{
  "type": "URL",
  "indicator": "https://whois.arin.net/rest/org/SG-679",
  "general": {
    "sections": [
      "general",
      "url_list",
      "http_scans",
      "screenshot"
    ],
    "indicator": "https://whois.arin.net/rest/org/SG-679",
    "type": "url",
    "type_title": "URL",
    "validation": [
      {
        "source": "akamai",
        "message": "Akamai rank: #6937",
        "name": "Akamai Popular Domain"
      },
      {
        "source": "whitelist",
        "message": "Whitelisted domain arin.net",
        "name": "Whitelisted domain"
      },
      {
        "source": "majestic",
        "message": "Whitelisted domain arin.net",
        "name": "Whitelisted domain"
      }
    ],
    "base_indicator": {
      "id": 4286614719,
      "indicator": "https://whois.arin.net/rest/org/SG-679",
      "type": "URL",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 3,
      "pulses": [
        {
          "id": "69f2e790b5ca86510c384c2c",
          "name": "14.5k win[exe] comm, 14 ref, 89hxTrojans with ARINOPS -199.",
          "description": "[The following has been published on the website of the International Organization for the Prevention of Electronic Illness (IOC), which is based in the United States, and is subject to a security rev]\nCertificate before 8/20 expired. Client lost access to phone Aug 22-Sept 15 no reason given. Clients ADT alarm went of wehn sectigo cert expired Sept 8. Client went into Apple man in suit \"unlocked phone\" Sept 15. Was this a jailbreak?",
          "modified": "2026-05-30T05:18:49.034000",
          "created": "2026-04-30T05:24:32.866000",
          "tags": [
            "win32",
            "trojan",
            "united",
            "as393225",
            "mtb may",
            "mtb mar",
            "passive dns",
            "ip address",
            "backdoor",
            "mtb apr",
            "url analysis",
            "level",
            "title",
            "mirai",
            "orgtechhandle",
            "arin operations",
            "orgnochandle",
            "kassim",
            "oneill",
            "michael j",
            "nethandle",
            "net199",
            "net1990000",
            "arinops",
            "address range",
            "cidr",
            "network name",
            "allocation type",
            "whois server",
            "entity arinops",
            "handle",
            "key identifier",
            "x509v3 subject",
            "full name",
            "v3 serial",
            "number",
            "cus odigicert",
            "inc cndigicert",
            "global g2",
            "tls rsa",
            "sha256",
            "date"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Mirai",
              "display_name": "Mirai",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 1,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 215,
            "FileHash-SHA1": 178,
            "FileHash-SHA256": 594,
            "domain": 12,
            "CIDR": 60,
            "URL": 122,
            "hostname": 72,
            "email": 7,
            "CVE": 1
          },
          "indicator_count": 1261,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 67,
          "modified_text": "2 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "69f2e7933eca244995760f32",
          "name": "14.5k win[exe] comm, 14 ref, 89hxTrojans with ARINOPS -199.",
          "description": "[The following has been published on the website of the International Organization for the Prevention of Electronic Illness (IOC), which is based in the United States, and is subject to a security rev]\nCertificate before 8/20 expired. Client lost access to phone Aug 22-Sept 15 no reason given. Clients ADT alarm went of wehn sectigo cert expired Sept 8. Client went into Apple man in suit \"unlocked phone\" Sept 15. Was this a jailbreak?",
          "modified": "2026-05-30T05:18:49.034000",
          "created": "2026-04-30T05:24:35.619000",
          "tags": [
            "win32",
            "trojan",
            "united",
            "as393225",
            "mtb may",
            "mtb mar",
            "passive dns",
            "ip address",
            "backdoor",
            "mtb apr",
            "url analysis",
            "level",
            "title",
            "mirai",
            "orgtechhandle",
            "arin operations",
            "orgnochandle",
            "kassim",
            "oneill",
            "michael j",
            "nethandle",
            "net199",
            "net1990000",
            "arinops",
            "address range",
            "cidr",
            "network name",
            "allocation type",
            "whois server",
            "entity arinops",
            "handle",
            "key identifier",
            "x509v3 subject",
            "full name",
            "v3 serial",
            "number",
            "cus odigicert",
            "inc cndigicert",
            "global g2",
            "tls rsa",
            "sha256",
            "date"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Mirai",
