirms LevelBlue is legitimate.",
      "modified": "2026-01-27T21:02:45.343000",
      "created": "2025-12-28T21:22:48.383000",
      "tags": [
        "united",
        "servers",
        "moved",
        "ip address",
        "record value",
        "encrypt",
        "present jul",
        "present jun",
        "trojandropper",
        "passive dns",
        "ipv4 add",
        "urls",
        "files",
        "virtool",
        "united states",
        "dynamicloader",
        "directui",
        "element",
        "classinfobase",
        "write c",
        "medium",
        "yara rule",
        "msvisualbasic60",
        "high",
        "hwndelement",
        "explorer",
        "write",
        "movie",
        "insert",
        "program",
        "python",
        "http traffic",
        "trojan generic",
        "search",
        "cnc activity",
        "delphi",
        "win32",
        "launcher",
        "pony",
        "fareit",
        "malware",
        "push",
        "msie",
        "windows nt",
        "generic",
        "checkin",
        "post",
        "yara detections",
        "rxr",
        "inject",
        "memcommit",
        "cryptexportkey",
        "invalid pointer",
        "regsetvalueexa",
        "solutions ltd",
        "read c",
        "regdword",
        "mozilla",
        "persistence",
        "execution",
        "android",
        "unknown",
        "learn",
        "suspicious",
        "informative",
        "adversaries",
        "ck id",
        "name tactics",
        "command",
        "initial access",
        "defense evasion",
        "spawns",
        "t1590 gather",
        "flag",
        "click",
        "windir",
        "openurl c",
        "prefetch2",
        "analysis",
        "tor analysis",
        "dns requests",
        "domain address",
        "pattern match",
        "mitre att",
        "ck matrix",
        "href",
        "ascii text",
        "starfield",
        "hybrid",
        "general",
        "local",
        "path",
        "iframe",
        "palantir",
        "present nov",
        "present oct",
        "status",
        "present apr",
        "present dec",
        "cryp",
        "date",
        "trojan",
        "title",
        "name servers",
        "windows",
        "t1060",
        "disables proxy",
        "dock",
        "pegasus",
        "rootkit",
        "backdoor",
        "susp",
        "win32qqpass feb",
        "worm",
        "msr win32",
        "win64",
        "process32nextw",
        "findwindowa",
        "file execution",
        "writeconsolea",
        "procexpl",
        "file v2",
        "document",
        "document file",
        "v2 document",
        "lost",
        "tools",
        "pecompact",
        "media",
        "autorun",
        "service",
        "post http",
        "delete",
        "alerts",
        "emotet",
        "rkt",
        "autorun",
        "worm",
        "plugins",
        "title error",
        "body doctype",
        "html public",
        "w3cdtd html",
        "html head",
        "domain",
        "expiration date",
        "hostname add",
        "pulse pulses",
        "contacted hosts",
        "sha1",
        "sha256",
        "show technique",
        "strings",
        "t1480 execution",
        "signing defense",
        "script urls",
        "a domains",
        "unknown ns",
        "texas flyover",
        "script domains",
        "script script",
        "meta",
        "window",
        "process details",
        "contacted"
      ],
      "references": [
        "Cart.Guru",
        "Yara Detections: Delphi",
        "Chekin -Fareit/Pony Downloader Checkin 2 \u2022 Generic - POST To gate.php with no referer",
        "MSIL/Injector.RXR Variant CnC Activity Trojanr Generic - POST To gate.php with no referer",
        "HTTP traffic on port 443 (POST)",
        "IDS Detections Observed Suspicious UA (NSIS_Inetc (Mozilla)) Observed DNS Query",
        "Alerts: crime_win_cutwail_stage2  infostealer_browser infostealer_cookies recon_programs",
        "Alerts: banker_zeus_url procmem_yara suricata_alert infostealer_ftp dynamic_function_loading reads_self network_cnc_http",
        "Alerts: network_icmp persistence_autorun deletes_executed_files modifies_certificates",
        "Alerts: ransomware_dropped_files dumped_buffer network_cnc_http network_http",
        "Alerts: network_http_post allocates_rwx antisandbox_sleep antivm_disk_size creates_exe",
        "Alerts: exe_appdata antivm_network_adapters network_downloader_exe privilege_luid_check",
        "Alerts: checks_debugger generates_crypto_key modifies_proxy_wpad",
        "Yara Detections:  Nullsoft_NSIS    ...",
        "Win32:Evo-gen\\ [Susp] http://downwingbuttons.site/7/huge.dat",
        "Small: Win32:Malware-gen (Small) Yara Detections stack_string \u2022 Domains Contacted: amazon.com",
        "Small_Yara:   IP\u2019s Contacted  176.32.103.205  205.251.242.103",
        "Small_Alerts: persistence_autorun disables_proxy removes_zoneid_ads allocates_rwx",
        "Small _Alerts: antisandbox_foregroundwindows suspicious_process stealth_window packer_entropy",
        "Emotet IDS Detections: Win32/Emotet CnC Checkin Response",
        "Emotet Yara: Yara Detections ConventionEngine_Term_Desktop ,  ConventionEngine_Term_Users"
      ],
      "public": 1,
      "adversary": "Palantir Pegasus",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "RXR",
          "display_name": "RXR",
          "target": null
        },
        {
          "id": "Pony",
