{
  "type": "URL",
  "indicator": "https://uniproxy.messenger.alpha.yandex.md",
  "general": {
    "sections": [
      "general",
      "url_list",
      "http_scans",
      "screenshot"
    ],
    "indicator": "https://uniproxy.messenger.alpha.yandex.md",
    "type": "url",
    "type_title": "URL",
    "validation": [],
    "base_indicator": {
      "id": 3396124297,
      "indicator": "https://uniproxy.messenger.alpha.yandex.md",
      "type": "URL",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 18,
      "pulses": [
        {
          "id": "65709a0e8c20860fea88779a",
          "name": "https://surveyheart.com/form/619fb5dc68ff1721fc915f81",
          "description": "",
          "modified": "2023-12-06T15:58:06.293000",
          "created": "2023-12-06T15:58:06.293000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 3,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 3624,
            "FileHash-SHA256": 1584,
            "domain": 871,
            "hostname": 1290,
            "FileHash-MD5": 20,
            "FileHash-SHA1": 20
          },
          "indicator_count": 7409,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 110,
          "modified_text": "908 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "65709510e5b078aa5f09ca51",
          "name": "widevinecdm.dll seemingly problematic - supply chain holy god mother of fu.k",
          "description": "",
          "modified": "2023-12-06T15:36:48.409000",
          "created": "2023-12-06T15:36:48.409000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 3,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 1447,
            "FileHash-MD5": 199,
            "FileHash-SHA1": 197,
            "domain": 267,
            "hostname": 871,
            "URL": 1930,
            "email": 2
          },
          "indicator_count": 4913,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "908 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "65708beba2ba8bcfb1d10237",
          "name": "hostkey - Industroyer&ReduceRight",
          "description": "",
          "modified": "2023-12-06T14:57:47.430000",
          "created": "2023-12-06T14:57:47.430000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 3,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 304,
            "hostname": 563,
            "domain": 407,
            "URL": 1776,
            "FileHash-SHA1": 2
          },
          "indicator_count": 3052,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "908 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "65708b5e9b8ce0f5fd87fb98",
          "name": "ewqopweowia543.ga",
          "description": "",
          "modified": "2023-12-06T14:55:26.621000",
          "created": "2023-12-06T14:55:26.621000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "CVE": 1,
            "hostname": 706,
            "domain": 234,
            "FileHash-SHA256": 238,
            "URL": 1386
          },
          "indicator_count": 2565,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "908 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6570819e75a6b853df509785",
          "name": "http://projectorworld.ru/blog/770.htm",
          "description": "",
          "modified": "2023-12-06T14:13:50.518000",
          "created": "2023-12-06T14:13:50.518000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 447,
            "domain": 151,
            "URL": 991,
            "hostname": 334,
            "FileHash-MD5": 61,
            "FileHash-SHA1": 50,
            "email": 2,
            "SSLCertFingerprint": 2
          },
          "indicator_count": 2038,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "908 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "65708191cdba4e9f07ba1f93",
          "name": "mail.ru:%22,",
          "description": "",
          "modified": "2023-12-06T14:13:36.976000",
          "created": "2023-12-06T14:13:36.976000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 2753,
            "hostname": 1341,
            "domain": 447,
            "URL": 3301,
            "CIDR": 65,
            "FileHash-MD5": 112,
            "FileHash-SHA1": 2
          },
          "indicator_count": 8021,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 110,
          "modified_text": "908 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6570816fa5b73f6d66bce4bb",
          "name": "Sandbox - Vi;https://edu-cisco.org - conti touched",
          "description": "",
          "modified": "2023-12-06T14:13:03.193000",
          "created": "2023-12-06T14:13:03.193000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 231,
            "domain": 42,
            "hostname": 154,
            "URL": 419,
            "FileHash-MD5": 59,
            "FileHash-SHA1": 46,
            "email": 2
          },
          "indicator_count": 953,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "908 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6451ac22105fabd34fbdf476",
          "name": "https://surveyheart.com/form/619fb5dc68ff1721fc915f81",
          "description": "Albert Hill fake profile has 1 follower and 1 follow. the one follow has this url in the p rofile",
          "modified": "2023-05-03T00:34:42.633000",
          "created": "2023-05-03T00:34:42.633000",
          "tags": [
            "entity"
          ],
          "references": [
            "https://www.virustotal.com/graph/g5cc372545fb241bdab97ceedfdc72d87d6ec1e42c9a545ae9f824ed1e99521d9",
            "g5cc372545fb241bdab97ceedfdc72d87d6ec1e42c9a545ae9f824ed1e99521d9.json"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 8,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "callmeDoris",
            "id": "205385",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 3624,
            "FileHash-SHA256": 1584,
            "hostname": 1290,
            "domain": 871,
            "IPv4": 95,
            "FileHash-MD5": 20,
            "FileHash-SHA1": 20
          },
          "indicator_count": 7504,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 93,
          "modified_text": "1125 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6398fe16df6290d8fcac2f77",
          "name": "widevinecdm.dll seemingly problematic - supply chain holy god mother of fu.k",
          "description": "https://hybrid-analysis.com/sample/db695a96adb70d5f6246273f4e6c218b2c44f02b3726c3dee4d56b6428bb0ddf",
          "modified": "2023-01-12T21:02:22.235000",
          "created": "2022-12-13T22:35:02.021000",
          "tags": [
            "sandbox",
            "malware",
            "analysis",
            "online",
            "submit",
            "vxstream",
            "sample",
            "download",
            "trojan",
            "apt",
            "runtime data",
            "ansi",
            "threat level",
            "date",
            "sha256",
            "unicode",
            "size",
            "pcap",
            "pcap processing",
            "runtime process",
            "accept",
            "suspicious",
            "hybrid",
            "malicious",
            "close",
            "click",
            "hosts",
            "ransomware",
            "general",
            "local",
            "path",
            "mozilla",
            "strings",
            "localappdata",
            "temp",
            "prefetch8 ansi",
            "entropy",
            "win64",
            "disabled hash",
            "friendly",
            "mozi",
            "trident",
            "copy md5",
            "copy sha1",
            "copy sha256",
            "file",
            "type data",
            "download file",
