{
  "type": "URL",
  "indicator": "https://ww16.this.group",
  "general": {
    "sections": [
      "general",
      "url_list",
      "http_scans",
      "screenshot"
    ],
    "indicator": "https://ww16.this.group",
    "type": "url",
    "type_title": "URL",
    "validation": [],
    "base_indicator": {
      "id": 3415708717,
      "indicator": "https://ww16.this.group",
      "type": "URL",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 12,
      "pulses": [
        {
          "id": "65708beba2ba8bcfb1d10237",
          "name": "hostkey - Industroyer&ReduceRight",
          "description": "",
          "modified": "2023-12-06T14:57:47.430000",
          "created": "2023-12-06T14:57:47.430000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 3,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 304,
            "hostname": 563,
            "domain": 407,
            "URL": 1776,
            "FileHash-SHA1": 2
          },
          "indicator_count": 3052,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "865 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "65708aa1dca4e6c505e4fc9e",
          "name": "Botnet c&c",
          "description": "",
          "modified": "2023-12-06T14:52:16.286000",
          "created": "2023-12-06T14:52:16.286000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 214,
            "hostname": 334,
            "URL": 1182,
            "FileHash-SHA256": 33
          },
          "indicator_count": 1763,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "865 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "64407a3c423306cfb9d66c6d",
          "name": "https://ads.twitter.com/?ref=gl-tw-tw-twitter-advertise0",
          "description": "",
          "modified": "2023-04-19T23:33:16.257000",
          "created": "2023-04-19T23:33:16.257000",
          "tags": [
            "zarma"
          ],
          "references": [
            "https://hybrid-analysis.com/sample/98d509ee5c88d85c96e401cf9a599a9bed2799101079f99e7e4ae974131ebcc1/643e852b401612eba8065bbb"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1480",
              "name": "Execution Guardrails",
              "display_name": "T1480 - Execution Guardrails"
            },
            {
              "id": "T1497",
              "name": "Virtualization/Sandbox Evasion",
              "display_name": "T1497 - Virtualization/Sandbox Evasion"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1555",
              "name": "Credentials from Password Stores",
              "display_name": "T1555 - Credentials from Password Stores"
            },
            {
              "id": "T1574",
              "name": "Hijack Execution Flow",
              "display_name": "T1574 - Hijack Execution Flow"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 5,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "callmeDoris",
            "id": "205385",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 178,
            "hostname": 612,
            "URL": 1892,
            "email": 4,
            "IPv4": 5,
            "FileHash-SHA256": 63,
            "FileHash-MD5": 59,
            "FileHash-SHA1": 58
          },
          "indicator_count": 2871,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 92,
          "modified_text": "1096 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "642620d51d298e5a95b15599",
          "name": "api.3f94642a.js via source of twitter login page using edge browser latest version 111.",
          "description": "WebpackChunk_Twitter-responsive-web=webpack chunks, as well as its own webpack, to create a single \"bundle\" for all of the sites.",
          "modified": "2023-03-31T00:06:55.719000",
          "created": "2023-03-30T23:52:53.828000",
          "tags": [
            "malware",
            "vxstream",
            "trojan",
            "ansi",
            "memoryfile scan",
            "scalarfield",
            "linkedfield",
            "runtime data",
            "requiredfield",
            "throw",
            "user",
            "apiuser",
            "error",
            "path",
            "slice",
            "date",
            "suspicious",
            "unknown",
            "stats",
            "bouncer",
            "hybrid",
            "model",
            "close",
            "click",
            "general",
            "strings",
            "malicious",
            "qakbot"
          ],
          "references": [
            "https://hybrid-analysis.com/sample/31ab3088c37fe023e4e38296f7083905a64aa3b77c94735815f89906418d2926/642613dabe4297d3b60d91be",
            "twitter.com/i/flow/login"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1012",
              "name": "Query Registry",
              "display_name": "T1012 - Query Registry"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1056",
              "name": "Input Capture",
              "display_name": "T1056 - Input Capture"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1113",
              "name": "Screen Capture",
              "display_name": "T1113 - Screen Capture"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1546",
              "name": "Event Triggered Execution",
              "display_name": "T1546 - Event Triggered Execution"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1562",
              "name": "Impair Defenses",
              "display_name": "T1562 - Impair Defenses"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            },
            {
              "id": "T1614",
              "name": "System Location Discovery",
              "display_name": "T1614 - System Location Discovery"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 6,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "callmeDoris",
            "id": "205385",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 322,
            "hostname": 61,
            "domain": 105,
            "FileHash-SHA256": 24,
            "FileHash-MD5": 11,
            "FileHash-SHA1": 2
          },
          "indicator_count": 525,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 90,
          "modified_text": "1116 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "63a3b9aaaca8891186e6f7a2",
          "name": "vt errors on edge 21 dec 2022",
          "description": "var n-i,n-n, r.test, is a new type of webpack, which uses a set of rules to store data in the form of a single address, or code.",
          "modified": "2023-01-21T00:01:41.590000",
          "created": "2022-12-22T01:58:02.495000",
          "tags": [
            "eaca",
            "eace",
            "iaca",
            "iace",
            "boolean",
            "object",
            "path",
            "aacf",
            "customevent",
            "string",
            "span",
            "error",
            "code",
            "virustotal",
            "date",
            "null",
            "contact",
            "blank",
            "close",
            "twitter",
            "unknown",
            "download",
            "this",
            "easy",
            "desktop",
            "body",
            "requires",
            "footer",
            "refresh",
            "patch",
            "write",
            "cobalt strike",
            "shell",
            "zero",
            "harmless",
            "main",
            "aalfe",
            "getclass",
            "copy",
            "iframe",
            "divi",
            "roboto",
            "insert",
            "template",
            "class",
            "void",
            "form",
            "back",
            "ransomware",
            "trace",
            "comment",
            "tools",
            "premium",
            "bufferwriter",
            "bufferreader",
            "array",
            "typeerror",
            "vtuibutton",
            "number",
            "typeof o",
            "urls",
            "please",
            "javascript",
            "https://www.virustotal.com/gui/vt-ui-sw-installer.e0eb1a1e08d651",
            "https://www.virustotal.com/gui/main.900e36f7a852b9863014.js"
          ],
          "references": [
            "https://www.virustotal.com/gui/vt-ui-sw-installer.e0eb1a1e08d6512ba355.js/ Depreciated",
            "https://www.virustotal.com/gui/main.900e36f7a852b9863014.js"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "BufferReader",
              "display_name": "BufferReader",
              "target": null
            },
            {
              "id": "BufferWriter",