          "display_name": "Pony",
          "target": null
        },
        {
          "id": "VirTool:Win32/Obfuscator",
          "display_name": "VirTool:Win32/Obfuscator",
          "target": "/malware/VirTool:Win32/Obfuscator"
        },
        {
          "id": "Trojan:Win32/Bagsu!rfn",
          "display_name": "Trojan:Win32/Bagsu!rfn",
          "target": "/malware/Trojan:Win32/Bagsu!rfn"
        },
        {
          "id": "#LowFiEnableDTContinueAfterUnpacking",
          "display_name": "#LowFiEnableDTContinueAfterUnpacking",
          "target": null
        },
        {
          "id": "Win32:MalOb-BX\\ [Cryp]",
          "display_name": "Win32:MalOb-BX\\ [Cryp]",
          "target": null
        },
        {
          "id": "TrojanDownloader:Win32/Cutwail",
          "display_name": "TrojanDownloader:Win32/Cutwail",
          "target": "/malware/TrojanDownloader:Win32/Cutwail"
        },
        {
          "id": "#Lowfi:Win32/SandboxProductId",
          "display_name": "#Lowfi:Win32/SandboxProductId",
          "target": "/malware/#Lowfi:Win32/SandboxProductId"
        },
        {
          "id": "Win32:Backdoor",
          "display_name": "Win32:Backdoor",
          "target": null
        },
        {
          "id": "Tofsee",
          "display_name": "Tofsee",
          "target": null
        },
        {
          "id": "Win32:Evo-gen\\ [Susp]",
          "display_name": "Win32:Evo-gen\\ [Susp]",
          "target": null
        },
        {
          "id": "ALF:Trojan:MSIL/BlackFus.C",
          "display_name": "ALF:Trojan:MSIL/BlackFus.C",
          "target": null
        },
        {
          "id": "Win32:Malware",
          "display_name": "Win32:Malware",
          "target": null
        },
        {
          "id": "TrojanProxy:Win32/Ceutv.A",
          "display_name": "TrojanProxy:Win32/Ceutv.A",
          "target": "/malware/TrojanProxy:Win32/Ceutv.A"
        },
        {
          "id": "VirTool:Win32/Obfuscator.AHU",
          "display_name": "VirTool:Win32/Obfuscator.AHU",
          "target": "/malware/VirTool:Win32/Obfuscator.AHU"
        },
        {
          "id": "ShellCode",
          "display_name": "ShellCode",
          "target": null
        },
        {
          "id": "Win32:Rootkit",
          "display_name": "Win32:Rootkit",
          "target": null
        },
        {
          "id": "VB Flash",
          "display_name": "VB Flash",
          "target": null
        },
        {
          "id": "Worm:Win32/Autorun",
          "display_name": "Worm:Win32/Autorun",
          "target": "/malware/Worm:Win32/Autorun"
        },
        {
          "id": "Win.Packed.Razy-6847895-0",
          "display_name": "Win.Packed.Razy-6847895-0",
          "target": null
        },
        {
          "id": "Backdoor:Win32/Plugx.N!",
          "display_name": "Backdoor:Win32/Plugx.N!",
          "target": "/malware/Backdoor:Win32/Plugx.N!"
        },
        {
          "id": "Win.Dropper.QQpass-7194329-0",
          "display_name": "Win.Dropper.QQpass-7194329-0",
          "target": null
        },
        {
          "id": "Trojan:Win32/QQpass",
          "display_name": "Trojan:Win32/QQpass",
          "target": "/malware/Trojan:Win32/QQpass"
        },
        {
          "id": "Win32:Agent",
          "display_name": "Win32:Agent",
          "target": null
        },
        {
          "id": "Win.Trojan.Agent",
          "display_name": "Win.Trojan.Agent",
          "target": null
        },
        {
          "id": "Win.Trojan.Emotet-7545664-0",
          "display_name": "Win.Trojan.Emotet-7545664-0",
          "target": null
        },
        {
          "id": "Pegasus - MOB-S0005",
          "display_name": "Pegasus - MOB-S0005",
          "target": null
        },
        {
          "id": "Pegasus",
          "display_name": "Pegasus",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1045",
          "name": "Software Packing",
          "display_name": "T1045 - Software Packing"
        },
        {
          "id": "T1119",
          "name": "Automated Collection",
          "display_name": "T1119 - Automated Collection"
        },
        {
          "id": "T1040",
          "name": "Network Sniffing",
          "display_name": "T1040 - Network Sniffing"
        },
        {
          "id": "T1053",
          "name": "Scheduled Task/Job",
          "display_name": "T1053 - Scheduled Task/Job"
        },
        {
          "id": "T1060",
          "name": "Registry Run Keys / Startup Folder",
          "display_name": "T1060 - Registry Run Keys / Startup Folder"
        },
        {
          "id": "T1070",
          "name": "Indicator Removal on Host",
          "display_name": "T1070 - Indicator Removal on Host"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1112",
          "name": "Modify Registry",
          "display_name": "T1112 - Modify Registry"
        },
        {
          "id": "T1129",
          "name": "Shared Modules",
          "display_name": "T1129 - Shared Modules"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1069",
          "name": "Permission Groups Discovery",
          "display_name": "T1069 - Permission Groups Discovery"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1480",
          "name": "Execution Guardrails",
          "display_name": "T1480 - Execution Guardrails"
        },
        {
          "id": "T1553",
          "name": "Subvert Trust Controls",
          "display_name": "T1553 - Subvert Trust Controls"
        },
        {
          "id": "T1562",
