{
  "type": "URL",
  "indicator": "https://wap.ac/wp-signup.php",
  "general": {
    "sections": [
      "general",
      "url_list",
      "http_scans",
      "screenshot"
    ],
    "indicator": "https://wap.ac/wp-signup.php",
    "type": "url",
    "type_title": "URL",
    "validation": [],
    "base_indicator": {
      "id": 3956529998,
      "indicator": "https://wap.ac/wp-signup.php",
      "type": "URL",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 9,
      "pulses": [
        {
          "id": "69ff110180abb3beb39c04bc",
          "name": "Microsoft security reporting portal CREATED 2 YEARS AGO MODIFIED 1 YEAR AGO by Arek-BTC [2024 and older]",
          "description": "",
          "modified": "2026-05-09T12:20:54.997000",
          "created": "2026-05-09T10:48:33.286000",
          "tags": [
            "microsoft",
            "security",
            "reporting",
            "portal",
            "abuse",
            "privacy",
            "infringement",
            "trademark",
            "trademark infringement",
            "abuse report",
            "privacy report",
            "security report",
            "security reporting",
            "abuse reporting",
            "privacy reporting",
            "security reporting portal",
            "abuse reporting portal",
            "privacy reporting portal",
            "security reporting form",
            "abuse reporting form",
            "privacy reporting form",
            "security reporting website",
            "abuse reporting website",
            "privacy reporting website",
            "security reporting site",
            "abuse reporting site",
            "privacy reporting site",
            "security reporting page",
            "abuse reporting page",
            "privacy reporting page",
            "security reporting web page",
            "abuse reporting web page",
            "privacy reporting web page",
            "security reporting webform",
            "abuse reporting webform",
            "privacy reporting webform",
            "security reporting web form",
            "abuse reporting web form",
            "privacy reporting web form",
            "javascript"
          ],
          "references": [
            "https://cert.microsoft.com"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": "66e9c5a4cc3b60c38e6381b8",
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "email": 10,
            "IPv4": 46,
            "FileHash-SHA256": 1684,
            "URL": 337,
            "SSLCertFingerprint": 4,
            "CIDR": 65,
            "IPv6": 8,
            "FileHash-SHA1": 149,
            "domain": 130,
            "FileHash-MD5": 169,
            "hostname": 152,
            "CVE": 3
          },
          "indicator_count": 2757,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 66,
          "modified_text": "22 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "66d45dab14a189645153e8a6",
          "name": "Reverse WHOIS results for vgt.pl ( GANG VGT)",
          "description": "",
          "modified": "2024-12-17T14:47:57",
          "created": "2024-09-01T12:27:23.777000",
          "tags": [
            "ipv4 domain",
            "ipv4 url",
            "domain",
            "sha1",
            "sha256",
            "pehash",
            "vhash",
            "ssdeep"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Arek-BTC",
            "id": "212764",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_212764/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 1286,
            "FileHash-SHA1": 1286,
            "FileHash-SHA256": 2722,
            "URL": 4729,
            "domain": 1909,
            "hostname": 2082,
            "IPv4": 97,
            "CVE": 4,
            "YARA": 1
          },
          "indicator_count": 14116,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 127,
          "modified_text": "530 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "66e9c5a4cc3b60c38e6381b8",
          "name": "Microsoft security reporting portal",
          "description": "130.0/11.5/12.3/13.4.6.7.8.1.2/14.9. 0/16.25/17..",
          "modified": "2024-12-17T14:35:36.786000",
          "created": "2024-09-17T18:08:36.835000",
          "tags": [
            "microsoft",
            "security",
            "reporting",
            "portal",
            "abuse",
            "privacy",
            "infringement",
            "trademark",
            "trademark infringement",
            "abuse report",
            "privacy report",
            "security report",
            "security reporting",
            "abuse reporting",
            "privacy reporting",
            "security reporting portal",
            "abuse reporting portal",
            "privacy reporting portal",
            "security reporting form",
            "abuse reporting form",
            "privacy reporting form",
            "security reporting website",
            "abuse reporting website",
            "privacy reporting website",
            "security reporting site",
            "abuse reporting site",
            "privacy reporting site",
            "security reporting page",
            "abuse reporting page",
            "privacy reporting page",
            "security reporting web page",
            "abuse reporting web page",
            "privacy reporting web page",
            "security reporting webform",
            "abuse reporting webform",
            "privacy reporting webform",
            "security reporting web form",
            "abuse reporting web form",
            "privacy reporting web form",
            "javascript"
          ],
          "references": [
            "https://cert.microsoft.com"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Arek-BTC",
