{
  "type": "URL",
  "indicator": "https://www.8659.se/",
  "general": {
    "sections": [
      "general",
      "url_list",
      "http_scans",
      "screenshot"
    ],
    "indicator": "https://www.8659.se/",
    "type": "url",
    "type_title": "URL",
    "validation": [
      {
        "source": "private",
        "message": "Private IP Address",
        "name": "Private / Internal IP"
      }
    ],
    "base_indicator": {
      "id": 4171661938,
      "indicator": "https://www.8659.se/",
      "type": "URL",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 49,
      "pulses": [
        {
          "id": "6954c79d5e6d3536b0e2c2b1",
          "name": "OSINT Volley 2025-12-31 - ClearFake/Unknown malware/Cobalt Strike",
          "description": "Automated OSINT sweep from ThreatFox. Top malware: ClearFake(265), Unknown malware(151), Cobalt Strike(108), GootLoader(63), Sliver(62). Source: abuse.ch ThreatFox API. SSL enriched: 103 IPs with HTTPS, 17 self-signed (C2 candidates). Pattern 54: sweep\u2192volley automation.",
          "modified": "2026-01-30T06:00:51.865000",
          "created": "2025-12-31T06:50:05.401000",
          "tags": [
            "osint-volley",
            "threatfox",
            "automated",
            "clearfake",
            "unknown-malware",
            "cobalt-strike",
            "c2-infrastructure"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix-feed/v2",
            "https://threatfox.abuse.ch"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "ClearFake",
              "display_name": "ClearFake",
              "target": null
            },
            {
              "id": "Unknown malware",
              "display_name": "Unknown malware",
              "target": null
            },
            {
              "id": "Cobalt Strike",
              "display_name": "Cobalt Strike",
              "target": null
            },
            {
              "id": "GootLoader",
              "display_name": "GootLoader",
              "target": null
            },
            {
              "id": "Sliver",
              "display_name": "Sliver",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1189",
              "name": "Drive-by Compromise",
              "display_name": "T1189 - Drive-by Compromise"
            },
            {
              "id": "T1204.002",
              "name": "Malicious File",
              "display_name": "T1204.002 - Malicious File"
            },
            {
              "id": "T1566.002",
              "name": "Spearphishing Link",
              "display_name": "T1566.002 - Spearphishing Link"
            },
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1059.001",
              "name": "PowerShell",
              "display_name": "T1059.001 - PowerShell"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 76,
            "URL": 67,
            "domain": 5
          },
          "indicator_count": 148,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "123 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6954c095f9326c2811926a9e",
          "name": "OSINT Volley 2025-12-31 - ClearFake/Unknown malware/Cobalt Strike",
          "description": "Automated OSINT sweep from ThreatFox. Top malware: ClearFake(265), Unknown malware(151), Cobalt Strike(108), GootLoader(63), Sliver(62). Source: abuse.ch ThreatFox API. SSL enriched: 103 IPs with HTTPS, 17 self-signed (C2 candidates). Pattern 54: sweep\u2192volley automation.",
          "modified": "2026-01-30T06:00:51.865000",
          "created": "2025-12-31T06:20:05.383000",
          "tags": [
            "osint-volley",
            "threatfox",
            "automated",
            "clearfake",
            "unknown-malware",
            "cobalt-strike",
            "c2-infrastructure"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix-feed/v2",
            "https://threatfox.abuse.ch"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "ClearFake",
              "display_name": "ClearFake",
              "target": null
            },
            {
              "id": "Unknown malware",
              "display_name": "Unknown malware",
              "target": null
            },
            {
              "id": "Cobalt Strike",
              "display_name": "Cobalt Strike",
              "target": null
            },
            {
              "id": "GootLoader",
              "display_name": "GootLoader",
              "target": null
            },
            {
              "id": "Sliver",
              "display_name": "Sliver",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1189",
              "name": "Drive-by Compromise",
              "display_name": "T1189 - Drive-by Compromise"
            },
            {
              "id": "T1204.002",
              "name": "Malicious File",
              "display_name": "T1204.002 - Malicious File"
            },
            {
              "id": "T1566.002",
              "name": "Spearphishing Link",
              "display_name": "T1566.002 - Spearphishing Link"
            },
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1059.001",
              "name": "PowerShell",
              "display_name": "T1059.001 - PowerShell"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 76,
            "URL": 67,
            "domain": 5
          },
          "indicator_count": 148,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "123 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6954b98c294205f7f86672e6",
          "name": "OSINT Volley 2025-12-31 - ClearFake/Unknown malware/Cobalt Strike",
          "description": "Automated OSINT sweep from ThreatFox. Top malware: ClearFake(265), Unknown malware(151), Cobalt Strike(108), GootLoader(63), Sliver(62). Source: abuse.ch ThreatFox API. SSL enriched: 103 IPs with HTTPS, 17 self-signed (C2 candidates). Pattern 54: sweep\u2192volley automation.",
          "modified": "2026-01-30T05:00:01.077000",
          "created": "2025-12-31T05:50:04.286000",
          "tags": [
            "osint-volley",
            "threatfox",
            "automated",
            "clearfake",
            "unknown-malware",
            "cobalt-strike",
            "c2-infrastructure"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix-feed/v2",
