{
  "type": "URL",
  "indicator": "https://v423pop.dns0.org/",
  "general": {
    "sections": [
      "general",
      "url_list",
      "http_scans",
      "screenshot"
    ],
    "indicator": "https://v423pop.dns0.org/",
    "type": "url",
    "type_title": "URL",
    "validation": [],
    "base_indicator": {
      "id": 4016731047,
      "indicator": "https://v423pop.dns0.org/",
      "type": "URL",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 7,
      "pulses": [
        {
          "id": "69ba97dadbd6e4729709fa6d",
          "name": "pobierz.zip Sygn. akt II K 909/23 oskar clone by arek-BTC",
          "description": "",
          "modified": "2026-03-18T12:17:30.176000",
          "created": "2026-03-18T12:17:30.176000",
          "tags": [
            "typ pliku",
            "ascii",
            "sqlite",
            "tekst",
            "postscript",
            "cza typ",
            "windows",
            "152 x",
            "utf8",
            "dziennik",
            "sha1",
            "json",
            "foxpro fpt",
            "sha256",
            "mwdb",
            "bazar",
            "sha3384",
            "crc32 c69b0751",
            "gboki",
            "settings",
            "categories",
            "default",
            "toolspanose",
            "cname",
            "nova cond",
            "inprocserver32",
            "metadata",
            "lcid1033",
            "syslcid1033",
            "light"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": "67c44a6e14a21bec8ba63984",
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 210,
            "FileHash-SHA1": 53,
            "FileHash-SHA256": 599,
            "hostname": 151,
            "domain": 23,
            "URL": 233
          },
          "indicator_count": 1269,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 68,
          "modified_text": "76 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "676de64bb6892336196cfeb9",
          "name": "http://www.home.pl/  xn--gwna-qqa78b.pl ( g\u0142\u00f3wna.pl )",
          "description": "Wersja j\u0105dra maszyny wirtualnej\t6.1.7601.17514 (3844dbb9-2017-4967-be7a-a4a2c20430fa)\nThe following is a full list of text and images from the 2016 European Union (EU) conference, held in Berlin, Germany, which were held on Tuesday, 1 July 2016, at 19:00 BST.",
          "modified": "2025-05-14T21:15:08.161000",
          "created": "2024-12-26T23:27:06.044000",
          "tags": [
            "jak zmieni",
            "panelu klienta",
            "zmiana hasa",
            "strong",
            "obsuga poczty",
            "w tym",
            "za porednictwem",
            "panelu",
            "certyfikaty ssl",
            "kalendarz pracy",
            "jest",
            "facebook",
            "ciebie",
            "zamw teraz",
            "zobacz szczegy",
            "zobacz",
            "office",
            "chc wystartowa",
            "google",
            "zastanawiasz si",
            "zrobisz",
            "otrzymasz pomoc",
            "android",
            "pdf regulamin",
            "zacznik",
            "wiadczenia",
            "regulaminu usug",
            "usug",
            "regulaminy",
            "link regulamin",
            "regulamin usugi",
            "poczta",
            "teamviewer",
            "anydesk",
            "microsoft",
            "vps linux",
            "vps windows",
            "kreator www",
            "standard",
            "start",
            "premium",
            "asseco",
            "cennik",
            "starter",
            "twitch",
            "core",
            "ultimate",
            "defender",
            "enterprise",
            "solo",
            "import",
            "designer",
            "strona",
            "czsto zadawane",
            "status polityka",
            "polityka plikw",
            "poland",
            "germany",
            "lukow",
            "frankfurt am",
            "united",
            "warszawa",
            "ip location",
            "osint verdict",
            "katowice",
            "koeln porz",
            "main",
            "polska",
            "niemcy",
            "frankfurt",
            "menem",
            "szczecin",
            "san francisco",
            "kolonia porz",
            "szczecin strona",
            "n ty",
            "m mi",
            "a ty",
            "c mi",
            "h mi",
            "d mi",
            "span",
            "ihdr",
            "vu phys",
            "srgb",
            "gama aidatxp",
            "adobe xmp",
            "adobe photoshop",
            "windows",
            "dte6f7",
            "rfzt85drbqj2n",