            "id": "212764",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_212764/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "email": 10,
            "IPv4": 5,
            "FileHash-SHA256": 1674,
            "URL": 317,
            "SSLCertFingerprint": 4,
            "CIDR": 65,
            "IPv6": 8,
            "FileHash-SHA1": 139,
            "domain": 125,
            "FileHash-MD5": 159,
            "hostname": 50,
            "CVE": 1
          },
          "indicator_count": 2557,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 126,
          "modified_text": "530 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "66d44926ed517bfd841682d8",
          "name": "http://virusshare.com/ efa9780d188576155d1594ca9f6bf06217427be0fb8ccddb6165a675f247fce8 KAV_py2.exe ip 71.105.224.116",
          "description": "http://virusshare.com/hashes/VirusShare_00010.md5\nhttp://virusshare.com/hashes/VirusShare_00002.md5\nhttp://virusshare.com/hashes/VirusShare_00003.md5\nhttp://virusshare.com/hashes/VirusShare_00008.md5\nhttp://virusshare.com/\nhttp://virusshare.com/hashes/VirusShare_00001.md5\nhttp://virusshare.com/hashes/VirusShare_00009.md5\nhttp://virusshare.com/hashes/VirusShare_00006.md5\nhttp://virusshare.com/hashes/VirusShare_00005.md5\nhttp://virusshare.com/hashes/VirusShare_00007.md5\nhttp://virusshare.com/hashes/VirusShare_00004.md5",
          "modified": "2024-12-17T14:35:28.860000",
          "created": "2024-09-01T10:59:50.034000",
          "tags": [
            "foundrndate",
            "klucz publiczny",
            "intel",
            "ms windows",
            "pe32",
            "ascii text",
            "crlf line",
            "type md5",
            "process name",
            "ascii",
            "pe32 executable",
            "sha1",
            "richhash",
            "expiration",
            "url https",
            "url http",
            "no expiration",
            "hostname",
            "filehashsha1",
            "filehashsha256",
            "sha256",
            "imphash",
            "segoe ui",
            "emoji",
            "arial",
            "roboto",
            "helvetica neue",
            "noto",
            "apple color",
            "symbol",
            "noto color",
            "liberation sans",
            "firefox",
            "london",
            "ttl3600"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Arek-BTC",
            "id": "212764",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_212764/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 875,
            "hostname": 213,
            "domain": 82,
            "IPv4": 15,
            "FileHash-MD5": 127,
            "FileHash-SHA1": 123,
            "FileHash-SHA256": 308,
            "IPv6": 2,
            "CVE": 2
          },
          "indicator_count": 1747,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 125,
          "modified_text": "530 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "66d3e0652560b9b323d0e5a0",
          "name": "validator/site/nu-script.js at main \u00b7 validator/validator \u00b7 GitHub   128.30.52.73",
          "description": "GitHub is the world's most advanced open source platform, powered by artificial intelligence (AI), and you can now access all your code, repositories, users, issues and other data at any time.",
          "modified": "2024-12-17T14:35:28.041000",
          "created": "2024-09-01T03:32:53.350000",
          "tags": [
            "sign",
            "github",
            "github copilot",
            "search",
            "validator",
            "code issues",
            "pull",
            "wiki security",
            "skip",
            "navigation",
            "write",
            "star",
            "footer",
            "valid",
            "algorithm",
            "thumbprint",
            "serial number",
            "from",
            "valid from",
            "pca issuer",
            "microsoft root",
            "signing ca",
            "microsoft code",
            "class"
          ],
          "references": [
            "https://github.com/validator/validator/blob/main/site/nu-script.js"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Arek-BTC",
            "id": "212764",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_212764/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA1": 29,
            "URL": 140,
            "FileHash-MD5": 21,
            "email": 1,
            "FileHash-SHA256": 74,
            "domain": 17,
            "hostname": 42,
            "IPv4": 8,
            "CVE": 1
          },
          "indicator_count": 333,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 124,
          "modified_text": "530 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "66abb26614baf2276d4892cf",
          "name": "kir.pl  KIR: Hub technologiczny. Dostawca cyfrowych rozwiaza\u0144 dla firm, bank\u00f3w oraz klient\u00f3w indywidualnych.Kluczowy podmiot infrastruktury polskiego systemu p\u0142atniczego.",
          "description": "934f391c263fe1fb3bca071898f45579c905280f 2022-09-14 *.kir.pl 00e172c1ce91876722ae2faa48df5b17a32c3be9 2021-10-01 *.kir.pl 9bebeaa50825eb88fc9e8899955d821620ac6fe6 2020-10-07 *.kir.pl 4b885389c599abdaa45e11481924600738a5ea37 2020-03-18 *.kir.pl 3b969974bc6f07b8a45dd0ee89f9ee64b862571b 2019-08-14 *.kir.pl 6a69a861061c5e768070c68576127237a43de9c2\nZobacz ca\u0142y artyku\u0142 Elixir malware 08.07.2024 Statystyki system\u00f3w rozliczeniowych KIR w czerwcu 2024 r. W czerwcu przetworzyli\u015bmy w systemie szkodliwe oprogramowanie Elixir 177,85 mln transakcji o warto\u015bci 722,96 mld z\u0142. Zamiast tego w Express Elixir rozliczyli\u015bmy 44,95 mln przelew\u00f3w natychmiastowych o warto\u015bci 21,65 mld z\u0142. Zobacz ca\u0142y artyku\u0142 Elixir malware 10.06.2024 Statystyki system\u00f3w rozliczeniowych KIR w maju 2024 r. W maju 2024 r. przetworzyli\u015bmy w systemie szkodliwe oprogramowanie Elixir 185,8 mln transakcji o warto\u015bci 744,83 mld z\u0142.",