              "display_name": "BufferWriter",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1568",
              "name": "Dynamic Resolution",
              "display_name": "T1568 - Dynamic Resolution"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 11,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "callmeDoris",
            "id": "205385",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 1051,
            "FileHash-SHA256": 204,
            "hostname": 275,
            "domain": 212,
            "CVE": 1,
            "FileHash-MD5": 1,
            "FileHash-SHA1": 1
          },
          "indicator_count": 1745,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 92,
          "modified_text": "1185 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "626a8a564da0d5b27dc02619",
          "name": "App By Web",
          "description": "Israeli malware hosting",
          "modified": "2022-05-28T00:03:46.141000",
          "created": "2022-04-28T12:36:38.103000",
          "tags": [
            "hebrew",
            "truetype",
            "woff2",
            "woff",
            "body",
            "fh5cooffcanvas",
            "function",
            "click",
            "main menu",
            "superfish var",
            "parallax",
            "offcanvas",
            "mobile menu",
            "animations var",
            "mstouchaction",
            "superfish menu",
            "plugin",
            "copyright",
            "joel birch",
            "dual",
            "fill",
            "touchaction",
            "y position",
            "hoverintent",
            "brian cherne",
            "param",
            "threshold",
            "mit license",
            "or selector",
            "author",
            "1parseint",
            "mark dalgleish",
            "http",
            "webkitopacity",
            "webkit",
            "khtmlopacity",
            "khtml",
            "typeof d",
            "error",
            "this",
            "caleb troughton",
            "typeof f",
            "adapter",
            "bootstrap",
            "javascript",
            "typeof c",
            "twitter",
            "focus",
            "azaz",
            "including",
            "this software",
            "but not",
            "limited to",
            "terms of",
            "open",
            "bsd license",
            "redistribution",
            "redistributions",
            "neither",
            "direct",
            "gc",
            "regexp",
            "typeof b",
            "pseudo",
            "child",
            "array",
            "width",
            "sufeffxa0",
            "class",
            "null",
            "date",
            "accept",
            "boolean",
            "modernizr",
            "custom build",
            "build",
            "afunction",
            "cfunction",
            "typeerror",
            "object",
            "documenttouch",
            "websocket",
            "string",
            "silk",
            "script",
            "arial",
            "edge",
            "iframe",
            "promise",
            "void",
            "android",
            "trident",
            "embed",
            "meta",
            "roboto",
            "term",
            "\u05d4\u05d6\u05de\u05e0\u05ea \u05de\u05d5\u05e0\u05d9\u05ea",
            "wtaxi",
            "wapp",
            "app by web ltd",
            "03-5115656",
            "03-5109109",
            "+97235115656",
            "\u05de\u05e2\u05e8\u05db\u05d5\u05ea \u05d4\u05e1\u05e2\u05d9\u05dd",
            "\u05db\u05e8\u05d8\u05d9\u05e1 \u05d0\u05e9\u05e8\u05d0\u05d9 \u05d1\u05de\u05d5\u05e0\u05d9\u05ea",
            "web ltd",
            "reserved"
          ],
          "references": [
            "xfe-URL-appbyweb.net-stix2-2.1-export.json",
            "http://appbyweb.net/AppByWeb",
            "https://partner.googleadservices.com/gampad/cookie.js?domain=appbyweb.net&callback=_gfp_s_&client=ca-pub-2581829468247892",
            "https://pagead2.googlesyndication.com/pagead/managed/js/adsense/m202204200101/show_ads_impl_fy2019.js",
            "http://appbyweb.net/AppByWeb/js/modernizr-2.6.2.min.js",
            "http://appbyweb.net/AppByWeb/js/jquery.min.js",
            "http://appbyweb.net/AppByWeb/js/jquery.easing.1.3.js",
            "http://appbyweb.net/AppByWeb/js/bootstrap.min.js",
            "http://appbyweb.net/AppByWeb/js/jquery.waypoints.min.js",
            "http://appbyweb.net/AppByWeb/js/jquery.stellar.min.js",
            "http://appbyweb.net/AppByWeb/js/hoverIntent.js",
            "http://appbyweb.net/AppByWeb/js/superfish.js",
            "http://appbyweb.net/AppByWeb/js/main.js",
            "https://files.appbyweb.net/Fonts/OpenSansHebrew/font.css",
            "https://googleads.g.doubleclick.net/pagead/ads?client=ca-pub-2581829468247892&output=html&adk=1812271804&adf=3025194257&lmt=1651149220&plat=16%3A8388608%2C17%3A32%2C24%3A32%2C25%3A32%2C32%3A32&format=0x0&url=http%3A%2F%2Fappbyweb.net%2FAppByWeb%2F&ea=0&pra=5&wgl=1&dt=1651149220376&bpp=1&bdt=121&idt=18&shv=r20220425&mjsv=m202204200101&ptt=9&saldr=aa&abxe=1&cookie=ID%3De83d6067a4dac5b6-229192c549d200d1%3AT%3D1651148802%3ART%3D1651148802%3AS%3DALNI_MZSt9utXhYBHAIH9xwQp72WuxQxTw&nras=1&correlator=1655793633284&"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Gc",
              "display_name": "Gc",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 8,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "adjadex1@gmail.com",
            "id": "187163",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 1554,
            "hostname": 533,
            "domain": 211,
            "FileHash-SHA256": 199
          },
          "indicator_count": 2497,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 69,
          "modified_text": "1423 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6266e98d7f3281e3039a7773",
          "name": "Dynadot.com&Webuzo &#8211; Multiuser Hosting Control Panel",
          "description": "Web Hosting Control Panel Webuzo is a web hosting platform which helps you manage your cloud or dedicated server, while offering the tools you need to develop and test your web applications and websites.",
          "modified": "2022-05-25T00:04:03.622000",
          "created": "2022-04-25T18:33:49.551000",
          "tags": [
            "20px",
            "webkitkeyframes",
            "45deg",
            "180deg",
            "5deg",
            "free",
            "10deg",
            "90deg",
            "font awesome",
            "2000px00",
            "flex",
            "mega",
            "contact",
            "form",
            "code",
            "typebutton",
            "typesubmit",
            "typesearch",
            "ff3834",
            "ff7133",
            "important",
            "ffffff",
            "theme name",
            "theme uri",
            "sitepad team",
            "import",
            "model",
            "number",
            "string",
            "copyright",
            "date",
            "closure library",
            "xdfunction",
            "cdfunction",
            "ddfunction",
            "bded",
            "kefunction",
            "click",
            "null",
            "pagelayersetup",
            "class",
            "show",
            "width",
            "setup",
            "error",
            "already setup",
            "false",
            "scroll",
            "body",
            "desktop",
            "trigger",
            "span",
            "window",
            "close",
            "jquery",
            "this",
            "bubble",
            "sticky",
            "facebook",
            "value",
            "foundation",
            "migrate",
            "backcompat",
            "quirks mode",
            "typeof f",
            "html",
            "regexp",
            "typeof e",
            "typeof t",
            "attr",
            "pseudo",
            "child",
            "function",
            "typeof module",
            "webuzo",
            "control panel",
            "apps",
            "multi user",
            "subscribe",
            "noc noc",
            "providers",
            "resellers",
            "website owners",
            "web hosting",
            "apache",
            "python",
            "easy",
            "payment"
          ],
          "references": [
            "https://www.webuzo.com/",
            "xfe-URL-Webuzo.com-stix2-2.1-export.json",