          "name": "Impair Defenses",
          "display_name": "T1562 - Impair Defenses"
        },
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        },
        {
          "id": "T1568",
          "name": "Dynamic Resolution",
          "display_name": "T1568 - Dynamic Resolution"
        },
        {
          "id": "T1583",
          "name": "Acquire Infrastructure",
          "display_name": "T1583 - Acquire Infrastructure"
        },
        {
          "id": "T1590",
          "name": "Gather Victim Network Information",
          "display_name": "T1590 - Gather Victim Network Information"
        },
        {
          "id": "T1562.001",
          "name": "Disable or Modify Tools",
          "display_name": "T1562.001 - Disable or Modify Tools"
        },
        {
          "id": "T1553.002",
          "name": "Code Signing",
          "display_name": "T1553.002 - Code Signing"
        },
        {
          "id": "T1069.002",
          "name": "Domain Groups",
          "display_name": "T1069.002 - Domain Groups"
        },
        {
          "id": "T1071.004",
          "name": "DNS",
          "display_name": "T1071.004 - DNS"
        },
        {
          "id": "T1568.002",
          "name": "Domain Generation Algorithms",
          "display_name": "T1568.002 - Domain Generation Algorithms"
        },
        {
          "id": "T1071.001",
          "name": "Web Protocols",
          "display_name": "T1071.001 - Web Protocols"
        },
        {
          "id": "T1584.005",
          "name": "Botnet",
          "display_name": "T1584.005 - Botnet"
        },
        {
          "id": "T1096",
          "name": "NTFS File Attributes",
          "display_name": "T1096 - NTFS File Attributes"
        },
        {
          "id": "T1143",
          "name": "Hidden Window",
          "display_name": "T1143 - Hidden Window"
        },
        {
          "id": "T1014",
          "name": "Rootkit",
          "display_name": "T1014 - Rootkit"
        },
        {
          "id": "T1054",
          "name": "Indicator Blocking",
          "display_name": "T1054 - Indicator Blocking"
        },
        {
          "id": "T1089",
          "name": "Disabling Security Tools",
          "display_name": "T1089 - Disabling Security Tools"
        },
        {
          "id": "T1091",
          "name": "Replication Through Removable Media",
          "display_name": "T1091 - Replication Through Removable Media"
        },
        {
          "id": "T1158",
          "name": "Hidden Files and Directories",
          "display_name": "T1158 - Hidden Files and Directories"
        },
        {
          "id": "T1031",
          "name": "Modify Existing Service",
          "display_name": "T1031 - Modify Existing Service"
        },
        {
          "id": "T1113",
          "name": "Screen Capture",
          "display_name": "T1113 - Screen Capture"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 19,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Q.Vashti",
        "id": "337942",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 2362,
        "domain": 449,
        "hostname": 710,
        "email": 6,
        "FileHash-MD5": 260,
        "FileHash-SHA1": 201,
        "FileHash-SHA256": 333,
        "SSLCertFingerprint": 27
      },
      "indicator_count": 4348,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 140,
      "modified_text": "81 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "69519fa81048ad057eb9beaa",
      "name": "Cart.Guru Malware Hosting - Malware Packed _Pegasus Espionage Detected (Positive)",
      "description": "I really love using this tool (LevelBlue -OTX) In all reality this information would have been sent to the government. CISA , NSA, Homeland Security, Citizens Lab, Canada based international organization would have been involved years ago. | \nWhere does this information goes. Citizens Lab would has been attempting to track 1000\u2019s of affected Pegasus targets. OTX detected and tagged Pegasus. I suspected it. This is from a Palantir Malware Hosting Honey Pot. \n\nWhen Pegasus was discovered in the wild , credited to those who found what the real team (T8) found, Citizens Lab then conducted tests in 2021\non the cell phone of Jamal Khashoggi, a Saudi dissident journalist. Pegasus is a kill list. \n\nVictims need help. There are a few people even on this platform that are on this list. Unless it\u2019s the US government who has ordered these actions, I don\u2019t know what is going on. The targets are not only innocent, some are crime victims, some are going mad. AT&T corporate easily confirms LevelBlue is legitimate.",
      "modified": "2026-01-27T21:02:45.343000",
      "created": "2025-12-28T21:22:48.595000",
      "tags": [
        "united",
        "servers",
        "moved",
        "ip address",
        "record value",
        "encrypt",
        "present jul",
        "present jun",
        "trojandropper",
        "passive dns",
        "ipv4 add",
        "urls",
        "files",
        "virtool",
        "united states",
        "dynamicloader",
        "directui",
        "element",
        "classinfobase",
        "write c",
        "medium",
        "yara rule",
        "msvisualbasic60",
        "high",
        "hwndelement",
        "explorer",
        "write",
        "movie",
        "insert",
        "program",
        "python",
        "http traffic",
        "trojan generic",
        "search",
        "cnc activity",
        "delphi",
        "win32",
        "launcher",