          "modified": "2024-11-02T18:45:44.304000",
          "created": "2024-08-01T16:05:58.828000",
          "tags": [
            "epodpis z",
            "express elixir",
            "dostp",
            "zobacz",
            "polityka",
            "czytaj wicej",
            "zobacz cay",
            "elixir",
            "kir w",
            "mobilny",
            "banki",
            "teraz"
          ],
          "references": [
            "http://Kir.pl/",
            "https://kir.pl/",
            "https://www.kir.pl/",
            "http://www.kir.pl/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Elixir",
              "display_name": "Elixir",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 13,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Arek-BTC",
            "id": "212764",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_212764/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 45,
            "URL": 415,
            "hostname": 187,
            "FileHash-MD5": 64,
            "FileHash-SHA1": 36,
            "FileHash-SHA256": 102,
            "IPv4": 53,
            "email": 4,
            "SSLCertFingerprint": 9,
            "CVE": 2,
            "CIDR": 1
          },
          "indicator_count": 918,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 125,
          "modified_text": "575 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "66a27442c3dd6aa438bd8d67",
          "name": "http://crd.gov.pl/wzor/",
          "description": "sha256-b92ea141ea59c122b8425068c06465c8d6ff86571aa02e5a6f55d3dd8096d583\nnaruszony_redirector_witryny_z_kodu_charcode\n, \ncve_2014_6332",
          "modified": "2024-10-25T19:56:22.489000",
          "created": "2024-07-25T15:50:26.922000",
          "tags": [
            "bezterminowo",
            "adres url",
            "plikhashsha256",
            "email biuro",
            "nazwa hosta",
            "nazwa",
            "filehashsha1",
            "sha1",
            "filehashmd5",
            "md5 z",
            "sha1 dla"
          ],
          "references": [
            ""
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 11,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Arek-BTC",
            "id": "212764",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_212764/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 773,
            "FileHash-SHA256": 802,
            "email": 14,
            "hostname": 121,
            "domain": 65,
            "FileHash-MD5": 253,
            "FileHash-SHA1": 256,
            "IPv4": 9,
            "YARA": 1,
            "CVE": 12
          },
          "indicator_count": 2306,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 127,
          "modified_text": "583 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "669b8fa0d807682987a33cb7",
          "name": "https://ssl-proxy.my-addr.org/myaddrproxy.php/https/www.vgt.pl",
          "description": "Here is the full text of the X509 certificate, signed by Google LLC, which is published on 1 July 2014:. \u00c2\u00a31.4m.. (\u20ac2.3m)",
          "modified": "2024-10-20T00:48:20.932000",
          "created": "2024-07-20T10:21:20.075000",
          "tags": [
            "submission",
            "globalsign root",
            "ougwny urzd",
            "oglobalsign",
            "ssdeep",
            "magic",
            "trid der",
            "file size",
            "history first",
            "analysis",
            "win32 exe",
            "narzdzie nokia",
            "best bb5",
            "aaaaa"
          ],
          "references": [
            "https://viz.greynoise.io/analysis/399e2039-4568-4e91-95b1-56e4de"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 9,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Arek-BTC",
            "id": "212764",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_212764/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 18,
            "FileHash-SHA1": 19,
            "FileHash-SHA256": 92,
            "IPv6": 6,
            "hostname": 111,
            "domain": 60,
            "URL": 638,
            "YARA": 1,
            "FileHash-IMPHASH": 1,
            "email": 4,
            "IPv4": 6,
            "CVE": 2
          },
          "indicator_count": 958,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 126,
          "modified_text": "589 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "668bfcb0b48a387b9d2c8562",
          "name": "Ministerstwo Finans\u00f3w - Portal Gov.pl",
          "description": "Pliki cookie zosta\u0142y ju\u017c zapisane i wydrukowane.\n5852be629358e18160c5483bfc8c9f0023b974565f2d59ce7f4497cc734b4ecd 30 pa\u017a 2022 b8a2476b55132fdf0531d6cd48126b759dc08a8f5b019917b62373e536a0b8c9 26 pa\u017a 2022 2700fbe4001e27ba55d72841817b0b9454954b496f21e4259c88919027172694 6 wrze\u015bnia 2022 r. 91da570586b7c04e3012215469ed8b8c5aa036068cc48ba7a7ac0d8cce34290e 5 wrze\u015bnia 2022 r. 1757d8363e28b35b9e29c44d0bc87e2a03d90ca50dadd780924528e0a13d49e1 31 sierpnia 2022 r. fe5744ed48406b90eae1747aab5386645406ad61cdc629ebc7ded97aa099ae28 30 lipca 2022 r. c730bac7a1da3b6263e7672c85cb4deb229c45479bd64bc7194a9a8bb16b8cb6 16 lipca 2022 r. 177b428ac63ad3b6c606ed11b33c9fc4d79f6ff5e6b3ac3ee849f1e2d1f2c903 16 lipca 2022 r. a35121637b79b7d926b63afceae409fdb35c14ad5431ecd199179622e1711ca6",
          "modified": "2024-10-17T05:28:49.118000",
          "created": "2024-07-08T14:50:24.496000",
          "tags": [
            "polskiej",