            "xfe-URL-dynadot.com-stix2-2.1-export.json",
            "https://www.webuzo.com/site-inc/js/jquery/jquery.js?ver=1.12.4",
            "https://www.webuzo.com/site-inc/js/jquery/jquery-migrate.min.js?ver=1.4.1",
            "https://www.webuzo.com/site-data/plugins/pagelayer-pro/js/givejs.php?give=pagelayer-frontend.js%2Cnivo-lightbox.min.js%2Cwow.min.js%2Cjquery-numerator.js%2CsimpleParallax.min.js%2Cowl.carousel.min.js&premium=%2Cchart.min.js%2Cpremium-frontend.js%2Cshuffle.min.js&ver=1.6.7",
            "https://www.googletagmanager.com/gtag/js?id=UA-128076350-1",
            "https://www.webuzo.com/sitepad-data/themes/ui/style.css?ver=5.1.6",
            "https://www.webuzo.com/site-data/plugins/pagelayer-pro/css/givecss.php?give=pagelayer-frontend.css%2Cnivo-lightbox.css%2Canimate.min.css%2Cowl.carousel.min.css%2Cowl.theme.default.min.css%2Cfont-awesome5.min.css&premium=%2Cpremium-frontend.css&ver=1.6.7"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1218",
              "name": "Signed Binary Proxy Execution",
              "display_name": "T1218 - Signed Binary Proxy Execution"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 7,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "adjadex1@gmail.com",
            "id": "187163",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 1527,
            "hostname": 411,
            "FileHash-SHA256": 219,
            "domain": 583
          },
          "indicator_count": 2740,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 70,
          "modified_text": "1426 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "62634f4db80546374654f4c4",
          "name": "frantech.ca - malware",
          "description": "T,t.F, t.f, is written in the same place as the following:t, d. F, has been added to the end of the document, as well as its own propertyDescriptor.",
          "modified": "2022-05-22T00:01:01.264000",
          "created": "2022-04-23T00:58:53.444000",
          "tags": [
            "overview",
            "typeof symbol",
            "error",
            "typeerror",
            "object",
            "typeof t",
            "string",
            "typeof e",
            "function",
            "array",
            "promise",
            "date",
            "target",
            "class",
            "path",
            "back",
            "bounce",
            "this",
            "iframe",
            "null",
            "0x105684",
            "0xb66229",
            "0xb9b329",
            "0x3eed40",
            "0x2923e0",
            "cookie",
            "0x1d2d25",
            "0x2d6b",
            "0x538ea5",
            "0x240c1a",
            "push",
            "shift",
            "open"
          ],
          "references": [
            "xfe-URL-https___my.frantech.ca_-stix2-2.1-export.json",
            "xfe-URL-frantech.ca-stix2-2.1-export.json",
            "https://my.frantech.ca/templates/lagom/assets/js/lagom-app.min.js?v=1.4.3",
            "https://my.frantech.ca/templates/lagom/assets/js/whmcs-custom.min.js?v=1.4.3"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 5,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "adjadex1@gmail.com",
            "id": "187163",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 757,
            "hostname": 498,
            "domain": 311,
            "FileHash-SHA256": 21
          },
          "indicator_count": 1587,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 68,
          "modified_text": "1429 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "624a5c500fa7977cca286c2a",
          "name": "Timelapse - malware",
          "description": "New RegExp(M) is a new type, and it will change any of the elements to the same type if you want to add them to your HTML page or add a third element.",
          "modified": "2022-05-04T02:03:41.813000",
          "created": "2022-04-04T02:47:44.169000",
          "tags": [
            "layoutmode",
            "outlayer",
            "item",
            "pluginclass",
            "evemitter",
            "namespace",
            "function",
            "fitrows",
            "vertical",
            "error",
            "lvcafrontend",
            "typeof",
            "this",
            "copyright",
            "caleb troughton",
            "mit license",
            "typeof f",
            "adapter",
            "typeof define",
            "typeof module",
            "html tags",
            "ox20trnf",
            "dom element",
            "regexp",
            "typeof e",
            "typeof t",
            "class",
            "attr",
            "pseudo",
            "child",
            "udc66udc67",
            "ud83d",
            "ufe0f",
            "ud83e",
            "udc68udc69",
            "udfcbudfcc",
            "u2640u2642",
            "source",
            "image",
            "ud83dudc6cud83c",
            "timelapse",
            "lighthouse",
            "imk internet",
            "marketing",
            "vimeo"
          ],
          "references": [
            "https://player.vimeo.com/video/51589652?h=836062ff9b&dnt=1&app_id=122963",
            "https://www.dubaioffplan-properties.com/wp-includes/js/wp-emoji-release.min.js?ver=5.9.2",
            "https://www.dubaioffplan-properties.com/wp-includes/js/jquery/jquery.min.js?ver=3.6.0",
            "https://www.dubaioffplan-properties.com/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.3.2",
            "https://www.dubaioffplan-properties.com/wp-content/plugins/addons-for-visual-composer/assets/js/jquery.waypoints.min.js?ver=2.8",
            "https://www.dubaioffplan-properties.com/wp-content/plugins/addons-for-visual-composer/assets/js/lvca-frontend.min.js?ver=2.8",
            "https://www.dubaioffplan-properties.com/wp-content/plugins/addons-for-visual-composer/assets/js/isotope.pkgd.min.js?ver=2.8",
            "https://www.dubaioffplan-properties.com/wp-content/plugins/Ultimate_VC_Addons/assets/min-js/ultimate-params.min.js?ver=3.19.9",
            "https://www.dubaioffplan-properties.com/wp-content/plugins/Ultimate_VC_Addons/assets/min-js/headings.min.js?ver=3.19.9"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 5,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "adjadex1@gmail.com",
            "id": "187163",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 117,
            "URL": 377,
            "domain": 49,
            "FileHash-SHA256": 40
          },
          "indicator_count": 583,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 68,
          "modified_text": "1447 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "625eecb6fbc4353a109fe71c",
          "name": "hostkey - Industroyer&ReduceRight",
          "description": "Fbevents-PostalCodeType:f.exports, f.1, is a new addition to the list of \"signals\" that can be added to phone numbers.",
          "modified": "2022-04-19T17:09:10.196000",
          "created": "2022-04-19T17:09:10.196000",
          "tags": [
            "livechat",
            "sign up",
            "free",
            "grow",
            "policy",
            "sign",
            "strong",
            "sorry",
            "identify",
            "increase",
            "lzutf8",
            "typeerror",
            "uint8array",
            "array",
            "error",
            "typeof r",
            "class",
            "invalid",
            "post",
            "uint32array",
            "date",
            "null",
            "papvisitorid",
            "string",
            "regexp",
            "value",
            "property",
            "valuenumber",
            "activexobject",
            "postaffparams",
            "object",
            "number",
            "boolean",
            "typeof e",
            "math",
            "first",
            "raid",
            "window",
            "service",
            "ukraine",
            "epsilon",
            "arrow",
            "target",
            "keepalive",
            "void",
            "shell",
            "econnaborted",
            "hkwfunction",
            "typeof symbol",
            "function",
            "promise",
            "request",
            "network error",
            "livechatwidget",
            "ticket form",
            "prechat survey",
            "postchat survey",
            "typeof n",
            "chat",
            "blank",
            "win32",
            "iframe",
            "reduceright",
            "copyright",
