{
  "type": "URL",
  "indicator": "https://ww16.wegardn.com",
  "general": {
    "sections": [
      "general",
      "url_list",
      "http_scans",
      "screenshot"
    ],
    "indicator": "https://ww16.wegardn.com",
    "type": "url",
    "type_title": "URL",
    "validation": [],
    "base_indicator": {
      "id": 3454274392,
      "indicator": "https://ww16.wegardn.com",
      "type": "URL",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 12,
      "pulses": [
        {
          "id": "66d8e7e014fc1110089effc7",
          "name": "UCRANIA AFECTACI\u00d3N 26-07-2022 (by sirowa7979) enriched",
          "description": "",
          "modified": "2025-06-16T13:56:26.068000",
          "created": "2024-09-04T23:06:08.626000",
          "tags": [],
          "references": [
            "672469157e58844350382fd51bc0fee1605982609c1f80a0b3df3906fbeb49a3.csv",
            "https://www.virustotal.com/gui/collection/672469157e58844350382fd51bc0fee1605982609c1f80a0b3df3906fbeb49a3/summary"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "Ukraine"
          ],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "skocherhan",
            "id": "249290",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_249290/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 67,
            "FileHash-SHA1": 67,
            "FileHash-SHA256": 449,
            "domain": 113,
            "hostname": 357,
            "URL": 1246,
            "CVE": 1
          },
          "indicator_count": 2300,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 184,
          "modified_text": "349 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "66c5dcd42da951f32ee24e0f",
          "name": "https://mypornwap.fun/downloads/5/search/white-dpt-jeffrey-reimer-loves-pretty-indian-patient-forces-sex-3gp-video-tsara-brashesrs",
          "description": "",
          "modified": "2024-08-21T12:25:56.328000",
          "created": "2024-08-21T12:25:56.328000",
          "tags": [
            "cins active",
            "poor reputation",
            "host",
            "threats et",
            "ip tcp",
            "detection list",
            "ip address",
            "blacklist",
            "macedonia",
            "former yugoslav",
            "site",
            "cisco umbrella",
            "alexa top",
            "million",
            "alexa",
            "threat report",
            "ip summary",
            "url summary",
            "summary",
            "sample",
            "samples",
            "paypal",
            "team phishing",
            "blacknet rat",
            "loki password",
            "stealer",
            "malicious url",
            "malicious site",
            "azorult",
            "phishing",
            "service",
            "runescape",
            "facebook",
            "bank",
            "download",
            "blacknet",
            "site top",
            "million alexa",
            "safe site",
            "malware",
            "genpack",
            "deepscan",
            "cobalt strike",
            "malicious",
            "zbot",
            "memscan",
            "cl0p",
            "cyber threat",
            "heur",
            "engineering",
            "united",
            "covid19",
            "malicious host",
            "team",
            "virut",
            "nymaim",
            "pony",
            "ransomware",
            "bradesco",
            "opencandy",
            "ramnit",
            "adload",
            "simda",
            "zeus",
            "pykspa",
            "riskware",
            "generic",
            "artemis",
            "downldr",
            "binder",
            "sutra",
            "steam",
            "asyncrat",
            "revengerat",
            "downloader",
            "exploit",
            "emailworm",
            "agent",
            "tinba",
            "maltiverse safe",
            "generic malware",
            "phishing site",
            "outbrowse",
            "suppobox",
            "vawtrak",
            "solimba",
            "wacatac",
            "msil",
            "outbreak",
            "installcore",
            "acint",
            "conduit",
            "installpack",
            "iobit",
            "dropper",
            "mediaget",
            "crack",
            "blacklist http",
            "ascii text",
            "nysp",
            "appdata",
            "jpeg image",
            "jfif standard",
            "file",
            "0xeae6b5",
            "function",
            "0x308d49",
            "x6a4",
            "push",
            "shift",
            "cookie",
            "slice",
            "path",
            "window",
            "error",
            "false",
            "hybrid",
            "crypto",
            "open",
            "blank",
            "template",
            "target",
            "trim",
            "write",
            "period",
            "touchmove",
            "click",
            "close",
            "body",
            "screen",
            "android",
            "canvas",
            "class",
            "span",
            "trident",
            "accept",
            "general",
            "local",
            "html",
            "unsafe",
            "downer",
            "shell",
            "mediamagnet",
            "sality",
            "swrort",
            "adaptivebee",
            "unruy",
            "trojanx",
            "webshell",
            "iframe",
            "patcher",
            "driverpack",
            "union",
            "maltiverse",
            "blacklist https",
            "google",
            "noname057",
            "redlinestealer"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "BlackNET",
              "display_name": "BlackNET",
              "target": null
            },
            {
              "id": "Cl0p",
              "display_name": "Cl0p",
              "target": null
            },
            {
              "id": "Maltiverse",
              "display_name": "Maltiverse",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": "655d0ec7b7cb12c66cac457d",
          "export_count": 22,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scoreblue",
            "id": "254100",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 884,
            "hostname": 1809,
            "FileHash-MD5": 635,
            "FileHash-SHA1": 321,
            "FileHash-SHA256": 2079,
            "CVE": 16,
            "URL": 6434
          },
          "indicator_count": 12178,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 228,
          "modified_text": "648 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "65eff46bdd371899ca5be7d7",
          "name": "CrypterX-gen | Video-lal.com | M. Brian Sabey \u2022 Hall Render | Rexxfield",
          "description": "Videolal results. Parked. Owner of domain has subsidiaries including Huge Domains. It's possible for attacker to post a 404 error page,  park, post it for sale, malvertize. HoneyPotBot? \n\nFireeye. A bit much. william.ballenthin@fireeye.com\t\ncontain a resource (.rsrc) section moritz.raabe@fireeye.com. Overkill. What would Scooby Doo? Scooby!? \nTarget reports opening her MacBook Pro after it was replaced by Apple. It hadn't been in use. She opened it, surprised it was on, automatically connected to a store wifi (she was home) A worker was typing away in terminal. Fought hacker for recordings app containing Jeffrey Reimers aggressions. She lost. Terrified she murdered her MacBook by drowning  & dismemberment. Big mistake. Cloned MacBook.  Clicked on links trigger malicious downloads, network & DNS issues.",
          "modified": "2024-04-11T04:01:24.166000",
          "created": "2024-03-12T06:21:31.484000",
          "tags": [
            "upatre malware",
            "rwi dtools",
            "page dow",
            "security",
            "bitfender",
            "yandex",
            "malware",
            "all octoseek",
            "av detections",
            "ids detections",
            "yara detections",
            "alerts",
            "file score",
            "fireeye",
            "injection",
            "worm",
            "trojan",
            "network",
            "poster",
            "honeybots",
            "united",
            "unknown",
            "win32upatre mar",
            "passive dns",
            "entries",
            "ipv4",
            "body",
            "artro",
            "generic malware",
            "formbook",
            "tag count",
            "threat report",
            "ip summary",
            "url summary",
            "generic",
            "hostnames",
            "pattern match",
            "ascii text",
            "png image",
            "root ca",
            "file",
            "authority",
            "indicator",
            "mitre att",
            "ck id",
            "class",
            "date",
            "enterprise",
            "hybrid",
            "accept",
            "general",
            "local",
            "click",
            "strings",
            "trident",
            "as47846",
            "germany unknown",
            "as2906 netflix",
            "scan endpoints",
            "domain",
            "urls",
            "files",
            "trojanspy",
            "mozilla",
            "dynamicloader",
            "medium",
            "title",
            "ms windows",
            "head",
            "intel",
            "inetsim http",
            "delete c",
            "show",
            "winnt",
            "copy",
            "powershell",
            "write",
            "next",
            "suspicious",
            "shop",
            "graph api",
            "status",
            "join",
            "vt community",
            "api key",
            "xcitium verdict",
            "cloud",
            "contacted",
            "contacted urls",
            "ssl certificate",
            "referrer",
            "historical ssl",
            "parent domain",
            "apple ios",
            "resolutions",
            "execution",
            "hacktool",
            "outbound connection",
            "detection list",
            "blacklist"
          ],
          "references": [
            "http://videolal.com/tsara-brashears-dead.html \u2022 http://videolal.com/ \u2022",
            "http://systemforex.de/search/redirect.php?f= | http://it.marksypark.com | dont-delete.hugedomains.com | http://selfsparkcentral.com",
            "william.ballenthin@fireeye.com contain a resource (.rsrc) section\tmoritz.raabe@fireeye.com | Pattern match: \"jloup@gzip.org\" & \"fancybox@3.5.7\"",
            "FormBook: 104.247.81.53 \u2022 http://www.nimtax.com/k9/,Formbook,Medium,9/9/2019,1/7/2020",
            "Win32:CrypterX-gen\\ [Trj] | FileHash-MD5   6878e9896fdd84dcc11c997c9b7330ba",
            "Win32:CrypterX-gen\\ [Trj] | FileHash-SHA1   2e586f8db46953532b5e25e07add4dbaeea83a79",
            "Win32:CrypterX-gen\\ [Trj] | FileHash-SHA256  00027d11309d55312ae77f32d4ae79671c91f541e577bace7a5a5abde05563ad",
            "Win32/Renos: https://otx.alienvault.com/malware/ALF:JASYP:TrojanDownloader:Win32%2FRenos/",
            "Other:Malware-gen\\ [Trj] | FileHash-MD5 b5168dab50187b33460201b35b96dea7",
            "Other:Malware-gen\\ [Trj] | FileHash-SHA1 68868b3d0115e3d06f5fddb9d2ea6ad54270166c",
            "Other:Malware-gen\\ [Trj] | FileHash-SHA256 0000ba467dd40046e240c11251d9db03636d0e7c6f9f96354a46a441c2003143",
            "allocates_execute_remote_process \u2022 injection_write_memory \u2022 injection_resumethread \u2022 packer_entropy \u2022 network _icmp \u2022 injection_runpe",
            "injection_write_memory_exe \u2022 injection_ntsetcontextthread \u2022 dumped_buffer \u2022 checks_debugger \u2022 generates_crypto_key  \u2022 antivm_memory_available",
            "CnC IP Addresses: 104.247.81.53 \u2022 185.64.219.6 \u2022 199.191.50.82 \u2022 203.107.45.167 \u2022 91.195.240.94 \u2022 167.235.143.33",
            "AA47 More AV Detection Ratio 984  / 1000 IDS Detections Win32.Renos/ArtroMALWARETrojan Checkin M1 Possible Fake AV Checkin Fakealert. AA47 More AV Detection Ratio 984  / 1000 IDS Detections /Trojan Checkin M1 Possible Fake AV Checkin Fakealert.",
            "Videolal: 18.119.154.66:80 (endpoint request) \u2022 54.209.32.212 \u2022 http://videolal.com (phishing) \u2022 http://videolal.com/ \u2022 videolal.com \u2022 www.videolal.com \u2022",
            "www.videolal.com \u2022 httpvideolal.com \u2022 https://videolal.com/videos/jeffrey-reimer-dpt-assaulted-tsara-brashears-massage-sexual-misconduct.html",
            "https://www.hugedomains.com/domain_profile.cfm?d=videolal.com \u2022 https://www.hugedomains.com/domain_profile.cfm?d=videolal.com\"",