            "przejd",
            "usugi dla",
            "logowanie",
            "profil zaufany",
            "skarbowa",
            "zobacz",
            "ksef",
            "zastpca szefa",
            "stopka",
            "rada",
            "inquest labs",
            "vba project",
            "vbaproject",
            "kopiuj md5",
            "kopiuj sha1",
            "skopiuj sha256",
            "sha1",
            "sha256",
            "typ tekst",
            "opis tekst",
            "ascii md5",
            "rozmiar",
            "typ dane",
            "pdf c",
            "text c",
            "ounizeto",
            "validation ca",
            "sha2",
            "odigicert inc",
            "cusa",
            "authority",
            "rsa ca",
            "cncertum domain",
            "cngeotrust ev",
            "oglobalsign",
            "unicode",
            "z bom",
            "crlf",
            "rgba",
            "dane obrazu",
            "tekst utf8",
            "v2 dokument",
            "dane",
            "dokument html",
            "jpeg",
            "skrt",
            "opis",
            "poczenie",
            "wifi",
            "start",
            "nazwa typ",
            "md5 nazwa",
            "procesu plik",
            "pe32",
            "intel",
            "pejzasz",
            "ms windows",
            "plik dokumentu",
            "nie c",
            "win32 exe",
            "crt.sh",
            "ct",
            "certificate transparency",
            "certificate search",
            "ssl certificate",
            "sectigo",
            "comodo ca",
            "comodo",
            "tls web",
            "criteria id",
            "647257375",
            "timestamp entry",
            "log operator",
            "log url",
            "google https",
            "ca mechanism",
            "provider status",
            "error",
            "log id",
            "647257567",
            "summary leaf",
            "sectigo https",
            "expired",
            "certificate",
            "lets",
            "key usage",
            "identifier",
            "551852229",
            "digicert https",
            "479894151",
            "479896285",
            "tylne drzwi",
            "win32",
            "imphasz",
            "wirustotal",
            "emaile",
            "emaile pnewell",
            "emaile khunter",
            "emaile eooshea",
            "emaile regadmin",
            "microsoft excel",
            "wed jan",
            "submission",
            "vhash",
            "ssdeep",
            "file type",
            "ms excel",
            "xls magic",
            "file v2",
            "document",
            "number",
            "algorithm",
            "certum",
            "unizeto",
            "warszawa",
            "31915086",
            "nitro pro",
            "nitro sign",
            "nitro",
            "nitro pdf",
            "primopdf",
            "pdfs",
            "business nitro",
            "pdf nitro",
            "pdf pro",
            "desktop",
            "premium",
            "service",
            "ja3s",
            "mnie",
            "sysv",
            "lsb executable",
            "eabi4 version",
            "msb executable",
            "mips",
            "mipsi version",
            "trojan",
            "imphash",
            "pehash",
            "name type",
            "md5 process",
            "fault",
            "header",
            "bezterminowo",
            "adres url",
            "nazwa hosta",
            "ipv4",
            "ccie asnas8075",
            "nie mona",
            "trojandropper",
            "url skryptw",
            "domeny a",
            "kliknij",
            "prbka skrt",
            "uwzgldnij",
            "nieobecny",
            "procesu",
            "ascii z",
            "ascii bez",
            "mirai",
            "win32virut",
            "procesu zastpy",
            "tekst ascii",
            "z terminatorami"
          ],
          "references": [
            "http://www.mf.gov.pl/tutaj/a./p/body/html",
            "https://www.mf.gov.pl/tutaj/a./p/body/html",
            "https://mdec.nelreports.net/api/report?cat=mdocs",
            "https://crt.sh/?id=647257375",
            "https://crt.sh/?id=647257567",
            "https://crt.sh/?id=551852229",
            "https://crt.sh/?id=479894151",
            "https://crt.sh/?id=479896285",
            "https://crt.sh/?d=49659844",
            "https://crt.sh/?id=31915086",
            "http://www.primopdf.com/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Mirai",
              "display_name": "Mirai",
              "target": null
            },
            {
              "id": "e74755ff8b4927e257566302296e17e5d28cef17a6daf287cda9e63ce6c6f575 ELF :Mirai- MALWARE GH\\ [Trj] 23 pa\u017a 2016 bf0f346f4a51732e31d88eb47dcac82c7f7ed973312926819f1e1023b9c51121 23 pa\u017a 2016 5a92b73f354d54b9",
              "display_name": "e74755ff8b4927e257566302296e17e5d28cef17a6daf287cda9e63ce6c6f575 ELF :Mirai- MALWARE GH\\ [Trj] 23 pa\u017a 2016 bf0f346f4a51732e31d88eb47dcac82c7f7ed973312926819f1e1023b9c51121 23 pa\u017a 2016 5a92b73f354d54b9",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1056",
              "name": "Input Capture",
              "display_name": "T1056 - Input Capture"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 127,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Arek-BTC",
            "id": "212764",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_212764/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 627,
            "email": 41,
            "FileHash-SHA1": 1565,
            "FileHash-SHA256": 5520,