            "https://threatfox.abuse.ch"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "ClearFake",
              "display_name": "ClearFake",
              "target": null
            },
            {
              "id": "Unknown malware",
              "display_name": "Unknown malware",
              "target": null
            },
            {
              "id": "Cobalt Strike",
              "display_name": "Cobalt Strike",
              "target": null
            },
            {
              "id": "GootLoader",
              "display_name": "GootLoader",
              "target": null
            },
            {
              "id": "Sliver",
              "display_name": "Sliver",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1189",
              "name": "Drive-by Compromise",
              "display_name": "T1189 - Drive-by Compromise"
            },
            {
              "id": "T1204.002",
              "name": "Malicious File",
              "display_name": "T1204.002 - Malicious File"
            },
            {
              "id": "T1566.002",
              "name": "Spearphishing Link",
              "display_name": "T1566.002 - Spearphishing Link"
            },
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1059.001",
              "name": "PowerShell",
              "display_name": "T1059.001 - PowerShell"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 67,
            "hostname": 76,
            "domain": 5
          },
          "indicator_count": 148,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "123 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6954ab794f39613db3e136fa",
          "name": "OSINT Volley 2025-12-31 - ClearFake/Unknown malware/Cobalt Strike",
          "description": "Automated OSINT sweep from ThreatFox. Top malware: ClearFake(265), Unknown malware(143), Cobalt Strike(108), GootLoader(63), Sliver(62). Source: abuse.ch ThreatFox API. SSL enriched: 103 IPs with HTTPS, 17 self-signed (C2 candidates). Pattern 54: sweep\u2192volley automation.",
          "modified": "2026-01-30T04:03:08.625000",
          "created": "2025-12-31T04:50:01.971000",
          "tags": [
            "osint-volley",
            "threatfox",
            "automated",
            "clearfake",
            "unknown-malware",
            "cobalt-strike",
            "c2-infrastructure"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix-feed/v2",
            "https://threatfox.abuse.ch"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "ClearFake",
              "display_name": "ClearFake",
              "target": null
            },
            {
              "id": "Unknown malware",
              "display_name": "Unknown malware",
              "target": null
            },
            {
              "id": "Cobalt Strike",
              "display_name": "Cobalt Strike",
              "target": null
            },
            {
              "id": "GootLoader",
              "display_name": "GootLoader",
              "target": null
            },
            {
              "id": "Sliver",
              "display_name": "Sliver",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1189",
              "name": "Drive-by Compromise",
              "display_name": "T1189 - Drive-by Compromise"
            },
            {
              "id": "T1204.002",
              "name": "Malicious File",
              "display_name": "T1204.002 - Malicious File"
            },
            {
              "id": "T1566.002",
              "name": "Spearphishing Link",
              "display_name": "T1566.002 - Spearphishing Link"
            },
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1059.001",
              "name": "PowerShell",
              "display_name": "T1059.001 - PowerShell"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 3,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 80,
            "URL": 59,
            "domain": 5
          },
          "indicator_count": 144,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "123 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6954a47345eb9d2e5bb21694",
          "name": "OSINT Volley 2025-12-31 - ClearFake/Unknown malware/Cobalt Strike",
          "description": "Automated OSINT sweep from ThreatFox. Top malware: ClearFake(265), Unknown malware(143), Cobalt Strike(108), GootLoader(63), Sliver(62). Source: abuse.ch ThreatFox API. SSL enriched: 103 IPs with HTTPS, 17 self-signed (C2 candidates). Pattern 54: sweep\u2192volley automation.",
          "modified": "2026-01-30T04:03:08.625000",
          "created": "2025-12-31T04:20:03.638000",
          "tags": [
            "osint-volley",
            "threatfox",
            "automated",
            "clearfake",
            "unknown-malware",
            "cobalt-strike",
            "c2-infrastructure"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix-feed/v2",
            "https://threatfox.abuse.ch"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "ClearFake",
              "display_name": "ClearFake",
              "target": null
            },
            {
              "id": "Unknown malware",
              "display_name": "Unknown malware",
              "target": null
            },
            {
              "id": "Cobalt Strike",
              "display_name": "Cobalt Strike",
              "target": null
            },
            {
              "id": "GootLoader",
              "display_name": "GootLoader",
              "target": null
            },
            {
              "id": "Sliver",
              "display_name": "Sliver",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1189",
              "name": "Drive-by Compromise",
              "display_name": "T1189 - Drive-by Compromise"
            },
            {
              "id": "T1204.002",
              "name": "Malicious File",
              "display_name": "T1204.002 - Malicious File"
            },
            {
              "id": "T1566.002",
              "name": "Spearphishing Link",
              "display_name": "T1566.002 - Spearphishing Link"
            },
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1059.001",
              "name": "PowerShell",
              "display_name": "T1059.001 - PowerShell"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 80,
            "URL": 59,
            "domain": 5