            "closure library",
            "xdfunction",
            "adfunction",
            "cdfunction",
            "ddfunction",
            "bded",
            "x3e div",
            "trackevent",
            "landingpagegpu",
            "x3e table",
            "gpudraw",
            "path",
            "code",
            "functional",
            "member",
            "hnew regexp",
            "qfunction",
            "adview",
            "addbillinginfo",
            "addtocart",
            "addtolist",
            "contact",
            "download",
            "install",
            "symbol",
            "iterator",
            "extractor",
            "pixel",
            "facebook",
            "meta",
            "65535",
            "counter",
            "segoe ui",
            "lucida",
            "ecommerce",
            "ext link",
            "comic",
            "form",
            "impact",
            "light"
          ],
          "references": [
            "https://mc.yandex.ru/metrika/watch.js",
            "https://connect.facebook.net/signals/config/785878845108827",
            "https://snap.licdn.com/li.lms-analytics/insight.min.js",
            "https://www.googletagmanager.com/gtm.js?id=GTM-M9D76H",
            "https://www.googletagmanager.com/gtag/js?id=UA-73589630-1",
            "https://cdn.livechatinc.com/tracking.js",
            "https://rec.smartlook.com/main-20220331074633.js",
            "https://hostkey.com/hk/widgets/ext/build/stock.bundle.js",
            "https://hostkey.com/hk/widgets/ext/src/hostkey.js",
            "https://hostkey.postaffiliatepro.com/scripts/Oy173jux8",
            "https://hostkey.postaffiliatepro.com/scripts/Oy173rux8?accountld=default1&url=S_hostkey.com%2F&referrer=&isInlframe=false&getParams=&anchor=",
            "https://widget.trustpilot.com/trustboxes/5613c9cde69ddc09340c6beb/index.html?templateld=5613c9cde69ddc09340c6beb&businessunitld=55e46b640000ff000582c91e#locale=en-GB&styleHeight=100%25&styleWidth=100%25&theme=light",
            "https://secure.livechatinc.com/"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "Tunisia"
          ],
          "malware_families": [
            {
              "id": "ReduceRight",
              "display_name": "ReduceRight",
              "target": null
            },
            {
              "id": "Industroyer - S0604",
              "display_name": "Industroyer - S0604",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1125",
              "name": "Video Capture",
              "display_name": "T1125 - Video Capture"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 8,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "adjadex1@gmail.com",
            "id": "187163",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 1778,
            "hostname": 563,
            "FileHash-SHA256": 304,
            "domain": 407,
            "FileHash-SHA1": 2
          },
          "indicator_count": 3054,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 68,
          "modified_text": "1461 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "625028edfe0ff22af87b9d66",
          "name": "Virustotal.com",
          "description": "If you want to know how to delete an object from your browser, try these three-second-long, four-point-result-results-free-to-get-it-out-the-objectIterator.",
          "modified": "2022-04-08T12:22:05.307000",
          "created": "2022-04-08T12:22:05.307000",
          "tags": [
            "symbol",
            "object",
            "string",
            "denis pushkarev",
            "json",
            "corejs",
            "source",
            "etrt",
            "atfunction",
            "stfunction",
            "error",
            "typeerror",
            "asynciterator",
            "generator",
            "typeof l",
            "nonce",
            "script",
            "please do",
            "not copy",
            "and paste",
            "this code",
            "cgrecaptchacfg",
            "ngrecaptcha",
            "recaptchaapi",
            "render",
            "waaa",
            "bufferwriter",
            "bufferreader",
            "qace",
            "search",
            "cafebabe",
            "c2c url",
            "jgfunilwcpc",
            "gmbh",
            "return",
            "freemium gmbh",
            "open xml",
            "virustotal",
            "keep learning",
            "select",
            "uint8array",
            "array",
            "null",
            "function",
            "math",
            "edge",
            "number",
            "date",
            "this",
            "verify",
            "android",
            "iframe",
            "void",
            "trident",
            "span",
            "form",
            "click",
            "enterprise",
            "infinity",
            "template",
            "next",
            "body"
          ],
          "references": [
            "https://www.gstatic.com/recaptcha/releases/Y-cOIEkAqcfDdup_qnnmkxIC/recaptcha__en.js",
            "https://www.virustotal.com/gui/main.6d41e0dc139508f21963.js",
            "https://www.recaptcha.net/recaptcha/api.js?render=explicit",
            "https://www.virustotal.com/gui/polyfills/regenerator-runtime.95dc763885f05111a2f88232a2d0cf2d.js",
            "https://www.virustotal.com/gui/polyfills/core-js.c92df5c57caa3e436cd3ef38e4b4f503.js"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "WAAA",
              "display_name": "WAAA",
              "target": null
            },
            {
              "id": "QACE",
              "display_name": "QACE",
              "target": null
            },
            {
              "id": "BufferReader",
              "display_name": "BufferReader",
              "target": null
            },
            {
              "id": "BufferWriter",
              "display_name": "BufferWriter",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1568",
              "name": "Dynamic Resolution",
              "display_name": "T1568 - Dynamic Resolution"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 4,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "adjadex1@gmail.com",
            "id": "187163",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 392,
            "URL": 1356,
            "domain": 330,
            "FileHash-SHA256": 177
          },
          "indicator_count": 2255,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 68,
          "modified_text": "1472 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "624ade33b2dd93cdc7ef4b58",
          "name": "Botnet c&c",
          "description": "ParallelAxisIndex:0,label:1,lineStyle:2,inactiveOpacity: 1.05,m.g,graphicKey: m.style,t.",
          "modified": "2022-04-04T12:01:54.999000",
          "created": "2022-04-04T12:01:54.999000",
          "tags": [
            "datav6a0cc948",
            "pingfang sc",
            "microsoft yahei",
            "helvetica neue",
            "helvetica",
            "hiragino sans",
            "arial",
            "datav11c9d7e6",
            "datava3f4887a",
            "datav12834d8c",
            "span",
            "open",
            "date",
            "function",
            "typeof t",
            "regexp",
            "number",
            "typeof e",
            "null",
            "width",
            "typeof s",
            "error",
            "this",
            "class",
            "accept",
            "d mmmm",
            "yyyy",
            "yyyy hh",
            "llll",
            "pjh5",
            "dddd",
            "ds5p",
            "void",
            "android",
            "backspace",
            "typeof define",
            "load",
            "mika tuupola",
            "boolean"
          ],
          "references": [
            "https://cdf5cxngkkxd.com/#/home",
            "https://cdf5cxngkkxd.com/static/js/lazyload.min.js",
            "https://cdf5cxngkkxd.com/static/js/manifest.e4d52d2f9dae6cd41eb4.js",
            "https://cdf5cxngkkxd.com/static/js/vendor.084bf9e0e16f0b2b6faa.js",
            "https://cdf5cxngkkxd.com/static/js/app.e16f8acb87917d3eab20.js",
            "https://cdf5cxngkkxd.com/static/css/app.7b16cc13d7ec8824766fa8255c64a800.css"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 4,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "adjadex1@gmail.com",
            "id": "187163",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 334,
            "URL": 1182,