            "URL": 1821,
            "FileHash-MD5": 1861,
            "SSLCertFingerprint": 10,
            "domain": 167,
            "IPv4": 31,
            "YARA": 7,
            "CVE": 7
          },
          "indicator_count": 11657,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 128,
          "modified_text": "591 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "http://Kir.pl/",
        "",
        "https://github.com/validator/validator/blob/main/site/nu-script.js",
        "https://mdec.nelreports.net/api/report?cat=mdocs",
        "https://crt.sh/?id=479894151",
        "https://crt.sh/?id=551852229",
        "http://www.kir.pl/",
        "https://crt.sh/?d=49659844",
        "https://crt.sh/?id=479896285",
        "https://viz.greynoise.io/analysis/399e2039-4568-4e91-95b1-56e4de",
        "https://www.kir.pl/",
        "https://www.mf.gov.pl/tutaj/a./p/body/html",
        "https://crt.sh/?id=31915086",
        "http://www.primopdf.com/",
        "https://crt.sh/?id=647257375",
        "https://cert.microsoft.com",
        "http://www.mf.gov.pl/tutaj/a./p/body/html",
        "https://kir.pl/",
        "https://crt.sh/?id=647257567"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 0
        },
        "other": {
          "adversary": [],
          "malware_families": [
            "E74755ff8b4927e257566302296e17e5d28cef17a6daf287cda9e63ce6c6f575 elf :mirai- malware gh\\ [trj] 23 pa\u017a 2016 bf0f346f4a51732e31d88eb47dcac82c7f7ed973312926819f1e1023b9c51121 23 pa\u017a 2016 5a92b73f354d54b9",
            "Mirai",
            "Elixir"
          ],
          "industries": [],
          "unique_indicators": 30612
        }
      }
    },
    "false_positive": [],
    "alexa": "http://www.alexa.com/siteinfo/wap.ac",
    "whois": "http://whois.domaintools.com/wap.ac",
    "domain": "wap.ac",
    "hostname": "Unavailable"
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 9,
  "pulses": [
    {
      "id": "69ff110180abb3beb39c04bc",
      "name": "Microsoft security reporting portal CREATED 2 YEARS AGO MODIFIED 1 YEAR AGO by Arek-BTC [2024 and older]",
      "description": "",
      "modified": "2026-05-09T12:20:54.997000",
      "created": "2026-05-09T10:48:33.286000",
      "tags": [
        "microsoft",
        "security",
        "reporting",
        "portal",
        "abuse",
        "privacy",
        "infringement",
        "trademark",
        "trademark infringement",
        "abuse report",
        "privacy report",
        "security report",
        "security reporting",
        "abuse reporting",
        "privacy reporting",
        "security reporting portal",
        "abuse reporting portal",
        "privacy reporting portal",
        "security reporting form",
        "abuse reporting form",
        "privacy reporting form",
        "security reporting website",
        "abuse reporting website",
        "privacy reporting website",
        "security reporting site",
        "abuse reporting site",
        "privacy reporting site",
        "security reporting page",
        "abuse reporting page",
        "privacy reporting page",
        "security reporting web page",
        "abuse reporting web page",
        "privacy reporting web page",
        "security reporting webform",
        "abuse reporting webform",
        "privacy reporting webform",
        "security reporting web form",
        "abuse reporting web form",
        "privacy reporting web form",
        "javascript"
      ],
      "references": [
        "https://cert.microsoft.com"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": "66e9c5a4cc3b60c38e6381b8",
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "email": 10,
        "IPv4": 46,
        "FileHash-SHA256": 1684,
        "URL": 337,
        "SSLCertFingerprint": 4,
        "CIDR": 65,
        "IPv6": 8,
        "FileHash-SHA1": 149,
        "domain": 130,
        "FileHash-MD5": 169,
        "hostname": 152,
        "CVE": 3
      },
      "indicator_count": 2757,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 66,
      "modified_text": "22 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "66d45dab14a189645153e8a6",
      "name": "Reverse WHOIS results for vgt.pl ( GANG VGT)",
      "description": "",
      "modified": "2024-12-17T14:47:57",
      "created": "2024-09-01T12:27:23.777000",
      "tags": [
        "ipv4 domain",
        "ipv4 url",
        "domain",
        "sha1",
        "sha256",
        "pehash",
        "vhash",
        "ssdeep"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Arek-BTC",
        "id": "212764",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_212764/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 1286,
        "FileHash-SHA1": 1286,
        "FileHash-SHA256": 2722,
        "URL": 4729,
        "domain": 1909,
        "hostname": 2082,
        "IPv4": 97,
        "CVE": 4,
        "YARA": 1
      },
      "indicator_count": 14116,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 127,
      "modified_text": "530 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "66e9c5a4cc3b60c38e6381b8",
      "name": "Microsoft security reporting portal",
      "description": "130.0/11.5/12.3/13.4.6.7.8.1.2/14.9. 0/16.25/17..",
      "modified": "2024-12-17T14:35:36.786000",
      "created": "2024-09-17T18:08:36.835000",
      "tags": [
        "microsoft",
        "security",
        "reporting",
        "portal",
        "abuse",
        "privacy",
        "infringement",
        "trademark",
        "trademark infringement",
        "abuse report",
        "privacy report",
        "security report",
        "security reporting",
        "abuse reporting",
        "privacy reporting",
        "security reporting portal",
        "abuse reporting portal",