            "db695a96adb70d5f6246273f4e6c218b2c44f02b3726c3dee4d56b6428bb0ddf",
            "widevinecdm.dll",
            "https://hybrid-analysis.com/sample/db695a96adb70d5f6246273f4e6c2"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1005",
              "name": "Data from Local System",
              "display_name": "T1005 - Data from Local System"
            },
            {
              "id": "T1043",
              "name": "Commonly Used Port",
              "display_name": "T1043 - Commonly Used Port"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1179",
              "name": "Hooking",
              "display_name": "T1179 - Hooking"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 32,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "dorkingbeauty1",
            "id": "80137",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 871,
            "URL": 1930,
            "domain": 267,
            "FileHash-SHA256": 1447,
            "FileHash-MD5": 199,
            "FileHash-SHA1": 197,
            "email": 2
          },
          "indicator_count": 4913,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 397,
          "modified_text": "1235 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "627ee9ff7d36c1432328ebe7",
          "name": "\u041b\u0438\u043d\u0438\u044f \u043f\u043e\u043c\u043e\u0449\u0438 \u00ab\u0414\u0435\u0442\u0438 \u043e\u043d\u043b\u0430\u0439\u043d\u00bb \u2014 \u0424\u043e\u043d\u0434 \u0420\u0430\u0437\u0432\u0438\u0442\u0438\u044f \u0418\u043d\u0442\u0435\u0440\u043d\u0435\u0442 FID.SU",
          "description": "Foundation for Internet development \u2013 Soviet Union",
          "modified": "2022-06-12T00:06:23.557000",
          "created": "2022-05-13T23:30:07.788000",
          "tags": [
            "cecece",
            "e9031d",
            "domen su",
            "font awesome",
            "license",
            "bootstrap",
            "sil open",
            "font license",
            "less",
            "sass",
            "mit license",
            "cc by",
            "dave gandy",
            "contact",
            "twitter",
            "class",
            "regexp",
            "null",
            "array",
            "pseudo",
            "child",
            "x20trnf",
            "name",
            "attr",
            "cfunction",
            "error",
            "block",
            "last",
            "parent",
            "blogger",
            "diary",
            "digg",
            "evernote",
            "facebook",
            "google plus",
            "juick",
            "linkedin",
            "liveinternet",
            "livejournal",
            "youtube",
            "function",
            "width",
            "date",
            "accept",
            "gc",
            "65535",
            "boolean",
            "counter",
            "typeof c",
            "segoe ui",
            "typeerror",
            "lucida",
            "ecommerce",
            "ext link",
            "form",
            "impact",
            "light"
          ],
          "references": [
            "http://www.fid.su/projects/detionline",
            "http://mc.yandex.ru/metrika/watch.js",
            "xfe-IP-172.247.55.179-stix2-2.1-export.json",
            "xfe-URL-cnservers.com-stix2-2.1-export.json",
            "xfe-URL-Ceranetworks.com-stix2-2.1-export 2.json",
            "http://www.youtube.com/embed/Bo_238D72rw?rel=0",
            "http://yandex.st/share/share.js",
            "http://www.fid.su/js/toggleTree.js",
            "http://www.fid.su/js/show.js",
            "http://www.fid.su/js/jquery-1.8.2.min.js",
            "http://cdnjs.cloudflare.com/ajax/libs/font-awesome/3.1.0/css/font-awesome.css",
            "http://www.fid.su/css/index.css"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "New Caledonia"
          ],
          "malware_families": [
            {
              "id": "Gc",
              "display_name": "Gc",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 9,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "adjadex1@gmail.com",
            "id": "187163",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 1817,
            "hostname": 705,
            "domain": 381,
            "FileHash-SHA256": 201,
            "email": 2
          },
          "indicator_count": 3106,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 69,
          "modified_text": "1450 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6261f2763fabd1214a79f0e5",
          "name": "Masterhost.ru - malware hosting",
          "description": "Here is the code-decode for the punycode-overflow test, which is based on the results of the following test-run by the UK's Office of National Statistics (ONS).",
          "modified": "2022-05-21T00:03:44.725000",
          "created": "2022-04-22T00:10:30.250000",
          "tags": [
            "fffe37",
            "b76810",
            "helvetica",
            "arial",
            "pf din",
            "text comp",
            "circe",
            "span",
            "button",
            "90deg",
            "object",
            "typeof t",
            "date",
            "promise",
            "function",
            "array",
            "regexp",
            "error",
            "typeof symbol",
            "typeof n",
            "null",
            "backspace",
            "void",
            "window",
            "vd",
            "gc",
            "typeof e",
            "sufeffxa0",
            "class",
            "attr",
            "pseudo",
            "child",
            "typeof module",
            "string",
            "weakmap",
            "proxy",
            "number",
            "boolean",
            "trnf",
            "keepalive",
            "transitiongroup",
            "hello",
            "comment",
            "infinity",
            "this",
            "copyright",
            "closure library",
            "xdfunction",
            "cdfunction",
            "ddfunction",
            "bded",
            "kefunction",
            "65535",
            "counter",
            "typeof c",
            "segoe ui",
            "typeerror",
            "lucida",
            "vwtabguid",
            "form",
            "impact",
            "light",
            "cureit",
            "bu durumda",
            "ip address",
            "devam",
            "yandex",
            "help section",
            "captcha code",
            "support service",
            "search",
            "edge",
            "swhealthlog",
            "logsdatabasev2",
            "trident",
            "android",
            "rangeerror",
            "webpackexports",
            "illegal input",
            "webpackrequire"
          ],
          "references": [
            "https://admin.verbox.ru/support/support.js?h=afe80d31a1cabd6ae5c00580688f27d2",
            "https://www.youtube.com/s/player/534c466c/www-widgetapi.vflset/www-widgetapi.js",
            "https://site.yandex.net/v2.0/js/all.js",
            "https://mc.yandex.ru/metrika/tag.js",
            "https://www.googletagmanager.com/gtag/js?id=UA-36935570-1",
            "https://masterhost.ru/s/masterhost_v2/build/js/app.js?v=WivgGVzt/Ynv",
            "https://masterhost.ru/s/masterhost_v2/build/js/compiled.min.js?v=Q/hhNATxy3sx",
            "https://static.me-talk.ru/cabinet/build/chat/modern.support.js",
            "https://masterhost.ru/s/masterhost_v2/build/css/global.css?v=MUmvaY06hvKf"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Gc",
              "display_name": "Gc",
              "target": null
            },
            {
              "id": "Vd",