          },
          "indicator_count": 144,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "123 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "69549d6d0809241237ea459d",
          "name": "OSINT Volley 2025-12-31 - ClearFake/Unknown malware/Cobalt Strike",
          "description": "Automated OSINT sweep from ThreatFox. Top malware: ClearFake(265), Unknown malware(137), Cobalt Strike(106), GootLoader(63), Sliver(62). Source: abuse.ch ThreatFox API. SSL enriched: 97 IPs with HTTPS, 17 self-signed (C2 candidates). Pattern 54: sweep\u2192volley automation.",
          "modified": "2026-01-30T03:04:44.497000",
          "created": "2025-12-31T03:50:03.518000",
          "tags": [
            "osint-volley",
            "threatfox",
            "automated",
            "clearfake",
            "unknown-malware",
            "cobalt-strike",
            "c2-infrastructure"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix-feed/v2",
            "https://threatfox.abuse.ch"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "ClearFake",
              "display_name": "ClearFake",
              "target": null
            },
            {
              "id": "Unknown malware",
              "display_name": "Unknown malware",
              "target": null
            },
            {
              "id": "Cobalt Strike",
              "display_name": "Cobalt Strike",
              "target": null
            },
            {
              "id": "GootLoader",
              "display_name": "GootLoader",
              "target": null
            },
            {
              "id": "Sliver",
              "display_name": "Sliver",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1189",
              "name": "Drive-by Compromise",
              "display_name": "T1189 - Drive-by Compromise"
            },
            {
              "id": "T1204.002",
              "name": "Malicious File",
              "display_name": "T1204.002 - Malicious File"
            },
            {
              "id": "T1566.002",
              "name": "Spearphishing Link",
              "display_name": "T1566.002 - Spearphishing Link"
            },
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1059.001",
              "name": "PowerShell",
              "display_name": "T1059.001 - PowerShell"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 94,
            "URL": 60,
            "domain": 5
          },
          "indicator_count": 159,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "123 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "69549663b367946d1418e92a",
          "name": "OSINT Volley 2025-12-31 - ClearFake/Unknown malware/Cobalt Strike",
          "description": "Automated OSINT sweep from ThreatFox. Top malware: ClearFake(265), Unknown malware(137), Cobalt Strike(106), GootLoader(63), Sliver(62). Source: abuse.ch ThreatFox API. SSL enriched: 97 IPs with HTTPS, 17 self-signed (C2 candidates). Pattern 54: sweep\u2192volley automation.",
          "modified": "2026-01-30T03:04:44.497000",
          "created": "2025-12-31T03:20:03.906000",
          "tags": [
            "osint-volley",
            "threatfox",
            "automated",
            "clearfake",
            "unknown-malware",
            "cobalt-strike",
            "c2-infrastructure"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix-feed/v2",
            "https://threatfox.abuse.ch"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "ClearFake",
              "display_name": "ClearFake",
              "target": null
            },
            {
              "id": "Unknown malware",
              "display_name": "Unknown malware",
              "target": null
            },
            {
              "id": "Cobalt Strike",
              "display_name": "Cobalt Strike",
              "target": null
            },
            {
              "id": "GootLoader",
              "display_name": "GootLoader",
              "target": null
            },
            {
              "id": "Sliver",
              "display_name": "Sliver",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1189",
              "name": "Drive-by Compromise",
              "display_name": "T1189 - Drive-by Compromise"
            },
            {
              "id": "T1204.002",
              "name": "Malicious File",
              "display_name": "T1204.002 - Malicious File"
            },
            {
              "id": "T1566.002",
              "name": "Spearphishing Link",
              "display_name": "T1566.002 - Spearphishing Link"
            },
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1059.001",
              "name": "PowerShell",
              "display_name": "T1059.001 - PowerShell"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 94,
            "URL": 60,
            "domain": 5
          },
          "indicator_count": 159,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "123 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "695488536274682db9451c77",
          "name": "OSINT Volley 2025-12-31 - ClearFake/Unknown malware/Cobalt Strike",
          "description": "Automated OSINT sweep from ThreatFox. Top malware: ClearFake(265), Unknown malware(137), Cobalt Strike(106), GootLoader(63), Sliver(62). Source: abuse.ch ThreatFox API. SSL enriched: 97 IPs with HTTPS, 17 self-signed (C2 candidates). Pattern 54: sweep\u2192volley automation.",
          "modified": "2026-01-30T02:00:24.431000",
          "created": "2025-12-31T02:20:03.938000",
          "tags": [
            "osint-volley",
            "threatfox",
            "automated",
            "clearfake",
            "unknown-malware",
            "cobalt-strike",
            "c2-infrastructure"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix-feed/v2",
            "https://threatfox.abuse.ch"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "ClearFake",
              "display_name": "ClearFake",
              "target": null
            },
            {
              "id": "Unknown malware",
              "display_name": "Unknown malware",
              "target": null
            },
            {
              "id": "Cobalt Strike",
              "display_name": "Cobalt Strike",
              "target": null
            },
            {
              "id": "GootLoader",