              "display_name": "Mirai",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 152,
            "FileHash-SHA1": 153,
            "FileHash-SHA256": 495,
            "domain": 2,
            "CIDR": 1,
            "URL": 70,
            "hostname": 7,
            "email": 5
          },
          "indicator_count": 885,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 67,
          "modified_text": "2 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "69ca5d583057aaefed16789a",
          "name": "CAPE Sandbox- Stealc Config CNCs\thttp://170.130.55.38\\/ad23d4a47cfd4c13.php botnet\tnewbuild2",
          "description": "A complete list of details about who is registered on the Whois website:..1.0/16:30 GMT on 1 January 2019. (00:00 GMT).-1:<Pretext -- Stealc Config\nCNCs\thttp://170.130.55.38\\/ad23d4a47cfd4c13.php\nbotnet\tnewbuild2",
          "modified": "2026-04-29T11:26:13.615000",
          "created": "2026-03-30T11:24:08.053000",
          "tags": [
            "file size",
            "mwdb",
            "bazaar",
            "sha3384",
            "ssdeep",
            "file type",
            "default",
            "sha256",
            "sha1",
            "data",
            "info",
            "accept",
            "win64",
            "damage",
            "openssl",
            "shutdown",
            "direct",
            "explorer",
            "title",
            "payload",
            "rdap",
            "ip version",
            "address range",
            "cidr",
            "network name",
            "allocation type",
            "whois server",
            "entity sg679",
            "handle",
            "stealc config",
            "cncs http"
          ],
          "references": [
            "https://vtbehaviour.commondatastorage.googleapis.com/1ca8b15684a1143e38ef87f31d8a89c7b25a1107aeaf03d43ad9fd611c4a35ba_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1774869821&Signature=dm0pQf9ykZMucZEHHViqEfYFoBozAF57ZHYUPo3i79Fb6al02qn6AeYk%2FxR1vzLE4NQkG40Rm1LFUVN79w5CNETgwiRzCx%2BSpUCvPnYIv7E3SEmv5wZrhcuObW%2FE%2B1Ef7e53KrnREKePmmVmLYO34EXBewDpQF4DTIUvGnHdoQkf8pmNquGPuJZRRodaPAkoAEufbI%2BMk4zTqA%2BXbEP%2FpFBi5v30azilsKQ8R%2BLyJYHnYE"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 351,
            "URL": 392,
            "FileHash-MD5": 149,
            "FileHash-SHA1": 168,
            "FileHash-SHA256": 197,
            "email": 12,
            "hostname": 68,
            "CIDR": 4
          },
          "indicator_count": 1341,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 68,
          "modified_text": "33 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "https://vtbehaviour.commondatastorage.googleapis.com/1ca8b15684a1143e38ef87f31d8a89c7b25a1107aeaf03d43ad9fd611c4a35ba_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1774869821&Signature=dm0pQf9ykZMucZEHHViqEfYFoBozAF57ZHYUPo3i79Fb6al02qn6AeYk%2FxR1vzLE4NQkG40Rm1LFUVN79w5CNETgwiRzCx%2BSpUCvPnYIv7E3SEmv5wZrhcuObW%2FE%2B1Ef7e53KrnREKePmmVmLYO34EXBewDpQF4DTIUvGnHdoQkf8pmNquGPuJZRRodaPAkoAEufbI%2BMk4zTqA%2BXbEP%2FpFBi5v30azilsKQ8R%2BLyJYHnYE"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 0
        },
        "other": {
          "adversary": [],
          "malware_families": [
            "Mirai"
          ],
          "industries": [],
          "unique_indicators": 2083
        }
      }
    },
    "false_positive": [],
    "alexa": "http://www.alexa.com/siteinfo/arin.net",
    "whois": "http://whois.domaintools.com/arin.net",
    "domain": "arin.net",
    "hostname": "whois.arin.net"
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 3,
  "pulses": [
    {
      "id": "69f2e790b5ca86510c384c2c",
      "name": "14.5k win[exe] comm, 14 ref, 89hxTrojans with ARINOPS -199.",
      "description": "[The following has been published on the website of the International Organization for the Prevention of Electronic Illness (IOC), which is based in the United States, and is subject to a security rev]\nCertificate before 8/20 expired. Client lost access to phone Aug 22-Sept 15 no reason given. Clients ADT alarm went of wehn sectigo cert expired Sept 8. Client went into Apple man in suit \"unlocked phone\" Sept 15. Was this a jailbreak?",
      "modified": "2026-05-30T05:18:49.034000",
      "created": "2026-04-30T05:24:32.866000",
      "tags": [
        "win32",
        "trojan",
        "united",
        "as393225",
        "mtb may",
        "mtb mar",
        "passive dns",
        "ip address",
        "backdoor",
        "mtb apr",
        "url analysis",
        "level",
        "title",
        "mirai",
        "orgtechhandle",
        "arin operations",
        "orgnochandle",
        "kassim",
        "oneill",
        "michael j",
        "nethandle",
        "net199",
        "net1990000",
        "arinops",
        "address range",
        "cidr",
        "network name",
        "allocation type",
        "whois server",
        "entity arinops",
        "handle",
        "key identifier",
        "x509v3 subject",
        "full name",
        "v3 serial",