              "display_name": "Vd",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 3,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "adjadex1@gmail.com",
            "id": "187163",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 1991,
            "hostname": 678,
            "FileHash-SHA256": 247,
            "domain": 404,
            "email": 1,
            "FileHash-MD5": 51
          },
          "indicator_count": 3372,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 70,
          "modified_text": "1472 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "625f05c71e903844d907b1ae",
          "name": "Russian Malware Strain",
          "description": "The full text of the new Dictionary of Human Rights, compiled by the Office of National Statistics (ONS), has been published on the internet, with the help of a few words: \"Glasgow\".",
          "modified": "2022-05-19T00:00:49.028000",
          "created": "2022-04-19T18:56:07.131000",
          "tags": [
            "bapunycode",
            "s700",
            "array",
            "topmailru",
            "error",
            "tmrtmr",
            "rbclickid",
            "tmrdebug1",
            "tadaeaxbyb",
            "bbdaea",
            "cbdaea",
            "uadaea",
            "ver1",
            "typemini",
            "verb0",
            "youtube",
            "content",
            "smartbanner",
            "null",
            "text",
            "smart banner",
            "copyright",
            "android",
            "windows store",
            "title",
            "price",
            "click",
            "date",
            "twitter",
            "string",
            "regexp",
            "number",
            "typeerror",
            "symbol",
            "array int8array",
            "argument",
            "rafunction",
            "iframe",
            "please",
            "image",
            "v[1]-1:k+=",
            "dpjquery",
            "document",
            "function",
            "this",
            "left",
            "bottom",
            "html",
            "nulle",
            "next",
            "february",
            "april",
            "june",
            "august",
            "atom",
            "cookie",
            "back",
            "bounce",
            "attr",
            "class",
            "invalid json",
            "domparser",
            "edge",
            "sxa0",
            "qafunction",
            "trident",
            "ondomready",
            "make sure",
            "gc",
            "65535",
            "boolean",
            "counter",
            "segoe ui",
            "lucida",
            "ecommerce",
            "ext link",
            "comic",
            "form",
            "impact",
            "light",
            "bad idp",
            "cvtx",
            "bad event",
            "typeof b",
            "closure library",
            "f1518500249",
            "f1859775393",
            "body"
          ],
          "references": [
            "xfe-IP-185.44.14.140-stix2-2.1-export 2.json",
            "xfe-URL-Xelent.ru-stix2-2.1-export.json",
            "https://apis.google.com/_/scs/abc-static/_/js/k=gapi.lb.en.iTmf4rxOyWc.O/m=auth/exm=plusone/rt=j/sv=1/d=1/ed=1/rs=AHpOoo-LTnDn-AS2QlMWYZdnaV1OuFR7Iw/cb=gapi.loaded_1?le=scs",
            "http://mc.yandex.ru/metrika/watch.js",
            "http://metrika.installtraffic.com/js/watch.js",
            "https://apis.google.com/_/scs/abc-static/_/js/k=gapi.lb.en.iTmf4rxOyWc.O/m=plusone/rt=j/sv=1/d=1/ed=1/rs=AHpOoo-LTnDn-AS2QlMWYZdnaV1OuFR7Iw/cb=gapi.loaded_0?le=scs",
            "http://loviotvet.ru/lib/jquery/jquery-1.7.2.min.js",
            "http://loviotvet.ru/lib/jquery-ui/jquery-ui-1.10.1.custom.min.js",
            "http://loviotvet.ru/lib/project/common.js",
            "http://loviotvet.ru/lib/fancybox/jquery.fancybox.pack.js",
            "https://apis.google.com/js/plusone.js",
            "http://loviotvet.ru/lib/smartbanner/jquery.smartbanner.js",
            "http://www.youtube.com/embed/MoDJIS6UH5U?rel=0",
            "https://top-fwz1.mail.ru/js/code.js",
            "https://bitrix.info/ba.js"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "V[1]-1:k+=",
              "display_name": "V[1]-1:k+=",
              "target": null
            },
            {
              "id": "Gc",
              "display_name": "Gc",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 6,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "adjadex1@gmail.com",
            "id": "187163",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 1987,
            "hostname": 733,
            "FileHash-SHA256": 294,
            "domain": 354
          },
          "indicator_count": 3368,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 69,
          "modified_text": "1474 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "62572a94139a622eaf588448",
          "name": "Misc Malware",
          "description": "TacklingConsentEvents:function(e,t,n), Object.g.t.notes, in the full text of all the following:.-TackingConsents.",
          "modified": "2022-05-13T00:03:35.765000",
          "created": "2022-04-13T19:55:00.620000",
          "tags": [
            "string",
            "regexp",
            "date",
            "error",
            "number",
            "typeerror",
            "symbol",
            "array int8array",
            "argument",
            "rafunction",
            "iframe",
            "eq",
            "edge",
            "ajfunction",
            "sxa0",
            "trident",
            "android",
            "ondomready",
            "function",
            "make sure",
            "gc",
            "65535",
            "boolean",
            "counter",
            "segoe ui",
            "lucida",
            "ecommerce",
            "ext link",
            "comic",
            "null",
            "form",
            "impact",
            "light",
            "cvrx",
            "typeof b",
            "copyright",
            "closure library",
            "f1518500249",
            "f1859775393",
            "f2400959708",
            "f3395469782",
            "body",
            "typeof e",
            "pseudo",
            "child",
            "typeof t",
            "sufeffxa0",
            "class",
            "attr",
            "this",
            "1rem",
            "tdtd",
            "rolebutton",
            "summary",
            "typecheckbox",
            "typenumber",
            "canvastext",
            "arrowup",
            "arrowdown",
            "htmlelement",
            "product",
            "domparser",
            "escape",
            "detailsmodal",
            "customevent",
            "post",
            "rfunction",
            "boomrstart",
            "samesitelax",
            "typeof",
            "typeof r",
            "array",
            "object",
            "iterator",
            "typeof window",
            "typeof self",
            "typeof g",
            "promise",
            "filereader",
            "invalid attempt",
            "modaldialog",
            "slidercomponent",
            "quantityinput",
            "event",
            "menudrawer",
            "headerdrawer",
            "modalopener",
            "deferredmedia",
            "span",
            "accept",
            "othis",
            "gdpr",
            "ccpa",
            "ithis"
          ],
          "references": [
            "xfe-URL-youtubec3.top-stix2-2.1-export.json",
            "https://cdn.shopify.com/s/trekkie.storefront.7a1e33ad1202f755768e4821a6acd8fe61f84871.min.js",