        "privacy reporting portal",
        "security reporting form",
        "abuse reporting form",
        "privacy reporting form",
        "security reporting website",
        "abuse reporting website",
        "privacy reporting website",
        "security reporting site",
        "abuse reporting site",
        "privacy reporting site",
        "security reporting page",
        "abuse reporting page",
        "privacy reporting page",
        "security reporting web page",
        "abuse reporting web page",
        "privacy reporting web page",
        "security reporting webform",
        "abuse reporting webform",
        "privacy reporting webform",
        "security reporting web form",
        "abuse reporting web form",
        "privacy reporting web form",
        "javascript"
      ],
      "references": [
        "https://cert.microsoft.com"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Arek-BTC",
        "id": "212764",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_212764/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "email": 10,
        "IPv4": 5,
        "FileHash-SHA256": 1674,
        "URL": 317,
        "SSLCertFingerprint": 4,
        "CIDR": 65,
        "IPv6": 8,
        "FileHash-SHA1": 139,
        "domain": 125,
        "FileHash-MD5": 159,
        "hostname": 50,
        "CVE": 1
      },
      "indicator_count": 2557,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 126,
      "modified_text": "530 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "66d44926ed517bfd841682d8",
      "name": "http://virusshare.com/ efa9780d188576155d1594ca9f6bf06217427be0fb8ccddb6165a675f247fce8 KAV_py2.exe ip 71.105.224.116",
      "description": "http://virusshare.com/hashes/VirusShare_00010.md5\nhttp://virusshare.com/hashes/VirusShare_00002.md5\nhttp://virusshare.com/hashes/VirusShare_00003.md5\nhttp://virusshare.com/hashes/VirusShare_00008.md5\nhttp://virusshare.com/\nhttp://virusshare.com/hashes/VirusShare_00001.md5\nhttp://virusshare.com/hashes/VirusShare_00009.md5\nhttp://virusshare.com/hashes/VirusShare_00006.md5\nhttp://virusshare.com/hashes/VirusShare_00005.md5\nhttp://virusshare.com/hashes/VirusShare_00007.md5\nhttp://virusshare.com/hashes/VirusShare_00004.md5",
      "modified": "2024-12-17T14:35:28.860000",
      "created": "2024-09-01T10:59:50.034000",
      "tags": [
        "foundrndate",
        "klucz publiczny",
        "intel",
        "ms windows",
        "pe32",
        "ascii text",
        "crlf line",
        "type md5",
        "process name",
        "ascii",
        "pe32 executable",
        "sha1",
        "richhash",
        "expiration",
        "url https",
        "url http",
        "no expiration",
        "hostname",
        "filehashsha1",
        "filehashsha256",
        "sha256",
        "imphash",
        "segoe ui",
        "emoji",
        "arial",
        "roboto",
        "helvetica neue",
        "noto",
        "apple color",
        "symbol",
        "noto color",
        "liberation sans",
        "firefox",
        "london",
        "ttl3600"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Arek-BTC",
        "id": "212764",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_212764/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 875,
        "hostname": 213,
        "domain": 82,
        "IPv4": 15,
        "FileHash-MD5": 127,
        "FileHash-SHA1": 123,
        "FileHash-SHA256": 308,
        "IPv6": 2,
        "CVE": 2
      },
      "indicator_count": 1747,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 125,
      "modified_text": "530 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "66d3e0652560b9b323d0e5a0",
      "name": "validator/site/nu-script.js at main \u00b7 validator/validator \u00b7 GitHub   128.30.52.73",
      "description": "GitHub is the world's most advanced open source platform, powered by artificial intelligence (AI), and you can now access all your code, repositories, users, issues and other data at any time.",
      "modified": "2024-12-17T14:35:28.041000",
      "created": "2024-09-01T03:32:53.350000",
      "tags": [
        "sign",
        "github",
        "github copilot",
        "search",
        "validator",
        "code issues",
        "pull",
        "wiki security",
        "skip",
        "navigation",
        "write",
        "star",
        "footer",
        "valid",
        "algorithm",
        "thumbprint",
        "serial number",
        "from",
        "valid from",
        "pca issuer",
        "microsoft root",
        "signing ca",
        "microsoft code",
        "class"
      ],
      "references": [
        "https://github.com/validator/validator/blob/main/site/nu-script.js"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Arek-BTC",
        "id": "212764",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_212764/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA1": 29,
        "URL": 140,
        "FileHash-MD5": 21,
        "email": 1,
        "FileHash-SHA256": 74,
        "domain": 17,
        "hostname": 42,
        "IPv4": 8,
        "CVE": 1
      },
      "indicator_count": 333,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 124,
      "modified_text": "530 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "66abb26614baf2276d4892cf",
      "name": "kir.pl  KIR: Hub technologiczny. Dostawca cyfrowych rozwiaza\u0144 dla firm, bank\u00f3w oraz klient\u00f3w indywidualnych.Kluczowy podmiot infrastruktury polskiego systemu p\u0142atniczego.",