            "https://videolal.com/videos/jeffrey-reimer-dpt-assaulted-tsara-brashears-massage-misconduct-miscinception.html \u2022",
            "https://videolal.com/videos/jeffrey-reimer-dpt-assaulted-tsara-brashears-massage-sexual-misconduct-miscinception.html",
            "https://videolal.com/videos/tsara-brashears-assaulted-by-jeffrey-reimer-metlife-login-retirement.html \u2022 https://videolal.com/css/js/jquery-ui.min.js",
            "https://videolal.com/videos/tsara-brashears-dead-by-daylight.html \u2022 https://videolal.com/css/jquery-ui.css \u2022 http://videolal.com/tsara-brashears.html",
            "http://videolal.com/tsara-brashears-dead.html \u2022 http://videolal.com/tsara-brashears.html \u2022 http://videolal.com/videos/jeffrey-reimer-dpt-assaulted-tsara-brashears-massage-misconduct-miscinception.html",
            "http://videolal.com/videos/jeffrey-reimer-dpt-assaulted-tsara-brashears-massage-misconduct-miscinception.html",
            "http://videolal.com/jeffrey-reimer-dpt-sexual-misconduct.html \u2022 http://videolal.com/tsara-brashears.html",
            "http://videolal.com/tsara-brashears-dead-or-alive-song-rap.html \u2022 http://videolal.com/the-man-who-built-america-1.html",
            "http://videolal.com/the-man-who-built-america-1.html \u2022 http://videolal.com/pinnacol-assurance-assaulted-by-jeffrey-",
            "http://videolal.com/jeffrey-reimer-dpt-physical-therapy-assaulted-patient.html \u2022 http://videolal.com/jeff-reimer-",
            "http://videolal.com/jeffrey-reimer-dpt-assaulted-tsara-brashears-denver.html \u2022",
            "http://videolal.com/jeff-reimer-dpt-buys-assault-victims-silence.html \u2022 http://videolal.com/jeffrey-reimer-dpt-assaulted-tsara-brashears-denver.html",
            "https://otx.alienvault.com/otxapi/indicators/file/screenshot/4998a7eac2a056833d01ee1e60c68c1f83f9ad6cd790ced9511e73cc12780f3c",
            "https://otx.alienvault.com/malware/Trojan:Win32%2FCrypterX/",
            "\u2192https://otx.alienvault.com/pulse/65eedf74b7bdda41057bef3e",
            "\u2192https://otx.alienvault.com/pulse/65ef3723d27863fc33a6b671",
            "\u2192https://otx.alienvault.com/pulse/65e85fd4842119fff4e327cf",
            "\u2192https://otx.alienvault.com/pulse/65e843669f4ba77affa4b297"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "Win32:CrypterX-gen\\ [Trj]",
              "display_name": "Win32:CrypterX-gen\\ [Trj]",
              "target": null
            },
            {
              "id": "Other:Malware-gen\\ [Trj]",
              "display_name": "Other:Malware-gen\\ [Trj]",
              "target": null
            },
            {
              "id": "Artro",
              "display_name": "Artro",
              "target": null
            },
            {
              "id": "Win32.Renos/Artro",
              "display_name": "Win32.Renos/Artro",
              "target": null
            },
            {
              "id": "Generic",
              "display_name": "Generic",
              "target": null
            },
            {
              "id": "I-Worm/Bagle.QE",
              "display_name": "I-Worm/Bagle.QE",
              "target": null
            },
            {
              "id": "Worm.Bagle-44",
              "display_name": "Worm.Bagle-44",
              "target": null
            },
            {
              "id": "TrojanSpy",
              "display_name": "TrojanSpy",
              "target": null
            },
            {
              "id": "TrojanSpy:Win32/Nivdort.DE",
              "display_name": "TrojanSpy:Win32/Nivdort.DE",
              "target": "/malware/TrojanSpy:Win32/Nivdort.DE"
            },
            {
              "id": "Win.Trojan.Generic-9897526-0",
              "display_name": "Win.Trojan.Generic-9897526-0",
              "target": null
            },
            {
              "id": "Win.Trojan.Knigsfot-125",
              "display_name": "Win.Trojan.Knigsfot-125",
              "target": null
            },
            {
              "id": "ALF:TrojanDownloader:Win32/Vadokrist.A",
              "display_name": "ALF:TrojanDownloader:Win32/Vadokrist.A",
              "target": null
            },
            {
              "id": "Win.Trojan.Generic-9957168-0",
              "display_name": "Win.Trojan.Generic-9957168-0",
              "target": null
            },
            {
              "id": "Win.Adware.RelevantKnowledge-9821121-0",
              "display_name": "Win.Adware.RelevantKnowledge-9821121-0",
              "target": null
            },
            {
              "id": "ALF:HeraklezEval:Trojan:Win32/Neurevt",
              "display_name": "ALF:HeraklezEval:Trojan:Win32/Neurevt",
              "target": null
            },
            {
              "id": "FormBook",
              "display_name": "FormBook",
              "target": null
            },
            {
              "id": "HackTool",
              "display_name": "HackTool",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1041",
              "name": "Exfiltration Over C2 Channel",
              "display_name": "T1041 - Exfiltration Over C2 Channel"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1100",
              "name": "Web Shell",
              "display_name": "T1100 - Web Shell"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1114",
              "name": "Email Collection",
              "display_name": "T1114 - Email Collection"
            },
            {
              "id": "T1560",
              "name": "Archive Collected Data",
              "display_name": "T1560 - Archive Collected Data"
            },
            {
              "id": "T1059.007",
              "name": "JavaScript",
              "display_name": "T1059.007 - JavaScript"
            },
            {
              "id": "T1071.003",
              "name": "Mail Protocols",
              "display_name": "T1071.003 - Mail Protocols"
            },
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1071.004",
              "name": "DNS",
              "display_name": "T1071.004 - DNS"
            },
            {
              "id": "T1063",
              "name": "Security Software Discovery",
              "display_name": "T1063 - Security Software Discovery"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 42,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 1622,
            "FileHash-SHA1": 934,
            "FileHash-SHA256": 3289,
            "URL": 9605,
            "domain": 2321,
            "hostname": 2411,
            "CVE": 1,
            "email": 3
          },
          "indicator_count": 20186,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 223,
          "modified_text": "780 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "659331580cd1571f730b8de2",
          "name": "Agent Tesla | Spyware | Tracking Android & Apple users | Malware Attack",
          "description": "",
          "modified": "2024-01-31T14:03:30.344000",
          "created": "2024-01-01T21:40:40.242000",
          "tags": [
            "maxads0",
            "kld1063",
            "ioc search",
            "new ioc",
            "teams api",
            "contact",
            "threat analyzer",
            "threat",
            "paste",
            "iocs",
            "hostnames",
            "urls http",
            "ssl certificate",
            "whois record",
            "contacted",
            "referrer",
            "historical ssl",
            "march",
            "communicating",
            "copy",
            "january",
            "collections",
            "execution",
            "malware",
            "startpage",
            "malicious",
            "ransomware",
            "agent tesla",
            "attack",
            "android",
            "name verdict",
            "falcon sandbox",
            "reports",
            "falcon",
            "windir",
            "path",
            "programfiles",
            "pe32",
            "ms windows",
            "getprocaddress",
            "file type",
            "mitre att",
            "ck id",
            "show technique",
            "win64",
            "date",
            "open",
            "hybrid",
            "cookie",
            "tracking",
            "apple",
            "spyware",
            "malware",
            "tablet",
            "superwebbysearch",
            "hallrender",
            "pegasus",
            "briansabey",
            "aig",
            "abuse",
            "tulach"
          ],
          "references": [
            "findbetterresults.com",
            "https://hybrid-analysis.com/sample/bba36b3ae7c49d1cffcc5f8e045d81e9307a2e1a86b923f89008e9377d171fb6",
            "https://www.virustotal.com/gui/url/eed406872c2e6ef550b948510fe0b7b4c71f752f58551c2f8e61d31a19d2a153/summary",
            "http://www.applerewards.website/pl/3/index.html?voluumdata=BASE64dmlkLi4wMDAwMDAwMi00NGFiLTQzNDktODAwMC0wMDAwMDAwMDAwMDBfX3ZwaWQuLjJhYWQzMDAwLWJiMzYtMTFlNi04YTYyLTBlYzcxZTllMDMzMV9fY2FpZC4uNjBhMjIwOWUtNWMzNC00OGQ4LWIyNDctYWM5YzVkOTM3MzZhX19ydC4uUl9fbGlkLi4yYTRjOTA4My0zY2RmLTQyNDktOGJmOS0yODMxZWYzNGRhYTlfX29pZDEuLjUwMGE4NDhjLTA2NGEtNDYyZi05MDNmLTgxYzY4ODNmODEwZl9fdmFyMS4uNjA4OTYxX192YXIyLi42NzEwMjhfX3JkLi5vbmNsaWNrYWRzXC5cbmV0X19haWQuLl9fYWIuLl9fc2lkLi4&zoneid=608961&campaignid=671028&visitor_id=4003954",
            "www2.megawebfind.com                [command_and_control]",
            "https://search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas_sfp&command=   [command_and_control]   stolec kradnie krypto"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Agent Tesla",
              "display_name": "Agent Tesla",
              "target": null
            },
            {
              "id": "Ransomware",
              "display_name": "Ransomware",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1012",
              "name": "Query Registry",
              "display_name": "T1012 - Query Registry"
            },
            {
              "id": "T1033",
              "name": "System Owner/User Discovery",
              "display_name": "T1033 - System Owner/User Discovery"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1053",
              "name": "Scheduled Task/Job",
              "display_name": "T1053 - Scheduled Task/Job"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1070",
              "name": "Indicator Removal on Host",
              "display_name": "T1070 - Indicator Removal on Host"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1074",
              "name": "Data Staged",
              "display_name": "T1074 - Data Staged"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1112",
              "name": "Modify Registry",
              "display_name": "T1112 - Modify Registry"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1218",
              "name": "Signed Binary Proxy Execution",
              "display_name": "T1218 - Signed Binary Proxy Execution"
            },
            {
              "id": "T1518",
              "name": "Software Discovery",
              "display_name": "T1518 - Software Discovery"
            },
            {
              "id": "T1614",
              "name": "System Location Discovery",
              "display_name": "T1614 - System Location Discovery"
            },
            {
              "id": "TA0011",
              "name": "Command and Control",
              "display_name": "TA0011 - Command and Control"
            },
            {
              "id": "T1155",
              "name": "AppleScript",
              "display_name": "T1155 - AppleScript"
            },
            {
              "id": "T1449",
              "name": "Exploit SS7 to Redirect Phone Calls/SMS",
              "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
            },
            {
              "id": "T1031",
              "name": "Modify Existing Service",
              "display_name": "T1031 - Modify Existing Service"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 24,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 2368,
            "FileHash-SHA256": 4539,
            "hostname": 2892,
            "URL": 9741,
            "FileHash-MD5": 836,
            "FileHash-SHA1": 461,
            "CVE": 1
          },
          "indicator_count": 20838,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 222,
          "modified_text": "851 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "659331589faf01b909c1802d",
          "name": "Agent Tesla | Spyware | Tracking Android & Apple users | Malware Attack",
          "description": "",
          "modified": "2024-01-31T14:03:30.344000",
          "created": "2024-01-01T21:40:40.413000",
          "tags": [
            "maxads0",
            "kld1063",
