{
  "type": "URL",
  "indicator": "https://wolf.apptimemachine.com",
  "general": {
    "sections": [
      "general",
      "url_list",
      "http_scans",
      "screenshot"
    ],
    "indicator": "https://wolf.apptimemachine.com",
    "type": "url",
    "type_title": "URL",
    "validation": [],
    "base_indicator": {
      "id": 4156677461,
      "indicator": "https://wolf.apptimemachine.com",
      "type": "URL",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 2,
      "pulses": [
        {
          "id": "692e8cd886e0bb692e8a9d08",
          "name": "Blocker Ransomware affecting Apple and iCloud  | Injection",
          "description": "Wild! Hackers attack-ack-acking!\nThey\u2019re quite good. Persistent. Angry. \nIt\u2019s the same group of hackers.",
          "modified": "2026-01-01T06:01:02.583000",
          "created": "2025-12-02T06:53:12.823000",
          "tags": [
            "url https",
            "url http",
            "domain",
            "fh no",
            "ipv4",
            "united",
            "flag",
            "windir",
            "openurl c",
            "prefetch2",
            "analysis",
            "tor analysis",
            "dns requests",
            "domain address",
            "contacted hosts",
            "pattern match",
            "mitre att",
            "ck id",
            "ck matrix",
            "ascii text",
            "href",
            "network traffic",
            "general",
            "local",
            "click",
            "strings",
            "learn",
            "name tactics",
            "suspicious",
            "informative",
            "found",
            "command",
            "adversaries",
            "spawns",
            "defense evasion",
            "dynamicloader",
            "windows nt",
            "wow64",
            "khtml",
            "gecko",
            "write c",
            "unknown",
            "virtool",
            "write",
            "defender",
            "malware",
            "delete",
            "alerts",
            "backdoor",
            "high",
            "ip address",
            "t1045",
            "packing",
            "t1055",
            "injection",
            "t1060",
            "run keys",
            "startup",
            "folder",
            "t1119",
            "t1027",
            "tools",
            "families",
            "mirai",
            "indicator role",
            "active related",
            "hackers",
            "ahmann",
            "usual suspects"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "#VirTool:Win32/Obfuscator.ADB",
              "display_name": "#VirTool:Win32/Obfuscator.ADB",
              "target": "/malware/#VirTool:Win32/Obfuscator.ADB"
            },
            {
              "id": "Tofsee",
              "display_name": "Tofsee",
              "target": null
            },
            {
              "id": "Backdoor:Win32/Drixed",
              "display_name": "Backdoor:Win32/Drixed",
              "target": "/malware/Backdoor:Win32/Drixed"
            },
            {
              "id": "Mirai",
              "display_name": "Mirai",
              "target": null
            },
            {
              "id": "VirTool:Win32/Injector",
              "display_name": "VirTool:Win32/Injector",
              "target": "/malware/VirTool:Win32/Injector"
            },
            {
              "id": "Ransom:Win32/Blocker.NN!MTB",
              "display_name": "Ransom:Win32/Blocker.NN!MTB",
              "target": "/malware/Ransom:Win32/Blocker.NN!MTB"
            },
            {
              "id": "Unix.Trojan.Mirai-7135937-0",
              "display_name": "Unix.Trojan.Mirai-7135937-0",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1056",
              "name": "Input Capture",
              "display_name": "T1056 - Input Capture"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1069",
              "name": "Permission Groups Discovery",
              "display_name": "T1069 - Permission Groups Discovery"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1480",
              "name": "Execution Guardrails",
              "display_name": "T1480 - Execution Guardrails"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1113",
              "name": "Screen Capture",
              "display_name": "T1113 - Screen Capture"
            },
            {
              "id": "T1470",
              "name": "Obtain Device Cloud Backups",
              "display_name": "T1470 - Obtain Device Cloud Backups"
            },
            {
              "id": "T1045",
              "name": "Software Packing",
              "display_name": "T1045 - Software Packing"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1060",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1060 - Registry Run Keys / Startup Folder"
            },
            {
              "id": "T1066",
              "name": "Indicator Removal from Tools",
              "display_name": "T1066 - Indicator Removal from Tools"
            },
            {
              "id": "T1070",