              "display_name": "GootLoader",
              "target": null
            },
            {
              "id": "Sliver",
              "display_name": "Sliver",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1189",
              "name": "Drive-by Compromise",
              "display_name": "T1189 - Drive-by Compromise"
            },
            {
              "id": "T1204.002",
              "name": "Malicious File",
              "display_name": "T1204.002 - Malicious File"
            },
            {
              "id": "T1566.002",
              "name": "Spearphishing Link",
              "display_name": "T1566.002 - Spearphishing Link"
            },
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1059.001",
              "name": "PowerShell",
              "display_name": "T1059.001 - PowerShell"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 60,
            "domain": 5,
            "hostname": 94
          },
          "indicator_count": 159,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "123 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "69571965fd278704548024e0",
          "name": "ThreatFox Hunt: GootLoader IOCs - 2026-01-02",
          "description": "Automated ThreatFox hunt for GootLoader indicators. 82 IOCs collected via Pattern 49 intelligence streaming. MITRE ATT&CK: T1071.001, T1105. Reference: https://analytics.dugganusa.com",
          "modified": "2026-01-02T01:03:33.873000",
          "created": "2026-01-02T01:03:33.873000",
          "tags": [
            "gootloader",
            "threatfox",
            "automated-hunt",
            "pattern-49",
            "dugganusa",
            "loader"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix-feed/v2",
            "https://threatfox.abuse.ch"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "GootLoader",
              "display_name": "GootLoader",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 25,
            "domain": 5,
            "URL": 52
          },
          "indicator_count": 82,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "151 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "69570e6e20bb1811a53de517",
          "name": "ThreatFox Hunt: GootLoader IOCs - 2026-01-02",
          "description": "Automated ThreatFox hunt for GootLoader indicators. 82 IOCs collected via Pattern 49 intelligence streaming. MITRE ATT&CK: T1071.001, T1105. Reference: https://analytics.dugganusa.com",
          "modified": "2026-01-02T00:16:45.998000",
          "created": "2026-01-02T00:16:45.998000",
          "tags": [
            "gootloader",
            "threatfox",
            "automated-hunt",
            "pattern-49",
            "dugganusa",
            "loader"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix-feed/v2",
            "https://threatfox.abuse.ch"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "GootLoader",
              "display_name": "GootLoader",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 25,
            "domain": 5,
            "URL": 52
          },
          "indicator_count": 82,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "152 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "69570d41508620267362e520",
          "name": "ThreatFox Hunt: GootLoader IOCs - 2026-01-02",
          "description": "Automated ThreatFox hunt for GootLoader indicators. 82 IOCs collected via Pattern 49 intelligence streaming. MITRE ATT&CK: T1071.001, T1105. Reference: https://analytics.dugganusa.com",
          "modified": "2026-01-02T00:11:45.262000",
          "created": "2026-01-02T00:11:45.262000",
          "tags": [
            "gootloader",
            "threatfox",
            "automated-hunt",
            "pattern-49",
            "dugganusa",
            "loader"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix-feed/v2",
            "https://threatfox.abuse.ch"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "GootLoader",
              "display_name": "GootLoader",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 25,
            "domain": 5,
            "URL": 52
          },
          "indicator_count": 82,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "152 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "695708ec33f7b3a47d24d0f9",
          "name": "ThreatFox Hunt: GootLoader IOCs - 2026-01-01",
          "description": "Automated ThreatFox hunt for GootLoader indicators. 82 IOCs collected via Pattern 49 intelligence streaming. MITRE ATT&CK: T1071.001, T1105. Reference: https://analytics.dugganusa.com",
          "modified": "2026-01-01T23:53:16.969000",
          "created": "2026-01-01T23:53:16.969000",
          "tags": [
            "gootloader",
            "threatfox",
            "automated-hunt",
            "pattern-49",
            "dugganusa",
            "loader"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix-feed/v2",
            "https://threatfox.abuse.ch"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "GootLoader",
              "display_name": "GootLoader",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 25,
            "domain": 5,
            "URL": 52
          },
          "indicator_count": 82,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "152 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6956ed30c18f9ae38e2ad2e4",
          "name": "ThreatFox Hunt: GootLoader IOCs - 2026-01-01",
          "description": "Automated ThreatFox hunt for GootLoader indicators. 82 IOCs collected via Pattern 49 intelligence streaming. MITRE ATT&CK: T1071.001, T1105. Reference: https://analytics.dugganusa.com",
          "modified": "2026-01-01T21:54:56.724000",
          "created": "2026-01-01T21:54:56.724000",
          "tags": [
            "gootloader",
            "threatfox",
            "automated-hunt",
            "pattern-49",
            "dugganusa",
            "loader"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix-feed/v2",
            "https://threatfox.abuse.ch"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "GootLoader",
              "display_name": "GootLoader",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 25,
            "domain": 5,
            "URL": 52
          },