      "description": "934f391c263fe1fb3bca071898f45579c905280f 2022-09-14 *.kir.pl 00e172c1ce91876722ae2faa48df5b17a32c3be9 2021-10-01 *.kir.pl 9bebeaa50825eb88fc9e8899955d821620ac6fe6 2020-10-07 *.kir.pl 4b885389c599abdaa45e11481924600738a5ea37 2020-03-18 *.kir.pl 3b969974bc6f07b8a45dd0ee89f9ee64b862571b 2019-08-14 *.kir.pl 6a69a861061c5e768070c68576127237a43de9c2\nZobacz ca\u0142y artyku\u0142 Elixir malware 08.07.2024 Statystyki system\u00f3w rozliczeniowych KIR w czerwcu 2024 r. W czerwcu przetworzyli\u015bmy w systemie szkodliwe oprogramowanie Elixir 177,85 mln transakcji o warto\u015bci 722,96 mld z\u0142. Zamiast tego w Express Elixir rozliczyli\u015bmy 44,95 mln przelew\u00f3w natychmiastowych o warto\u015bci 21,65 mld z\u0142. Zobacz ca\u0142y artyku\u0142 Elixir malware 10.06.2024 Statystyki system\u00f3w rozliczeniowych KIR w maju 2024 r. W maju 2024 r. przetworzyli\u015bmy w systemie szkodliwe oprogramowanie Elixir 185,8 mln transakcji o warto\u015bci 744,83 mld z\u0142.",
      "modified": "2024-11-02T18:45:44.304000",
      "created": "2024-08-01T16:05:58.828000",
      "tags": [
        "epodpis z",
        "express elixir",
        "dostp",
        "zobacz",
        "polityka",
        "czytaj wicej",
        "zobacz cay",
        "elixir",
        "kir w",
        "mobilny",
        "banki",
        "teraz"
      ],
      "references": [
        "http://Kir.pl/",
        "https://kir.pl/",
        "https://www.kir.pl/",
        "http://www.kir.pl/"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Elixir",
          "display_name": "Elixir",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 13,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Arek-BTC",
        "id": "212764",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_212764/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 45,
        "URL": 415,
        "hostname": 187,
        "FileHash-MD5": 64,
        "FileHash-SHA1": 36,
        "FileHash-SHA256": 102,
        "IPv4": 53,
        "email": 4,
        "SSLCertFingerprint": 9,
        "CVE": 2,
        "CIDR": 1
      },
      "indicator_count": 918,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 125,
      "modified_text": "575 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "66a27442c3dd6aa438bd8d67",
      "name": "http://crd.gov.pl/wzor/",
      "description": "sha256-b92ea141ea59c122b8425068c06465c8d6ff86571aa02e5a6f55d3dd8096d583\nnaruszony_redirector_witryny_z_kodu_charcode\n, \ncve_2014_6332",
      "modified": "2024-10-25T19:56:22.489000",
      "created": "2024-07-25T15:50:26.922000",
      "tags": [
        "bezterminowo",
        "adres url",
        "plikhashsha256",
        "email biuro",
        "nazwa hosta",
        "nazwa",
        "filehashsha1",
        "sha1",
        "filehashmd5",
        "md5 z",
        "sha1 dla"
      ],
      "references": [
        ""
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 11,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Arek-BTC",
        "id": "212764",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_212764/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 773,
        "FileHash-SHA256": 802,
        "email": 14,
        "hostname": 121,
        "domain": 65,
        "FileHash-MD5": 253,
        "FileHash-SHA1": 256,
        "IPv4": 9,
        "YARA": 1,
        "CVE": 12
      },
      "indicator_count": 2306,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 127,
      "modified_text": "583 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "669b8fa0d807682987a33cb7",
      "name": "https://ssl-proxy.my-addr.org/myaddrproxy.php/https/www.vgt.pl",
      "description": "Here is the full text of the X509 certificate, signed by Google LLC, which is published on 1 July 2014:. \u00c2\u00a31.4m.. (\u20ac2.3m)",
      "modified": "2024-10-20T00:48:20.932000",
      "created": "2024-07-20T10:21:20.075000",
      "tags": [
        "submission",
        "globalsign root",
        "ougwny urzd",
        "oglobalsign",
        "ssdeep",
        "magic",
        "trid der",
        "file size",
        "history first",
        "analysis",
        "win32 exe",
        "narzdzie nokia",
        "best bb5",
        "aaaaa"
      ],
      "references": [
        "https://viz.greynoise.io/analysis/399e2039-4568-4e91-95b1-56e4de"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 9,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Arek-BTC",
        "id": "212764",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_212764/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 18,
        "FileHash-SHA1": 19,
        "FileHash-SHA256": 92,
        "IPv6": 6,
        "hostname": 111,
        "domain": 60,
        "URL": 638,
        "YARA": 1,
        "FileHash-IMPHASH": 1,
        "email": 4,
        "IPv4": 6,
        "CVE": 2
      },
      "indicator_count": 958,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 126,
      "modified_text": "589 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "668bfcb0b48a387b9d2c8562",
      "name": "Ministerstwo Finans\u00f3w - Portal Gov.pl",
      "description": "Pliki cookie zosta\u0142y ju\u017c zapisane i wydrukowane.\n5852be629358e18160c5483bfc8c9f0023b974565f2d59ce7f4497cc734b4ecd 30 pa\u017a 2022 b8a2476b55132fdf0531d6cd48126b759dc08a8f5b019917b62373e536a0b8c9 26 pa\u017a 2022 2700fbe4001e27ba55d72841817b0b9454954b496f21e4259c88919027172694 6 wrze\u015bnia 2022 r. 91da570586b7c04e3012215469ed8b8c5aa036068cc48ba7a7ac0d8cce34290e 5 wrze\u015bnia 2022 r. 1757d8363e28b35b9e29c44d0bc87e2a03d90ca50dadd780924528e0a13d49e1 31 sierpnia 2022 r. fe5744ed48406b90eae1747aab5386645406ad61cdc629ebc7ded97aa099ae28 30 lipca 2022 r. c730bac7a1da3b6263e7672c85cb4deb229c45479bd64bc7194a9a8bb16b8cb6 16 lipca 2022 r. 177b428ac63ad3b6c606ed11b33c9fc4d79f6ff5e6b3ac3ee849f1e2d1f2c903 16 lipca 2022 r. a35121637b79b7d926b63afceae409fdb35c14ad5431ecd199179622e1711ca6",
      "modified": "2024-10-17T05:28:49.118000",
      "created": "2024-07-08T14:50:24.496000",
      "tags": [
        "polskiej",