            "ud0 c",
            "rjxrj2ooy",
            "gwnj",
            "sosj im",
            "donex",
            "sha256",
            "sha1",
            "june",
            "copyright",
            "doscom sha256",
            "dosexe",
            "http request",
            "method get",
            "country a",
            "polandpoland as",
            "name",
            "number",
            "protocol h3",
            "type",
            "mime type",
            "data size",
            "identyfikator",
            "https dane",
            "v3 numer",
            "odcisk palca",
            "wystawca",
            "us cn",
            "encrypt wano",
            "nie wczeniej",
            "nie po",
            "informacje"
          ],
          "references": [
            "https://pomoc.home.pl/faq/5",
            "http://www.home.pl./",
            "http://www.home.pl/",
            "https://home.pl/regulaminy",
            "https://home.pl/cennik",
            "https://www.home.pl/regulaminy",
            "https://home.pl/login"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1218",
              "name": "Signed Binary Proxy Execution",
              "display_name": "T1218 - Signed Binary Proxy Execution"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 19,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Arek-BTC",
            "id": "212764",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_212764/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA1": 19,
            "FileHash-SHA256": 615,
            "CIDR": 1,
            "domain": 243,
            "URL": 1520,
            "hostname": 413,
            "email": 1,
            "FileHash-MD5": 26,
            "IPv4": 32,
            "YARA": 1
          },
          "indicator_count": 2871,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 124,
          "modified_text": "383 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "676c22688c20f970ad67e408",
          "name": "Exploit/Shellcode Zawiera ukryty ci\u0105g bajt\u00f3w (cz\u0119sto cz\u0119\u015b\u0107 zaciemnionego kodu pow\u0142oki)",
          "description": "https://hybrid-analysis.com/sample/f03c81c8e39139eab248f5c3355f918f87b9ffe740a866c13b7782ef719af914/64eb8574b43749bb740d2f8a",
          "modified": "2025-05-14T20:57:23.962000",
          "created": "2024-12-25T15:19:04.989000",
          "tags": [
            "united",
            "portland",
            "aws ec2",
            "wskaniki",
            "sha256",
            "a mi",
            "c mi",
            "ihdr8gvsrgb",
            "idatx",
            "bbygx",
            "idat b",
            "4m mviendb",
            "peexe c",
            "date",
            "file sha256",
            "dhsdh",
            "sarsrx",
            "gramatyka",
            "pisownia",
            "yczerejestru",
            "x308b",
            "merriamwebster",
            "wunder",
            "politico",
            "purdue",
            "roboto"
          ],
          "references": [
            "http://ip-api.com/json/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 7,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Arek-BTC",
            "id": "212764",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_212764/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 93,
            "FileHash-SHA1": 35,
            "FileHash-SHA256": 308,
            "IPv4": 28,
            "hostname": 107,
            "URL": 35,
            "domain": 626
          },
          "indicator_count": 1232,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 125,
          "modified_text": "383 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "67c44a6e14a21bec8ba63984",
          "name": "pobierz.zip   Sygn. akt II K 909/23 oskar\u017conego z art. 190 \u00a7 1 k.k. i inne",
          "description": "Sugerowane identyfikatory ATT&CK:\n7eab0ed0a8a050ad34f71dfd3e2109ff SHA1 c60c3d64cfa19fb1f19eabc656aafdcf12d87dd4 SHA256 3d0f3f98cea613718def2eb9dca707ad57d3d96d4e6b593aca38c8574a578905 [VT] [MWDB] [Bazar] SHA3-384 32d70abaa630d0a8e6237b1df88da306306d27096950469ff7e99d754274e28cfaa0736af43ad55f3d57fc66d9812d4d CRC32 C69B0751 TLSH T1013413B6C8A16CF2D93D2BF2D89A3715DFDAB2C28156C057EB22C09359CE5D817438D8 G\u0142\u0119boki 6144:E8FhrpzjsHyC6DgXapizwbZ8ePb85pNLmih2tC:vrpESCUgX8ikbZ8ePb8J0E",
          "modified": "2025-04-01T09:03:52.165000",
          "created": "2025-03-02T12:09:18.878000",
          "tags": [
            "typ pliku",
            "ascii",
            "sqlite",
            "tekst",
            "postscript",
            "cza typ",
            "windows",
            "152 x",
            "utf8",
            "dziennik",
            "sha1",