            "ioc search",
            "new ioc",
            "teams api",
            "contact",
            "threat analyzer",
            "threat",
            "paste",
            "iocs",
            "hostnames",
            "urls http",
            "ssl certificate",
            "whois record",
            "contacted",
            "referrer",
            "historical ssl",
            "march",
            "communicating",
            "copy",
            "january",
            "collections",
            "execution",
            "malware",
            "startpage",
            "malicious",
            "ransomware",
            "agent tesla",
            "attack",
            "android",
            "name verdict",
            "falcon sandbox",
            "reports",
            "falcon",
            "windir",
            "path",
            "programfiles",
            "pe32",
            "ms windows",
            "getprocaddress",
            "file type",
            "mitre att",
            "ck id",
            "show technique",
            "win64",
            "date",
            "open",
            "hybrid",
            "cookie",
            "tracking",
            "apple",
            "spyware",
            "malware",
            "tablet",
            "superwebbysearch",
            "hallrender",
            "pegasus",
            "briansabey",
            "aig",
            "abuse",
            "tulach"
          ],
          "references": [
            "findbetterresults.com",
            "https://hybrid-analysis.com/sample/bba36b3ae7c49d1cffcc5f8e045d81e9307a2e1a86b923f89008e9377d171fb6",
            "https://www.virustotal.com/gui/url/eed406872c2e6ef550b948510fe0b7b4c71f752f58551c2f8e61d31a19d2a153/summary",
            "http://www.applerewards.website/pl/3/index.html?voluumdata=BASE64dmlkLi4wMDAwMDAwMi00NGFiLTQzNDktODAwMC0wMDAwMDAwMDAwMDBfX3ZwaWQuLjJhYWQzMDAwLWJiMzYtMTFlNi04YTYyLTBlYzcxZTllMDMzMV9fY2FpZC4uNjBhMjIwOWUtNWMzNC00OGQ4LWIyNDctYWM5YzVkOTM3MzZhX19ydC4uUl9fbGlkLi4yYTRjOTA4My0zY2RmLTQyNDktOGJmOS0yODMxZWYzNGRhYTlfX29pZDEuLjUwMGE4NDhjLTA2NGEtNDYyZi05MDNmLTgxYzY4ODNmODEwZl9fdmFyMS4uNjA4OTYxX192YXIyLi42NzEwMjhfX3JkLi5vbmNsaWNrYWRzXC5cbmV0X19haWQuLl9fYWIuLl9fc2lkLi4&zoneid=608961&campaignid=671028&visitor_id=4003954",
            "www2.megawebfind.com                [command_and_control]",
            "https://search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas_sfp&command=   [command_and_control]   stolec kradnie krypto"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Agent Tesla",
              "display_name": "Agent Tesla",
              "target": null
            },
            {
              "id": "Ransomware",
              "display_name": "Ransomware",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1012",
              "name": "Query Registry",
              "display_name": "T1012 - Query Registry"
            },
            {
              "id": "T1033",
              "name": "System Owner/User Discovery",
              "display_name": "T1033 - System Owner/User Discovery"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1053",
              "name": "Scheduled Task/Job",
              "display_name": "T1053 - Scheduled Task/Job"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1070",
              "name": "Indicator Removal on Host",
              "display_name": "T1070 - Indicator Removal on Host"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1074",
              "name": "Data Staged",
              "display_name": "T1074 - Data Staged"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1106",
              "name": "Native API",
              "display_name": "T1106 - Native API"
            },
            {
              "id": "T1112",
              "name": "Modify Registry",
              "display_name": "T1112 - Modify Registry"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1218",
              "name": "Signed Binary Proxy Execution",
              "display_name": "T1218 - Signed Binary Proxy Execution"
            },
            {
              "id": "T1518",
              "name": "Software Discovery",
              "display_name": "T1518 - Software Discovery"
            },
            {
              "id": "T1614",
              "name": "System Location Discovery",
              "display_name": "T1614 - System Location Discovery"
            },
            {
              "id": "TA0011",
              "name": "Command and Control",
              "display_name": "TA0011 - Command and Control"
            },
            {
              "id": "T1155",
              "name": "AppleScript",
              "display_name": "T1155 - AppleScript"
            },
            {
              "id": "T1449",
              "name": "Exploit SS7 to Redirect Phone Calls/SMS",
              "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
            },
            {
              "id": "T1031",
              "name": "Modify Existing Service",
              "display_name": "T1031 - Modify Existing Service"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 29,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 2368,
            "FileHash-SHA256": 4539,
            "hostname": 2892,
            "URL": 9741,
            "FileHash-MD5": 836,
            "FileHash-SHA1": 461,
            "CVE": 1
          },
          "indicator_count": 20838,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 221,
          "modified_text": "851 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "655d0ec7b7cb12c66cac457d",
          "name": "https://mypornwap.fun/downloads/5/search/white-dpt-jeffrey-reimer-loves-pretty-indian-patient-forces-sex-3gp-video-tsara-brashears-gzip",
          "description": "Exploit\nContains escaped byte string (often part of obfuscated shellcode), Malicious\nhttps://www.profitabledisplaycontent.com/watch.375255570190.js, Malvertizing a true crime, child pornographer.\n\nSource: https://mypornwap.fun/downloads/5/search/white-dpt-jeffrey-reimer-loves-pretty-indian-patient-forces-sex-3gp-video-tsara-brashears-gzip\n\nResource: https://www.hybrid-analysis.com/sample/f0233084bd810eb266cd29a879dc58d84c2a85032ba58b4b50d5643e7a41a144/655cf15b9f12303f990942e9",
          "modified": "2023-12-21T19:03:27.243000",
          "created": "2023-11-21T20:10:47.792000",
          "tags": [
            "cins active",
            "poor reputation",
            "host",
            "threats et",
            "ip tcp",
            "detection list",
            "ip address",
            "blacklist",
            "macedonia",
            "former yugoslav",
            "site",
            "cisco umbrella",
            "alexa top",
            "million",
            "alexa",
            "threat report",
            "ip summary",
            "url summary",
            "summary",
            "sample",
            "samples",
            "paypal",
            "team phishing",
            "blacknet rat",
            "loki password",
            "stealer",
            "malicious url",
            "malicious site",
            "azorult",
            "phishing",
            "service",
            "runescape",
            "facebook",
            "bank",
            "download",
            "blacknet",
            "site top",
            "million alexa",
            "safe site",
            "malware",
            "genpack",
            "deepscan",
            "cobalt strike",
            "malicious",
            "zbot",
            "memscan",
            "cl0p",
            "cyber threat",
            "heur",
            "engineering",
            "united",
            "covid19",
            "malicious host",
            "team",
            "virut",
            "nymaim",
            "pony",
            "ransomware",
            "bradesco",
            "opencandy",
            "ramnit",
            "adload",
            "simda",
            "zeus",
            "pykspa",
            "riskware",
            "generic",
            "artemis",
            "downldr",
            "binder",
            "sutra",
            "steam",
            "asyncrat",
            "revengerat",
            "downloader",
            "exploit",
            "emailworm",
            "agent",
            "tinba",
            "maltiverse safe",
            "generic malware",
            "phishing site",
            "outbrowse",
            "suppobox",
            "vawtrak",
            "solimba",
            "wacatac",
            "msil",
            "outbreak",
            "installcore",
            "acint",
            "conduit",
            "installpack",
            "iobit",
            "dropper",
            "mediaget",
            "crack",
            "blacklist http",
            "ascii text",
            "nysp",
            "appdata",
            "jpeg image",
            "jfif standard",
            "file",
            "0xeae6b5",
            "function",
            "0x308d49",
            "x6a4",
            "push",
            "shift",
            "cookie",
            "slice",
            "path",
            "window",
            "error",
            "false",
            "hybrid",
            "crypto",
            "open",
            "blank",
            "template",
            "target",
            "trim",
            "write",
            "period",
            "touchmove",
            "click",
            "close",
            "body",
            "screen",
            "android",
            "canvas",
            "class",
            "span",
            "trident",
            "accept",
            "general",
            "local",
            "html",
            "unsafe",
            "downer",
            "shell",
            "mediamagnet",
            "sality",
            "swrort",
            "adaptivebee",
            "unruy",
            "trojanx",
            "webshell",
            "iframe",
            "patcher",
            "driverpack",
            "union",
            "maltiverse",
            "blacklist https",
            "google",
            "noname057",
            "redlinestealer"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "BlackNET",
              "display_name": "BlackNET",
              "target": null
            },
            {
              "id": "Cl0p",
              "display_name": "Cl0p",
              "target": null
            },
            {
              "id": "Maltiverse",
              "display_name": "Maltiverse",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 69,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 884,
            "hostname": 1809,
            "FileHash-MD5": 635,
            "FileHash-SHA1": 321,
            "FileHash-SHA256": 2079,
            "CVE": 16,
            "URL": 6434
          },
          "indicator_count": 12178,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 221,
          "modified_text": "892 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "655d0edbb8c22bcb4e5969b8",
          "name": "https://mypornwap.fun/downloads/5/search/white-dpt-jeffrey-reimer-loves-pretty-indian-patient-forces-sex-3gp-video-tsara-brashears-gzip",
          "description": "Exploit\nContains escaped byte string (often part of obfuscated shellcode), Malicious\nhttps://www.profitabledisplaycontent.com/watch.375255570190.js, Malvertizing a true crime, child pornographer.\n\nSource: https://mypornwap.fun/downloads/5/search/white-dpt-jeffrey-reimer-loves-pretty-indian-patient-forces-sex-3gp-video-tsara-brashears-gzip\n\nResource: https://www.hybrid-analysis.com/sample/f0233084bd810eb266cd29a879dc58d84c2a85032ba58b4b50d5643e7a41a144/655cf15b9f12303f990942e9",
          "modified": "2023-12-21T19:03:27.243000",
          "created": "2023-11-21T20:11:07.064000",
          "tags": [
            "cins active",
            "poor reputation",
            "host",
            "threats et",
            "ip tcp",
            "detection list",
            "ip address",
            "blacklist",
            "macedonia",
            "former yugoslav",
            "site",
            "cisco umbrella",
            "alexa top",
            "million",
            "alexa",
            "threat report",
            "ip summary",
            "url summary",
            "summary",
            "sample",
            "samples",
            "paypal",
            "team phishing",
            "blacknet rat",
            "loki password",
            "stealer",
            "malicious url",
            "malicious site",
            "azorult",
            "phishing",
            "service",
            "runescape",
            "facebook",
            "bank",
            "download",
            "blacknet",
            "site top",
            "million alexa",
            "safe site",
            "malware",
            "genpack",
            "deepscan",