            "domain": 214,
            "FileHash-SHA256": 33
          },
          "indicator_count": 1763,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 68,
          "modified_text": "1476 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "http://appbyweb.net/AppByWeb/js/jquery.min.js",
        "https://www.dubaioffplan-properties.com/wp-content/plugins/addons-for-visual-composer/assets/js/lvca-frontend.min.js?ver=2.8",
        "https://www.dubaioffplan-properties.com/wp-content/plugins/Ultimate_VC_Addons/assets/min-js/headings.min.js?ver=3.19.9",
        "https://www.virustotal.com/gui/main.900e36f7a852b9863014.js",
        "https://www.gstatic.com/recaptcha/releases/Y-cOIEkAqcfDdup_qnnmkxIC/recaptcha__en.js",
        "twitter.com/i/flow/login",
        "xfe-URL-appbyweb.net-stix2-2.1-export.json",
        "https://hostkey.postaffiliatepro.com/scripts/Oy173jux8",
        "https://cdf5cxngkkxd.com/static/js/app.e16f8acb87917d3eab20.js",
        "https://secure.livechatinc.com/",
        "https://pagead2.googlesyndication.com/pagead/managed/js/adsense/m202204200101/show_ads_impl_fy2019.js",
        "http://appbyweb.net/AppByWeb/js/jquery.easing.1.3.js",
        "http://appbyweb.net/AppByWeb/js/hoverIntent.js",
        "https://www.dubaioffplan-properties.com/wp-content/plugins/addons-for-visual-composer/assets/js/isotope.pkgd.min.js?ver=2.8",
        "https://hostkey.postaffiliatepro.com/scripts/Oy173rux8?accountld=default1&url=S_hostkey.com%2F&referrer=&isInlframe=false&getParams=&anchor=",
        "https://www.googletagmanager.com/gtag/js?id=UA-73589630-1",
        "https://widget.trustpilot.com/trustboxes/5613c9cde69ddc09340c6beb/index.html?templateld=5613c9cde69ddc09340c6beb&businessunitld=55e46b640000ff000582c91e#locale=en-GB&styleHeight=100%25&styleWidth=100%25&theme=light",
        "http://appbyweb.net/AppByWeb/js/main.js",
        "https://www.webuzo.com/sitepad-data/themes/ui/style.css?ver=5.1.6",
        "https://cdf5cxngkkxd.com/static/css/app.7b16cc13d7ec8824766fa8255c64a800.css",
        "https://files.appbyweb.net/Fonts/OpenSansHebrew/font.css",
        "https://cdf5cxngkkxd.com/static/js/lazyload.min.js",
        "https://www.recaptcha.net/recaptcha/api.js?render=explicit",
        "http://appbyweb.net/AppByWeb/js/jquery.stellar.min.js",
        "https://www.webuzo.com/site-data/plugins/pagelayer-pro/css/givecss.php?give=pagelayer-frontend.css%2Cnivo-lightbox.css%2Canimate.min.css%2Cowl.carousel.min.css%2Cowl.theme.default.min.css%2Cfont-awesome5.min.css&premium=%2Cpremium-frontend.css&ver=1.6.7",
        "xfe-URL-dynadot.com-stix2-2.1-export.json",
        "http://appbyweb.net/AppByWeb/js/modernizr-2.6.2.min.js",
        "https://www.googletagmanager.com/gtag/js?id=UA-128076350-1",
        "https://my.frantech.ca/templates/lagom/assets/js/whmcs-custom.min.js?v=1.4.3",
        "https://www.dubaioffplan-properties.com/wp-content/plugins/Ultimate_VC_Addons/assets/min-js/ultimate-params.min.js?ver=3.19.9",
        "https://connect.facebook.net/signals/config/785878845108827",
        "http://appbyweb.net/AppByWeb/js/bootstrap.min.js",
        "https://cdf5cxngkkxd.com/#/home",
        "https://www.virustotal.com/gui/main.6d41e0dc139508f21963.js",
        "https://my.frantech.ca/templates/lagom/assets/js/lagom-app.min.js?v=1.4.3",
        "https://www.webuzo.com/site-inc/js/jquery/jquery-migrate.min.js?ver=1.4.1",
        "https://www.googletagmanager.com/gtm.js?id=GTM-M9D76H",
        "https://www.virustotal.com/gui/polyfills/core-js.c92df5c57caa3e436cd3ef38e4b4f503.js",
        "https://www.webuzo.com/",
        "https://player.vimeo.com/video/51589652?h=836062ff9b&dnt=1&app_id=122963",
        "https://rec.smartlook.com/main-20220331074633.js",
        "https://www.webuzo.com/site-data/plugins/pagelayer-pro/js/givejs.php?give=pagelayer-frontend.js%2Cnivo-lightbox.min.js%2Cwow.min.js%2Cjquery-numerator.js%2CsimpleParallax.min.js%2Cowl.carousel.min.js&premium=%2Cchart.min.js%2Cpremium-frontend.js%2Cshuffle.min.js&ver=1.6.7",
        "xfe-URL-frantech.ca-stix2-2.1-export.json",
        "https://www.dubaioffplan-properties.com/wp-includes/js/wp-emoji-release.min.js?ver=5.9.2",
        "https://hybrid-analysis.com/sample/98d509ee5c88d85c96e401cf9a599a9bed2799101079f99e7e4ae974131ebcc1/643e852b401612eba8065bbb",
        "xfe-URL-https___my.frantech.ca_-stix2-2.1-export.json",
        "https://www.dubaioffplan-properties.com/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.3.2",
        "https://www.virustotal.com/gui/polyfills/regenerator-runtime.95dc763885f05111a2f88232a2d0cf2d.js",
        "https://cdn.livechatinc.com/tracking.js",
        "https://cdf5cxngkkxd.com/static/js/manifest.e4d52d2f9dae6cd41eb4.js",
        "https://googleads.g.doubleclick.net/pagead/ads?client=ca-pub-2581829468247892&output=html&adk=1812271804&adf=3025194257&lmt=1651149220&plat=16%3A8388608%2C17%3A32%2C24%3A32%2C25%3A32%2C32%3A32&format=0x0&url=http%3A%2F%2Fappbyweb.net%2FAppByWeb%2F&ea=0&pra=5&wgl=1&dt=1651149220376&bpp=1&bdt=121&idt=18&shv=r20220425&mjsv=m202204200101&ptt=9&saldr=aa&abxe=1&cookie=ID%3De83d6067a4dac5b6-229192c549d200d1%3AT%3D1651148802%3ART%3D1651148802%3AS%3DALNI_MZSt9utXhYBHAIH9xwQp72WuxQxTw&nras=1&correlator=1655793633284&",
        "https://hybrid-analysis.com/sample/31ab3088c37fe023e4e38296f7083905a64aa3b77c94735815f89906418d2926/642613dabe4297d3b60d91be",
        "https://partner.googleadservices.com/gampad/cookie.js?domain=appbyweb.net&callback=_gfp_s_&client=ca-pub-2581829468247892",
        "xfe-URL-Webuzo.com-stix2-2.1-export.json",
        "https://www.virustotal.com/gui/vt-ui-sw-installer.e0eb1a1e08d6512ba355.js/ Depreciated",
        "http://appbyweb.net/AppByWeb",
        "https://cdf5cxngkkxd.com/static/js/vendor.084bf9e0e16f0b2b6faa.js",
        "http://appbyweb.net/AppByWeb/js/jquery.waypoints.min.js",
        "https://www.dubaioffplan-properties.com/wp-content/plugins/addons-for-visual-composer/assets/js/jquery.waypoints.min.js?ver=2.8",
        "https://hostkey.com/hk/widgets/ext/src/hostkey.js",
        "http://appbyweb.net/AppByWeb/js/superfish.js",
        "https://hostkey.com/hk/widgets/ext/build/stock.bundle.js",
        "https://mc.yandex.ru/metrika/watch.js",
        "https://snap.licdn.com/li.lms-analytics/insight.min.js",
        "https://www.dubaioffplan-properties.com/wp-includes/js/jquery/jquery.min.js?ver=3.6.0",
        "https://www.webuzo.com/site-inc/js/jquery/jquery.js?ver=1.12.4"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 0
        },
        "other": {
          "adversary": [],
          "malware_families": [
            "Qace",
            "Gc",
            "Bufferreader",
            "Waaa",
            "Bufferwriter",
            "Industroyer - s0604",
            "Reduceright"
          ],
          "industries": [],
          "unique_indicators": 13596
        }
      }
    },
    "false_positive": [],
    "alexa": "http://www.alexa.com/siteinfo/this.group",
    "whois": "http://whois.domaintools.com/this.group",
    "domain": "this.group",
    "hostname": "ww16.this.group"
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 12,
  "pulses": [
    {
      "id": "65708beba2ba8bcfb1d10237",
      "name": "hostkey - Industroyer&ReduceRight",
      "description": "",
      "modified": "2023-12-06T14:57:47.430000",
      "created": "2023-12-06T14:57:47.430000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 3,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 304,
        "hostname": 563,
        "domain": 407,
        "URL": 1776,
        "FileHash-SHA1": 2
      },
      "indicator_count": 3052,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "865 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "65708aa1dca4e6c505e4fc9e",
      "name": "Botnet c&c",
      "description": "",
      "modified": "2023-12-06T14:52:16.286000",
      "created": "2023-12-06T14:52:16.286000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 214,
        "hostname": 334,
        "URL": 1182,
        "FileHash-SHA256": 33
      },
      "indicator_count": 1763,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "865 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "64407a3c423306cfb9d66c6d",
      "name": "https://ads.twitter.com/?ref=gl-tw-tw-twitter-advertise0",
      "description": "",
      "modified": "2023-04-19T23:33:16.257000",
      "created": "2023-04-19T23:33:16.257000",
      "tags": [
        "zarma"
      ],
      "references": [