            "json",
            "foxpro fpt",
            "sha256",
            "mwdb",
            "bazar",
            "sha3384",
            "crc32 c69b0751",
            "gboki",
            "settings",
            "categories",
            "default",
            "toolspanose",
            "cname",
            "nova cond",
            "inprocserver32",
            "metadata",
            "lcid1033",
            "syslcid1033",
            "light"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 8,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Arek-BTC",
            "id": "212764",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_212764/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 210,
            "FileHash-SHA1": 53,
            "FileHash-SHA256": 599,
            "hostname": 151,
            "domain": 23,
            "URL": 233
          },
          "indicator_count": 1269,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 127,
          "modified_text": "427 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "67c3c9bb1edaafe8b41e6fe9",
          "name": "instrukcja-polaczenia-jitsi---dla-obywatela-v1.4.LNK  e4d22d61973fb50ae6236d032ca9cd29cb8e05ccdcc533ada089f61cb192ff5e",
          "description": "Link target id list\nCLSID_ShellDesktop\nName\nCLSID_ShellDesktop\n CLSID\n20d04fe0-3aea-1069-a2d8-08002b30309d\nZnaczniki iFrame\nZawarto\u015b\u0107 wszystkich znacznik\u00f3w iframe znalezionych w pliku.\nc4a66081d8d55b92a6487767cdd20db98cc609eb36b1a1509e7c2f001c6606bc",
          "modified": "2025-04-01T02:02:25.113000",
          "created": "2025-03-02T03:00:11.425000",
          "tags": [
            "rozmiar pliku",
            "typ pliku",
            "microsoft word",
            "sha1",
            "sha512",
            "crc32",
            "gboki",
            "oszczdno",
            "vhash",
            "ssdeep",
            "k usuga",
            "uytkownik",
            "k netsvcs",
            "s storsvc",
            "pliki",
            "w32time c",
            "sha256",
            "mitre att",
            "ck wykonanie"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1001",
              "name": "Data Obfuscation",
              "display_name": "T1001 - Data Obfuscation"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "TA0005",
              "name": "Defense Evasion",
              "display_name": "TA0005 - Defense Evasion"
            },
            {
              "id": "TA0004",
              "name": "Privilege Escalation",
              "display_name": "TA0004 - Privilege Escalation"
            },
            {
              "id": "TA0007",
              "name": "Discovery",
              "display_name": "TA0007 - Discovery"
            },
            {
              "id": "TA0011",
              "name": "Command and Control",
              "display_name": "TA0011 - Command and Control"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 5,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Arek-BTC",
            "id": "212764",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_212764/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 28,
            "FileHash-SHA1": 13,
            "FileHash-SHA256": 57,
            "hostname": 10,
            "URL": 23,
            "domain": 2
          },
          "indicator_count": 133,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 123,
          "modified_text": "427 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6774a3ec9b253daddfc902a3",
          "name": "Sample_5adcc978b45f6a54af936c48.exe  MD5 1f37eebe61bc9252bd72e643f4223896",
          "description": "Names\n1f37eebe61bc9252bd72e643f4223896\nSample_5adcc978b45f6a54af936c48.exe\nAutoTRON.exe\nc28961e7a22e2d5c5bce189214974a91faa11275\n17abbc9e2cd58563aba1d2f3ceb539eced16ec950ddcc3f8e068f9d0c5441096._exe",
          "modified": "2025-01-31T02:00:02.600000",
          "created": "2025-01-01T02:09:48.512000",
          "tags": [
            "sha256",
            "pejzasz",
            "wersja pliku",
            "v2 dokument",
            "tekst ascii",
            "z terminatorami",
            "crlf",
            "tekst w",
            "ascii",
            "zgodny z",
            "user",
            "settings",
            "autoit",
            "sangfor zsand",
            "tencent habo",
            "zenbox",
            "rules not",
            "c2 server",
            "memory pattern",
            "analysis date",
            "malware",
            "stealer",
            "ransom",
            "phishing"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 15,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Arek-BTC",