            "cobalt strike",
            "malicious",
            "zbot",
            "memscan",
            "cl0p",
            "cyber threat",
            "heur",
            "engineering",
            "united",
            "covid19",
            "malicious host",
            "team",
            "virut",
            "nymaim",
            "pony",
            "ransomware",
            "bradesco",
            "opencandy",
            "ramnit",
            "adload",
            "simda",
            "zeus",
            "pykspa",
            "riskware",
            "generic",
            "artemis",
            "downldr",
            "binder",
            "sutra",
            "steam",
            "asyncrat",
            "revengerat",
            "downloader",
            "exploit",
            "emailworm",
            "agent",
            "tinba",
            "maltiverse safe",
            "generic malware",
            "phishing site",
            "outbrowse",
            "suppobox",
            "vawtrak",
            "solimba",
            "wacatac",
            "msil",
            "outbreak",
            "installcore",
            "acint",
            "conduit",
            "installpack",
            "iobit",
            "dropper",
            "mediaget",
            "crack",
            "blacklist http",
            "ascii text",
            "nysp",
            "appdata",
            "jpeg image",
            "jfif standard",
            "file",
            "0xeae6b5",
            "function",
            "0x308d49",
            "x6a4",
            "push",
            "shift",
            "cookie",
            "slice",
            "path",
            "window",
            "error",
            "false",
            "hybrid",
            "crypto",
            "open",
            "blank",
            "template",
            "target",
            "trim",
            "write",
            "period",
            "touchmove",
            "click",
            "close",
            "body",
            "screen",
            "android",
            "canvas",
            "class",
            "span",
            "trident",
            "accept",
            "general",
            "local",
            "html",
            "unsafe",
            "downer",
            "shell",
            "mediamagnet",
            "sality",
            "swrort",
            "adaptivebee",
            "unruy",
            "trojanx",
            "webshell",
            "iframe",
            "patcher",
            "driverpack",
            "union",
            "maltiverse",
            "blacklist https",
            "google",
            "noname057",
            "redlinestealer"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "BlackNET",
              "display_name": "BlackNET",
              "target": null
            },
            {
              "id": "Cl0p",
              "display_name": "Cl0p",
              "target": null
            },
            {
              "id": "Maltiverse",
              "display_name": "Maltiverse",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 68,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 884,
            "hostname": 1809,
            "FileHash-MD5": 635,
            "FileHash-SHA1": 321,
            "FileHash-SHA256": 2079,
            "CVE": 16,
            "URL": 6434
          },
          "indicator_count": 12178,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 222,
          "modified_text": "892 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "655d0f94ad4d7cdc5e3f0a98",
          "name": "BlackNET",
          "description": "Exploit\nContains escaped byte string (often part of obfuscated shellcode), Malicious\nhttps://www.profitabledisplaycontent.com/watch.375255570190.js, Malvertizing a true crime, child pornographer.\n\nSource: https://mypornwap.fun/downloads/5/search/white-dpt-jeffrey-reimer-loves-pretty-indian-patient-forces-sex-3gp-video-tsara-brashears-gzip\n\nResource: https://www.hybrid-analysis.com/sample/f0233084bd810eb266cd29a879dc58d84c2a85032ba58b4b50d5643e7a41a144/655cf15b9f12303f990942e9",
          "modified": "2023-12-21T19:03:27.243000",
          "created": "2023-11-21T20:14:12.454000",
          "tags": [
            "cins active",
            "poor reputation",
            "host",
            "threats et",
            "ip tcp",
            "detection list",
            "ip address",
            "blacklist",
            "macedonia",
            "former yugoslav",
            "site",
            "cisco umbrella",
            "alexa top",
            "million",
            "alexa",
            "threat report",
            "ip summary",
            "url summary",
            "summary",
            "sample",
            "samples",
            "paypal",
            "team phishing",
            "blacknet rat",
            "loki password",
            "stealer",
            "malicious url",
            "malicious site",
            "azorult",
            "phishing",
            "service",
            "runescape",
            "facebook",
            "bank",
            "download",
            "blacknet",
            "site top",
            "million alexa",
            "safe site",
            "malware",
            "genpack",
            "deepscan",
            "cobalt strike",
            "malicious",
            "zbot",
            "memscan",
            "cl0p",
            "cyber threat",
            "heur",
            "engineering",
            "united",
            "covid19",
            "malicious host",
            "team",
            "virut",
            "nymaim",
            "pony",
            "ransomware",
            "bradesco",
            "opencandy",
            "ramnit",
            "adload",
            "simda",
            "zeus",
            "pykspa",
            "riskware",
            "generic",
            "artemis",
            "downldr",
            "binder",
            "sutra",
            "steam",
            "asyncrat",
            "revengerat",
            "downloader",
            "exploit",
            "emailworm",
            "agent",
            "tinba",
            "maltiverse safe",
            "generic malware",
            "phishing site",
            "outbrowse",
            "suppobox",
            "vawtrak",
            "solimba",
            "wacatac",
            "msil",
            "outbreak",
            "installcore",
            "acint",
            "conduit",
            "installpack",
            "iobit",
            "dropper",
            "mediaget",
            "crack",
            "blacklist http",
            "ascii text",
            "nysp",
            "appdata",
            "jpeg image",
            "jfif standard",
            "file",
            "0xeae6b5",
            "function",
            "0x308d49",
            "x6a4",
            "push",
            "shift",
            "cookie",
            "slice",
            "path",
            "window",
            "error",
            "false",
            "hybrid",
            "crypto",
            "open",
            "blank",
            "template",
            "target",
            "trim",
            "write",
            "period",
            "touchmove",
            "click",
            "close",
            "body",
            "screen",
            "android",
            "canvas",
            "class",
            "span",
            "trident",
            "accept",
            "general",
            "local",
            "html",
            "unsafe",
            "downer",
            "shell",
            "mediamagnet",
            "sality",
            "swrort",
            "adaptivebee",
            "unruy",
            "trojanx",
            "webshell",
            "iframe",
            "patcher",
            "driverpack",
            "union",
            "maltiverse",
            "blacklist https",
            "google",
            "noname057",
            "redlinestealer"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [
            {
              "id": "BlackNET",
              "display_name": "BlackNET",
              "target": null
            },
            {
              "id": "Cl0p",
              "display_name": "Cl0p",
              "target": null
            },
            {
              "id": "Maltiverse",
              "display_name": "Maltiverse",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 73,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "OctoSeek",
            "id": "243548",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 884,
            "hostname": 1809,
            "FileHash-MD5": 635,
            "FileHash-SHA1": 321,
            "FileHash-SHA256": 2079,
            "CVE": 16,
            "URL": 6434
          },
          "indicator_count": 12178,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 227,
          "modified_text": "892 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6570914fe73d6efb17198812",
          "name": "https://areyou1or0.com/ - just like a lucky dip",
          "description": "",
          "modified": "2023-12-06T15:20:47.515000",
          "created": "2023-12-06T15:20:47.515000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "CVE": 2,
            "hostname": 496,
            "FileHash-SHA256": 351,
            "FileHash-MD5": 56,
            "FileHash-SHA1": 50,
            "URL": 2028,
            "domain": 711,
            "email": 1
          },
          "indicator_count": 3695,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "907 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "65708e7ca78fb9ed8bda43d0",
          "name": "Part 2 of the small sub section post - This a sample of the infrastructure on the perimeter of each of those controlled websrv and devuces on home lans",
          "description": "",
          "modified": "2023-12-06T15:08:44.795000",
          "created": "2023-12-06T15:08:44.795000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "CVE": 19,
            "hostname": 404,
            "FileHash-SHA256": 1484,
            "FileHash-SHA1": 1,
            "URL": 1141,
            "domain": 202,
            "FileHash-MD5": 1
          },
          "indicator_count": 3252,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 110,
          "modified_text": "907 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "62f578d9bd71fef18276273b",
          "name": "https://areyou1or0.com/ - just like a lucky dip",
          "description": "",
          "modified": "2022-09-10T00:03:24.542000",
          "created": "2022-08-11T21:47:05.669000",
          "tags": [
            "https://areyou1or0.com/",
            "http://direct.digitallanding.com/javascript/9.5.11.0/en-US/strin"
          ],
          "references": [
            "g09925ed356e14431a1e64a663b9575c0939804b376704d96b75c2aea4245b05d.json",
            "http://direct.digitallanding.com/javascript/9.5.11.0/en-US/strings.js"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 9,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "dorkingbeauty1",
            "id": "80137",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 2047,
            "FileHash-SHA256": 351,
            "hostname": 503,
            "domain": 724,
            "CVE": 2,
            "FileHash-MD5": 56,
            "FileHash-SHA1": 50,
            "email": 1
          },
          "indicator_count": 3734,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 395,
          "modified_text": "1359 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6286f196943a5ae10bc4e72c",
          "name": "Part 2 of the small sub section post - This a sample of the infrastructure on the perimeter of each of those controlled websrv and devuces on home lans",
          "description": "",
          "modified": "2022-06-19T00:05:22.053000",
          "created": "2022-05-20T01:40:38.150000",
          "tags": [],
          "references": [
            "layer 2"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 8,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "dorkingbeauty1",
            "id": "80137",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 404,
            "FileHash-SHA256": 1484,
            "URL": 1141,
            "domain": 202,
            "CVE": 19,
            "FileHash-MD5": 1,
            "FileHash-SHA1": 1
          },
          "indicator_count": 3252,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 395,
          "modified_text": "1442 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "http://videolal.com/tsara-brashears-dead.html \u2022 http://videolal.com/ \u2022",
        "\u2192https://otx.alienvault.com/pulse/65ef3723d27863fc33a6b671",
        "http://direct.digitallanding.com/javascript/9.5.11.0/en-US/strings.js",
        "\u2192https://otx.alienvault.com/pulse/65e85fd4842119fff4e327cf",