        "pony",
        "fareit",
        "malware",
        "push",
        "msie",
        "windows nt",
        "generic",
        "checkin",
        "post",
        "yara detections",
        "rxr",
        "inject",
        "memcommit",
        "cryptexportkey",
        "invalid pointer",
        "regsetvalueexa",
        "solutions ltd",
        "read c",
        "regdword",
        "mozilla",
        "persistence",
        "execution",
        "android",
        "unknown",
        "learn",
        "suspicious",
        "informative",
        "adversaries",
        "ck id",
        "name tactics",
        "command",
        "initial access",
        "defense evasion",
        "spawns",
        "t1590 gather",
        "flag",
        "click",
        "windir",
        "openurl c",
        "prefetch2",
        "analysis",
        "tor analysis",
        "dns requests",
        "domain address",
        "pattern match",
        "mitre att",
        "ck matrix",
        "href",
        "ascii text",
        "starfield",
        "hybrid",
        "general",
        "local",
        "path",
        "iframe",
        "palantir",
        "present nov",
        "present oct",
        "status",
        "present apr",
        "present dec",
        "cryp",
        "date",
        "trojan",
        "title",
        "name servers",
        "windows",
        "t1060",
        "disables proxy",
        "dock",
        "pegasus",
        "rootkit",
        "backdoor",
        "susp",
        "win32qqpass feb",
        "worm",
        "msr win32",
        "win64",
        "process32nextw",
        "findwindowa",
        "file execution",
        "writeconsolea",
        "procexpl",
        "file v2",
        "document",
        "document file",
        "v2 document",
        "lost",
        "tools",
        "pecompact",
        "media",
        "autorun",
        "service",
        "post http",
        "delete",
        "alerts",
        "emotet",
        "rkt",
        "autorun",
        "worm",
        "plugins",
        "title error",
        "body doctype",
        "html public",
        "w3cdtd html",
        "html head",
        "domain",
        "expiration date",
        "hostname add",
        "pulse pulses",
        "contacted hosts",
        "sha1",
        "sha256",
        "show technique",
        "strings",
        "t1480 execution",
        "signing defense",
        "script urls",
        "a domains",
        "unknown ns",
        "texas flyover",
        "script domains",
        "script script",
        "meta",
        "window",
        "process details",
        "contacted"
      ],
      "references": [
        "Cart.Guru",
        "Yara Detections: Delphi",
        "Chekin -Fareit/Pony Downloader Checkin 2 \u2022 Generic - POST To gate.php with no referer",
        "MSIL/Injector.RXR Variant CnC Activity Trojanr Generic - POST To gate.php with no referer",
        "HTTP traffic on port 443 (POST)",
        "IDS Detections Observed Suspicious UA (NSIS_Inetc (Mozilla)) Observed DNS Query",
        "Alerts: crime_win_cutwail_stage2  infostealer_browser infostealer_cookies recon_programs",
        "Alerts: banker_zeus_url procmem_yara suricata_alert infostealer_ftp dynamic_function_loading reads_self network_cnc_http",
        "Alerts: network_icmp persistence_autorun deletes_executed_files modifies_certificates",
        "Alerts: ransomware_dropped_files dumped_buffer network_cnc_http network_http",
        "Alerts: network_http_post allocates_rwx antisandbox_sleep antivm_disk_size creates_exe",
        "Alerts: exe_appdata antivm_network_adapters network_downloader_exe privilege_luid_check",
        "Alerts: checks_debugger generates_crypto_key modifies_proxy_wpad",
        "Yara Detections:  Nullsoft_NSIS    ...",
        "Win32:Evo-gen\\ [Susp] http://downwingbuttons.site/7/huge.dat",
        "Small: Win32:Malware-gen (Small) Yara Detections stack_string \u2022 Domains Contacted: amazon.com",
        "Small_Yara:   IP\u2019s Contacted  176.32.103.205  205.251.242.103",
        "Small_Alerts: persistence_autorun disables_proxy removes_zoneid_ads allocates_rwx",
        "Small _Alerts: antisandbox_foregroundwindows suspicious_process stealth_window packer_entropy",
        "Emotet IDS Detections: Win32/Emotet CnC Checkin Response",
        "Emotet Yara: Yara Detections ConventionEngine_Term_Desktop ,  ConventionEngine_Term_Users"
      ],
      "public": 1,
      "adversary": "Palantir Pegasus",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "RXR",
          "display_name": "RXR",
          "target": null
        },
        {
          "id": "Pony",
          "display_name": "Pony",
          "target": null
        },
        {
          "id": "VirTool:Win32/Obfuscator",
          "display_name": "VirTool:Win32/Obfuscator",
          "target": "/malware/VirTool:Win32/Obfuscator"
        },
        {
          "id": "Trojan:Win32/Bagsu!rfn",
          "display_name": "Trojan:Win32/Bagsu!rfn",
          "target": "/malware/Trojan:Win32/Bagsu!rfn"
        },
        {
          "id": "#LowFiEnableDTContinueAfterUnpacking",
          "display_name": "#LowFiEnableDTContinueAfterUnpacking",
          "target": null
        },
        {
          "id": "Win32:MalOb-BX\\ [Cryp]",
          "display_name": "Win32:MalOb-BX\\ [Cryp]",
          "target": null
        },
        {
          "id": "TrojanDownloader:Win32/Cutwail",
          "display_name": "TrojanDownloader:Win32/Cutwail",
          "target": "/malware/TrojanDownloader:Win32/Cutwail"
        },