            "https://cdn.shopify.com/s/files/1/0613/4340/0109/t/1/assets/global.js?v=13511647614100697069",
            "https://cdn.shopify.com/shopifycloud/shopify/assets/storefront/load_feature-8efd97e96728f91aa74d4a6e8acbe8011adda17d2c0b6ccd8600a1bdd2453392.js",
            "https://cdn.shopify.com/shopifycloud/shopify/assets/shopify_pay/storefront-b61f50798075db890698930c4405673937fe89353f7fea7be88b5ce16a9c0af8.js?v=20210208",
            "https://cdn.shopify.com/shopifycloud/shopify/assets/storefront/features-87e8399988880142f2c62771b9d8f2ff6c290b3ff745dd426eb0dfe0db9d1dae.js",
            "https://cdn.shopify.com/shopifycloud/shopify/assets/shop_events_listener-fa61fd11817b231631d2fe43dc869d0b1d14a06332792d42f1a1d94bda5aa31e.js",
            "https://cdn.shopify.com/shopifycloud/boomerang/shopify-boomerang-1.0.0.min.js",
            "https://cdn.shopify.com/s/files/1/0613/4340/0109/t/1/assets/details-disclosure.js?v=9382762063644384478",
            "https://cdn.shopify.com/s/files/1/0613/4340/0109/t/1/assets/details-modal.js?v=451176189667266969",
            "https://cdn.shopify.com/s/files/1/0613/4340/0109/t/1/assets/cart-notification.js?v=11046494563428290095",
            "https://cdn.shopify.com/s/files/1/0613/4340/0109/t/1/assets/predictive-search.js?v=3127871086358158403",
            "https://cdn.shopify.com/s/files/1/0613/4340/0109/t/1/assets/base.css?v=14499708248636525874",
            "https://cdn.shopify.com/s/files/1/0613/4340/0109/t/1/assets/component-predictive-search.css?v=16564466128908848865",
            "https://cdn.shopify.com/s/files/1/0613/4340/0109/t/1/assets/component-search.css?v=9645568919885132178",
            "https://cdn.shopify.com/s/files/1/0613/4340/0109/t/1/assets/component-menu-drawer.css?v=12673181874805599423",
            "https://cdn.shopify.com/s/files/1/0613/4340/0109/t/1/assets/component-cart-notification.css?v=10701990056532666329",
            "https://cdn.shopify.com/s/files/1/0613/4340/0109/t/1/assets/component-cart-items.css?v=3522426644373936959",
            "https://cdn.shopify.com/s/files/1/0613/4340/0109/t/1/assets/component-loading-overlay.css?v=16731047084359357984",
            "https://cdn.shopify.com/s/files/1/0613/4340/0109/t/1/assets/section-image-banner.css?v=17648756444066888014",
            "https://cdn.shopify.com/s/files/1/0613/4340/0109/t/1/assets/disclosure.css?v=64659519099960134",
            "https://cdn.shopify.com/s/files/1/0613/4340/0109/t/1/assets/component-rte.css?v=6991943663851532978",
            "https://cdn.shopify.com/s/files/1/0613/4340/0109/t/1/assets/component-list-social.css?v=5221166315372665906",
            "https://cdn.shopify.com/s/files/1/0613/4340/0109/t/1/assets/component-list-payment.css?v=6925396141077183850",
            "https://cdn.shopify.com/s/files/1/0613/4340/0109/t/1/assets/component-list-menu.css?v=12926705887708249657",
            "https://cdn.shopify.com/s/files/1/0613/4340/0109/t/1/assets/component-newsletter.css?v=10347248205600305355",
            "https://cdn.shopify.com/s/files/1/0613/4340/0109/t/1/assets/component-rating.css?v=2457308526394124043",
            "https://cdn.shopify.com/s/files/1/0613/4340/0109/t/1/assets/component-card.css?v=12741305300284413781",
            "http://code.jquery.com/jquery-3.3.1.min.js",
            "https://apis.google.com/_/scs/abc-static/_/js/k=gapi.lb.en.NnK9YPjtg-w.O/m=auth/exm=plusone/rt=j/sv=1/d=1/ed=1/rs=AHpOoo9KePDGVlGjp-rlXwDM1kUO2Eh4gg/cb=gapi.loaded_1?le=scs",
            "http://mc.yandex.ru/metrika/watch.js",
            "http://metrika.installtraffic.com/js/watch.js",
            "https://apis.google.com/_/scs/abc-static/_/js/k=gapi.lb.en.NnK9YPjtg-w.O/m=plusone/rt=j/sv=1/d=1/ed=1/rs=AHpOoo9KePDGVlGjp-rlXwDM1kUO2Eh4gg/cb=gapi.loaded_0?le=scs",
            "https://apis.google.com/js/plusone.js",
            "xfe-IP-185.44.14.140-stix2-2.1-export.json"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Eq",
              "display_name": "Eq",
              "target": null
            },
            {
              "id": "Gc",
              "display_name": "Gc",
              "target": null
            }
          ],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 4,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "adjadex1@gmail.com",
            "id": "187163",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 1973,
            "hostname": 539,
            "FileHash-SHA256": 314,
            "domain": 352,
            "FileHash-MD5": 1
          },
          "indicator_count": 3179,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 68,
          "modified_text": "1480 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "625045b8e764847c54ed286e",
          "name": "ewqopweowia543.ga",
          "description": "If you want to know what type of Touches you will get when you get stuck in the middle of a page, then ask for a random number of letters or numbers, or, if you can't find one.",
          "modified": "2022-05-08T00:03:14.586000",
          "created": "2022-04-08T14:24:56.301000",
          "tags": [
            "90deg",
            "250px",
            "helvetica neue",
            "helvetica",
            "roboto",
            "georgia",
            "typesearch",
            "typecheckbox",
            "label",
            "liberation mono",
            "function",
            "constructor",
            "param",
            "object",
            "class",
            "event",
            "abide",
            "number",
            "initializes",
            "drilldown",
            "window",
            "sticky",
            "false",
            "null",
            "body",
            "this",
            "date",
            "path",
            "anchor",
            "open",
            "trigger",
            "small",
            "close",
            "void",
            "form",
            "fast",
            "prop",
            "error",
            "shift",
            "test",
            "burn",
            "android",
            "back",
            "killswitch",
            "find",
            "desktop",
            "fall",
            "linear",
            "value",
            "webpackrequire",
            "return",
            "mouse",
            "factory",
            "moduleid",
            "apple cmd",
            "regexp",
            "elem",
            "handle",
            "expando",
            "match",
            "selector",
            "type",
            "sizzle",
            "target",
            "mark",
            "copy",
            "capture",
            "seed",
            "pass",
            "code",
            "bind",
            "core",
            "local",
            "verify",
            "accept",
            "done",
            "internal",
            "inject",
            "possible",
            "hold",
            "camel",
            "first",
            "middle",
            "gc",
            "eq",
            "post",
            "xava",
            "gbva",
            "hbva",
            "ibva",
            "lcva",
            "cdva",
            "oeva",
            "peva",
            "65535",
            "boolean",
            "counter",
            "segoe ui",
            "typeerror",
            "lucida",
            "ecommerce",
            "ext link",
            "comic",
            "impact",
            "light"
          ],
          "references": [
            "xfe-URL-ewqopweowia543.ga-stix2-2.0-export.json",
            "https://mc.yandex.ru/metrika/watch.js",
            "https://ssl.google-analytics.com/ga.js",
            "https://vestacp.com/bower_components/jquery/dist/jquery.js",