            "id": "212764",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_212764/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 75,
            "FileHash-SHA1": 2,
            "FileHash-SHA256": 144,
            "URL": 260,
            "domain": 51,
            "hostname": 110
          },
          "indicator_count": 642,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 123,
          "modified_text": "487 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6772d3f77b251a2e1e8eacbf",
          "name": "39a2201a88f10d81b220c973737f0becedab2e73426ab9923880fb0fb990c5cc.bin.pr\u00f3bka",
          "description": "http://crl.microsoft.com/pki/mscorp/crl/Microsoft%20IT%20TLS%20CA%205.crl\nHere is a full list of details of the top 10 most-wanted malware releases for the next three years:. and the most likely ones for 2023-24 January 2018.-.",
          "modified": "2025-01-28T13:05:35.415000",
          "created": "2024-12-30T17:10:15.131000",
          "tags": [
            "sha1",
            "sha256",
            "imphasz",
            "trojandropper",
            "robak",
            "lowfi",
            "rticon english",
            "english us",
            "ico rtgroupicon",
            "xml rtmanifest",
            "overlay chi2",
            "win32 exe",
            "intel",
            "date",
            "submission",
            "visionone",
            "rsa code",
            "signing ca",
            "timestamp",
            "vhash",
            "authentihash",
            "pecompact",
            "peexe c",
            "text c",
            "xml c",
            "lnk c",
            "user",
            "imphash",
            "ssdeep",
            "tools",
            "detection rule",
            "license",
            "roth",
            "nextron",
            "yzhpluqa",
            "yara rule",
            "set author",
            "roth date",
            "identifier",
            "pyinstaller",
            "released",
            "bartblaze",
            "identifies",
            "info",
            "writefile",
            "readfile",
            "isbadreadptr",
            "setfilepointer",
            "inquest labs",
            "windows api",
            "inquestpii",
            "loadlibrarya",
            "shellexecutea",
            "getprocaddress"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 12,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Arek-BTC",
            "id": "212764",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_212764/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 58,
            "FileHash-SHA1": 41,
            "FileHash-SHA256": 381,
            "hostname": 8,
            "URL": 26,
            "domain": 1,
            "YARA": 27
          },
          "indicator_count": 542,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 125,
          "modified_text": "490 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "http://ip-api.com/json/",
        "https://home.pl/regulaminy",
        "http://www.home.pl./",
        "https://pomoc.home.pl/faq/5",
        "https://www.home.pl/regulaminy",
        "https://home.pl/login",
        "https://home.pl/cennik",
        "http://www.home.pl/"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 0
        },
        "other": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 6626
        }
      }
    },
    "false_positive": [],
    "alexa": "http://www.alexa.com/siteinfo/dns0.org",
    "whois": "http://whois.domaintools.com/dns0.org",
    "domain": "dns0.org",
    "hostname": "v423pop.dns0.org"
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 7,
  "pulses": [
    {
      "id": "69ba97dadbd6e4729709fa6d",
      "name": "pobierz.zip Sygn. akt II K 909/23 oskar clone by arek-BTC",
      "description": "",
      "modified": "2026-03-18T12:17:30.176000",
      "created": "2026-03-18T12:17:30.176000",
      "tags": [
        "typ pliku",
        "ascii",
        "sqlite",
        "tekst",
        "postscript",
        "cza typ",
        "windows",
        "152 x",
        "utf8",
        "dziennik",
        "sha1",
        "json",
        "foxpro fpt",
        "sha256",
        "mwdb",
        "bazar",
        "sha3384",
        "crc32 c69b0751",
        "gboki",
        "settings",
        "categories",
        "default",
        "toolspanose",
        "cname",
        "nova cond",
        "inprocserver32",
        "metadata",
        "lcid1033",
        "syslcid1033",
        "light"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": "67c44a6e14a21bec8ba63984",
      "export_count": 1,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 210,
        "FileHash-SHA1": 53,
        "FileHash-SHA256": 599,
        "hostname": 151,
        "domain": 23,