        {
          "id": "#Lowfi:Win32/SandboxProductId",
          "display_name": "#Lowfi:Win32/SandboxProductId",
          "target": "/malware/#Lowfi:Win32/SandboxProductId"
        },
        {
          "id": "Win32:Backdoor",
          "display_name": "Win32:Backdoor",
          "target": null
        },
        {
          "id": "Tofsee",
          "display_name": "Tofsee",
          "target": null
        },
        {
          "id": "Win32:Evo-gen\\ [Susp]",
          "display_name": "Win32:Evo-gen\\ [Susp]",
          "target": null
        },
        {
          "id": "ALF:Trojan:MSIL/BlackFus.C",
          "display_name": "ALF:Trojan:MSIL/BlackFus.C",
          "target": null
        },
        {
          "id": "Win32:Malware",
          "display_name": "Win32:Malware",
          "target": null
        },
        {
          "id": "TrojanProxy:Win32/Ceutv.A",
          "display_name": "TrojanProxy:Win32/Ceutv.A",
          "target": "/malware/TrojanProxy:Win32/Ceutv.A"
        },
        {
          "id": "VirTool:Win32/Obfuscator.AHU",
          "display_name": "VirTool:Win32/Obfuscator.AHU",
          "target": "/malware/VirTool:Win32/Obfuscator.AHU"
        },
        {
          "id": "ShellCode",
          "display_name": "ShellCode",
          "target": null
        },
        {
          "id": "Win32:Rootkit",
          "display_name": "Win32:Rootkit",
          "target": null
        },
        {
          "id": "VB Flash",
          "display_name": "VB Flash",
          "target": null
        },
        {
          "id": "Worm:Win32/Autorun",
          "display_name": "Worm:Win32/Autorun",
          "target": "/malware/Worm:Win32/Autorun"
        },
        {
          "id": "Win.Packed.Razy-6847895-0",
          "display_name": "Win.Packed.Razy-6847895-0",
          "target": null
        },
        {
          "id": "Backdoor:Win32/Plugx.N!",
          "display_name": "Backdoor:Win32/Plugx.N!",
          "target": "/malware/Backdoor:Win32/Plugx.N!"
        },
        {
          "id": "Win.Dropper.QQpass-7194329-0",
          "display_name": "Win.Dropper.QQpass-7194329-0",
          "target": null
        },
        {
          "id": "Trojan:Win32/QQpass",
          "display_name": "Trojan:Win32/QQpass",
          "target": "/malware/Trojan:Win32/QQpass"
        },
        {
          "id": "Win32:Agent",
          "display_name": "Win32:Agent",
          "target": null
        },
        {
          "id": "Win.Trojan.Agent",
          "display_name": "Win.Trojan.Agent",
          "target": null
        },
        {
          "id": "Win.Trojan.Emotet-7545664-0",
          "display_name": "Win.Trojan.Emotet-7545664-0",
          "target": null
        },
        {
          "id": "Pegasus - MOB-S0005",
          "display_name": "Pegasus - MOB-S0005",
          "target": null
        },
        {
          "id": "Pegasus",
          "display_name": "Pegasus",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1045",
          "name": "Software Packing",
          "display_name": "T1045 - Software Packing"
        },
        {
          "id": "T1119",
          "name": "Automated Collection",
          "display_name": "T1119 - Automated Collection"
        },
        {
          "id": "T1040",
          "name": "Network Sniffing",
          "display_name": "T1040 - Network Sniffing"
        },
        {
          "id": "T1053",
          "name": "Scheduled Task/Job",
          "display_name": "T1053 - Scheduled Task/Job"
        },
        {
          "id": "T1060",
          "name": "Registry Run Keys / Startup Folder",
          "display_name": "T1060 - Registry Run Keys / Startup Folder"
        },
        {
          "id": "T1070",
          "name": "Indicator Removal on Host",
          "display_name": "T1070 - Indicator Removal on Host"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1112",
          "name": "Modify Registry",
          "display_name": "T1112 - Modify Registry"
        },
        {
          "id": "T1129",
          "name": "Shared Modules",
          "display_name": "T1129 - Shared Modules"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1069",
          "name": "Permission Groups Discovery",
          "display_name": "T1069 - Permission Groups Discovery"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1480",
          "name": "Execution Guardrails",
          "display_name": "T1480 - Execution Guardrails"
        },
        {
          "id": "T1553",
          "name": "Subvert Trust Controls",
          "display_name": "T1553 - Subvert Trust Controls"
        },
        {
          "id": "T1562",
          "name": "Impair Defenses",
          "display_name": "T1562 - Impair Defenses"
        },
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        },
        {
          "id": "T1568",
          "name": "Dynamic Resolution",
          "display_name": "T1568 - Dynamic Resolution"
        },
        {
          "id": "T1583",
          "name": "Acquire Infrastructure",
          "display_name": "T1583 - Acquire Infrastructure"
        },
        {
          "id": "T1590",
          "name": "Gather Victim Network Information",
          "display_name": "T1590 - Gather Victim Network Information"
        },
        {
          "id": "T1562.001",
          "name": "Disable or Modify Tools",
          "display_name": "T1562.001 - Disable or Modify Tools"
        },
        {
          "id": "T1553.002",
          "name": "Code Signing",
          "display_name": "T1553.002 - Code Signing"
        },