          "indicator_count": 82,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "152 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6956d2524168cd5dcc2dcf70",
          "name": "ThreatFox Hunt: GootLoader IOCs - 2026-01-01",
          "description": "Automated ThreatFox hunt for GootLoader indicators. 82 IOCs collected via Pattern 49 intelligence streaming. MITRE ATT&CK: T1071.001, T1105. Reference: https://analytics.dugganusa.com",
          "modified": "2026-01-01T20:00:18.660000",
          "created": "2026-01-01T20:00:18.660000",
          "tags": [
            "gootloader",
            "threatfox",
            "automated-hunt",
            "pattern-49",
            "dugganusa",
            "loader"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix-feed/v2",
            "https://threatfox.abuse.ch"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "GootLoader",
              "display_name": "GootLoader",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 25,
            "domain": 5,
            "URL": 52
          },
          "indicator_count": 82,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "152 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "695629e9b6bebf40eb633ac9",
          "name": "ThreatFox Hunt: GootLoader IOCs - 2026-01-01",
          "description": "Automated ThreatFox hunt for GootLoader indicators. 66 IOCs collected via Pattern 49 intelligence streaming. MITRE ATT&CK: T1071.001, T1105. Reference: https://analytics.dugganusa.com",
          "modified": "2026-01-01T08:01:45.500000",
          "created": "2026-01-01T08:01:45.500000",
          "tags": [
            "gootloader",
            "threatfox",
            "automated-hunt",
            "pattern-49",
            "dugganusa",
            "loader"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix-feed/v2",
            "https://threatfox.abuse.ch"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "GootLoader",
              "display_name": "GootLoader",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1071.001",
              "name": "Web Protocols",
              "display_name": "T1071.001 - Web Protocols"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 3,
            "URL": 52,
            "hostname": 11
          },
          "indicator_count": 66,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "152 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6954d35f677ebdd97ea55358",
          "name": "PreCog Sweep - 2025-12-31 07h",
          "description": "Novel threat indicators detected by PreCog Sweep Engine",
          "modified": "2025-12-31T07:40:15.728000",
          "created": "2025-12-31T07:40:15.728000",
          "tags": [
            "precog",
            "automated",
            "novel-ioc",
            "c2",
            "malware"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix/master",
            "https://github.com/pduggusa/dugganusa-research"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 93,
            "hostname": 182,
            "domain": 23
          },
          "indicator_count": 298,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "153 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6954d106f0100ed589a32518",
          "name": "PreCog Sweep - 2025-12-31 07h",
          "description": "Novel threat indicators detected by PreCog Sweep Engine",
          "modified": "2025-12-31T07:30:14.085000",
          "created": "2025-12-31T07:30:14.085000",
          "tags": [
            "precog",
            "automated",
            "novel-ioc",
            "c2",
            "malware"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix/master",
            "https://github.com/pduggusa/dugganusa-research"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 182,
            "URL": 92,
            "domain": 23
          },
          "indicator_count": 297,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 198,
          "modified_text": "153 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6954ceb0bfd74475d8cd5989",
          "name": "PreCog Sweep - 2025-12-31 07h",
          "description": "Novel threat indicators detected by PreCog Sweep Engine",
          "modified": "2025-12-31T07:20:16.616000",
          "created": "2025-12-31T07:20:16.616000",
          "tags": [
            "precog",
            "automated",
            "novel-ioc",
            "c2",
            "malware"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix/master",
            "https://github.com/pduggusa/dugganusa-research"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 182,
            "URL": 92,
            "domain": 23
          },
          "indicator_count": 297,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "153 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6954cc566e467afbb9421e30",
          "name": "PreCog Sweep - 2025-12-31 07h",
          "description": "Novel threat indicators detected by PreCog Sweep Engine",
          "modified": "2025-12-31T07:10:14.418000",
          "created": "2025-12-31T07:10:14.418000",
          "tags": [
            "precog",
            "automated",
            "novel-ioc",
            "c2",
            "malware"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix/master",
            "https://github.com/pduggusa/dugganusa-research"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 182,
            "URL": 92,
            "domain": 23
          },
          "indicator_count": 297,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "153 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6954c9fff425bd72f1e83878",
          "name": "PreCog Sweep - 2025-12-31 07h",
          "description": "Novel threat indicators detected by PreCog Sweep Engine",
          "modified": "2025-12-31T07:00:15",
          "created": "2025-12-31T07:00:15",
          "tags": [
            "precog",
            "automated",
            "novel-ioc",
            "c2",
            "malware"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix/master",
            "https://github.com/pduggusa/dugganusa-research"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 182,
            "URL": 92,
            "domain": 23
          },
          "indicator_count": 297,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "153 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6954c7a7397a7f18b6397b60",