            "https://vestacp.com/bower_components/what-input/dist/what-input.js",
            "https://vestacp.com/bower_components/foundation-sites/dist/js/foundation.js",
            "https://vestacp.com/js/app.js",
            "https://vestacp.com/css/app.css"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Eq",
              "display_name": "Eq",
              "target": null
            },
            {
              "id": "Gc",
              "display_name": "Gc",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1056",
              "name": "Input Capture",
              "display_name": "T1056 - Input Capture"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1546",
              "name": "Event Triggered Execution",
              "display_name": "T1546 - Event Triggered Execution"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1574",
              "name": "Hijack Execution Flow",
              "display_name": "T1574 - Hijack Execution Flow"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 3,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "adjadex1@gmail.com",
            "id": "187163",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 706,
            "URL": 1386,
            "CVE": 1,
            "FileHash-SHA256": 238,
            "domain": 234
          },
          "indicator_count": 2565,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 68,
          "modified_text": "1485 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "625eecb6fbc4353a109fe71c",
          "name": "hostkey - Industroyer&ReduceRight",
          "description": "Fbevents-PostalCodeType:f.exports, f.1, is a new addition to the list of \"signals\" that can be added to phone numbers.",
          "modified": "2022-04-19T17:09:10.196000",
          "created": "2022-04-19T17:09:10.196000",
          "tags": [
            "livechat",
            "sign up",
            "free",
            "grow",
            "policy",
            "sign",
            "strong",
            "sorry",
            "identify",
            "increase",
            "lzutf8",
            "typeerror",
            "uint8array",
            "array",
            "error",
            "typeof r",
            "class",
            "invalid",
            "post",
            "uint32array",
            "date",
            "null",
            "papvisitorid",
            "string",
            "regexp",
            "value",
            "property",
            "valuenumber",
            "activexobject",
            "postaffparams",
            "object",
            "number",
            "boolean",
            "typeof e",
            "math",
            "first",
            "raid",
            "window",
            "service",
            "ukraine",
            "epsilon",
            "arrow",
            "target",
            "keepalive",
            "void",
            "shell",
            "econnaborted",
            "hkwfunction",
            "typeof symbol",
            "function",
            "promise",
            "request",
            "network error",
            "livechatwidget",
            "ticket form",
            "prechat survey",
            "postchat survey",
            "typeof n",
            "chat",
            "blank",
            "win32",
            "iframe",
            "reduceright",
            "copyright",
            "closure library",
            "xdfunction",
            "adfunction",
            "cdfunction",
            "ddfunction",
            "bded",
            "x3e div",
            "trackevent",
            "landingpagegpu",
            "x3e table",
            "gpudraw",
            "path",
            "code",
            "functional",
            "member",
            "hnew regexp",
            "qfunction",
            "adview",
            "addbillinginfo",
            "addtocart",
            "addtolist",
            "contact",
            "download",
            "install",
            "symbol",
            "iterator",
            "extractor",
            "pixel",
            "facebook",
            "meta",
            "65535",
            "counter",
            "segoe ui",
            "lucida",
            "ecommerce",
            "ext link",
            "comic",
            "form",
            "impact",
            "light"
          ],
          "references": [
            "https://mc.yandex.ru/metrika/watch.js",
            "https://connect.facebook.net/signals/config/785878845108827",
            "https://snap.licdn.com/li.lms-analytics/insight.min.js",
            "https://www.googletagmanager.com/gtm.js?id=GTM-M9D76H",
            "https://www.googletagmanager.com/gtag/js?id=UA-73589630-1",
            "https://cdn.livechatinc.com/tracking.js",
            "https://rec.smartlook.com/main-20220331074633.js",
            "https://hostkey.com/hk/widgets/ext/build/stock.bundle.js",
            "https://hostkey.com/hk/widgets/ext/src/hostkey.js",
            "https://hostkey.postaffiliatepro.com/scripts/Oy173jux8",
            "https://hostkey.postaffiliatepro.com/scripts/Oy173rux8?accountld=default1&url=S_hostkey.com%2F&referrer=&isInlframe=false&getParams=&anchor=",
            "https://widget.trustpilot.com/trustboxes/5613c9cde69ddc09340c6beb/index.html?templateld=5613c9cde69ddc09340c6beb&businessunitld=55e46b640000ff000582c91e#locale=en-GB&styleHeight=100%25&styleWidth=100%25&theme=light",
            "https://secure.livechatinc.com/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "Tunisia"
          ],
          "malware_families": [
            {
              "id": "ReduceRight",
              "display_name": "ReduceRight",
              "target": null
            },
            {
              "id": "Industroyer - S0604",
              "display_name": "Industroyer - S0604",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1125",
              "name": "Video Capture",
              "display_name": "T1125 - Video Capture"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 8,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "adjadex1@gmail.com",
            "id": "187163",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 1778,
            "hostname": 563,
            "FileHash-SHA256": 304,
            "domain": 407,
            "FileHash-SHA1": 2
          },
          "indicator_count": 3054,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 68,
          "modified_text": "1504 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "622bff66af821729750147ab",
          "name": "Sandbox - Vi;https://edu-cisco.org - conti touched",
          "description": "",
          "modified": "2022-04-11T00:04:29.819000",
          "created": "2022-03-12T02:03:18.697000",
          "tags": [
            "sandbox",
            "malware",
            "analysis",
            "online",
            "submit",
            "vxstream",
            "sample",
            "download",
            "trojan",
            "apt",
            "ansi",
            "data",
            "decrypted ssl",
            "windows nt",
            "threat level",
            "date",
            "sha256",
            "pcap",
            "pcap processing",
            "windows",
            "path",
            "accept",
            "body",
            "format",
            "xbtl",
            "hybrid",
            "close",
            "click",
            "hosts",
            "malicious",
            "general",
            "local",
            "factory",
            "strings",
            "suspicious",
            "conti"
          ],
          "references": [