        "number",
        "cus odigicert",
        "inc cndigicert",
        "global g2",
        "tls rsa",
        "sha256",
        "date"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Mirai",
          "display_name": "Mirai",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 1,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 215,
        "FileHash-SHA1": 178,
        "FileHash-SHA256": 594,
        "domain": 12,
        "CIDR": 60,
        "URL": 122,
        "hostname": 72,
        "email": 7,
        "CVE": 1
      },
      "indicator_count": 1261,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 67,
      "modified_text": "2 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "69f2e7933eca244995760f32",
      "name": "14.5k win[exe] comm, 14 ref, 89hxTrojans with ARINOPS -199.",
      "description": "[The following has been published on the website of the International Organization for the Prevention of Electronic Illness (IOC), which is based in the United States, and is subject to a security rev]\nCertificate before 8/20 expired. Client lost access to phone Aug 22-Sept 15 no reason given. Clients ADT alarm went of wehn sectigo cert expired Sept 8. Client went into Apple man in suit \"unlocked phone\" Sept 15. Was this a jailbreak?",
      "modified": "2026-05-30T05:18:49.034000",
      "created": "2026-04-30T05:24:35.619000",
      "tags": [
        "win32",
        "trojan",
        "united",
        "as393225",
        "mtb may",
        "mtb mar",
        "passive dns",
        "ip address",
        "backdoor",
        "mtb apr",
        "url analysis",
        "level",
        "title",
        "mirai",
        "orgtechhandle",
        "arin operations",
        "orgnochandle",
        "kassim",
        "oneill",
        "michael j",
        "nethandle",
        "net199",
        "net1990000",
        "arinops",
        "address range",
        "cidr",
        "network name",
        "allocation type",
        "whois server",
        "entity arinops",
        "handle",
        "key identifier",
        "x509v3 subject",
        "full name",
        "v3 serial",
        "number",
        "cus odigicert",
        "inc cndigicert",
        "global g2",
        "tls rsa",
        "sha256",
        "date"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Mirai",
          "display_name": "Mirai",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 152,
        "FileHash-SHA1": 153,
        "FileHash-SHA256": 495,
        "domain": 2,
        "CIDR": 1,
        "URL": 70,
        "hostname": 7,
        "email": 5
      },
      "indicator_count": 885,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 67,
      "modified_text": "2 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "69ca5d583057aaefed16789a",
      "name": "CAPE Sandbox- Stealc Config CNCs\thttp://170.130.55.38\\/ad23d4a47cfd4c13.php botnet\tnewbuild2",
      "description": "A complete list of details about who is registered on the Whois website:..1.0/16:30 GMT on 1 January 2019. (00:00 GMT).-1:<Pretext -- Stealc Config\nCNCs\thttp://170.130.55.38\\/ad23d4a47cfd4c13.php\nbotnet\tnewbuild2",
      "modified": "2026-04-29T11:26:13.615000",
      "created": "2026-03-30T11:24:08.053000",
      "tags": [
        "file size",
        "mwdb",
        "bazaar",
        "sha3384",
        "ssdeep",
        "file type",
        "default",
        "sha256",
        "sha1",
        "data",
        "info",
        "accept",
        "win64",
        "damage",
        "openssl",
        "shutdown",
        "direct",
        "explorer",
        "title",
        "payload",
        "rdap",
        "ip version",
        "address range",
        "cidr",
        "network name",
        "allocation type",
        "whois server",
        "entity sg679",
        "handle",
        "stealc config",
        "cncs http"
      ],
      "references": [
        "https://vtbehaviour.commondatastorage.googleapis.com/1ca8b15684a1143e38ef87f31d8a89c7b25a1107aeaf03d43ad9fd611c4a35ba_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1774869821&Signature=dm0pQf9ykZMucZEHHViqEfYFoBozAF57ZHYUPo3i79Fb6al02qn6AeYk%2FxR1vzLE4NQkG40Rm1LFUVN79w5CNETgwiRzCx%2BSpUCvPnYIv7E3SEmv5wZrhcuObW%2FE%2B1Ef7e53KrnREKePmmVmLYO34EXBewDpQF4DTIUvGnHdoQkf8pmNquGPuJZRRodaPAkoAEufbI%2BMk4zTqA%2BXbEP%2FpFBi5v30azilsKQ8R%2BLyJYHnYE"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 1,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 351,
        "URL": 392,
        "FileHash-MD5": 149,
        "FileHash-SHA1": 168,
        "FileHash-SHA256": 197,
        "email": 12,
        "hostname": 68,
        "CIDR": 4
      },
      "indicator_count": 1341,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 68,
      "modified_text": "33 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "https://whois.arin.net/rest/org/SG-679",
    "type": "URL"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "https://whois.arin.net/rest/org/SG-679",
    "type": "URL",
    "found": false,
    "verdict": "clean",
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780347636.7243097
}