        {
          "id": "T1069.002",
          "name": "Domain Groups",
          "display_name": "T1069.002 - Domain Groups"
        },
        {
          "id": "T1071.004",
          "name": "DNS",
          "display_name": "T1071.004 - DNS"
        },
        {
          "id": "T1568.002",
          "name": "Domain Generation Algorithms",
          "display_name": "T1568.002 - Domain Generation Algorithms"
        },
        {
          "id": "T1071.001",
          "name": "Web Protocols",
          "display_name": "T1071.001 - Web Protocols"
        },
        {
          "id": "T1584.005",
          "name": "Botnet",
          "display_name": "T1584.005 - Botnet"
        },
        {
          "id": "T1096",
          "name": "NTFS File Attributes",
          "display_name": "T1096 - NTFS File Attributes"
        },
        {
          "id": "T1143",
          "name": "Hidden Window",
          "display_name": "T1143 - Hidden Window"
        },
        {
          "id": "T1014",
          "name": "Rootkit",
          "display_name": "T1014 - Rootkit"
        },
        {
          "id": "T1054",
          "name": "Indicator Blocking",
          "display_name": "T1054 - Indicator Blocking"
        },
        {
          "id": "T1089",
          "name": "Disabling Security Tools",
          "display_name": "T1089 - Disabling Security Tools"
        },
        {
          "id": "T1091",
          "name": "Replication Through Removable Media",
          "display_name": "T1091 - Replication Through Removable Media"
        },
        {
          "id": "T1158",
          "name": "Hidden Files and Directories",
          "display_name": "T1158 - Hidden Files and Directories"
        },
        {
          "id": "T1031",
          "name": "Modify Existing Service",
          "display_name": "T1031 - Modify Existing Service"
        },
        {
          "id": "T1113",
          "name": "Screen Capture",
          "display_name": "T1113 - Screen Capture"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 18,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 1,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Q.Vashti",
        "id": "337942",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 2362,
        "domain": 449,
        "hostname": 710,
        "email": 6,
        "FileHash-MD5": 260,
        "FileHash-SHA1": 201,
        "FileHash-SHA256": 333,
        "SSLCertFingerprint": 27
      },
      "indicator_count": 4348,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 140,
      "modified_text": "81 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6892e73b32af18aa302df0dc",
      "name": "Part 1.5",
      "description": "Dark web media \u2022 Political news \u2022 Malvertizing\nlocate \u2022\ntrack [stalk] \u2022 record calls \u2022 control media [youtube , etc] http://t.name?n[++i]=e:this.removeEventListener\t\t\nJeeng &\nPowebox [ accidentally left out in original post pulse]",
      "modified": "2025-09-05T04:03:06.929000",
      "created": "2025-08-06T05:25:15.369000",
      "tags": [
        "chromeua",
        "optout",
        "object",
        "path",
        "value",
        "access type",
        "setval",
        "windir",
        "localappdata",
        "null",
        "win64",
        "error",
        "generator",
        "close",
        "roboto",
        "date",
        "format",
        "light",
        "span",
        "template",
        "void",
        "android",
        "body",
        "trident",
        "mexico",
        "sonic",
        "black",
        "critical",
        "desktop",
        "dark",
        "meta",
        "this",
        "june",
        "hybrid",
        "apache",
        "write",
        "crypto",
        "autodetect",
        "face",
        "courier",
        "gigi",
        "impact",
        "shadow",
        "click",
        "strings",
        "cray",
        "smwg",
        "eret",
        "footer",
        "infinity",
        "window",
        "canvas",
        "legend",
        "nuke",
        "lion",
        "4629",
        "ahav",
        "olsa",
        "false",
        "learn",
        "command",
        "ck id",
        "name tactics",
        "suspicious",
        "informative",
        "spawns",
        "defense evasion",
        "t1480 execution",
        "file defense",
        "copy md5",
        "copy sha1",
        "copy sha256",
        "sha1",
        "sha256",
        "script",
        "mitre att",
        "pattern match",
        "show technique",
        "iframe",
        "refresh",
        "august",
        "general",
        "local",
        "tools",
        "demo",
        "look",
        "verify",
        "restart",
        "url http",
        "small",
        "pulses url",
        "tellyoun",
        "showing",
        "entries",
        "url https",
        "indicator role",
        "title added",
        "active related",
        "type indicator",
        "role title",
        "added active",
        "related pulses",
        "cc08",
        "f06a6b",
        "sfurl",
        "filehashsha256",
        "types",
        "indicators show",
        "search",
        "pulses",
        "filehashsha1",
        "adversaries",
        "found",
        "webp image",
        "ascii text",
        "riff",
        "size",
        "encrypt",
        "legacy",
        "filehashmd5",
        "united",
        "flag",
        "server",
        "markmonitor",
        "name server",
        "llc name",
        "overview dns",
        "requests domain",
        "country",
        "win32",