          "name": "PreCog Sweep - 2025-12-31 06h",
          "description": "Novel threat indicators detected by PreCog Sweep Engine",
          "modified": "2025-12-31T06:50:15.036000",
          "created": "2025-12-31T06:50:15.036000",
          "tags": [
            "precog",
            "automated",
            "novel-ioc",
            "c2",
            "malware"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix/master",
            "https://github.com/pduggusa/dugganusa-research"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 182,
            "URL": 92,
            "domain": 23
          },
          "indicator_count": 297,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "153 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6954c54e5f23d43dee181dfb",
          "name": "PreCog Sweep - 2025-12-31 06h",
          "description": "Novel threat indicators detected by PreCog Sweep Engine",
          "modified": "2025-12-31T06:40:14.792000",
          "created": "2025-12-31T06:40:14.792000",
          "tags": [
            "precog",
            "automated",
            "novel-ioc",
            "c2",
            "malware"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix/master",
            "https://github.com/pduggusa/dugganusa-research"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 182,
            "URL": 92,
            "domain": 23
          },
          "indicator_count": 297,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "153 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6954c2f520fc2aa55c2187b4",
          "name": "PreCog Sweep - 2025-12-31 06h",
          "description": "Novel threat indicators detected by PreCog Sweep Engine",
          "modified": "2025-12-31T06:30:13.487000",
          "created": "2025-12-31T06:30:13.487000",
          "tags": [
            "precog",
            "automated",
            "novel-ioc",
            "c2",
            "malware"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix/master",
            "https://github.com/pduggusa/dugganusa-research"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 182,
            "URL": 92,
            "domain": 23
          },
          "indicator_count": 297,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "153 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6954c09e3758e5d88105113a",
          "name": "PreCog Sweep - 2025-12-31 06h",
          "description": "Novel threat indicators detected by PreCog Sweep Engine",
          "modified": "2025-12-31T06:20:14.494000",
          "created": "2025-12-31T06:20:14.494000",
          "tags": [
            "precog",
            "automated",
            "novel-ioc",
            "c2",
            "malware"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix/master",
            "https://github.com/pduggusa/dugganusa-research"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 182,
            "URL": 92,
            "domain": 23
          },
          "indicator_count": 297,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "153 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6954be452905039a1f3dc280",
          "name": "PreCog Sweep - 2025-12-31 06h",
          "description": "Novel threat indicators detected by PreCog Sweep Engine",
          "modified": "2025-12-31T06:10:13.816000",
          "created": "2025-12-31T06:10:13.816000",
          "tags": [
            "precog",
            "automated",
            "novel-ioc",
            "c2",
            "malware"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix/master",
            "https://github.com/pduggusa/dugganusa-research"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 182,
            "URL": 92,
            "domain": 23
          },
          "indicator_count": 297,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "153 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6954bbef6a5b63ee482fd327",
          "name": "PreCog Sweep - 2025-12-31 06h",
          "description": "Novel threat indicators detected by PreCog Sweep Engine",
          "modified": "2025-12-31T06:00:15.423000",
          "created": "2025-12-31T06:00:15.423000",
          "tags": [
            "precog",
            "automated",
            "novel-ioc",
            "c2",
            "malware"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix/master",
            "https://github.com/pduggusa/dugganusa-research"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 92,
            "hostname": 181,
            "domain": 23
          },
          "indicator_count": 296,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "153 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6954b99888121cdca6e8175b",
          "name": "PreCog Sweep - 2025-12-31 05h",
          "description": "Novel threat indicators detected by PreCog Sweep Engine",
          "modified": "2025-12-31T05:50:16.043000",
          "created": "2025-12-31T05:50:16.043000",
          "tags": [
            "precog",
            "automated",
            "novel-ioc",
            "c2",
            "malware"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix/master",
            "https://github.com/pduggusa/dugganusa-research"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 92,
            "hostname": 181,
            "domain": 23
          },
          "indicator_count": 296,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "153 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6954b73eae2fed348bc2b231",
          "name": "PreCog Sweep - 2025-12-31 05h",
          "description": "Novel threat indicators detected by PreCog Sweep Engine",
          "modified": "2025-12-31T05:40:14.082000",
          "created": "2025-12-31T05:40:14.082000",
          "tags": [
            "precog",
            "automated",
            "novel-ioc",
            "c2",
            "malware"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix/master",
            "https://github.com/pduggusa/dugganusa-research"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 92,
            "hostname": 181,
            "domain": 23
          },
          "indicator_count": 296,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "153 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6954b4e722c89a9d6010ea8d",
          "name": "PreCog Sweep - 2025-12-31 05h",