        "https://hybrid-analysis.com/sample/98d509ee5c88d85c96e401cf9a599a9bed2799101079f99e7e4ae974131ebcc1/643e852b401612eba8065bbb"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1083",
          "name": "File and Directory Discovery",
          "display_name": "T1083 - File and Directory Discovery"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1480",
          "name": "Execution Guardrails",
          "display_name": "T1480 - Execution Guardrails"
        },
        {
          "id": "T1497",
          "name": "Virtualization/Sandbox Evasion",
          "display_name": "T1497 - Virtualization/Sandbox Evasion"
        },
        {
          "id": "T1547",
          "name": "Boot or Logon Autostart Execution",
          "display_name": "T1547 - Boot or Logon Autostart Execution"
        },
        {
          "id": "T1555",
          "name": "Credentials from Password Stores",
          "display_name": "T1555 - Credentials from Password Stores"
        },
        {
          "id": "T1574",
          "name": "Hijack Execution Flow",
          "display_name": "T1574 - Hijack Execution Flow"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 5,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "callmeDoris",
        "id": "205385",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 178,
        "hostname": 612,
        "URL": 1892,
        "email": 4,
        "IPv4": 5,
        "FileHash-SHA256": 63,
        "FileHash-MD5": 59,
        "FileHash-SHA1": 58
      },
      "indicator_count": 2871,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 92,
      "modified_text": "1096 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "642620d51d298e5a95b15599",
      "name": "api.3f94642a.js via source of twitter login page using edge browser latest version 111.",
      "description": "WebpackChunk_Twitter-responsive-web=webpack chunks, as well as its own webpack, to create a single \"bundle\" for all of the sites.",
      "modified": "2023-03-31T00:06:55.719000",
      "created": "2023-03-30T23:52:53.828000",
      "tags": [
        "malware",
        "vxstream",
        "trojan",
        "ansi",
        "memoryfile scan",
        "scalarfield",
        "linkedfield",
        "runtime data",
        "requiredfield",
        "throw",
        "user",
        "apiuser",
        "error",
        "path",
        "slice",
        "date",
        "suspicious",
        "unknown",
        "stats",
        "bouncer",
        "hybrid",
        "model",
        "close",
        "click",
        "general",
        "strings",
        "malicious",
        "qakbot"
      ],
      "references": [
        "https://hybrid-analysis.com/sample/31ab3088c37fe023e4e38296f7083905a64aa3b77c94735815f89906418d2926/642613dabe4297d3b60d91be",
        "twitter.com/i/flow/login"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1012",
          "name": "Query Registry",
          "display_name": "T1012 - Query Registry"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1056",
          "name": "Input Capture",
          "display_name": "T1056 - Input Capture"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1083",
          "name": "File and Directory Discovery",
          "display_name": "T1083 - File and Directory Discovery"
        },
        {
          "id": "T1106",
          "name": "Native API",
          "display_name": "T1106 - Native API"
        },
        {
          "id": "T1113",
          "name": "Screen Capture",
          "display_name": "T1113 - Screen Capture"
        },
        {
          "id": "T1129",
          "name": "Shared Modules",
          "display_name": "T1129 - Shared Modules"
        },
        {
          "id": "T1546",
          "name": "Event Triggered Execution",
          "display_name": "T1546 - Event Triggered Execution"
        },
        {
          "id": "T1547",
          "name": "Boot or Logon Autostart Execution",
          "display_name": "T1547 - Boot or Logon Autostart Execution"
        },
        {
          "id": "T1562",
          "name": "Impair Defenses",
          "display_name": "T1562 - Impair Defenses"
        },
        {
          "id": "T1573",
          "name": "Encrypted Channel",
          "display_name": "T1573 - Encrypted Channel"
        },
        {
          "id": "T1614",
          "name": "System Location Discovery",
          "display_name": "T1614 - System Location Discovery"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 6,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "callmeDoris",
        "id": "205385",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 322,
        "hostname": 61,
        "domain": 105,
        "FileHash-SHA256": 24,
        "FileHash-MD5": 11,
        "FileHash-SHA1": 2
      },
      "indicator_count": 525,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 90,
      "modified_text": "1116 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "63a3b9aaaca8891186e6f7a2",
      "name": "vt errors on edge 21 dec 2022",
      "description": "var n-i,n-n, r.test, is a new type of webpack, which uses a set of rules to store data in the form of a single address, or code.",
      "modified": "2023-01-21T00:01:41.590000",
      "created": "2022-12-22T01:58:02.495000",
      "tags": [
        "eaca",
        "eace",
        "iaca",
        "iace",
        "boolean",
        "object",
        "path",
        "aacf",
        "customevent",
        "string",
        "span",
        "error",
        "code",
        "virustotal",
        "date",
        "null",
        "contact",
        "blank",
        "close",
        "twitter",
        "unknown",
        "download",
        "this",
        "easy",
        "desktop",
        "body",
        "requires",
        "footer",
        "refresh",
        "patch",
        "write",
        "cobalt strike",
        "shell",
        "zero",
        "harmless",
        "main",
        "aalfe",
        "getclass",
        "copy",
        "iframe",
        "divi",
        "roboto",
        "insert",
        "template",
        "class",
        "void",
        "form",
        "back",
        "ransomware",
        "trace",
        "comment",
        "tools",
        "premium",
        "bufferwriter",
        "bufferreader",
        "array",
        "typeerror",
        "vtuibutton",
        "number",
        "typeof o",
        "urls",
        "please",
        "javascript",
        "https://www.virustotal.com/gui/vt-ui-sw-installer.e0eb1a1e08d651",
        "https://www.virustotal.com/gui/main.900e36f7a852b9863014.js"
      ],
      "references": [
        "https://www.virustotal.com/gui/vt-ui-sw-installer.e0eb1a1e08d6512ba355.js/ Depreciated",
        "https://www.virustotal.com/gui/main.900e36f7a852b9863014.js"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "BufferReader",
          "display_name": "BufferReader",
          "target": null
        },
        {
          "id": "BufferWriter",
          "display_name": "BufferWriter",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        },
        {
          "id": "T1568",
          "name": "Dynamic Resolution",
          "display_name": "T1568 - Dynamic Resolution"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 11,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "callmeDoris",
        "id": "205385",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 1051,
        "FileHash-SHA256": 204,
        "hostname": 275,
        "domain": 212,
        "CVE": 1,
        "FileHash-MD5": 1,
        "FileHash-SHA1": 1
      },
      "indicator_count": 1745,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 92,
      "modified_text": "1185 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "626a8a564da0d5b27dc02619",
      "name": "App By Web",
      "description": "Israeli malware hosting",
      "modified": "2022-05-28T00:03:46.141000",
      "created": "2022-04-28T12:36:38.103000",
      "tags": [
        "hebrew",
        "truetype",
        "woff2",
        "woff",
        "body",
        "fh5cooffcanvas",
        "function",
        "click",
        "main menu",
        "superfish var",
        "parallax",
        "offcanvas",
        "mobile menu",
        "animations var",
        "mstouchaction",
        "superfish menu",
        "plugin",
        "copyright",
        "joel birch",
        "dual",
        "fill",
        "touchaction",
        "y position",
        "hoverintent",
        "brian cherne",
        "param",
        "threshold",
        "mit license",
        "or selector",
        "author",
        "1parseint",
        "mark dalgleish",
        "http",