        "przejd",
        "usugi dla",
        "logowanie",
        "profil zaufany",
        "skarbowa",
        "zobacz",
        "ksef",
        "zastpca szefa",
        "stopka",
        "rada",
        "inquest labs",
        "vba project",
        "vbaproject",
        "kopiuj md5",
        "kopiuj sha1",
        "skopiuj sha256",
        "sha1",
        "sha256",
        "typ tekst",
        "opis tekst",
        "ascii md5",
        "rozmiar",
        "typ dane",
        "pdf c",
        "text c",
        "ounizeto",
        "validation ca",
        "sha2",
        "odigicert inc",
        "cusa",
        "authority",
        "rsa ca",
        "cncertum domain",
        "cngeotrust ev",
        "oglobalsign",
        "unicode",
        "z bom",
        "crlf",
        "rgba",
        "dane obrazu",
        "tekst utf8",
        "v2 dokument",
        "dane",
        "dokument html",
        "jpeg",
        "skrt",
        "opis",
        "poczenie",
        "wifi",
        "start",
        "nazwa typ",
        "md5 nazwa",
        "procesu plik",
        "pe32",
        "intel",
        "pejzasz",
        "ms windows",
        "plik dokumentu",
        "nie c",
        "win32 exe",
        "crt.sh",
        "ct",
        "certificate transparency",
        "certificate search",
        "ssl certificate",
        "sectigo",
        "comodo ca",
        "comodo",
        "tls web",
        "criteria id",
        "647257375",
        "timestamp entry",
        "log operator",
        "log url",
        "google https",
        "ca mechanism",
        "provider status",
        "error",
        "log id",
        "647257567",
        "summary leaf",
        "sectigo https",
        "expired",
        "certificate",
        "lets",
        "key usage",
        "identifier",
        "551852229",
        "digicert https",
        "479894151",
        "479896285",
        "tylne drzwi",
        "win32",
        "imphasz",
        "wirustotal",
        "emaile",
        "emaile pnewell",
        "emaile khunter",
        "emaile eooshea",
        "emaile regadmin",
        "microsoft excel",
        "wed jan",
        "submission",
        "vhash",
        "ssdeep",
        "file type",
        "ms excel",
        "xls magic",
        "file v2",
        "document",
        "number",
        "algorithm",
        "certum",
        "unizeto",
        "warszawa",
        "31915086",
        "nitro pro",
        "nitro sign",
        "nitro",
        "nitro pdf",
        "primopdf",
        "pdfs",
        "business nitro",
        "pdf nitro",
        "pdf pro",
        "desktop",
        "premium",
        "service",
        "ja3s",
        "mnie",
        "sysv",
        "lsb executable",
        "eabi4 version",
        "msb executable",
        "mips",
        "mipsi version",
        "trojan",
        "imphash",
        "pehash",
        "name type",
        "md5 process",
        "fault",
        "header",
        "bezterminowo",
        "adres url",
        "nazwa hosta",
        "ipv4",
        "ccie asnas8075",
        "nie mona",
        "trojandropper",
        "url skryptw",
        "domeny a",
        "kliknij",
        "prbka skrt",
        "uwzgldnij",
        "nieobecny",
        "procesu",
        "ascii z",
        "ascii bez",
        "mirai",
        "win32virut",
        "procesu zastpy",
        "tekst ascii",
        "z terminatorami"
      ],
      "references": [
        "http://www.mf.gov.pl/tutaj/a./p/body/html",
        "https://www.mf.gov.pl/tutaj/a./p/body/html",
        "https://mdec.nelreports.net/api/report?cat=mdocs",
        "https://crt.sh/?id=647257375",
        "https://crt.sh/?id=647257567",
        "https://crt.sh/?id=551852229",
        "https://crt.sh/?id=479894151",
        "https://crt.sh/?id=479896285",
        "https://crt.sh/?d=49659844",
        "https://crt.sh/?id=31915086",
        "http://www.primopdf.com/"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Mirai",
          "display_name": "Mirai",
          "target": null
        },
        {
          "id": "e74755ff8b4927e257566302296e17e5d28cef17a6daf287cda9e63ce6c6f575 ELF :Mirai- MALWARE GH\\ [Trj] 23 pa\u017a 2016 bf0f346f4a51732e31d88eb47dcac82c7f7ed973312926819f1e1023b9c51121 23 pa\u017a 2016 5a92b73f354d54b9",
          "display_name": "e74755ff8b4927e257566302296e17e5d28cef17a6daf287cda9e63ce6c6f575 ELF :Mirai- MALWARE GH\\ [Trj] 23 pa\u017a 2016 bf0f346f4a51732e31d88eb47dcac82c7f7ed973312926819f1e1023b9c51121 23 pa\u017a 2016 5a92b73f354d54b9",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1553",
          "name": "Subvert Trust Controls",
          "display_name": "T1553 - Subvert Trust Controls"
        },
        {
          "id": "T1056",
          "name": "Input Capture",
          "display_name": "T1056 - Input Capture"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 127,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Arek-BTC",
        "id": "212764",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_212764/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 627,
        "email": 41,
        "FileHash-SHA1": 1565,
        "FileHash-SHA256": 5520,
        "URL": 1821,
        "FileHash-MD5": 1861,
        "SSLCertFingerprint": 10,
        "domain": 167,
        "IPv4": 31,
        "YARA": 7,
        "CVE": 7
      },
      "indicator_count": 11657,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 128,
      "modified_text": "591 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "https://wap.ac/wp-signup.php",
    "type": "URL"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "https://wap.ac/wp-signup.php",
    "type": "URL",
    "found": false,
    "verdict": "clean",
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780276364.4953768
}