              "name": "Indicator Removal on Host",
              "display_name": "T1070 - Indicator Removal on Host"
            },
            {
              "id": "T1119",
              "name": "Automated Collection",
              "display_name": "T1119 - Automated Collection"
            },
            {
              "id": "T1185",
              "name": "Man in the Browser",
              "display_name": "T1185 - Man in the Browser"
            },
            {
              "id": "T1204",
              "name": "User Execution",
              "display_name": "T1204 - User Execution"
            },
            {
              "id": "T1408",
              "name": "Disguise Root/Jailbreak Indicators",
              "display_name": "T1408 - Disguise Root/Jailbreak Indicators"
            },
            {
              "id": "T1562",
              "name": "Impair Defenses",
              "display_name": "T1562 - Impair Defenses"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1568",
              "name": "Dynamic Resolution",
              "display_name": "T1568 - Dynamic Resolution"
            },
            {
              "id": "T1583",
              "name": "Acquire Infrastructure",
              "display_name": "T1583 - Acquire Infrastructure"
            },
            {
              "id": "T1584",
              "name": "Compromise Infrastructure",
              "display_name": "T1584 - Compromise Infrastructure"
            },
            {
              "id": "T1054",
              "name": "Indicator Blocking",
              "display_name": "T1054 - Indicator Blocking"
            },
            {
              "id": "T1590.002",
              "name": "DNS",
              "display_name": "T1590.002 - DNS"
            },
            {
              "id": "T1210",
              "name": "Exploitation of Remote Services",
              "display_name": "T1210 - Exploitation of Remote Services"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 5,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Q.Vashti",
            "id": "337942",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 234,
            "FileHash-SHA1": 219,
            "FileHash-SHA256": 841,
            "URL": 2606,
            "domain": 298,
            "hostname": 772,
            "SSLCertFingerprint": 2,
            "CVE": 1
          },
          "indicator_count": 4973,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 138,
          "modified_text": "108 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "692e7870eb1d3db6241c7771",
          "name": "Apple iCloud Stealer  \u2022 Mirai",
          "description": "*Mirai - Absolutely adventurous attack! They don\u2019t forget. |\nObserved. Targeted iPhone  remotely attacked. RMS user? . Fully updated device. with only one iOS application downloaded. Chaerged iOS was powered on to research suspicious activity. \nThe phone was powered off after glitched. Reset itself ,  presents a new device , icons and apps changed. Passwords stolen. Barely noticeable side drive by. iCloud unavailable. Hackers are logging in frequently, I cannot change password. The cloud is not accessible. Device has some accounts with threat research on it. Hacker is wiping. Hackers are answering the phone. Phone does not ring for other team members. Much more. Device unlocked since 10/2024. Fixed , hacked repeatedly.\nUsed to examine hacker behavior. It\u2019s  pretty sad. The ability for this level of hacker to infect other devices around devices is high / risky. \n\nHosts contacted.",
          "modified": "2026-01-01T04:03:48.354000",
          "created": "2025-12-02T05:26:08.084000",
          "tags": [
            "no expiration",
            "url http",
            "url https",
            "iocs",
            "domain",
            "enter source",
            "url or",
            "urls",
            "url add",
            "http",
            "files domain",
            "files related",
            "related tags",
            "present dec",
            "present nov",
            "united",
            "ip address",
            "tpp wholesale",
            "pty ltd",
            "unknown soa",
            "passive dns",
            "ostname add",
            "files",
            "files ip",
            "address",
            "related nids",
            "files location",
            "australia flag",
            "gmt server",
            "unix",
            "gmt etag",
            "avast avg",
            "scans record",
            "value",
            "mirai",
            "ipv4",
            "reverse dns",
            "australia asn",
            "dns resolutions",
            "domains top",
            "level",
            "twitter",
            "present jun",
            "present oct",
            "present jul",
            "proxy error",
            "web address",
            "search",
            "apache",
            "next associated",
            "flag",
            "windir",
            "openurl c",
            "prefetch2",
            "analysis",
            "tor analysis",