        "http://videolal.com/jeffrey-reimer-dpt-physical-therapy-assaulted-patient.html \u2022 http://videolal.com/jeff-reimer-",
        "Win32:CrypterX-gen\\ [Trj] | FileHash-MD5   6878e9896fdd84dcc11c997c9b7330ba",
        "g09925ed356e14431a1e64a663b9575c0939804b376704d96b75c2aea4245b05d.json",
        "672469157e58844350382fd51bc0fee1605982609c1f80a0b3df3906fbeb49a3.csv",
        "http://videolal.com/jeff-reimer-dpt-buys-assault-victims-silence.html \u2022 http://videolal.com/jeffrey-reimer-dpt-assaulted-tsara-brashears-denver.html",
        "Win32:CrypterX-gen\\ [Trj] | FileHash-SHA1   2e586f8db46953532b5e25e07add4dbaeea83a79",
        "william.ballenthin@fireeye.com contain a resource (.rsrc) section\tmoritz.raabe@fireeye.com | Pattern match: \"jloup@gzip.org\" & \"fancybox@3.5.7\"",
        "Other:Malware-gen\\ [Trj] | FileHash-SHA256 0000ba467dd40046e240c11251d9db03636d0e7c6f9f96354a46a441c2003143",
        "http://systemforex.de/search/redirect.php?f= | http://it.marksypark.com | dont-delete.hugedomains.com | http://selfsparkcentral.com",
        "www.videolal.com \u2022 httpvideolal.com \u2022 https://videolal.com/videos/jeffrey-reimer-dpt-assaulted-tsara-brashears-massage-sexual-misconduct.html",
        "\u2192https://otx.alienvault.com/pulse/65eedf74b7bdda41057bef3e",
        "AA47 More AV Detection Ratio 984  / 1000 IDS Detections Win32.Renos/ArtroMALWARETrojan Checkin M1 Possible Fake AV Checkin Fakealert. AA47 More AV Detection Ratio 984  / 1000 IDS Detections /Trojan Checkin M1 Possible Fake AV Checkin Fakealert.",
        "Win32:CrypterX-gen\\ [Trj] | FileHash-SHA256  00027d11309d55312ae77f32d4ae79671c91f541e577bace7a5a5abde05563ad",
        "\u2192https://otx.alienvault.com/pulse/65e843669f4ba77affa4b297",
        "CnC IP Addresses: 104.247.81.53 \u2022 185.64.219.6 \u2022 199.191.50.82 \u2022 203.107.45.167 \u2022 91.195.240.94 \u2022 167.235.143.33",
        "allocates_execute_remote_process \u2022 injection_write_memory \u2022 injection_resumethread \u2022 packer_entropy \u2022 network _icmp \u2022 injection_runpe",
        "layer 2",
        "Videolal: 18.119.154.66:80 (endpoint request) \u2022 54.209.32.212 \u2022 http://videolal.com (phishing) \u2022 http://videolal.com/ \u2022 videolal.com \u2022 www.videolal.com \u2022",
        "http://videolal.com/jeffrey-reimer-dpt-sexual-misconduct.html \u2022 http://videolal.com/tsara-brashears.html",
        "http://videolal.com/tsara-brashears-dead-or-alive-song-rap.html \u2022 http://videolal.com/the-man-who-built-america-1.html",
        "injection_write_memory_exe \u2022 injection_ntsetcontextthread \u2022 dumped_buffer \u2022 checks_debugger \u2022 generates_crypto_key  \u2022 antivm_memory_available",
        "https://search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas_sfp&command=   [command_and_control]   stolec kradnie krypto",
        "http://videolal.com/the-man-who-built-america-1.html \u2022 http://videolal.com/pinnacol-assurance-assaulted-by-jeffrey-",
        "https://videolal.com/videos/jeffrey-reimer-dpt-assaulted-tsara-brashears-massage-misconduct-miscinception.html \u2022",
        "https://otx.alienvault.com/otxapi/indicators/file/screenshot/4998a7eac2a056833d01ee1e60c68c1f83f9ad6cd790ced9511e73cc12780f3c",
        "https://www.virustotal.com/gui/url/eed406872c2e6ef550b948510fe0b7b4c71f752f58551c2f8e61d31a19d2a153/summary",
        "https://www.virustotal.com/gui/collection/672469157e58844350382fd51bc0fee1605982609c1f80a0b3df3906fbeb49a3/summary",
        "Other:Malware-gen\\ [Trj] | FileHash-SHA1 68868b3d0115e3d06f5fddb9d2ea6ad54270166c",
        "www2.megawebfind.com                [command_and_control]",
        "Other:Malware-gen\\ [Trj] | FileHash-MD5 b5168dab50187b33460201b35b96dea7",
        "http://www.applerewards.website/pl/3/index.html?voluumdata=BASE64dmlkLi4wMDAwMDAwMi00NGFiLTQzNDktODAwMC0wMDAwMDAwMDAwMDBfX3ZwaWQuLjJhYWQzMDAwLWJiMzYtMTFlNi04YTYyLTBlYzcxZTllMDMzMV9fY2FpZC4uNjBhMjIwOWUtNWMzNC00OGQ4LWIyNDctYWM5YzVkOTM3MzZhX19ydC4uUl9fbGlkLi4yYTRjOTA4My0zY2RmLTQyNDktOGJmOS0yODMxZWYzNGRhYTlfX29pZDEuLjUwMGE4NDhjLTA2NGEtNDYyZi05MDNmLTgxYzY4ODNmODEwZl9fdmFyMS4uNjA4OTYxX192YXIyLi42NzEwMjhfX3JkLi5vbmNsaWNrYWRzXC5cbmV0X19haWQuLl9fYWIuLl9fc2lkLi4&zoneid=608961&campaignid=671028&visitor_id=4003954",
        "http://videolal.com/videos/jeffrey-reimer-dpt-assaulted-tsara-brashears-massage-misconduct-miscinception.html",
        "findbetterresults.com",
        "https://videolal.com/videos/jeffrey-reimer-dpt-assaulted-tsara-brashears-massage-sexual-misconduct-miscinception.html",
        "https://www.hugedomains.com/domain_profile.cfm?d=videolal.com \u2022 https://www.hugedomains.com/domain_profile.cfm?d=videolal.com\"",
        "https://otx.alienvault.com/malware/Trojan:Win32%2FCrypterX/",
        "Win32/Renos: https://otx.alienvault.com/malware/ALF:JASYP:TrojanDownloader:Win32%2FRenos/",
        "FormBook: 104.247.81.53 \u2022 http://www.nimtax.com/k9/,Formbook,Medium,9/9/2019,1/7/2020",
        "https://videolal.com/videos/tsara-brashears-assaulted-by-jeffrey-reimer-metlife-login-retirement.html \u2022 https://videolal.com/css/js/jquery-ui.min.js",
        "https://videolal.com/videos/tsara-brashears-dead-by-daylight.html \u2022 https://videolal.com/css/jquery-ui.css \u2022 http://videolal.com/tsara-brashears.html",
        "https://hybrid-analysis.com/sample/bba36b3ae7c49d1cffcc5f8e045d81e9307a2e1a86b923f89008e9377d171fb6",
        "http://videolal.com/tsara-brashears-dead.html \u2022 http://videolal.com/tsara-brashears.html \u2022 http://videolal.com/videos/jeffrey-reimer-dpt-assaulted-tsara-brashears-massage-misconduct-miscinception.html",
        "http://videolal.com/jeffrey-reimer-dpt-assaulted-tsara-brashears-denver.html \u2022"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 0
        },
        "other": {
          "adversary": [],
          "malware_families": [
            "Other:malware-gen\\ [trj]",
            "Hacktool",
            "I-worm/bagle.qe",
            "Win32.renos/artro",
            "Maltiverse",
            "Alf:heraklezeval:trojan:win32/neurevt",
            "Cl0p",
            "Agent tesla",
            "Ransomware",
            "Alf:trojandownloader:win32/vadokrist.a",
            "Trojanspy:win32/nivdort.de",
            "Blacknet",
            "Win.adware.relevantknowledge-9821121-0",
            "Artro",
            "Win.trojan.generic-9957168-0",
            "Worm.bagle-44",
            "Formbook",
            "Win.trojan.knigsfot-125",
            "Trojanspy",
            "Win.trojan.generic-9897526-0",
            "Generic",
            "Win32:crypterx-gen\\ [trj]"
          ],
          "industries": [],
          "unique_indicators": 60132
        }
      }
    },
    "false_positive": [],
    "alexa": "http://www.alexa.com/siteinfo/wegardn.com",
    "whois": "http://whois.domaintools.com/wegardn.com",
    "domain": "wegardn.com",
    "hostname": "ww16.wegardn.com"
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 12,
  "pulses": [
    {
      "id": "66d8e7e014fc1110089effc7",
      "name": "UCRANIA AFECTACI\u00d3N 26-07-2022 (by sirowa7979) enriched",
      "description": "",
      "modified": "2025-06-16T13:56:26.068000",
      "created": "2024-09-04T23:06:08.626000",
      "tags": [],
      "references": [
        "672469157e58844350382fd51bc0fee1605982609c1f80a0b3df3906fbeb49a3.csv",
        "https://www.virustotal.com/gui/collection/672469157e58844350382fd51bc0fee1605982609c1f80a0b3df3906fbeb49a3/summary"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "Ukraine"
      ],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 1,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "skocherhan",
        "id": "249290",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_249290/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 67,
        "FileHash-SHA1": 67,
        "FileHash-SHA256": 449,
        "domain": 113,
        "hostname": 357,
        "URL": 1246,
        "CVE": 1
      },
      "indicator_count": 2300,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 184,
      "modified_text": "349 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "66c5dcd42da951f32ee24e0f",
      "name": "https://mypornwap.fun/downloads/5/search/white-dpt-jeffrey-reimer-loves-pretty-indian-patient-forces-sex-3gp-video-tsara-brashesrs",
      "description": "",
      "modified": "2024-08-21T12:25:56.328000",
      "created": "2024-08-21T12:25:56.328000",
      "tags": [
        "cins active",
        "poor reputation",
        "host",
        "threats et",
        "ip tcp",
        "detection list",
        "ip address",
        "blacklist",
        "macedonia",
        "former yugoslav",
        "site",
        "cisco umbrella",
        "alexa top",
        "million",
        "alexa",
        "threat report",
        "ip summary",
        "url summary",
        "summary",
        "sample",
        "samples",
        "paypal",
        "team phishing",
        "blacknet rat",
        "loki password",
        "stealer",
        "malicious url",
        "malicious site",
        "azorult",
        "phishing",
        "service",
        "runescape",
        "facebook",
        "bank",
        "download",
        "blacknet",
        "site top",
        "million alexa",
        "safe site",
        "malware",
        "genpack",
        "deepscan",
        "cobalt strike",
        "malicious",
        "zbot",
        "memscan",
        "cl0p",
        "cyber threat",
        "heur",
        "engineering",
        "united",
        "covid19",
        "malicious host",
        "team",
        "virut",
        "nymaim",
        "pony",
        "ransomware",
        "bradesco",
        "opencandy",
        "ramnit",
        "adload",
        "simda",
        "zeus",
        "pykspa",
        "riskware",
        "generic",
        "artemis",
        "downldr",
        "binder",
        "sutra",
        "steam",
        "asyncrat",
        "revengerat",
        "downloader",
        "exploit",
        "emailworm",
        "agent",
        "tinba",
        "maltiverse safe",
        "generic malware",
        "phishing site",
        "outbrowse",
        "suppobox",
        "vawtrak",
        "solimba",
        "wacatac",
        "msil",
        "outbreak",
        "installcore",
        "acint",
        "conduit",
        "installpack",
        "iobit",
        "dropper",
        "mediaget",
        "crack",
        "blacklist http",
        "ascii text",
        "nysp",
        "appdata",
        "jpeg image",
        "jfif standard",
        "file",
        "0xeae6b5",
        "function",
        "0x308d49",
        "x6a4",
        "push",
        "shift",
        "cookie",
        "slice",
        "path",
        "window",
        "error",
        "false",
        "hybrid",
        "crypto",
        "open",
        "blank",
        "template",
        "target",
        "trim",
        "write",
        "period",
        "touchmove",
        "click",
        "close",
        "body",
        "screen",
        "android",
        "canvas",
        "class",
        "span",
        "trident",
        "accept",
        "general",
        "local",
        "html",
        "unsafe",
        "downer",
        "shell",
        "mediamagnet",
        "sality",
        "swrort",
        "adaptivebee",
        "unruy",
        "trojanx",
        "webshell",
        "iframe",
        "patcher",
        "driverpack",
        "union",
        "maltiverse",
        "blacklist https",
        "google",
        "noname057",
        "redlinestealer"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "BlackNET",
          "display_name": "BlackNET",
          "target": null
        },
        {
          "id": "Cl0p",
          "display_name": "Cl0p",
          "target": null
        },
        {
          "id": "Maltiverse",
          "display_name": "Maltiverse",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": "655d0ec7b7cb12c66cac457d",
      "export_count": 22,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "scoreblue",
        "id": "254100",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_254100/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 884,
        "hostname": 1809,
        "FileHash-MD5": 635,
        "FileHash-SHA1": 321,
        "FileHash-SHA256": 2079,
        "CVE": 16,
        "URL": 6434
      },
      "indicator_count": 12178,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 228,
      "modified_text": "648 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "65eff46bdd371899ca5be7d7",
      "name": "CrypterX-gen | Video-lal.com | M. Brian Sabey \u2022 Hall Render | Rexxfield",