        "URL": 233
      },
      "indicator_count": 1269,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 68,
      "modified_text": "76 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "676de64bb6892336196cfeb9",
      "name": "http://www.home.pl/  xn--gwna-qqa78b.pl ( g\u0142\u00f3wna.pl )",
      "description": "Wersja j\u0105dra maszyny wirtualnej\t6.1.7601.17514 (3844dbb9-2017-4967-be7a-a4a2c20430fa)\nThe following is a full list of text and images from the 2016 European Union (EU) conference, held in Berlin, Germany, which were held on Tuesday, 1 July 2016, at 19:00 BST.",
      "modified": "2025-05-14T21:15:08.161000",
      "created": "2024-12-26T23:27:06.044000",
      "tags": [
        "jak zmieni",
        "panelu klienta",
        "zmiana hasa",
        "strong",
        "obsuga poczty",
        "w tym",
        "za porednictwem",
        "panelu",
        "certyfikaty ssl",
        "kalendarz pracy",
        "jest",
        "facebook",
        "ciebie",
        "zamw teraz",
        "zobacz szczegy",
        "zobacz",
        "office",
        "chc wystartowa",
        "google",
        "zastanawiasz si",
        "zrobisz",
        "otrzymasz pomoc",
        "android",
        "pdf regulamin",
        "zacznik",
        "wiadczenia",
        "regulaminu usug",
        "usug",
        "regulaminy",
        "link regulamin",
        "regulamin usugi",
        "poczta",
        "teamviewer",
        "anydesk",
        "microsoft",
        "vps linux",
        "vps windows",
        "kreator www",
        "standard",
        "start",
        "premium",
        "asseco",
        "cennik",
        "starter",
        "twitch",
        "core",
        "ultimate",
        "defender",
        "enterprise",
        "solo",
        "import",
        "designer",
        "strona",
        "czsto zadawane",
        "status polityka",
        "polityka plikw",
        "poland",
        "germany",
        "lukow",
        "frankfurt am",
        "united",
        "warszawa",
        "ip location",
        "osint verdict",
        "katowice",
        "koeln porz",
        "main",
        "polska",
        "niemcy",
        "frankfurt",
        "menem",
        "szczecin",
        "san francisco",
        "kolonia porz",
        "szczecin strona",
        "n ty",
        "m mi",
        "a ty",
        "c mi",
        "h mi",
        "d mi",
        "span",
        "ihdr",
        "vu phys",
        "srgb",
        "gama aidatxp",
        "adobe xmp",
        "adobe photoshop",
        "windows",
        "dte6f7",
        "rfzt85drbqj2n",
        "ud0 c",
        "rjxrj2ooy",
        "gwnj",
        "sosj im",
        "donex",
        "sha256",
        "sha1",
        "june",
        "copyright",
        "doscom sha256",
        "dosexe",
        "http request",
        "method get",
        "country a",
        "polandpoland as",
        "name",
        "number",
        "protocol h3",
        "type",
        "mime type",
        "data size",
        "identyfikator",
        "https dane",
        "v3 numer",
        "odcisk palca",
        "wystawca",
        "us cn",
        "encrypt wano",
        "nie wczeniej",
        "nie po",
        "informacje"
      ],
      "references": [
        "https://pomoc.home.pl/faq/5",
        "http://www.home.pl./",
        "http://www.home.pl/",
        "https://home.pl/regulaminy",
        "https://home.pl/cennik",
        "https://www.home.pl/regulaminy",
        "https://home.pl/login"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1218",
          "name": "Signed Binary Proxy Execution",
          "display_name": "T1218 - Signed Binary Proxy Execution"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 19,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Arek-BTC",
        "id": "212764",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_212764/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA1": 19,
        "FileHash-SHA256": 615,
        "CIDR": 1,
        "domain": 243,
        "URL": 1520,
        "hostname": 413,
        "email": 1,
        "FileHash-MD5": 26,
        "IPv4": 32,
        "YARA": 1
      },
      "indicator_count": 2871,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 124,
      "modified_text": "383 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "676c22688c20f970ad67e408",
      "name": "Exploit/Shellcode Zawiera ukryty ci\u0105g bajt\u00f3w (cz\u0119sto cz\u0119\u015b\u0107 zaciemnionego kodu pow\u0142oki)",
      "description": "https://hybrid-analysis.com/sample/f03c81c8e39139eab248f5c3355f918f87b9ffe740a866c13b7782ef719af914/64eb8574b43749bb740d2f8a",
      "modified": "2025-05-14T20:57:23.962000",
      "created": "2024-12-25T15:19:04.989000",