            "dns requests",
            "domain address",
            "mtb oct",
            "toolbar",
            "ransom",
            "click",
            "yara detections",
            "alerts",
            "filehash",
            "md5 add",
            "pulse pulses",
            "av detections",
            "ids detections",
            "analysis date",
            "file score",
            "delphi",
            "dns query",
            "dyndns domain",
            "delphi alerts",
            "contacted",
            "pulses",
            "date june",
            "dynamicloader",
            "medium",
            "high",
            "yara rule",
            "write c",
            "win32",
            "entries",
            "write",
            "guard",
            "next",
            "code",
            "malware",
            "local",
            "unknown",
            "learn",
            "ck id",
            "name tactics",
            "suspicious",
            "informative",
            "command",
            "adversaries",
            "javascript",
            "spawns",
            "ck techniques",
            "initial access",
            "defense evasion",
            "ltd flag",
            "contacted hosts",
            "network related",
            "response risk",
            "mitre att",
            "detection",
            "detected",
            "external",
            "detected text",
            "general",
            "possible http",
            "xss attempt",
            "local source",
            "possible",
            "sinkhole cookie",
            "value snkz",
            "forbidden tls",
            "virtool",
            "copy",
            "geodata",
            "hacking",
            "cloud id"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Mirai",
              "display_name": "Mirai",
              "target": null
            },
            {
              "id": "Unix.Trojan.Mirai-7135937-0",
              "display_name": "Unix.Trojan.Mirai-7135937-0",
              "target": null
            },
            {
              "id": "Ransom:Win32/Blocker.NN!MTB",
              "display_name": "Ransom:Win32/Blocker.NN!MTB",
              "target": "/malware/Ransom:Win32/Blocker.NN!MTB"
            },
            {
              "id": "VirTool:Win32/Injector.CL",
              "display_name": "VirTool:Win32/Injector.CL",
              "target": "/malware/VirTool:Win32/Injector.CL"
            }
          ],
          "attack_ids": [
            {
              "id": "T1045",
              "name": "Software Packing",
              "display_name": "T1045 - Software Packing"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1060",
              "name": "Registry Run Keys / Startup Folder",
              "display_name": "T1060 - Registry Run Keys / Startup Folder"
            },
            {
              "id": "T1119",
              "name": "Automated Collection",
              "display_name": "T1119 - Automated Collection"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1069",
              "name": "Permission Groups Discovery",
              "display_name": "T1069 - Permission Groups Discovery"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1480",
              "name": "Execution Guardrails",
              "display_name": "T1480 - Execution Guardrails"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1568",
              "name": "Dynamic Resolution",
              "display_name": "T1568 - Dynamic Resolution"
            },
            {
              "id": "T1583",
              "name": "Acquire Infrastructure",
              "display_name": "T1583 - Acquire Infrastructure"
            },
            {
              "id": "T1204",
              "name": "User Execution",
              "display_name": "T1204 - User Execution"
            },
            {
              "id": "T1562",
              "name": "Impair Defenses",
              "display_name": "T1562 - Impair Defenses"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1584.005",
              "name": "Botnet",
              "display_name": "T1584.005 - Botnet"
            },
            {
              "id": "T1185",
              "name": "Man in the Browser",
              "display_name": "T1185 - Man in the Browser"
            },
            {
              "id": "T1066",
              "name": "Indicator Removal from Tools",
              "display_name": "T1066 - Indicator Removal from Tools"
            },
            {
              "id": "T1408",
              "name": "Disguise Root/Jailbreak Indicators",
              "display_name": "T1408 - Disguise Root/Jailbreak Indicators"
            },
            {
              "id": "T1070",
              "name": "Indicator Removal on Host",
              "display_name": "T1070 - Indicator Removal on Host"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 4,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Q.Vashti",
            "id": "337942",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 1647,
            "FileHash-MD5": 196,
            "FileHash-SHA1": 187,