      "description": "Videolal results. Parked. Owner of domain has subsidiaries including Huge Domains. It's possible for attacker to post a 404 error page,  park, post it for sale, malvertize. HoneyPotBot? \n\nFireeye. A bit much. william.ballenthin@fireeye.com\t\ncontain a resource (.rsrc) section moritz.raabe@fireeye.com. Overkill. What would Scooby Doo? Scooby!? \nTarget reports opening her MacBook Pro after it was replaced by Apple. It hadn't been in use. She opened it, surprised it was on, automatically connected to a store wifi (she was home) A worker was typing away in terminal. Fought hacker for recordings app containing Jeffrey Reimers aggressions. She lost. Terrified she murdered her MacBook by drowning  & dismemberment. Big mistake. Cloned MacBook.  Clicked on links trigger malicious downloads, network & DNS issues.",
      "modified": "2024-04-11T04:01:24.166000",
      "created": "2024-03-12T06:21:31.484000",
      "tags": [
        "upatre malware",
        "rwi dtools",
        "page dow",
        "security",
        "bitfender",
        "yandex",
        "malware",
        "all octoseek",
        "av detections",
        "ids detections",
        "yara detections",
        "alerts",
        "file score",
        "fireeye",
        "injection",
        "worm",
        "trojan",
        "network",
        "poster",
        "honeybots",
        "united",
        "unknown",
        "win32upatre mar",
        "passive dns",
        "entries",
        "ipv4",
        "body",
        "artro",
        "generic malware",
        "formbook",
        "tag count",
        "threat report",
        "ip summary",
        "url summary",
        "generic",
        "hostnames",
        "pattern match",
        "ascii text",
        "png image",
        "root ca",
        "file",
        "authority",
        "indicator",
        "mitre att",
        "ck id",
        "class",
        "date",
        "enterprise",
        "hybrid",
        "accept",
        "general",
        "local",
        "click",
        "strings",
        "trident",
        "as47846",
        "germany unknown",
        "as2906 netflix",
        "scan endpoints",
        "domain",
        "urls",
        "files",
        "trojanspy",
        "mozilla",
        "dynamicloader",
        "medium",
        "title",
        "ms windows",
        "head",
        "intel",
        "inetsim http",
        "delete c",
        "show",
        "winnt",
        "copy",
        "powershell",
        "write",
        "next",
        "suspicious",
        "shop",
        "graph api",
        "status",
        "join",
        "vt community",
        "api key",
        "xcitium verdict",
        "cloud",
        "contacted",
        "contacted urls",
        "ssl certificate",
        "referrer",
        "historical ssl",
        "parent domain",
        "apple ios",
        "resolutions",
        "execution",
        "hacktool",
        "outbound connection",
        "detection list",
        "blacklist"
      ],
      "references": [
        "http://videolal.com/tsara-brashears-dead.html \u2022 http://videolal.com/ \u2022",
        "http://systemforex.de/search/redirect.php?f= | http://it.marksypark.com | dont-delete.hugedomains.com | http://selfsparkcentral.com",
        "william.ballenthin@fireeye.com contain a resource (.rsrc) section\tmoritz.raabe@fireeye.com | Pattern match: \"jloup@gzip.org\" & \"fancybox@3.5.7\"",
        "FormBook: 104.247.81.53 \u2022 http://www.nimtax.com/k9/,Formbook,Medium,9/9/2019,1/7/2020",
        "Win32:CrypterX-gen\\ [Trj] | FileHash-MD5   6878e9896fdd84dcc11c997c9b7330ba",
        "Win32:CrypterX-gen\\ [Trj] | FileHash-SHA1   2e586f8db46953532b5e25e07add4dbaeea83a79",
        "Win32:CrypterX-gen\\ [Trj] | FileHash-SHA256  00027d11309d55312ae77f32d4ae79671c91f541e577bace7a5a5abde05563ad",
        "Win32/Renos: https://otx.alienvault.com/malware/ALF:JASYP:TrojanDownloader:Win32%2FRenos/",
        "Other:Malware-gen\\ [Trj] | FileHash-MD5 b5168dab50187b33460201b35b96dea7",
        "Other:Malware-gen\\ [Trj] | FileHash-SHA1 68868b3d0115e3d06f5fddb9d2ea6ad54270166c",
        "Other:Malware-gen\\ [Trj] | FileHash-SHA256 0000ba467dd40046e240c11251d9db03636d0e7c6f9f96354a46a441c2003143",
        "allocates_execute_remote_process \u2022 injection_write_memory \u2022 injection_resumethread \u2022 packer_entropy \u2022 network _icmp \u2022 injection_runpe",
        "injection_write_memory_exe \u2022 injection_ntsetcontextthread \u2022 dumped_buffer \u2022 checks_debugger \u2022 generates_crypto_key  \u2022 antivm_memory_available",
        "CnC IP Addresses: 104.247.81.53 \u2022 185.64.219.6 \u2022 199.191.50.82 \u2022 203.107.45.167 \u2022 91.195.240.94 \u2022 167.235.143.33",
        "AA47 More AV Detection Ratio 984  / 1000 IDS Detections Win32.Renos/ArtroMALWARETrojan Checkin M1 Possible Fake AV Checkin Fakealert. AA47 More AV Detection Ratio 984  / 1000 IDS Detections /Trojan Checkin M1 Possible Fake AV Checkin Fakealert.",
        "Videolal: 18.119.154.66:80 (endpoint request) \u2022 54.209.32.212 \u2022 http://videolal.com (phishing) \u2022 http://videolal.com/ \u2022 videolal.com \u2022 www.videolal.com \u2022",
        "www.videolal.com \u2022 httpvideolal.com \u2022 https://videolal.com/videos/jeffrey-reimer-dpt-assaulted-tsara-brashears-massage-sexual-misconduct.html",
        "https://www.hugedomains.com/domain_profile.cfm?d=videolal.com \u2022 https://www.hugedomains.com/domain_profile.cfm?d=videolal.com\"",
        "https://videolal.com/videos/jeffrey-reimer-dpt-assaulted-tsara-brashears-massage-misconduct-miscinception.html \u2022",
        "https://videolal.com/videos/jeffrey-reimer-dpt-assaulted-tsara-brashears-massage-sexual-misconduct-miscinception.html",
        "https://videolal.com/videos/tsara-brashears-assaulted-by-jeffrey-reimer-metlife-login-retirement.html \u2022 https://videolal.com/css/js/jquery-ui.min.js",
        "https://videolal.com/videos/tsara-brashears-dead-by-daylight.html \u2022 https://videolal.com/css/jquery-ui.css \u2022 http://videolal.com/tsara-brashears.html",
        "http://videolal.com/tsara-brashears-dead.html \u2022 http://videolal.com/tsara-brashears.html \u2022 http://videolal.com/videos/jeffrey-reimer-dpt-assaulted-tsara-brashears-massage-misconduct-miscinception.html",
        "http://videolal.com/videos/jeffrey-reimer-dpt-assaulted-tsara-brashears-massage-misconduct-miscinception.html",
        "http://videolal.com/jeffrey-reimer-dpt-sexual-misconduct.html \u2022 http://videolal.com/tsara-brashears.html",
        "http://videolal.com/tsara-brashears-dead-or-alive-song-rap.html \u2022 http://videolal.com/the-man-who-built-america-1.html",
        "http://videolal.com/the-man-who-built-america-1.html \u2022 http://videolal.com/pinnacol-assurance-assaulted-by-jeffrey-",
        "http://videolal.com/jeffrey-reimer-dpt-physical-therapy-assaulted-patient.html \u2022 http://videolal.com/jeff-reimer-",
        "http://videolal.com/jeffrey-reimer-dpt-assaulted-tsara-brashears-denver.html \u2022",
        "http://videolal.com/jeff-reimer-dpt-buys-assault-victims-silence.html \u2022 http://videolal.com/jeffrey-reimer-dpt-assaulted-tsara-brashears-denver.html",
        "https://otx.alienvault.com/otxapi/indicators/file/screenshot/4998a7eac2a056833d01ee1e60c68c1f83f9ad6cd790ced9511e73cc12780f3c",
        "https://otx.alienvault.com/malware/Trojan:Win32%2FCrypterX/",
        "\u2192https://otx.alienvault.com/pulse/65eedf74b7bdda41057bef3e",
        "\u2192https://otx.alienvault.com/pulse/65ef3723d27863fc33a6b671",
        "\u2192https://otx.alienvault.com/pulse/65e85fd4842119fff4e327cf",
        "\u2192https://otx.alienvault.com/pulse/65e843669f4ba77affa4b297"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "Win32:CrypterX-gen\\ [Trj]",
          "display_name": "Win32:CrypterX-gen\\ [Trj]",
          "target": null
        },
        {
          "id": "Other:Malware-gen\\ [Trj]",
          "display_name": "Other:Malware-gen\\ [Trj]",
          "target": null
        },
        {
          "id": "Artro",
          "display_name": "Artro",
          "target": null
        },
        {
          "id": "Win32.Renos/Artro",
          "display_name": "Win32.Renos/Artro",
          "target": null
        },
        {
          "id": "Generic",
          "display_name": "Generic",
          "target": null
        },
        {
          "id": "I-Worm/Bagle.QE",
          "display_name": "I-Worm/Bagle.QE",
          "target": null
        },
        {
          "id": "Worm.Bagle-44",
          "display_name": "Worm.Bagle-44",
          "target": null
        },
        {
          "id": "TrojanSpy",
          "display_name": "TrojanSpy",
          "target": null
        },
        {
          "id": "TrojanSpy:Win32/Nivdort.DE",
          "display_name": "TrojanSpy:Win32/Nivdort.DE",
          "target": "/malware/TrojanSpy:Win32/Nivdort.DE"
        },
        {
          "id": "Win.Trojan.Generic-9897526-0",
          "display_name": "Win.Trojan.Generic-9897526-0",
          "target": null
        },
        {
          "id": "Win.Trojan.Knigsfot-125",
          "display_name": "Win.Trojan.Knigsfot-125",
          "target": null
        },
        {
          "id": "ALF:TrojanDownloader:Win32/Vadokrist.A",
          "display_name": "ALF:TrojanDownloader:Win32/Vadokrist.A",
          "target": null
        },
        {
          "id": "Win.Trojan.Generic-9957168-0",
          "display_name": "Win.Trojan.Generic-9957168-0",
          "target": null
        },
        {
          "id": "Win.Adware.RelevantKnowledge-9821121-0",
          "display_name": "Win.Adware.RelevantKnowledge-9821121-0",
          "target": null
        },
        {
          "id": "ALF:HeraklezEval:Trojan:Win32/Neurevt",
          "display_name": "ALF:HeraklezEval:Trojan:Win32/Neurevt",
          "target": null
        },
        {
          "id": "FormBook",
          "display_name": "FormBook",
          "target": null
        },
        {
          "id": "HackTool",
          "display_name": "HackTool",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1041",
          "name": "Exfiltration Over C2 Channel",
          "display_name": "T1041 - Exfiltration Over C2 Channel"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1100",
          "name": "Web Shell",
          "display_name": "T1100 - Web Shell"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1114",
          "name": "Email Collection",
          "display_name": "T1114 - Email Collection"
        },
        {
          "id": "T1560",
          "name": "Archive Collected Data",
          "display_name": "T1560 - Archive Collected Data"
        },
        {
          "id": "T1059.007",
          "name": "JavaScript",
          "display_name": "T1059.007 - JavaScript"
        },
        {
          "id": "T1071.003",
          "name": "Mail Protocols",
          "display_name": "T1071.003 - Mail Protocols"
        },
        {
          "id": "T1071.001",
          "name": "Web Protocols",
          "display_name": "T1071.001 - Web Protocols"
        },
        {
          "id": "T1071.004",
          "name": "DNS",
          "display_name": "T1071.004 - DNS"
        },
        {
          "id": "T1063",
          "name": "Security Software Discovery",
          "display_name": "T1063 - Security Software Discovery"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 42,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 1622,
        "FileHash-SHA1": 934,
        "FileHash-SHA256": 3289,
        "URL": 9605,
        "domain": 2321,
        "hostname": 2411,
        "CVE": 1,
        "email": 3
      },
      "indicator_count": 20186,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 223,
      "modified_text": "780 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "659331580cd1571f730b8de2",
      "name": "Agent Tesla | Spyware | Tracking Android & Apple users | Malware Attack",
      "description": "",
      "modified": "2024-01-31T14:03:30.344000",
      "created": "2024-01-01T21:40:40.242000",
      "tags": [
        "maxads0",
        "kld1063",
        "ioc search",
        "new ioc",
        "teams api",
        "contact",
        "threat analyzer",
        "threat",
        "paste",
        "iocs",
        "hostnames",
        "urls http",
        "ssl certificate",
        "whois record",
        "contacted",
        "referrer",
        "historical ssl",
        "march",
        "communicating",
        "copy",
        "january",
        "collections",
        "execution",
        "malware",
        "startpage",
        "malicious",
        "ransomware",
        "agent tesla",
        "attack",
        "android",
        "name verdict",
        "falcon sandbox",
        "reports",
        "falcon",
        "windir",
        "path",
        "programfiles",
        "pe32",
        "ms windows",
        "getprocaddress",
        "file type",