      "tags": [
        "united",
        "portland",
        "aws ec2",
        "wskaniki",
        "sha256",
        "a mi",
        "c mi",
        "ihdr8gvsrgb",
        "idatx",
        "bbygx",
        "idat b",
        "4m mviendb",
        "peexe c",
        "date",
        "file sha256",
        "dhsdh",
        "sarsrx",
        "gramatyka",
        "pisownia",
        "yczerejestru",
        "x308b",
        "merriamwebster",
        "wunder",
        "politico",
        "purdue",
        "roboto"
      ],
      "references": [
        "http://ip-api.com/json/"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 7,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Arek-BTC",
        "id": "212764",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_212764/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 93,
        "FileHash-SHA1": 35,
        "FileHash-SHA256": 308,
        "IPv4": 28,
        "hostname": 107,
        "URL": 35,
        "domain": 626
      },
      "indicator_count": 1232,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 125,
      "modified_text": "383 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "67c44a6e14a21bec8ba63984",
      "name": "pobierz.zip   Sygn. akt II K 909/23 oskar\u017conego z art. 190 \u00a7 1 k.k. i inne",
      "description": "Sugerowane identyfikatory ATT&CK:\n7eab0ed0a8a050ad34f71dfd3e2109ff SHA1 c60c3d64cfa19fb1f19eabc656aafdcf12d87dd4 SHA256 3d0f3f98cea613718def2eb9dca707ad57d3d96d4e6b593aca38c8574a578905 [VT] [MWDB] [Bazar] SHA3-384 32d70abaa630d0a8e6237b1df88da306306d27096950469ff7e99d754274e28cfaa0736af43ad55f3d57fc66d9812d4d CRC32 C69B0751 TLSH T1013413B6C8A16CF2D93D2BF2D89A3715DFDAB2C28156C057EB22C09359CE5D817438D8 G\u0142\u0119boki 6144:E8FhrpzjsHyC6DgXapizwbZ8ePb85pNLmih2tC:vrpESCUgX8ikbZ8ePb8J0E",
      "modified": "2025-04-01T09:03:52.165000",
      "created": "2025-03-02T12:09:18.878000",
      "tags": [
        "typ pliku",
        "ascii",
        "sqlite",
        "tekst",
        "postscript",
        "cza typ",
        "windows",
        "152 x",
        "utf8",
        "dziennik",
        "sha1",
        "json",
        "foxpro fpt",
        "sha256",
        "mwdb",
        "bazar",
        "sha3384",
        "crc32 c69b0751",
        "gboki",
        "settings",
        "categories",
        "default",
        "toolspanose",
        "cname",
        "nova cond",
        "inprocserver32",
        "metadata",
        "lcid1033",
        "syslcid1033",
        "light"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 8,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Arek-BTC",
        "id": "212764",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_212764/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 210,
        "FileHash-SHA1": 53,
        "FileHash-SHA256": 599,
        "hostname": 151,
        "domain": 23,
        "URL": 233
      },
      "indicator_count": 1269,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 127,
      "modified_text": "427 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "67c3c9bb1edaafe8b41e6fe9",
      "name": "instrukcja-polaczenia-jitsi---dla-obywatela-v1.4.LNK  e4d22d61973fb50ae6236d032ca9cd29cb8e05ccdcc533ada089f61cb192ff5e",
      "description": "Link target id list\nCLSID_ShellDesktop\nName\nCLSID_ShellDesktop\n CLSID\n20d04fe0-3aea-1069-a2d8-08002b30309d\nZnaczniki iFrame\nZawarto\u015b\u0107 wszystkich znacznik\u00f3w iframe znalezionych w pliku.\nc4a66081d8d55b92a6487767cdd20db98cc609eb36b1a1509e7c2f001c6606bc",
      "modified": "2025-04-01T02:02:25.113000",
      "created": "2025-03-02T03:00:11.425000",
      "tags": [
        "rozmiar pliku",
        "typ pliku",
        "microsoft word",
        "sha1",
        "sha512",
        "crc32",
        "gboki",
        "oszczdno",
        "vhash",
        "ssdeep",
        "k usuga",
        "uytkownik",
        "k netsvcs",
        "s storsvc",
        "pliki",
        "w32time c",
        "sha256",
        "mitre att",
        "ck wykonanie"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1001",
          "name": "Data Obfuscation",
          "display_name": "T1001 - Data Obfuscation"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1573",
          "name": "Encrypted Channel",
          "display_name": "T1573 - Encrypted Channel"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "TA0005",
          "name": "Defense Evasion",
          "display_name": "TA0005 - Defense Evasion"
        },
        {
          "id": "TA0004",
          "name": "Privilege Escalation",
          "display_name": "TA0004 - Privilege Escalation"
        },
        {
          "id": "TA0007",
          "name": "Discovery",