        "webkitopacity",
        "webkit",
        "khtmlopacity",
        "khtml",
        "typeof d",
        "error",
        "this",
        "caleb troughton",
        "typeof f",
        "adapter",
        "bootstrap",
        "javascript",
        "typeof c",
        "twitter",
        "focus",
        "azaz",
        "including",
        "this software",
        "but not",
        "limited to",
        "terms of",
        "open",
        "bsd license",
        "redistribution",
        "redistributions",
        "neither",
        "direct",
        "gc",
        "regexp",
        "typeof b",
        "pseudo",
        "child",
        "array",
        "width",
        "sufeffxa0",
        "class",
        "null",
        "date",
        "accept",
        "boolean",
        "modernizr",
        "custom build",
        "build",
        "afunction",
        "cfunction",
        "typeerror",
        "object",
        "documenttouch",
        "websocket",
        "string",
        "silk",
        "script",
        "arial",
        "edge",
        "iframe",
        "promise",
        "void",
        "android",
        "trident",
        "embed",
        "meta",
        "roboto",
        "term",
        "\u05d4\u05d6\u05de\u05e0\u05ea \u05de\u05d5\u05e0\u05d9\u05ea",
        "wtaxi",
        "wapp",
        "app by web ltd",
        "03-5115656",
        "03-5109109",
        "+97235115656",
        "\u05de\u05e2\u05e8\u05db\u05d5\u05ea \u05d4\u05e1\u05e2\u05d9\u05dd",
        "\u05db\u05e8\u05d8\u05d9\u05e1 \u05d0\u05e9\u05e8\u05d0\u05d9 \u05d1\u05de\u05d5\u05e0\u05d9\u05ea",
        "web ltd",
        "reserved"
      ],
      "references": [
        "xfe-URL-appbyweb.net-stix2-2.1-export.json",
        "http://appbyweb.net/AppByWeb",
        "https://partner.googleadservices.com/gampad/cookie.js?domain=appbyweb.net&callback=_gfp_s_&client=ca-pub-2581829468247892",
        "https://pagead2.googlesyndication.com/pagead/managed/js/adsense/m202204200101/show_ads_impl_fy2019.js",
        "http://appbyweb.net/AppByWeb/js/modernizr-2.6.2.min.js",
        "http://appbyweb.net/AppByWeb/js/jquery.min.js",
        "http://appbyweb.net/AppByWeb/js/jquery.easing.1.3.js",
        "http://appbyweb.net/AppByWeb/js/bootstrap.min.js",
        "http://appbyweb.net/AppByWeb/js/jquery.waypoints.min.js",
        "http://appbyweb.net/AppByWeb/js/jquery.stellar.min.js",
        "http://appbyweb.net/AppByWeb/js/hoverIntent.js",
        "http://appbyweb.net/AppByWeb/js/superfish.js",
        "http://appbyweb.net/AppByWeb/js/main.js",
        "https://files.appbyweb.net/Fonts/OpenSansHebrew/font.css",
        "https://googleads.g.doubleclick.net/pagead/ads?client=ca-pub-2581829468247892&output=html&adk=1812271804&adf=3025194257&lmt=1651149220&plat=16%3A8388608%2C17%3A32%2C24%3A32%2C25%3A32%2C32%3A32&format=0x0&url=http%3A%2F%2Fappbyweb.net%2FAppByWeb%2F&ea=0&pra=5&wgl=1&dt=1651149220376&bpp=1&bdt=121&idt=18&shv=r20220425&mjsv=m202204200101&ptt=9&saldr=aa&abxe=1&cookie=ID%3De83d6067a4dac5b6-229192c549d200d1%3AT%3D1651148802%3ART%3D1651148802%3AS%3DALNI_MZSt9utXhYBHAIH9xwQp72WuxQxTw&nras=1&correlator=1655793633284&"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Gc",
          "display_name": "Gc",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 8,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "adjadex1@gmail.com",
        "id": "187163",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 1554,
        "hostname": 533,
        "domain": 211,
        "FileHash-SHA256": 199
      },
      "indicator_count": 2497,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 69,
      "modified_text": "1423 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6266e98d7f3281e3039a7773",
      "name": "Dynadot.com&Webuzo &#8211; Multiuser Hosting Control Panel",
      "description": "Web Hosting Control Panel Webuzo is a web hosting platform which helps you manage your cloud or dedicated server, while offering the tools you need to develop and test your web applications and websites.",
      "modified": "2022-05-25T00:04:03.622000",
      "created": "2022-04-25T18:33:49.551000",
      "tags": [
        "20px",
        "webkitkeyframes",
        "45deg",
        "180deg",
        "5deg",
        "free",
        "10deg",
        "90deg",
        "font awesome",
        "2000px00",
        "flex",
        "mega",
        "contact",
        "form",
        "code",
        "typebutton",
        "typesubmit",
        "typesearch",
        "ff3834",
        "ff7133",
        "important",
        "ffffff",
        "theme name",
        "theme uri",
        "sitepad team",
        "import",
        "model",
        "number",
        "string",
        "copyright",
        "date",
        "closure library",
        "xdfunction",
        "cdfunction",
        "ddfunction",
        "bded",
        "kefunction",
        "click",
        "null",
        "pagelayersetup",
        "class",
        "show",
        "width",
        "setup",
        "error",
        "already setup",
        "false",
        "scroll",
        "body",
        "desktop",
        "trigger",
        "span",
        "window",
        "close",
        "jquery",
        "this",
        "bubble",
        "sticky",
        "facebook",
        "value",
        "foundation",
        "migrate",
        "backcompat",
        "quirks mode",
        "typeof f",
        "html",
        "regexp",
        "typeof e",
        "typeof t",
        "attr",
        "pseudo",
        "child",
        "function",
        "typeof module",
        "webuzo",
        "control panel",
        "apps",
        "multi user",
        "subscribe",
        "noc noc",
        "providers",
        "resellers",
        "website owners",
        "web hosting",
        "apache",
        "python",
        "easy",
        "payment"
      ],
      "references": [
        "https://www.webuzo.com/",
        "xfe-URL-Webuzo.com-stix2-2.1-export.json",
        "xfe-URL-dynadot.com-stix2-2.1-export.json",
        "https://www.webuzo.com/site-inc/js/jquery/jquery.js?ver=1.12.4",
        "https://www.webuzo.com/site-inc/js/jquery/jquery-migrate.min.js?ver=1.4.1",
        "https://www.webuzo.com/site-data/plugins/pagelayer-pro/js/givejs.php?give=pagelayer-frontend.js%2Cnivo-lightbox.min.js%2Cwow.min.js%2Cjquery-numerator.js%2CsimpleParallax.min.js%2Cowl.carousel.min.js&premium=%2Cchart.min.js%2Cpremium-frontend.js%2Cshuffle.min.js&ver=1.6.7",
        "https://www.googletagmanager.com/gtag/js?id=UA-128076350-1",
        "https://www.webuzo.com/sitepad-data/themes/ui/style.css?ver=5.1.6",
        "https://www.webuzo.com/site-data/plugins/pagelayer-pro/css/givecss.php?give=pagelayer-frontend.css%2Cnivo-lightbox.css%2Canimate.min.css%2Cowl.carousel.min.css%2Cowl.theme.default.min.css%2Cfont-awesome5.min.css&premium=%2Cpremium-frontend.css&ver=1.6.7"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1218",
          "name": "Signed Binary Proxy Execution",
          "display_name": "T1218 - Signed Binary Proxy Execution"
        },
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 7,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "adjadex1@gmail.com",
        "id": "187163",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 1527,
        "hostname": 411,
        "FileHash-SHA256": 219,
        "domain": 583
      },
      "indicator_count": 2740,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 70,
      "modified_text": "1426 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "62634f4db80546374654f4c4",
      "name": "frantech.ca - malware",
      "description": "T,t.F, t.f, is written in the same place as the following:t, d. F, has been added to the end of the document, as well as its own propertyDescriptor.",
      "modified": "2022-05-22T00:01:01.264000",
      "created": "2022-04-23T00:58:53.444000",
      "tags": [
        "overview",
        "typeof symbol",
        "error",
        "typeerror",
        "object",
        "typeof t",
        "string",
        "typeof e",
        "function",
        "array",
        "promise",
        "date",
        "target",
        "class",
        "path",
        "back",
        "bounce",
        "this",
        "iframe",
        "null",
        "0x105684",
        "0xb66229",
        "0xb9b329",
        "0x3eed40",
        "0x2923e0",
        "cookie",
        "0x1d2d25",
        "0x2d6b",
        "0x538ea5",
        "0x240c1a",
        "push",
        "shift",
        "open"
      ],
      "references": [
        "xfe-URL-https___my.frantech.ca_-stix2-2.1-export.json",