        "mitre att",
        "ck id",
        "show technique",
        "win64",
        "date",
        "open",
        "hybrid",
        "cookie",
        "tracking",
        "apple",
        "spyware",
        "malware",
        "tablet",
        "superwebbysearch",
        "hallrender",
        "pegasus",
        "briansabey",
        "aig",
        "abuse",
        "tulach"
      ],
      "references": [
        "findbetterresults.com",
        "https://hybrid-analysis.com/sample/bba36b3ae7c49d1cffcc5f8e045d81e9307a2e1a86b923f89008e9377d171fb6",
        "https://www.virustotal.com/gui/url/eed406872c2e6ef550b948510fe0b7b4c71f752f58551c2f8e61d31a19d2a153/summary",
        "http://www.applerewards.website/pl/3/index.html?voluumdata=BASE64dmlkLi4wMDAwMDAwMi00NGFiLTQzNDktODAwMC0wMDAwMDAwMDAwMDBfX3ZwaWQuLjJhYWQzMDAwLWJiMzYtMTFlNi04YTYyLTBlYzcxZTllMDMzMV9fY2FpZC4uNjBhMjIwOWUtNWMzNC00OGQ4LWIyNDctYWM5YzVkOTM3MzZhX19ydC4uUl9fbGlkLi4yYTRjOTA4My0zY2RmLTQyNDktOGJmOS0yODMxZWYzNGRhYTlfX29pZDEuLjUwMGE4NDhjLTA2NGEtNDYyZi05MDNmLTgxYzY4ODNmODEwZl9fdmFyMS4uNjA4OTYxX192YXIyLi42NzEwMjhfX3JkLi5vbmNsaWNrYWRzXC5cbmV0X19haWQuLl9fYWIuLl9fc2lkLi4&zoneid=608961&campaignid=671028&visitor_id=4003954",
        "www2.megawebfind.com                [command_and_control]",
        "https://search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas_sfp&command=   [command_and_control]   stolec kradnie krypto"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Agent Tesla",
          "display_name": "Agent Tesla",
          "target": null
        },
        {
          "id": "Ransomware",
          "display_name": "Ransomware",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1012",
          "name": "Query Registry",
          "display_name": "T1012 - Query Registry"
        },
        {
          "id": "T1033",
          "name": "System Owner/User Discovery",
          "display_name": "T1033 - System Owner/User Discovery"
        },
        {
          "id": "T1036",
          "name": "Masquerading",
          "display_name": "T1036 - Masquerading"
        },
        {
          "id": "T1053",
          "name": "Scheduled Task/Job",
          "display_name": "T1053 - Scheduled Task/Job"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1070",
          "name": "Indicator Removal on Host",
          "display_name": "T1070 - Indicator Removal on Host"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1074",
          "name": "Data Staged",
          "display_name": "T1074 - Data Staged"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1106",
          "name": "Native API",
          "display_name": "T1106 - Native API"
        },
        {
          "id": "T1112",
          "name": "Modify Registry",
          "display_name": "T1112 - Modify Registry"
        },
        {
          "id": "T1129",
          "name": "Shared Modules",
          "display_name": "T1129 - Shared Modules"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1218",
          "name": "Signed Binary Proxy Execution",
          "display_name": "T1218 - Signed Binary Proxy Execution"
        },
        {
          "id": "T1518",
          "name": "Software Discovery",
          "display_name": "T1518 - Software Discovery"
        },
        {
          "id": "T1614",
          "name": "System Location Discovery",
          "display_name": "T1614 - System Location Discovery"
        },
        {
          "id": "TA0011",
          "name": "Command and Control",
          "display_name": "TA0011 - Command and Control"
        },
        {
          "id": "T1155",
          "name": "AppleScript",
          "display_name": "T1155 - AppleScript"
        },
        {
          "id": "T1449",
          "name": "Exploit SS7 to Redirect Phone Calls/SMS",
          "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
        },
        {
          "id": "T1031",
          "name": "Modify Existing Service",
          "display_name": "T1031 - Modify Existing Service"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 24,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 2368,
        "FileHash-SHA256": 4539,
        "hostname": 2892,
        "URL": 9741,
        "FileHash-MD5": 836,
        "FileHash-SHA1": 461,
        "CVE": 1
      },
      "indicator_count": 20838,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 222,
      "modified_text": "851 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "659331589faf01b909c1802d",
      "name": "Agent Tesla | Spyware | Tracking Android & Apple users | Malware Attack",
      "description": "",
      "modified": "2024-01-31T14:03:30.344000",
      "created": "2024-01-01T21:40:40.413000",
      "tags": [
        "maxads0",
        "kld1063",
        "ioc search",
        "new ioc",
        "teams api",
        "contact",
        "threat analyzer",
        "threat",
        "paste",
        "iocs",
        "hostnames",
        "urls http",
        "ssl certificate",
        "whois record",
        "contacted",
        "referrer",
        "historical ssl",
        "march",
        "communicating",
        "copy",
        "january",
        "collections",
        "execution",
        "malware",
        "startpage",
        "malicious",
        "ransomware",
        "agent tesla",
        "attack",
        "android",
        "name verdict",
        "falcon sandbox",
        "reports",
        "falcon",
        "windir",
        "path",
        "programfiles",
        "pe32",
        "ms windows",
        "getprocaddress",
        "file type",
        "mitre att",
        "ck id",
        "show technique",
        "win64",
        "date",
        "open",
        "hybrid",
        "cookie",
        "tracking",
        "apple",
        "spyware",
        "malware",
        "tablet",
        "superwebbysearch",
        "hallrender",
        "pegasus",
        "briansabey",
        "aig",
        "abuse",
        "tulach"
      ],
      "references": [
        "findbetterresults.com",
        "https://hybrid-analysis.com/sample/bba36b3ae7c49d1cffcc5f8e045d81e9307a2e1a86b923f89008e9377d171fb6",
        "https://www.virustotal.com/gui/url/eed406872c2e6ef550b948510fe0b7b4c71f752f58551c2f8e61d31a19d2a153/summary",
        "http://www.applerewards.website/pl/3/index.html?voluumdata=BASE64dmlkLi4wMDAwMDAwMi00NGFiLTQzNDktODAwMC0wMDAwMDAwMDAwMDBfX3ZwaWQuLjJhYWQzMDAwLWJiMzYtMTFlNi04YTYyLTBlYzcxZTllMDMzMV9fY2FpZC4uNjBhMjIwOWUtNWMzNC00OGQ4LWIyNDctYWM5YzVkOTM3MzZhX19ydC4uUl9fbGlkLi4yYTRjOTA4My0zY2RmLTQyNDktOGJmOS0yODMxZWYzNGRhYTlfX29pZDEuLjUwMGE4NDhjLTA2NGEtNDYyZi05MDNmLTgxYzY4ODNmODEwZl9fdmFyMS4uNjA4OTYxX192YXIyLi42NzEwMjhfX3JkLi5vbmNsaWNrYWRzXC5cbmV0X19haWQuLl9fYWIuLl9fc2lkLi4&zoneid=608961&campaignid=671028&visitor_id=4003954",
        "www2.megawebfind.com                [command_and_control]",
        "https://search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas_sfp&command=   [command_and_control]   stolec kradnie krypto"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Agent Tesla",
          "display_name": "Agent Tesla",
          "target": null
        },
        {
          "id": "Ransomware",
          "display_name": "Ransomware",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1012",
          "name": "Query Registry",
          "display_name": "T1012 - Query Registry"
        },
        {
          "id": "T1033",
          "name": "System Owner/User Discovery",
          "display_name": "T1033 - System Owner/User Discovery"
        },
        {
          "id": "T1036",
          "name": "Masquerading",
          "display_name": "T1036 - Masquerading"
        },
        {
          "id": "T1053",
          "name": "Scheduled Task/Job",
          "display_name": "T1053 - Scheduled Task/Job"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1070",
          "name": "Indicator Removal on Host",
          "display_name": "T1070 - Indicator Removal on Host"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1074",
          "name": "Data Staged",
          "display_name": "T1074 - Data Staged"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1106",
          "name": "Native API",
          "display_name": "T1106 - Native API"
        },
        {
          "id": "T1112",
          "name": "Modify Registry",
          "display_name": "T1112 - Modify Registry"
        },
        {
          "id": "T1129",
          "name": "Shared Modules",
          "display_name": "T1129 - Shared Modules"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1218",
          "name": "Signed Binary Proxy Execution",
          "display_name": "T1218 - Signed Binary Proxy Execution"
        },
        {
          "id": "T1518",
          "name": "Software Discovery",
          "display_name": "T1518 - Software Discovery"
        },
        {
          "id": "T1614",
          "name": "System Location Discovery",
          "display_name": "T1614 - System Location Discovery"
        },
        {
          "id": "TA0011",
          "name": "Command and Control",
          "display_name": "TA0011 - Command and Control"
        },
        {
          "id": "T1155",
          "name": "AppleScript",
          "display_name": "T1155 - AppleScript"
        },
        {
          "id": "T1449",
          "name": "Exploit SS7 to Redirect Phone Calls/SMS",
          "display_name": "T1449 - Exploit SS7 to Redirect Phone Calls/SMS"
        },
        {
          "id": "T1031",
          "name": "Modify Existing Service",
          "display_name": "T1031 - Modify Existing Service"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 29,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 2368,
        "FileHash-SHA256": 4539,
        "hostname": 2892,
        "URL": 9741,
        "FileHash-MD5": 836,
        "FileHash-SHA1": 461,
        "CVE": 1
      },
      "indicator_count": 20838,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 221,
      "modified_text": "851 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "655d0ec7b7cb12c66cac457d",
      "name": "https://mypornwap.fun/downloads/5/search/white-dpt-jeffrey-reimer-loves-pretty-indian-patient-forces-sex-3gp-video-tsara-brashears-gzip",
      "description": "Exploit\nContains escaped byte string (often part of obfuscated shellcode), Malicious\nhttps://www.profitabledisplaycontent.com/watch.375255570190.js, Malvertizing a true crime, child pornographer.\n\nSource: https://mypornwap.fun/downloads/5/search/white-dpt-jeffrey-reimer-loves-pretty-indian-patient-forces-sex-3gp-video-tsara-brashears-gzip\n\nResource: https://www.hybrid-analysis.com/sample/f0233084bd810eb266cd29a879dc58d84c2a85032ba58b4b50d5643e7a41a144/655cf15b9f12303f990942e9",
      "modified": "2023-12-21T19:03:27.243000",
      "created": "2023-11-21T20:10:47.792000",
      "tags": [
        "cins active",
        "poor reputation",
        "host",
        "threats et",
        "ip tcp",
        "detection list",
        "ip address",
        "blacklist",
        "macedonia",
        "former yugoslav",
        "site",
        "cisco umbrella",
        "alexa top",
        "million",
        "alexa",
        "threat report",
        "ip summary",
        "url summary",
        "summary",
        "sample",
        "samples",
        "paypal",
        "team phishing",
        "blacknet rat",
        "loki password",
        "stealer",
        "malicious url",
        "malicious site",
        "azorult",
        "phishing",
        "service",
        "runescape",
        "facebook",
        "bank",
        "download",
        "blacknet",
        "site top",
        "million alexa",
        "safe site",
        "malware",
        "genpack",
        "deepscan",
        "cobalt strike",
        "malicious",
        "zbot",
        "memscan",
        "cl0p",
        "cyber threat",
        "heur",
        "engineering",
        "united",
        "covid19",
        "malicious host",
        "team",
        "virut",
        "nymaim",
        "pony",
        "ransomware",
        "bradesco",
        "opencandy",
        "ramnit",
        "adload",
        "simda",
        "zeus",
        "pykspa",
        "riskware",
        "generic",
        "artemis",
        "downldr",
        "binder",
        "sutra",
        "steam",
        "asyncrat",
        "revengerat",
        "downloader",
        "exploit",
        "emailworm",
        "agent",
        "tinba",
        "maltiverse safe",
        "generic malware",
        "phishing site",
        "outbrowse",
        "suppobox",
        "vawtrak",
        "solimba",
        "wacatac",
        "msil",
        "outbreak",
        "installcore",
        "acint",
        "conduit",
        "installpack",
        "iobit",
        "dropper",
        "mediaget",
        "crack",
        "blacklist http",
        "ascii text",
        "nysp",
        "appdata",