            "https://hybrid-analysis.com/sample/257842aced71d6a8197f6269f4804e36a3e7aa40755e22479bbe34531411e0c0?environmentId=100"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 4,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "dorkingbeauty1",
            "id": "80137",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 231,
            "URL": 419,
            "hostname": 154,
            "domain": 42,
            "FileHash-MD5": 59,
            "FileHash-SHA1": 46,
            "email": 2
          },
          "indicator_count": 953,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 395,
          "modified_text": "1512 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "622d0de8dc376a8b02b4e32c",
          "name": "http://projectorworld.ru/blog/770.htm",
          "description": "",
          "modified": "2022-04-11T00:04:29.819000",
          "created": "2022-03-12T21:17:28.098000",
          "tags": [
            "sandbox",
            "malware",
            "analysis",
            "online",
            "submit",
            "vxstream",
            "sample",
            "download",
            "trojan",
            "apt",
            "ansi",
            "data",
            "decrypted ssl",
            "windows nt",
            "threat level",
            "date",
            "sha256",
            "pcap",
            "pcap processing",
            "reference",
            "path",
            "accept",
            "suspicious",
            "malicious",
            "kcor",
            "nenet",
            "mumo",
            "hybrid",
            "close",
            "click",
            "hosts",
            "general",
            "local",
            "factory",
            "strings",
            "format"
          ],
          "references": [
            "https://hybrid-analysis.com/sample/09e8201ad88a17ad98b0b47f25e9e60b54a15830420811927f1125463a5efab5?environmentId=100"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1012",
              "name": "Query Registry",
              "display_name": "T1012 - Query Registry"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 3,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "dorkingbeauty1",
            "id": "80137",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 334,
            "URL": 991,
            "FileHash-SHA256": 447,
            "domain": 151,
            "email": 2,
            "FileHash-MD5": 61,
            "FileHash-SHA1": 50,
            "SSLCertFingerprint": 2
          },
          "indicator_count": 2038,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 394,
          "modified_text": "1512 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "622ce493722da2314c26a477",
          "name": "mail.ru:%22,",
          "description": "",
          "modified": "2022-04-11T00:04:29.819000",
          "created": "2022-03-12T18:21:07.131000",
          "tags": [],
          "references": [
            "mail.ru:%22,.pdf"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 8,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Kailula4",
            "id": "131997",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 3301,
            "hostname": 1341,
            "domain": 447,
            "FileHash-SHA256": 2753,
            "CIDR": 65,
            "FileHash-MD5": 112,
            "FileHash-SHA1": 2
          },
          "indicator_count": 8021,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 406,
          "modified_text": "1512 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "https://site.yandex.net/v2.0/js/all.js",
        "http://loviotvet.ru/lib/smartbanner/jquery.smartbanner.js",
        "https://top-fwz1.mail.ru/js/code.js",
        "https://secure.livechatinc.com/",
        "http://www.fid.su/js/show.js",
        "http://code.jquery.com/jquery-3.3.1.min.js",
        "https://rec.smartlook.com/main-20220331074633.js",
        "g5cc372545fb241bdab97ceedfdc72d87d6ec1e42c9a545ae9f824ed1e99521d9.json",
        "https://bitrix.info/ba.js",
        "https://cdn.shopify.com/s/files/1/0613/4340/0109/t/1/assets/component-list-menu.css?v=12926705887708249657",
        "https://hostkey.com/hk/widgets/ext/build/stock.bundle.js",
        "xfe-URL-Xelent.ru-stix2-2.1-export.json",
        "xfe-URL-cnservers.com-stix2-2.1-export.json",
        "http://www.youtube.com/embed/Bo_238D72rw?rel=0",
        "https://cdn.shopify.com/shopifycloud/shopify/assets/shop_events_listener-fa61fd11817b231631d2fe43dc869d0b1d14a06332792d42f1a1d94bda5aa31e.js",
        "https://vestacp.com/bower_components/jquery/dist/jquery.js",
        "https://cdn.shopify.com/s/files/1/0613/4340/0109/t/1/assets/component-cart-items.css?v=3522426644373936959",
        "https://static.me-talk.ru/cabinet/build/chat/modern.support.js",
        "http://www.fid.su/projects/detionline",
        "http://metrika.installtraffic.com/js/watch.js",
        "https://cdn.shopify.com/s/files/1/0613/4340/0109/t/1/assets/component-cart-notification.css?v=10701990056532666329",
        "https://www.googletagmanager.com/gtm.js?id=GTM-M9D76H",
        "https://cdn.shopify.com/s/files/1/0613/4340/0109/t/1/assets/details-disclosure.js?v=9382762063644384478",
        "https://cdn.shopify.com/s/files/1/0613/4340/0109/t/1/assets/component-menu-drawer.css?v=12673181874805599423",
        "https://cdn.shopify.com/shopifycloud/shopify/assets/shopify_pay/storefront-b61f50798075db890698930c4405673937fe89353f7fea7be88b5ce16a9c0af8.js?v=20210208",
        "https://ssl.google-analytics.com/ga.js",
        "https://widget.trustpilot.com/trustboxes/5613c9cde69ddc09340c6beb/index.html?templateld=5613c9cde69ddc09340c6beb&businessunitld=55e46b640000ff000582c91e#locale=en-GB&styleHeight=100%25&styleWidth=100%25&theme=light",
        "xfe-URL-ewqopweowia543.ga-stix2-2.0-export.json",
        "https://vestacp.com/css/app.css",
        "https://cdn.shopify.com/s/files/1/0613/4340/0109/t/1/assets/section-image-banner.css?v=17648756444066888014",
        "https://cdn.shopify.com/s/files/1/0613/4340/0109/t/1/assets/component-card.css?v=12741305300284413781",
        "http://cdnjs.cloudflare.com/ajax/libs/font-awesome/3.1.0/css/font-awesome.css",
        "https://cdn.shopify.com/s/files/1/0613/4340/0109/t/1/assets/cart-notification.js?v=11046494563428290095",
        "https://www.youtube.com/s/player/534c466c/www-widgetapi.vflset/www-widgetapi.js",
        "http://loviotvet.ru/lib/project/common.js",
        "http://www.fid.su/js/jquery-1.8.2.min.js",
        "https://vestacp.com/bower_components/what-input/dist/what-input.js",
        "https://apis.google.com/_/scs/abc-static/_/js/k=gapi.lb.en.NnK9YPjtg-w.O/m=plusone/rt=j/sv=1/d=1/ed=1/rs=AHpOoo9KePDGVlGjp-rlXwDM1kUO2Eh4gg/cb=gapi.loaded_0?le=scs",
        "https://www.googletagmanager.com/gtag/js?id=UA-73589630-1",
        "http://www.youtube.com/embed/MoDJIS6UH5U?rel=0",
        "https://connect.facebook.net/signals/config/785878845108827",
        "https://www.googletagmanager.com/gtag/js?id=UA-36935570-1",
        "https://masterhost.ru/s/masterhost_v2/build/css/global.css?v=MUmvaY06hvKf",
        "https://cdn.shopify.com/s/files/1/0613/4340/0109/t/1/assets/details-modal.js?v=451176189667266969",
        "https://admin.verbox.ru/support/support.js?h=afe80d31a1cabd6ae5c00580688f27d2",
        "https://hostkey.com/hk/widgets/ext/src/hostkey.js",
        "https://cdn.shopify.com/s/files/1/0613/4340/0109/t/1/assets/component-newsletter.css?v=10347248205600305355",
        "https://hybrid-analysis.com/sample/09e8201ad88a17ad98b0b47f25e9e60b54a15830420811927f1125463a5efab5?environmentId=100",
        "https://www.virustotal.com/graph/g5cc372545fb241bdab97ceedfdc72d87d6ec1e42c9a545ae9f824ed1e99521d9",
        "https://cdn.shopify.com/s/files/1/0613/4340/0109/t/1/assets/disclosure.css?v=64659519099960134",