        "av detections",
        "ids detections",
        "yara detections",
        "alerts",
        "analysis date",
        "file score",
        "medium risk",
        "yara",
        "detections",
        "malware",
        "copy",
        "show",
        "icmp traffic",
        "packing t1045",
        "t1045",
        "pdb path",
        "pe resource",
        "extraction",
        "data upload",
        "enter sc",
        "type",
        "extra data",
        "please",
        "failed",
        "review",
        "exclude data",
        "included review",
        "ic data",
        "suggeste",
        "stop",
        "type onow",
        "domain",
        "passive dns",
        "urls",
        "files related",
        "pulses none",
        "related tags",
        "none google",
        "safe browsing",
        "sc data",
        "extr amanuav",
        "review included",
        "manualy",
        "sugges excluded",
        "filehash",
        "md5 add",
        "pulse pulses",
        "url add",
        "http",
        "hostname",
        "files domain",
        "pulses otx",
        "virustotal",
        "hsmi192547107",
        "pulses hostname",
        "r dec",
        "customer dec",
        "iski dec",
        "decision dec",
        "va dec",
        "bitcoin",
        "bitcoin dec",
        "petra",
        "torstatus dec",
        "paul dec",
        "sodesc",
        "planet dec",
        "emilia",
        "heroin dec",
        "difference dec",
        "palantir dec",
        "loraxlive dec",
        "chaturbate dec",
        "sandra",
        "free dec",
        "marvel dec",
        "benjis dec",
        "fresh dec",
        "sodesc dec",
        "srdirport",
        "srhostname",
        "link dec",
        "types of",
        "italy",
        "china",
        "australia",
        "france",
        "turkey",
        "discovery",
        "information",
        "ck ids",
        "t1005",
        "local system",
        "t1007",
        "system service",
        "part",
        "track",
        "locate",
        "political",
        "civil society",
        "news",
        "created",
        "hours ago",
        "report spam",
        "t1555",
        "password",
        "t1560",
        "collected data",
        "t1573",
        "channel",
        "t1574",
        "execution flow",
        "scan",
        "iocs",
        "t1497",
        "u0lhmq",
        "mtawmq",
        "t1480",
        "guardrails",
        "t1486",
        "data encrypted",
        "learn more",
        "unsubscribe aug",
        "protocol",
        "t1074",
        "staged",
        "t1083",
        "t1102",
        "web service",
        "t1105",
        "tool transfer",
        "t1140",
        "data engineer",
        "candidate",
        "tlsv1",
        "odigicert inc",
        "stcalifornia",
        "lsan jose",
        "oadobe systems",
        "incorporated",
        "cndigicert sha2",
        "push",
        "next",
        "high",
        "write c",
        "ireland as16509",
        "delete",
        "dirty",
        "tags",
        "t1012",
        "flow endpoint",
        "security scan",
        "t1106",
        "copyright",
        "levelblue"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1005",
          "name": "Data from Local System",
          "display_name": "T1005 - Data from Local System"
        },
        {
          "id": "T1007",
          "name": "System Service Discovery",
          "display_name": "T1007 - System Service Discovery"
        },
        {
          "id": "T1012",
          "name": "Query Registry",
          "display_name": "T1012 - Query Registry"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1033",
          "name": "System Owner/User Discovery",
          "display_name": "T1033 - System Owner/User Discovery"
        },
        {
          "id": "T1036",
          "name": "Masquerading",
          "display_name": "T1036 - Masquerading"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1074",
          "name": "Data Staged",
          "display_name": "T1074 - Data Staged"
        },
        {
          "id": "T1083",
          "name": "File and Directory Discovery",
          "display_name": "T1083 - File and Directory Discovery"
        },
        {
          "id": "T1102",
          "name": "Web Service",
          "display_name": "T1102 - Web Service"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1106",
          "name": "Native API",
          "display_name": "T1106 - Native API"
        },
        {
          "id": "T1112",
          "name": "Modify Registry",
          "display_name": "T1112 - Modify Registry"
        },
        {
          "id": "T1120",
          "name": "Peripheral Device Discovery",
          "display_name": "T1120 - Peripheral Device Discovery"
        },
        {
          "id": "T1129",
          "name": "Shared Modules",
          "display_name": "T1129 - Shared Modules"
        },
        {
          "id": "T1132",
          "name": "Data Encoding",
          "display_name": "T1132 - Data Encoding"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1480",
          "name": "Execution Guardrails",
          "display_name": "T1480 - Execution Guardrails"
        },
        {
          "id": "T1486",
          "name": "Data Encrypted for Impact",
          "display_name": "T1486 - Data Encrypted for Impact"
        },
        {
          "id": "T1497",
          "name": "Virtualization/Sandbox Evasion",
          "display_name": "T1497 - Virtualization/Sandbox Evasion"