        "jpeg image",
        "jfif standard",
        "file",
        "0xeae6b5",
        "function",
        "0x308d49",
        "x6a4",
        "push",
        "shift",
        "cookie",
        "slice",
        "path",
        "window",
        "error",
        "false",
        "hybrid",
        "crypto",
        "open",
        "blank",
        "template",
        "target",
        "trim",
        "write",
        "period",
        "touchmove",
        "click",
        "close",
        "body",
        "screen",
        "android",
        "canvas",
        "class",
        "span",
        "trident",
        "accept",
        "general",
        "local",
        "html",
        "unsafe",
        "downer",
        "shell",
        "mediamagnet",
        "sality",
        "swrort",
        "adaptivebee",
        "unruy",
        "trojanx",
        "webshell",
        "iframe",
        "patcher",
        "driverpack",
        "union",
        "maltiverse",
        "blacklist https",
        "google",
        "noname057",
        "redlinestealer"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "BlackNET",
          "display_name": "BlackNET",
          "target": null
        },
        {
          "id": "Cl0p",
          "display_name": "Cl0p",
          "target": null
        },
        {
          "id": "Maltiverse",
          "display_name": "Maltiverse",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 69,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 884,
        "hostname": 1809,
        "FileHash-MD5": 635,
        "FileHash-SHA1": 321,
        "FileHash-SHA256": 2079,
        "CVE": 16,
        "URL": 6434
      },
      "indicator_count": 12178,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 221,
      "modified_text": "892 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "655d0edbb8c22bcb4e5969b8",
      "name": "https://mypornwap.fun/downloads/5/search/white-dpt-jeffrey-reimer-loves-pretty-indian-patient-forces-sex-3gp-video-tsara-brashears-gzip",
      "description": "Exploit\nContains escaped byte string (often part of obfuscated shellcode), Malicious\nhttps://www.profitabledisplaycontent.com/watch.375255570190.js, Malvertizing a true crime, child pornographer.\n\nSource: https://mypornwap.fun/downloads/5/search/white-dpt-jeffrey-reimer-loves-pretty-indian-patient-forces-sex-3gp-video-tsara-brashears-gzip\n\nResource: https://www.hybrid-analysis.com/sample/f0233084bd810eb266cd29a879dc58d84c2a85032ba58b4b50d5643e7a41a144/655cf15b9f12303f990942e9",
      "modified": "2023-12-21T19:03:27.243000",
      "created": "2023-11-21T20:11:07.064000",
      "tags": [
        "cins active",
        "poor reputation",
        "host",
        "threats et",
        "ip tcp",
        "detection list",
        "ip address",
        "blacklist",
        "macedonia",
        "former yugoslav",
        "site",
        "cisco umbrella",
        "alexa top",
        "million",
        "alexa",
        "threat report",
        "ip summary",
        "url summary",
        "summary",
        "sample",
        "samples",
        "paypal",
        "team phishing",
        "blacknet rat",
        "loki password",
        "stealer",
        "malicious url",
        "malicious site",
        "azorult",
        "phishing",
        "service",
        "runescape",
        "facebook",
        "bank",
        "download",
        "blacknet",
        "site top",
        "million alexa",
        "safe site",
        "malware",
        "genpack",
        "deepscan",
        "cobalt strike",
        "malicious",
        "zbot",
        "memscan",
        "cl0p",
        "cyber threat",
        "heur",
        "engineering",
        "united",
        "covid19",
        "malicious host",
        "team",
        "virut",
        "nymaim",
        "pony",
        "ransomware",
        "bradesco",
        "opencandy",
        "ramnit",
        "adload",
        "simda",
        "zeus",
        "pykspa",
        "riskware",
        "generic",
        "artemis",
        "downldr",
        "binder",
        "sutra",
        "steam",
        "asyncrat",
        "revengerat",
        "downloader",
        "exploit",
        "emailworm",
        "agent",
        "tinba",
        "maltiverse safe",
        "generic malware",
        "phishing site",
        "outbrowse",
        "suppobox",
        "vawtrak",
        "solimba",
        "wacatac",
        "msil",
        "outbreak",
        "installcore",
        "acint",
        "conduit",
        "installpack",
        "iobit",
        "dropper",
        "mediaget",
        "crack",
        "blacklist http",
        "ascii text",
        "nysp",
        "appdata",
        "jpeg image",
        "jfif standard",
        "file",
        "0xeae6b5",
        "function",
        "0x308d49",
        "x6a4",
        "push",
        "shift",
        "cookie",
        "slice",
        "path",
        "window",
        "error",
        "false",
        "hybrid",
        "crypto",
        "open",
        "blank",
        "template",
        "target",
        "trim",
        "write",
        "period",
        "touchmove",
        "click",
        "close",
        "body",
        "screen",
        "android",
        "canvas",
        "class",
        "span",
        "trident",
        "accept",
        "general",
        "local",
        "html",
        "unsafe",
        "downer",
        "shell",
        "mediamagnet",
        "sality",
        "swrort",
        "adaptivebee",
        "unruy",
        "trojanx",
        "webshell",
        "iframe",
        "patcher",
        "driverpack",
        "union",
        "maltiverse",
        "blacklist https",
        "google",
        "noname057",
        "redlinestealer"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "BlackNET",
          "display_name": "BlackNET",
          "target": null
        },
        {
          "id": "Cl0p",
          "display_name": "Cl0p",
          "target": null
        },
        {
          "id": "Maltiverse",
          "display_name": "Maltiverse",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 68,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 884,
        "hostname": 1809,
        "FileHash-MD5": 635,
        "FileHash-SHA1": 321,
        "FileHash-SHA256": 2079,
        "CVE": 16,
        "URL": 6434
      },
      "indicator_count": 12178,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 222,
      "modified_text": "892 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "655d0f94ad4d7cdc5e3f0a98",
      "name": "BlackNET",
      "description": "Exploit\nContains escaped byte string (often part of obfuscated shellcode), Malicious\nhttps://www.profitabledisplaycontent.com/watch.375255570190.js, Malvertizing a true crime, child pornographer.\n\nSource: https://mypornwap.fun/downloads/5/search/white-dpt-jeffrey-reimer-loves-pretty-indian-patient-forces-sex-3gp-video-tsara-brashears-gzip\n\nResource: https://www.hybrid-analysis.com/sample/f0233084bd810eb266cd29a879dc58d84c2a85032ba58b4b50d5643e7a41a144/655cf15b9f12303f990942e9",
      "modified": "2023-12-21T19:03:27.243000",
      "created": "2023-11-21T20:14:12.454000",
      "tags": [
        "cins active",
        "poor reputation",
        "host",
        "threats et",
        "ip tcp",
        "detection list",
        "ip address",
        "blacklist",
        "macedonia",
        "former yugoslav",
        "site",
        "cisco umbrella",
        "alexa top",
        "million",
        "alexa",
        "threat report",
        "ip summary",
        "url summary",
        "summary",
        "sample",
        "samples",
        "paypal",
        "team phishing",
        "blacknet rat",
        "loki password",
        "stealer",
        "malicious url",
        "malicious site",
        "azorult",
        "phishing",
        "service",
        "runescape",
        "facebook",
        "bank",
        "download",
        "blacknet",
        "site top",
        "million alexa",
        "safe site",
        "malware",
        "genpack",
        "deepscan",
        "cobalt strike",
        "malicious",
        "zbot",
        "memscan",
        "cl0p",
        "cyber threat",
        "heur",
        "engineering",
        "united",
        "covid19",
        "malicious host",
        "team",
        "virut",
        "nymaim",
        "pony",
        "ransomware",
        "bradesco",
        "opencandy",
        "ramnit",
        "adload",
        "simda",
        "zeus",
        "pykspa",
        "riskware",
        "generic",
        "artemis",
        "downldr",
        "binder",
        "sutra",
        "steam",
        "asyncrat",
        "revengerat",
        "downloader",
        "exploit",
        "emailworm",
        "agent",
        "tinba",
        "maltiverse safe",
        "generic malware",
        "phishing site",
        "outbrowse",
        "suppobox",
        "vawtrak",
        "solimba",
        "wacatac",
        "msil",
        "outbreak",
        "installcore",
        "acint",
        "conduit",
        "installpack",
        "iobit",
        "dropper",
        "mediaget",
        "crack",
        "blacklist http",
        "ascii text",
        "nysp",
        "appdata",
        "jpeg image",
        "jfif standard",
        "file",
        "0xeae6b5",
        "function",
        "0x308d49",
        "x6a4",
        "push",
        "shift",
        "cookie",
        "slice",
        "path",
        "window",
        "error",
        "false",
        "hybrid",
        "crypto",
        "open",
        "blank",
        "template",
        "target",
        "trim",
        "write",
        "period",
        "touchmove",
        "click",
        "close",
        "body",
        "screen",
        "android",
        "canvas",
        "class",
        "span",
        "trident",
        "accept",
        "general",
        "local",
        "html",
        "unsafe",
        "downer",
        "shell",
        "mediamagnet",
        "sality",
        "swrort",
        "adaptivebee",
        "unruy",
        "trojanx",
        "webshell",
        "iframe",
        "patcher",
        "driverpack",
        "union",
        "maltiverse",
        "blacklist https",
        "google",
        "noname057",
        "redlinestealer"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [
        {
          "id": "BlackNET",
          "display_name": "BlackNET",
          "target": null
        },
        {
          "id": "Cl0p",
          "display_name": "Cl0p",
          "target": null
        },
        {
          "id": "Maltiverse",
          "display_name": "Maltiverse",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 73,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "OctoSeek",
        "id": "243548",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_243548/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 884,
        "hostname": 1809,
        "FileHash-MD5": 635,
        "FileHash-SHA1": 321,
        "FileHash-SHA256": 2079,
        "CVE": 16,
        "URL": 6434
      },
      "indicator_count": 12178,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 227,
      "modified_text": "892 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6570914fe73d6efb17198812",
      "name": "https://areyou1or0.com/ - just like a lucky dip",
      "description": "",
      "modified": "2023-12-06T15:20:47.515000",
      "created": "2023-12-06T15:20:47.515000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "CVE": 2,
        "hostname": 496,
        "FileHash-SHA256": 351,
        "FileHash-MD5": 56,
        "FileHash-SHA1": 50,
        "URL": 2028,
        "domain": 711,
        "email": 1
      },
      "indicator_count": 3695,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "907 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "65708e7ca78fb9ed8bda43d0",
      "name": "Part 2 of the small sub section post - This a sample of the infrastructure on the perimeter of each of those controlled websrv and devuces on home lans",
      "description": "",
      "modified": "2023-12-06T15:08:44.795000",
      "created": "2023-12-06T15:08:44.795000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "CVE": 19,
        "hostname": 404,
        "FileHash-SHA256": 1484,
        "FileHash-SHA1": 1,
        "URL": 1141,
        "domain": 202,
        "FileHash-MD5": 1
      },
      "indicator_count": 3252,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 110,
      "modified_text": "907 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "https://ww16.wegardn.com",
    "type": "URL"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "https://ww16.wegardn.com",
    "type": "URL",
    "found": false,
    "verdict": "clean",
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780266018.6908057
}