        "https://vestacp.com/js/app.js",
        "https://vestacp.com/bower_components/foundation-sites/dist/js/foundation.js",
        "https://cdn.shopify.com/s/files/1/0613/4340/0109/t/1/assets/component-list-social.css?v=5221166315372665906",
        "https://cdn.shopify.com/s/files/1/0613/4340/0109/t/1/assets/global.js?v=13511647614100697069",
        "http://mc.yandex.ru/metrika/watch.js",
        "https://hybrid-analysis.com/sample/257842aced71d6a8197f6269f4804e36a3e7aa40755e22479bbe34531411e0c0?environmentId=100",
        "https://apis.google.com/_/scs/abc-static/_/js/k=gapi.lb.en.iTmf4rxOyWc.O/m=auth/exm=plusone/rt=j/sv=1/d=1/ed=1/rs=AHpOoo-LTnDn-AS2QlMWYZdnaV1OuFR7Iw/cb=gapi.loaded_1?le=scs",
        "http://loviotvet.ru/lib/fancybox/jquery.fancybox.pack.js",
        "https://apis.google.com/_/scs/abc-static/_/js/k=gapi.lb.en.NnK9YPjtg-w.O/m=auth/exm=plusone/rt=j/sv=1/d=1/ed=1/rs=AHpOoo9KePDGVlGjp-rlXwDM1kUO2Eh4gg/cb=gapi.loaded_1?le=scs",
        "xfe-IP-172.247.55.179-stix2-2.1-export.json",
        "https://cdn.shopify.com/s/files/1/0613/4340/0109/t/1/assets/component-list-payment.css?v=6925396141077183850",
        "xfe-URL-Ceranetworks.com-stix2-2.1-export 2.json",
        "https://snap.licdn.com/li.lms-analytics/insight.min.js",
        "https://cdn.shopify.com/shopifycloud/boomerang/shopify-boomerang-1.0.0.min.js",
        "https://mc.yandex.ru/metrika/tag.js",
        "https://hostkey.postaffiliatepro.com/scripts/Oy173rux8?accountld=default1&url=S_hostkey.com%2F&referrer=&isInlframe=false&getParams=&anchor=",
        "https://cdn.shopify.com/s/files/1/0613/4340/0109/t/1/assets/component-rte.css?v=6991943663851532978",
        "xfe-IP-185.44.14.140-stix2-2.1-export 2.json",
        "http://www.fid.su/js/toggleTree.js",
        "https://cdn.shopify.com/s/files/1/0613/4340/0109/t/1/assets/component-loading-overlay.css?v=16731047084359357984",
        "http://loviotvet.ru/lib/jquery/jquery-1.7.2.min.js",
        "http://www.fid.su/css/index.css",
        "https://cdn.shopify.com/s/files/1/0613/4340/0109/t/1/assets/predictive-search.js?v=3127871086358158403",
        "https://cdn.shopify.com/shopifycloud/shopify/assets/storefront/features-87e8399988880142f2c62771b9d8f2ff6c290b3ff745dd426eb0dfe0db9d1dae.js",
        "https://cdn.shopify.com/s/trekkie.storefront.7a1e33ad1202f755768e4821a6acd8fe61f84871.min.js",
        "https://mc.yandex.ru/metrika/watch.js",
        "http://loviotvet.ru/lib/jquery-ui/jquery-ui-1.10.1.custom.min.js",
        "https://cdn.livechatinc.com/tracking.js",
        "https://masterhost.ru/s/masterhost_v2/build/js/compiled.min.js?v=Q/hhNATxy3sx",
        "mail.ru:%22,.pdf",
        "https://cdn.shopify.com/shopifycloud/shopify/assets/storefront/load_feature-8efd97e96728f91aa74d4a6e8acbe8011adda17d2c0b6ccd8600a1bdd2453392.js",
        "https://hostkey.postaffiliatepro.com/scripts/Oy173jux8",
        "http://yandex.st/share/share.js",
        "https://cdn.shopify.com/s/files/1/0613/4340/0109/t/1/assets/component-search.css?v=9645568919885132178",
        "xfe-URL-youtubec3.top-stix2-2.1-export.json",
        "https://cdn.shopify.com/s/files/1/0613/4340/0109/t/1/assets/base.css?v=14499708248636525874",
        "https://apis.google.com/_/scs/abc-static/_/js/k=gapi.lb.en.iTmf4rxOyWc.O/m=plusone/rt=j/sv=1/d=1/ed=1/rs=AHpOoo-LTnDn-AS2QlMWYZdnaV1OuFR7Iw/cb=gapi.loaded_0?le=scs",
        "https://cdn.shopify.com/s/files/1/0613/4340/0109/t/1/assets/component-rating.css?v=2457308526394124043",
        "https://apis.google.com/js/plusone.js",
        "https://cdn.shopify.com/s/files/1/0613/4340/0109/t/1/assets/component-predictive-search.css?v=16564466128908848865",
        "xfe-IP-185.44.14.140-stix2-2.1-export.json",
        "https://masterhost.ru/s/masterhost_v2/build/js/app.js?v=WivgGVzt/Ynv"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 0
        },
        "other": {
          "adversary": [],
          "malware_families": [
            "Industroyer - s0604",
            "V[1]-1:k+=",
            "Gc",
            "Vd",
            "Eq",
            "Reduceright"
          ],
          "industries": [],
          "unique_indicators": 32324
        }
      }
    },
    "false_positive": [],
    "alexa": "http://www.alexa.com/siteinfo/yandex.md",
    "whois": "http://whois.domaintools.com/yandex.md",
    "domain": "yandex.md",
    "hostname": "uniproxy.messenger.alpha.yandex.md"
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 18,
  "pulses": [
    {
      "id": "65709a0e8c20860fea88779a",
      "name": "https://surveyheart.com/form/619fb5dc68ff1721fc915f81",
      "description": "",
      "modified": "2023-12-06T15:58:06.293000",
      "created": "2023-12-06T15:58:06.293000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 3,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 3624,
        "FileHash-SHA256": 1584,
        "domain": 871,
        "hostname": 1290,
        "FileHash-MD5": 20,
        "FileHash-SHA1": 20
      },
      "indicator_count": 7409,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 110,
      "modified_text": "908 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "65709510e5b078aa5f09ca51",
      "name": "widevinecdm.dll seemingly problematic - supply chain holy god mother of fu.k",
      "description": "",
      "modified": "2023-12-06T15:36:48.409000",
      "created": "2023-12-06T15:36:48.409000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 3,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 1447,
        "FileHash-MD5": 199,
        "FileHash-SHA1": 197,
        "domain": 267,
        "hostname": 871,
        "URL": 1930,
        "email": 2
      },
      "indicator_count": 4913,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "908 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "65708beba2ba8bcfb1d10237",
      "name": "hostkey - Industroyer&ReduceRight",
      "description": "",
      "modified": "2023-12-06T14:57:47.430000",
      "created": "2023-12-06T14:57:47.430000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 3,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 304,
        "hostname": 563,
        "domain": 407,
        "URL": 1776,
        "FileHash-SHA1": 2
      },
      "indicator_count": 3052,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "908 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "65708b5e9b8ce0f5fd87fb98",
      "name": "ewqopweowia543.ga",
      "description": "",
      "modified": "2023-12-06T14:55:26.621000",
      "created": "2023-12-06T14:55:26.621000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "CVE": 1,
        "hostname": 706,
        "domain": 234,
        "FileHash-SHA256": 238,
        "URL": 1386
      },
      "indicator_count": 2565,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "908 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6570819e75a6b853df509785",
      "name": "http://projectorworld.ru/blog/770.htm",
      "description": "",
      "modified": "2023-12-06T14:13:50.518000",
      "created": "2023-12-06T14:13:50.518000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 447,
        "domain": 151,
        "URL": 991,
        "hostname": 334,
        "FileHash-MD5": 61,
        "FileHash-SHA1": 50,
        "email": 2,
        "SSLCertFingerprint": 2
      },
      "indicator_count": 2038,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "908 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "65708191cdba4e9f07ba1f93",
      "name": "mail.ru:%22,",
      "description": "",
      "modified": "2023-12-06T14:13:36.976000",
      "created": "2023-12-06T14:13:36.976000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 2753,