          "description": "Novel threat indicators detected by PreCog Sweep Engine",
          "modified": "2025-12-31T05:30:15.009000",
          "created": "2025-12-31T05:30:15.009000",
          "tags": [
            "precog",
            "automated",
            "novel-ioc",
            "c2",
            "malware"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix/master",
            "https://github.com/pduggusa/dugganusa-research"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 85,
            "hostname": 181,
            "domain": 23
          },
          "indicator_count": 289,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "153 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6954b28e1172311f359a6dd0",
          "name": "PreCog Sweep - 2025-12-31 05h",
          "description": "Novel threat indicators detected by PreCog Sweep Engine",
          "modified": "2025-12-31T05:20:14.432000",
          "created": "2025-12-31T05:20:14.432000",
          "tags": [
            "precog",
            "automated",
            "novel-ioc",
            "c2",
            "malware"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix/master",
            "https://github.com/pduggusa/dugganusa-research"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 85,
            "hostname": 181,
            "domain": 23
          },
          "indicator_count": 289,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "153 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6954b0380c042d3ed480ab33",
          "name": "PreCog Sweep - 2025-12-31 05h",
          "description": "Novel threat indicators detected by PreCog Sweep Engine",
          "modified": "2025-12-31T05:10:16.609000",
          "created": "2025-12-31T05:10:16.609000",
          "tags": [
            "precog",
            "automated",
            "novel-ioc",
            "c2",
            "malware"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix/master",
            "https://github.com/pduggusa/dugganusa-research"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 85,
            "hostname": 181,
            "domain": 23
          },
          "indicator_count": 289,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "153 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6954ade005de1705a4223d6b",
          "name": "PreCog Sweep - 2025-12-31 05h",
          "description": "Novel threat indicators detected by PreCog Sweep Engine",
          "modified": "2025-12-31T05:00:15.991000",
          "created": "2025-12-31T05:00:15.991000",
          "tags": [
            "precog",
            "automated",
            "novel-ioc",
            "c2",
            "malware"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix/master",
            "https://github.com/pduggusa/dugganusa-research"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 181,
            "URL": 84,
            "domain": 23
          },
          "indicator_count": 288,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "153 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6954ab8651a771fe3e8b1f93",
          "name": "PreCog Sweep - 2025-12-31 04h",
          "description": "Novel threat indicators detected by PreCog Sweep Engine",
          "modified": "2025-12-31T04:50:14.508000",
          "created": "2025-12-31T04:50:14.508000",
          "tags": [
            "precog",
            "automated",
            "novel-ioc",
            "c2",
            "malware"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix/master",
            "https://github.com/pduggusa/dugganusa-research"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 181,
            "URL": 84,
            "domain": 23
          },
          "indicator_count": 288,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "153 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6954a92f8c274737c5a75279",
          "name": "PreCog Sweep - 2025-12-31 04h",
          "description": "Novel threat indicators detected by PreCog Sweep Engine",
          "modified": "2025-12-31T04:40:15.167000",
          "created": "2025-12-31T04:40:15.167000",
          "tags": [
            "precog",
            "automated",
            "novel-ioc",
            "c2",
            "malware"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix/master",
            "https://github.com/pduggusa/dugganusa-research"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 181,
            "URL": 84,
            "domain": 23
          },
          "indicator_count": 288,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "153 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6954a6d6f84522ca63392dd0",
          "name": "PreCog Sweep - 2025-12-31 04h",
          "description": "Novel threat indicators detected by PreCog Sweep Engine",
          "modified": "2025-12-31T04:30:14.635000",
          "created": "2025-12-31T04:30:14.635000",
          "tags": [
            "precog",
            "automated",
            "novel-ioc",
            "c2",
            "malware"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix/master",
            "https://github.com/pduggusa/dugganusa-research"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 181,
            "URL": 84,
            "domain": 23
          },
          "indicator_count": 288,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "153 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6954a47e938961bead899427",
          "name": "PreCog Sweep - 2025-12-31 04h",
          "description": "Novel threat indicators detected by PreCog Sweep Engine",
          "modified": "2025-12-31T04:20:14.067000",
          "created": "2025-12-31T04:20:14.067000",
          "tags": [
            "precog",
            "automated",
            "novel-ioc",
            "c2",
            "malware"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix/master",
            "https://github.com/pduggusa/dugganusa-research"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 181,
            "URL": 84,
            "domain": 23
          },
          "indicator_count": 288,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "153 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6954a22741d655791f58a337",
          "name": "PreCog Sweep - 2025-12-31 04h",