            "FileHash-SHA256": 450,
            "domain": 211,
            "hostname": 779
          },
          "indicator_count": 3470,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 137,
          "modified_text": "108 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        }
      ],
      "references": [],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 0
        },
        "other": {
          "adversary": [],
          "malware_families": [
            "Virtool:win32/injector.cl",
            "Backdoor:win32/drixed",
            "Ransom:win32/blocker.nn!mtb",
            "Unix.trojan.mirai-7135937-0",
            "Tofsee",
            "#virtool:win32/obfuscator.adb",
            "Mirai",
            "Virtool:win32/injector"
          ],
          "industries": [],
          "unique_indicators": 7902
        }
      }
    },
    "false_positive": [],
    "alexa": "http://www.alexa.com/siteinfo/apptimemachine.com",
    "whois": "http://whois.domaintools.com/apptimemachine.com",
    "domain": "apptimemachine.com",
    "hostname": "wolf.apptimemachine.com"
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 2,
  "pulses": [
    {
      "id": "692e8cd886e0bb692e8a9d08",
      "name": "Blocker Ransomware affecting Apple and iCloud  | Injection",
      "description": "Wild! Hackers attack-ack-acking!\nThey\u2019re quite good. Persistent. Angry. \nIt\u2019s the same group of hackers.",
      "modified": "2026-01-01T06:01:02.583000",
      "created": "2025-12-02T06:53:12.823000",
      "tags": [
        "url https",
        "url http",
        "domain",
        "fh no",
        "ipv4",
        "united",
        "flag",
        "windir",
        "openurl c",
        "prefetch2",
        "analysis",
        "tor analysis",
        "dns requests",
        "domain address",
        "contacted hosts",
        "pattern match",
        "mitre att",
        "ck id",
        "ck matrix",
        "ascii text",
        "href",
        "network traffic",
        "general",
        "local",
        "click",
        "strings",
        "learn",
        "name tactics",
        "suspicious",
        "informative",
        "found",
        "command",
        "adversaries",
        "spawns",
        "defense evasion",
        "dynamicloader",
        "windows nt",
        "wow64",
        "khtml",
        "gecko",
        "write c",
        "unknown",
        "virtool",
        "write",
        "defender",
        "malware",
        "delete",
        "alerts",
        "backdoor",
        "high",
        "ip address",
        "t1045",
        "packing",
        "t1055",
        "injection",
        "t1060",
        "run keys",
        "startup",
        "folder",
        "t1119",
        "t1027",
        "tools",
        "families",
        "mirai",
        "indicator role",
        "active related",
        "hackers",
        "ahmann",
        "usual suspects"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "#VirTool:Win32/Obfuscator.ADB",
          "display_name": "#VirTool:Win32/Obfuscator.ADB",
          "target": "/malware/#VirTool:Win32/Obfuscator.ADB"
        },
        {
          "id": "Tofsee",
          "display_name": "Tofsee",
          "target": null
        },
        {
          "id": "Backdoor:Win32/Drixed",
          "display_name": "Backdoor:Win32/Drixed",
          "target": "/malware/Backdoor:Win32/Drixed"
        },
        {
          "id": "Mirai",
          "display_name": "Mirai",
          "target": null
        },
        {
          "id": "VirTool:Win32/Injector",
          "display_name": "VirTool:Win32/Injector",
          "target": "/malware/VirTool:Win32/Injector"
        },
        {
          "id": "Ransom:Win32/Blocker.NN!MTB",
          "display_name": "Ransom:Win32/Blocker.NN!MTB",
          "target": "/malware/Ransom:Win32/Blocker.NN!MTB"
        },
        {
          "id": "Unix.Trojan.Mirai-7135937-0",
          "display_name": "Unix.Trojan.Mirai-7135937-0",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1056",
          "name": "Input Capture",
          "display_name": "T1056 - Input Capture"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1069",
          "name": "Permission Groups Discovery",
          "display_name": "T1069 - Permission Groups Discovery"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1480",
          "name": "Execution Guardrails",
          "display_name": "T1480 - Execution Guardrails"
        },
        {
          "id": "T1553",
          "name": "Subvert Trust Controls",
          "display_name": "T1553 - Subvert Trust Controls"
        },
        {
          "id": "T1113",
          "name": "Screen Capture",
          "display_name": "T1113 - Screen Capture"
        },
        {
          "id": "T1470",
          "name": "Obtain Device Cloud Backups",
          "display_name": "T1470 - Obtain Device Cloud Backups"
        },
        {
          "id": "T1045",
          "name": "Software Packing",
          "display_name": "T1045 - Software Packing"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1060",