        "hostname": 1341,
        "domain": 447,
        "URL": 3301,
        "CIDR": 65,
        "FileHash-MD5": 112,
        "FileHash-SHA1": 2
      },
      "indicator_count": 8021,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 110,
      "modified_text": "908 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6570816fa5b73f6d66bce4bb",
      "name": "Sandbox - Vi;https://edu-cisco.org - conti touched",
      "description": "",
      "modified": "2023-12-06T14:13:03.193000",
      "created": "2023-12-06T14:13:03.193000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 231,
        "domain": 42,
        "hostname": 154,
        "URL": 419,
        "FileHash-MD5": 59,
        "FileHash-SHA1": 46,
        "email": 2
      },
      "indicator_count": 953,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "908 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6451ac22105fabd34fbdf476",
      "name": "https://surveyheart.com/form/619fb5dc68ff1721fc915f81",
      "description": "Albert Hill fake profile has 1 follower and 1 follow. the one follow has this url in the p rofile",
      "modified": "2023-05-03T00:34:42.633000",
      "created": "2023-05-03T00:34:42.633000",
      "tags": [
        "entity"
      ],
      "references": [
        "https://www.virustotal.com/graph/g5cc372545fb241bdab97ceedfdc72d87d6ec1e42c9a545ae9f824ed1e99521d9",
        "g5cc372545fb241bdab97ceedfdc72d87d6ec1e42c9a545ae9f824ed1e99521d9.json"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 8,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "callmeDoris",
        "id": "205385",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 3624,
        "FileHash-SHA256": 1584,
        "hostname": 1290,
        "domain": 871,
        "IPv4": 95,
        "FileHash-MD5": 20,
        "FileHash-SHA1": 20
      },
      "indicator_count": 7504,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 93,
      "modified_text": "1125 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6398fe16df6290d8fcac2f77",
      "name": "widevinecdm.dll seemingly problematic - supply chain holy god mother of fu.k",
      "description": "https://hybrid-analysis.com/sample/db695a96adb70d5f6246273f4e6c218b2c44f02b3726c3dee4d56b6428bb0ddf",
      "modified": "2023-01-12T21:02:22.235000",
      "created": "2022-12-13T22:35:02.021000",
      "tags": [
        "sandbox",
        "malware",
        "analysis",
        "online",
        "submit",
        "vxstream",
        "sample",
        "download",
        "trojan",
        "apt",
        "runtime data",
        "ansi",
        "threat level",
        "date",
        "sha256",
        "unicode",
        "size",
        "pcap",
        "pcap processing",
        "runtime process",
        "accept",
        "suspicious",
        "hybrid",
        "malicious",
        "close",
        "click",
        "hosts",
        "ransomware",
        "general",
        "local",
        "path",
        "mozilla",
        "strings",
        "localappdata",
        "temp",
        "prefetch8 ansi",
        "entropy",
        "win64",
        "disabled hash",
        "friendly",
        "mozi",
        "trident",
        "copy md5",
        "copy sha1",
        "copy sha256",
        "file",
        "type data",
        "download file",
        "db695a96adb70d5f6246273f4e6c218b2c44f02b3726c3dee4d56b6428bb0ddf",
        "widevinecdm.dll",
        "https://hybrid-analysis.com/sample/db695a96adb70d5f6246273f4e6c2"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1005",
          "name": "Data from Local System",
          "display_name": "T1005 - Data from Local System"
        },
        {
          "id": "T1043",
          "name": "Commonly Used Port",
          "display_name": "T1043 - Commonly Used Port"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1179",
          "name": "Hooking",
          "display_name": "T1179 - Hooking"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 32,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "dorkingbeauty1",
        "id": "80137",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 871,
        "URL": 1930,
        "domain": 267,
        "FileHash-SHA256": 1447,
        "FileHash-MD5": 199,
        "FileHash-SHA1": 197,
        "email": 2
      },
      "indicator_count": 4913,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 397,
      "modified_text": "1235 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "627ee9ff7d36c1432328ebe7",
      "name": "\u041b\u0438\u043d\u0438\u044f \u043f\u043e\u043c\u043e\u0449\u0438 \u00ab\u0414\u0435\u0442\u0438 \u043e\u043d\u043b\u0430\u0439\u043d\u00bb \u2014 \u0424\u043e\u043d\u0434 \u0420\u0430\u0437\u0432\u0438\u0442\u0438\u044f \u0418\u043d\u0442\u0435\u0440\u043d\u0435\u0442 FID.SU",
      "description": "Foundation for Internet development \u2013 Soviet Union",
      "modified": "2022-06-12T00:06:23.557000",
      "created": "2022-05-13T23:30:07.788000",
      "tags": [
        "cecece",
        "e9031d",
        "domen su",
        "font awesome",
        "license",
        "bootstrap",
        "sil open",
        "font license",
        "less",
        "sass",
        "mit license",
        "cc by",
        "dave gandy",
        "contact",
        "twitter",
        "class",
        "regexp",
        "null",
        "array",
        "pseudo",
        "child",
        "x20trnf",
        "name",
        "attr",
        "cfunction",
        "error",
        "block",
        "last",
        "parent",
        "blogger",
        "diary",
        "digg",
        "evernote",
        "facebook",
        "google plus",
        "juick",
        "linkedin",
        "liveinternet",
        "livejournal",
        "youtube",
        "function",
        "width",
        "date",
        "accept",
        "gc",
        "65535",
        "boolean",
        "counter",
        "typeof c",
        "segoe ui",
        "typeerror",
        "lucida",
        "ecommerce",
        "ext link",
        "form",
        "impact",
        "light"
      ],
      "references": [
        "http://www.fid.su/projects/detionline",
        "http://mc.yandex.ru/metrika/watch.js",
        "xfe-IP-172.247.55.179-stix2-2.1-export.json",
        "xfe-URL-cnservers.com-stix2-2.1-export.json",
        "xfe-URL-Ceranetworks.com-stix2-2.1-export 2.json",
        "http://www.youtube.com/embed/Bo_238D72rw?rel=0",
        "http://yandex.st/share/share.js",
        "http://www.fid.su/js/toggleTree.js",
        "http://www.fid.su/js/show.js",
        "http://www.fid.su/js/jquery-1.8.2.min.js",
        "http://cdnjs.cloudflare.com/ajax/libs/font-awesome/3.1.0/css/font-awesome.css",
        "http://www.fid.su/css/index.css"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "New Caledonia"
      ],
      "malware_families": [
        {
          "id": "Gc",
          "display_name": "Gc",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 9,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "adjadex1@gmail.com",
        "id": "187163",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 1817,
        "hostname": 705,
        "domain": 381,
        "FileHash-SHA256": 201,
        "email": 2
      },
      "indicator_count": 3106,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 69,
      "modified_text": "1450 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "https://uniproxy.messenger.alpha.yandex.md",
    "type": "URL"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "https://uniproxy.messenger.alpha.yandex.md",
    "type": "URL",
    "found": false,
    "verdict": "clean",
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780343595.5835638
}