          "display_name": "TA0007 - Discovery"
        },
        {
          "id": "TA0011",
          "name": "Command and Control",
          "display_name": "TA0011 - Command and Control"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 5,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Arek-BTC",
        "id": "212764",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_212764/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 28,
        "FileHash-SHA1": 13,
        "FileHash-SHA256": 57,
        "hostname": 10,
        "URL": 23,
        "domain": 2
      },
      "indicator_count": 133,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 123,
      "modified_text": "427 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6774a3ec9b253daddfc902a3",
      "name": "Sample_5adcc978b45f6a54af936c48.exe  MD5 1f37eebe61bc9252bd72e643f4223896",
      "description": "Names\n1f37eebe61bc9252bd72e643f4223896\nSample_5adcc978b45f6a54af936c48.exe\nAutoTRON.exe\nc28961e7a22e2d5c5bce189214974a91faa11275\n17abbc9e2cd58563aba1d2f3ceb539eced16ec950ddcc3f8e068f9d0c5441096._exe",
      "modified": "2025-01-31T02:00:02.600000",
      "created": "2025-01-01T02:09:48.512000",
      "tags": [
        "sha256",
        "pejzasz",
        "wersja pliku",
        "v2 dokument",
        "tekst ascii",
        "z terminatorami",
        "crlf",
        "tekst w",
        "ascii",
        "zgodny z",
        "user",
        "settings",
        "autoit",
        "sangfor zsand",
        "tencent habo",
        "zenbox",
        "rules not",
        "c2 server",
        "memory pattern",
        "analysis date",
        "malware",
        "stealer",
        "ransom",
        "phishing"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 15,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Arek-BTC",
        "id": "212764",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_212764/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 75,
        "FileHash-SHA1": 2,
        "FileHash-SHA256": 144,
        "URL": 260,
        "domain": 51,
        "hostname": 110
      },
      "indicator_count": 642,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 123,
      "modified_text": "487 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6772d3f77b251a2e1e8eacbf",
      "name": "39a2201a88f10d81b220c973737f0becedab2e73426ab9923880fb0fb990c5cc.bin.pr\u00f3bka",
      "description": "http://crl.microsoft.com/pki/mscorp/crl/Microsoft%20IT%20TLS%20CA%205.crl\nHere is a full list of details of the top 10 most-wanted malware releases for the next three years:. and the most likely ones for 2023-24 January 2018.-.",
      "modified": "2025-01-28T13:05:35.415000",
      "created": "2024-12-30T17:10:15.131000",
      "tags": [
        "sha1",
        "sha256",
        "imphasz",
        "trojandropper",
        "robak",
        "lowfi",
        "rticon english",
        "english us",
        "ico rtgroupicon",
        "xml rtmanifest",
        "overlay chi2",
        "win32 exe",
        "intel",
        "date",
        "submission",
        "visionone",
        "rsa code",
        "signing ca",
        "timestamp",
        "vhash",
        "authentihash",
        "pecompact",
        "peexe c",
        "text c",
        "xml c",
        "lnk c",
        "user",
        "imphash",
        "ssdeep",
        "tools",
        "detection rule",
        "license",
        "roth",
        "nextron",
        "yzhpluqa",
        "yara rule",
        "set author",
        "roth date",
        "identifier",
        "pyinstaller",
        "released",
        "bartblaze",
        "identifies",
        "info",
        "writefile",
        "readfile",
        "isbadreadptr",
        "setfilepointer",
        "inquest labs",
        "windows api",
        "inquestpii",
        "loadlibrarya",
        "shellexecutea",
        "getprocaddress"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 12,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Arek-BTC",
        "id": "212764",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_212764/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 58,
        "FileHash-SHA1": 41,
        "FileHash-SHA256": 381,
        "hostname": 8,
        "URL": 26,
        "domain": 1,
        "YARA": 27
      },
      "indicator_count": 542,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 125,
      "modified_text": "490 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "https://v423pop.dns0.org/",
    "type": "URL"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "https://v423pop.dns0.org/",
    "type": "URL",
    "found": false,
    "verdict": "clean",
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780432652.5304816
}