          "name": "Registry Run Keys / Startup Folder",
          "display_name": "T1060 - Registry Run Keys / Startup Folder"
        },
        {
          "id": "T1066",
          "name": "Indicator Removal from Tools",
          "display_name": "T1066 - Indicator Removal from Tools"
        },
        {
          "id": "T1070",
          "name": "Indicator Removal on Host",
          "display_name": "T1070 - Indicator Removal on Host"
        },
        {
          "id": "T1119",
          "name": "Automated Collection",
          "display_name": "T1119 - Automated Collection"
        },
        {
          "id": "T1185",
          "name": "Man in the Browser",
          "display_name": "T1185 - Man in the Browser"
        },
        {
          "id": "T1204",
          "name": "User Execution",
          "display_name": "T1204 - User Execution"
        },
        {
          "id": "T1408",
          "name": "Disguise Root/Jailbreak Indicators",
          "display_name": "T1408 - Disguise Root/Jailbreak Indicators"
        },
        {
          "id": "T1562",
          "name": "Impair Defenses",
          "display_name": "T1562 - Impair Defenses"
        },
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        },
        {
          "id": "T1568",
          "name": "Dynamic Resolution",
          "display_name": "T1568 - Dynamic Resolution"
        },
        {
          "id": "T1583",
          "name": "Acquire Infrastructure",
          "display_name": "T1583 - Acquire Infrastructure"
        },
        {
          "id": "T1584",
          "name": "Compromise Infrastructure",
          "display_name": "T1584 - Compromise Infrastructure"
        },
        {
          "id": "T1054",
          "name": "Indicator Blocking",
          "display_name": "T1054 - Indicator Blocking"
        },
        {
          "id": "T1590.002",
          "name": "DNS",
          "display_name": "T1590.002 - DNS"
        },
        {
          "id": "T1210",
          "name": "Exploitation of Remote Services",
          "display_name": "T1210 - Exploitation of Remote Services"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 5,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Q.Vashti",
        "id": "337942",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 234,
        "FileHash-SHA1": 219,
        "FileHash-SHA256": 841,
        "URL": 2606,
        "domain": 298,
        "hostname": 772,
        "SSLCertFingerprint": 2,
        "CVE": 1
      },
      "indicator_count": 4973,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 138,
      "modified_text": "108 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "692e7870eb1d3db6241c7771",
      "name": "Apple iCloud Stealer  \u2022 Mirai",
      "description": "*Mirai - Absolutely adventurous attack! They don\u2019t forget. |\nObserved. Targeted iPhone  remotely attacked. RMS user? . Fully updated device. with only one iOS application downloaded. Chaerged iOS was powered on to research suspicious activity. \nThe phone was powered off after glitched. Reset itself ,  presents a new device , icons and apps changed. Passwords stolen. Barely noticeable side drive by. iCloud unavailable. Hackers are logging in frequently, I cannot change password. The cloud is not accessible. Device has some accounts with threat research on it. Hacker is wiping. Hackers are answering the phone. Phone does not ring for other team members. Much more. Device unlocked since 10/2024. Fixed , hacked repeatedly.\nUsed to examine hacker behavior. It\u2019s  pretty sad. The ability for this level of hacker to infect other devices around devices is high / risky. \n\nHosts contacted.",
      "modified": "2026-01-01T04:03:48.354000",
      "created": "2025-12-02T05:26:08.084000",
      "tags": [
        "no expiration",
        "url http",
        "url https",
        "iocs",
        "domain",
        "enter source",
        "url or",
        "urls",
        "url add",
        "http",
        "files domain",
        "files related",
        "related tags",
        "present dec",
        "present nov",
        "united",
        "ip address",
        "tpp wholesale",
        "pty ltd",
        "unknown soa",
        "passive dns",
        "ostname add",
        "files",
        "files ip",
        "address",
        "related nids",
        "files location",
        "australia flag",
        "gmt server",
        "unix",
        "gmt etag",
        "avast avg",
        "scans record",
        "value",
        "mirai",
        "ipv4",
        "reverse dns",
        "australia asn",
        "dns resolutions",
        "domains top",
        "level",
        "twitter",
        "present jun",
        "present oct",
        "present jul",
        "proxy error",
        "web address",
        "search",
        "apache",
        "next associated",
        "flag",
        "windir",
        "openurl c",
        "prefetch2",
        "analysis",
        "tor analysis",
        "dns requests",
        "domain address",
        "mtb oct",
        "toolbar",
        "ransom",
        "click",
        "yara detections",