        },
        {
          "id": "T1555",
          "name": "Credentials from Password Stores",
          "display_name": "T1555 - Credentials from Password Stores"
        },
        {
          "id": "T1560",
          "name": "Archive Collected Data",
          "display_name": "T1560 - Archive Collected Data"
        },
        {
          "id": "T1573",
          "name": "Encrypted Channel",
          "display_name": "T1573 - Encrypted Channel"
        },
        {
          "id": "T1574",
          "name": "Hijack Execution Flow",
          "display_name": "T1574 - Hijack Execution Flow"
        },
        {
          "id": "T1553",
          "name": "Subvert Trust Controls",
          "display_name": "T1553 - Subvert Trust Controls"
        },
        {
          "id": "T1562",
          "name": "Impair Defenses",
          "display_name": "T1562 - Impair Defenses"
        },
        {
          "id": "T1568",
          "name": "Dynamic Resolution",
          "display_name": "T1568 - Dynamic Resolution"
        },
        {
          "id": "T1583",
          "name": "Acquire Infrastructure",
          "display_name": "T1583 - Acquire Infrastructure"
        },
        {
          "id": "T1045",
          "name": "Software Packing",
          "display_name": "T1045 - Software Packing"
        },
        {
          "id": "T1018",
          "name": "Remote System Discovery",
          "display_name": "T1018 - Remote System Discovery"
        },
        {
          "id": "T1041",
          "name": "Exfiltration Over C2 Channel",
          "display_name": "T1041 - Exfiltration Over C2 Channel"
        },
        {
          "id": "T1114",
          "name": "Email Collection",
          "display_name": "T1114 - Email Collection"
        },
        {
          "id": "T1063",
          "name": "Security Software Discovery",
          "display_name": "T1063 - Security Software Discovery"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 18,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Q.Vashti",
        "id": "337942",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 608,
        "FileHash-SHA1": 433,
        "FileHash-SHA256": 3663,
        "URL": 17104,
        "domain": 1316,
        "email": 39,
        "hostname": 4208,
        "SSLCertFingerprint": 17
      },
      "indicator_count": 27388,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 139,
      "modified_text": "226 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "684b932fcbcc577471a28c8a",
      "name": "Imaging Center Malware, Virus other manipulations",
      "description": "IMO Serious!  Virus, Trojans, potential cams? PHI , PII access. Super concerning potential manipulation , imaging, reports., records, billing\nis manipulated.\nMore research necessary.\nTrue potential for manipulation \nof x-ray , ct scan dosing.\nExcessive Adult content:\ncdn1-thumbs.pornhost.com | \ncdn28.eporncam.com | \t\ncdn35.thotporn.tv | \ncdnst7.pornburst.xxx | \nmcdns.vrporn.com |\nURL\nhttps://c845a1577e.mjedge.net/contents/videos_screenshots/3979000/3979719/preview.jpg&tbnid=rLNgRtn9SIlcgM&vet=10CAwQ1JoKKARqFwoTCIjlsv7v0Y0DFQAAAAAdAAAAABAH..i&imgrefurl=https:/it.vikiporn.com/videos/3979719/horror-porn-the-dark-side-of-the-woods/&docid=tVU1jbsRquWQLM&w=1920&h=1080&itg=1&q=horror porn&ved=0CAwQ1JoKKARqFwoTCIjlsv7v0Y0DFQAAAAAdAAAAABAH |\nhttps://cdn1-thumbs.pornhost.com/0/2/0235809321/001_150_112.jpg | \n\u2022 Den:Variant.Application.Bundler.Ludus.1\n\u2022 PUABundler:Win32/YandexBundled\n\u2022 Adware.Win32.DownWare.cl\n\u2022 pua:Win32/Catalina\n\u2022W32.AIDetectMalware\n* Why is my OTX account blocked from features",
      "modified": "2025-07-13T02:05:19.612000",
      "created": "2025-06-13T02:55:42.562000",
      "tags": [
        "united",
        "asn16509",
        "amazon02",
        "frankfurt",
        "main",
        "germany",
        "asn60068",
        "cdn77 datacamp",
        "limited",
        "browsing",
        "reverse dns",
        "protocol h2",
        "security tls",
        "general full",
        "url https",
        "resource",
        "hash",
        "software",
        "dalles",
        "june",
        "de indicators",
        "domains",
        "hashes",
        "verified",
        "ecdsa",
        "linux x8664",
        "khtml",
        "gecko",
        "aes256gcm",
        "veryhigh",
        "patch",
        "accept",
        "encrypt",
        "cookie",
        "sticky",
        "aaaa",
        "cname",
        "ttl value",
        "algorithm",
        "key identifier",
        "v3 serial",
        "number",
        "cus olet",
        "encrypt cne5",
        "validity",
        "subject public",
        "key info",
        "key algorithm",
        "record type",
        "thumbprint"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 27,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Q.Vashti",
        "id": "337942",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 836,
        "hostname": 1001,
        "domain": 193,
        "URL": 3007,
        "FileHash-MD5": 83,
        "FileHash-SHA1": 42,
        "CIDR": 5
      },
      "indicator_count": 5167,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 137,
      "modified_text": "280 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "https://swiperjs.com",
    "type": "URL"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "https://swiperjs.com",
    "type": "URL",
    "found": false,
    "verdict": "clean",
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1776631496.4198964
}