        "xfe-URL-frantech.ca-stix2-2.1-export.json",
        "https://my.frantech.ca/templates/lagom/assets/js/lagom-app.min.js?v=1.4.3",
        "https://my.frantech.ca/templates/lagom/assets/js/whmcs-custom.min.js?v=1.4.3"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 5,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "adjadex1@gmail.com",
        "id": "187163",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 757,
        "hostname": 498,
        "domain": 311,
        "FileHash-SHA256": 21
      },
      "indicator_count": 1587,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 68,
      "modified_text": "1429 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "624a5c500fa7977cca286c2a",
      "name": "Timelapse - malware",
      "description": "New RegExp(M) is a new type, and it will change any of the elements to the same type if you want to add them to your HTML page or add a third element.",
      "modified": "2022-05-04T02:03:41.813000",
      "created": "2022-04-04T02:47:44.169000",
      "tags": [
        "layoutmode",
        "outlayer",
        "item",
        "pluginclass",
        "evemitter",
        "namespace",
        "function",
        "fitrows",
        "vertical",
        "error",
        "lvcafrontend",
        "typeof",
        "this",
        "copyright",
        "caleb troughton",
        "mit license",
        "typeof f",
        "adapter",
        "typeof define",
        "typeof module",
        "html tags",
        "ox20trnf",
        "dom element",
        "regexp",
        "typeof e",
        "typeof t",
        "class",
        "attr",
        "pseudo",
        "child",
        "udc66udc67",
        "ud83d",
        "ufe0f",
        "ud83e",
        "udc68udc69",
        "udfcbudfcc",
        "u2640u2642",
        "source",
        "image",
        "ud83dudc6cud83c",
        "timelapse",
        "lighthouse",
        "imk internet",
        "marketing",
        "vimeo"
      ],
      "references": [
        "https://player.vimeo.com/video/51589652?h=836062ff9b&dnt=1&app_id=122963",
        "https://www.dubaioffplan-properties.com/wp-includes/js/wp-emoji-release.min.js?ver=5.9.2",
        "https://www.dubaioffplan-properties.com/wp-includes/js/jquery/jquery.min.js?ver=3.6.0",
        "https://www.dubaioffplan-properties.com/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.3.2",
        "https://www.dubaioffplan-properties.com/wp-content/plugins/addons-for-visual-composer/assets/js/jquery.waypoints.min.js?ver=2.8",
        "https://www.dubaioffplan-properties.com/wp-content/plugins/addons-for-visual-composer/assets/js/lvca-frontend.min.js?ver=2.8",
        "https://www.dubaioffplan-properties.com/wp-content/plugins/addons-for-visual-composer/assets/js/isotope.pkgd.min.js?ver=2.8",
        "https://www.dubaioffplan-properties.com/wp-content/plugins/Ultimate_VC_Addons/assets/min-js/ultimate-params.min.js?ver=3.19.9",
        "https://www.dubaioffplan-properties.com/wp-content/plugins/Ultimate_VC_Addons/assets/min-js/headings.min.js?ver=3.19.9"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 5,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "adjadex1@gmail.com",
        "id": "187163",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 117,
        "URL": 377,
        "domain": 49,
        "FileHash-SHA256": 40
      },
      "indicator_count": 583,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 68,
      "modified_text": "1447 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "625eecb6fbc4353a109fe71c",
      "name": "hostkey - Industroyer&ReduceRight",
      "description": "Fbevents-PostalCodeType:f.exports, f.1, is a new addition to the list of \"signals\" that can be added to phone numbers.",
      "modified": "2022-04-19T17:09:10.196000",
      "created": "2022-04-19T17:09:10.196000",
      "tags": [
        "livechat",
        "sign up",
        "free",
        "grow",
        "policy",
        "sign",
        "strong",
        "sorry",
        "identify",
        "increase",
        "lzutf8",
        "typeerror",
        "uint8array",
        "array",
        "error",
        "typeof r",
        "class",
        "invalid",
        "post",
        "uint32array",
        "date",
        "null",
        "papvisitorid",
        "string",
        "regexp",
        "value",
        "property",
        "valuenumber",
        "activexobject",
        "postaffparams",
        "object",
        "number",
        "boolean",
        "typeof e",
        "math",
        "first",
        "raid",
        "window",
        "service",
        "ukraine",
        "epsilon",
        "arrow",
        "target",
        "keepalive",
        "void",
        "shell",
        "econnaborted",
        "hkwfunction",
        "typeof symbol",
        "function",
        "promise",
        "request",
        "network error",
        "livechatwidget",
        "ticket form",
        "prechat survey",
        "postchat survey",
        "typeof n",
        "chat",
        "blank",
        "win32",
        "iframe",
        "reduceright",
        "copyright",
        "closure library",
        "xdfunction",
        "adfunction",
        "cdfunction",
        "ddfunction",
        "bded",
        "x3e div",
        "trackevent",
        "landingpagegpu",
        "x3e table",
        "gpudraw",
        "path",
        "code",
        "functional",
        "member",
        "hnew regexp",
        "qfunction",
        "adview",
        "addbillinginfo",
        "addtocart",
        "addtolist",
        "contact",
        "download",
        "install",
        "symbol",
        "iterator",
        "extractor",
        "pixel",
        "facebook",
        "meta",
        "65535",
        "counter",
        "segoe ui",
        "lucida",
        "ecommerce",
        "ext link",
        "comic",
        "form",
        "impact",
        "light"
      ],
      "references": [
        "https://mc.yandex.ru/metrika/watch.js",
        "https://connect.facebook.net/signals/config/785878845108827",
        "https://snap.licdn.com/li.lms-analytics/insight.min.js",
        "https://www.googletagmanager.com/gtm.js?id=GTM-M9D76H",
        "https://www.googletagmanager.com/gtag/js?id=UA-73589630-1",
        "https://cdn.livechatinc.com/tracking.js",
        "https://rec.smartlook.com/main-20220331074633.js",
        "https://hostkey.com/hk/widgets/ext/build/stock.bundle.js",
        "https://hostkey.com/hk/widgets/ext/src/hostkey.js",
        "https://hostkey.postaffiliatepro.com/scripts/Oy173jux8",
        "https://hostkey.postaffiliatepro.com/scripts/Oy173rux8?accountld=default1&url=S_hostkey.com%2F&referrer=&isInlframe=false&getParams=&anchor=",
        "https://widget.trustpilot.com/trustboxes/5613c9cde69ddc09340c6beb/index.html?templateld=5613c9cde69ddc09340c6beb&businessunitld=55e46b640000ff000582c91e#locale=en-GB&styleHeight=100%25&styleWidth=100%25&theme=light",
        "https://secure.livechatinc.com/"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "Tunisia"
      ],
      "malware_families": [
        {
          "id": "ReduceRight",
          "display_name": "ReduceRight",
          "target": null
        },
        {
          "id": "Industroyer - S0604",
          "display_name": "Industroyer - S0604",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1553",
          "name": "Subvert Trust Controls",
          "display_name": "T1553 - Subvert Trust Controls"
        },
        {
          "id": "T1125",
          "name": "Video Capture",
          "display_name": "T1125 - Video Capture"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1547",
          "name": "Boot or Logon Autostart Execution",
          "display_name": "T1547 - Boot or Logon Autostart Execution"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 8,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "adjadex1@gmail.com",
        "id": "187163",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 1778,
        "hostname": 563,
        "FileHash-SHA256": 304,
        "domain": 407,
        "FileHash-SHA1": 2
      },
      "indicator_count": 3054,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 68,
      "modified_text": "1461 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "https://ww16.this.group",
    "type": "URL"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "https://ww16.this.group",
    "type": "URL",
    "found": false,
    "verdict": "clean",
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1776670994.480924
}