        "alerts",
        "filehash",
        "md5 add",
        "pulse pulses",
        "av detections",
        "ids detections",
        "analysis date",
        "file score",
        "delphi",
        "dns query",
        "dyndns domain",
        "delphi alerts",
        "contacted",
        "pulses",
        "date june",
        "dynamicloader",
        "medium",
        "high",
        "yara rule",
        "write c",
        "win32",
        "entries",
        "write",
        "guard",
        "next",
        "code",
        "malware",
        "local",
        "unknown",
        "learn",
        "ck id",
        "name tactics",
        "suspicious",
        "informative",
        "command",
        "adversaries",
        "javascript",
        "spawns",
        "ck techniques",
        "initial access",
        "defense evasion",
        "ltd flag",
        "contacted hosts",
        "network related",
        "response risk",
        "mitre att",
        "detection",
        "detected",
        "external",
        "detected text",
        "general",
        "possible http",
        "xss attempt",
        "local source",
        "possible",
        "sinkhole cookie",
        "value snkz",
        "forbidden tls",
        "virtool",
        "copy",
        "geodata",
        "hacking",
        "cloud id"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Mirai",
          "display_name": "Mirai",
          "target": null
        },
        {
          "id": "Unix.Trojan.Mirai-7135937-0",
          "display_name": "Unix.Trojan.Mirai-7135937-0",
          "target": null
        },
        {
          "id": "Ransom:Win32/Blocker.NN!MTB",
          "display_name": "Ransom:Win32/Blocker.NN!MTB",
          "target": "/malware/Ransom:Win32/Blocker.NN!MTB"
        },
        {
          "id": "VirTool:Win32/Injector.CL",
          "display_name": "VirTool:Win32/Injector.CL",
          "target": "/malware/VirTool:Win32/Injector.CL"
        }
      ],
      "attack_ids": [
        {
          "id": "T1045",
          "name": "Software Packing",
          "display_name": "T1045 - Software Packing"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1060",
          "name": "Registry Run Keys / Startup Folder",
          "display_name": "T1060 - Registry Run Keys / Startup Folder"
        },
        {
          "id": "T1119",
          "name": "Automated Collection",
          "display_name": "T1119 - Automated Collection"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1069",
          "name": "Permission Groups Discovery",
          "display_name": "T1069 - Permission Groups Discovery"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1480",
          "name": "Execution Guardrails",
          "display_name": "T1480 - Execution Guardrails"
        },
        {
          "id": "T1553",
          "name": "Subvert Trust Controls",
          "display_name": "T1553 - Subvert Trust Controls"
        },
        {
          "id": "T1568",
          "name": "Dynamic Resolution",
          "display_name": "T1568 - Dynamic Resolution"
        },
        {
          "id": "T1583",
          "name": "Acquire Infrastructure",
          "display_name": "T1583 - Acquire Infrastructure"
        },
        {
          "id": "T1204",
          "name": "User Execution",
          "display_name": "T1204 - User Execution"
        },
        {
          "id": "T1562",
          "name": "Impair Defenses",
          "display_name": "T1562 - Impair Defenses"
        },
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        },
        {
          "id": "T1584.005",
          "name": "Botnet",
          "display_name": "T1584.005 - Botnet"
        },
        {
          "id": "T1185",
          "name": "Man in the Browser",
          "display_name": "T1185 - Man in the Browser"
        },
        {
          "id": "T1066",
          "name": "Indicator Removal from Tools",
          "display_name": "T1066 - Indicator Removal from Tools"
        },
        {
          "id": "T1408",
          "name": "Disguise Root/Jailbreak Indicators",
          "display_name": "T1408 - Disguise Root/Jailbreak Indicators"
        },
        {
          "id": "T1070",
          "name": "Indicator Removal on Host",
          "display_name": "T1070 - Indicator Removal on Host"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 4,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Q.Vashti",
        "id": "337942",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 1647,
        "FileHash-MD5": 196,
        "FileHash-SHA1": 187,
        "FileHash-SHA256": 450,
        "domain": 211,
        "hostname": 779
      },
      "indicator_count": 3470,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 137,
      "modified_text": "108 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "https://wolf.apptimemachine.com",
    "type": "URL"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "https://wolf.apptimemachine.com",
    "type": "URL",
    "found": false,
    "verdict": "clean",
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1776631554.448331
}