          "description": "Novel threat indicators detected by PreCog Sweep Engine",
          "modified": "2025-12-31T04:10:15.364000",
          "created": "2025-12-31T04:10:15.364000",
          "tags": [
            "precog",
            "automated",
            "novel-ioc",
            "c2",
            "malware"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix/master",
            "https://github.com/pduggusa/dugganusa-research"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 181,
            "URL": 84,
            "domain": 23
          },
          "indicator_count": 288,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "153 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "69549fce448971a167309d76",
          "name": "PreCog Sweep - 2025-12-31 04h",
          "description": "Novel threat indicators detected by PreCog Sweep Engine",
          "modified": "2025-12-31T04:00:14.749000",
          "created": "2025-12-31T04:00:14.749000",
          "tags": [
            "precog",
            "automated",
            "novel-ioc",
            "c2",
            "malware"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix/master",
            "https://github.com/pduggusa/dugganusa-research"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 181,
            "URL": 84,
            "domain": 23
          },
          "indicator_count": 288,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "153 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "69549d766ac08ff7cbfb708b",
          "name": "PreCog Sweep - 2025-12-31 03h",
          "description": "Novel threat indicators detected by PreCog Sweep Engine",
          "modified": "2025-12-31T03:50:14.852000",
          "created": "2025-12-31T03:50:14.852000",
          "tags": [
            "precog",
            "automated",
            "novel-ioc",
            "c2",
            "malware"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix/master",
            "https://github.com/pduggusa/dugganusa-research"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 181,
            "URL": 84,
            "domain": 23
          },
          "indicator_count": 288,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "153 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "69549b1d7b5e4785f5ecae18",
          "name": "PreCog Sweep - 2025-12-31 03h",
          "description": "Novel threat indicators detected by PreCog Sweep Engine",
          "modified": "2025-12-31T03:40:13.983000",
          "created": "2025-12-31T03:40:13.983000",
          "tags": [
            "precog",
            "automated",
            "novel-ioc",
            "c2",
            "malware"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix/master",
            "https://github.com/pduggusa/dugganusa-research"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 181,
            "URL": 84,
            "domain": 23
          },
          "indicator_count": 288,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "153 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "695498c6fc61cc602cb88906",
          "name": "PreCog Sweep - 2025-12-31 03h",
          "description": "Novel threat indicators detected by PreCog Sweep Engine",
          "modified": "2025-12-31T03:30:14.225000",
          "created": "2025-12-31T03:30:14.225000",
          "tags": [
            "precog",
            "automated",
            "novel-ioc",
            "c2",
            "malware"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix/master",
            "https://github.com/pduggusa/dugganusa-research"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 181,
            "URL": 84,
            "domain": 23
          },
          "indicator_count": 288,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "153 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "69549670b40334fac519cd02",
          "name": "PreCog Sweep - 2025-12-31 03h",
          "description": "Novel threat indicators detected by PreCog Sweep Engine",
          "modified": "2025-12-31T03:20:16.034000",
          "created": "2025-12-31T03:20:16.034000",
          "tags": [
            "precog",
            "automated",
            "novel-ioc",
            "c2",
            "malware"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix/master",
            "https://github.com/pduggusa/dugganusa-research"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 181,
            "URL": 84,
            "domain": 23
          },
          "indicator_count": 288,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "153 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6954941774b1a370fa363f0e",
          "name": "PreCog Sweep - 2025-12-31 03h",
          "description": "Novel threat indicators detected by PreCog Sweep Engine",
          "modified": "2025-12-31T03:10:15.532000",
          "created": "2025-12-31T03:10:15.532000",
          "tags": [
            "precog",
            "automated",
            "novel-ioc",
            "c2",
            "malware"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix/master",
            "https://github.com/pduggusa/dugganusa-research"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 181,
            "URL": 84,
            "domain": 23
          },
          "indicator_count": 288,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "153 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "695491bed7046f23508e9b8f",
          "name": "PreCog Sweep - 2025-12-31 03h",
          "description": "Novel threat indicators detected by PreCog Sweep Engine",
          "modified": "2025-12-31T03:00:14.173000",
          "created": "2025-12-31T03:00:14.173000",
          "tags": [
            "precog",
            "automated",
            "novel-ioc",
            "c2",
            "malware"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix/master",
            "https://github.com/pduggusa/dugganusa-research"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 84,
            "domain": 23,
            "hostname": 180
          },
          "indicator_count": 287,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "153 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "69548f663ae8c8eccf2f97b6",
          "name": "PreCog Sweep - 2025-12-31 02h",
          "description": "Novel threat indicators detected by PreCog Sweep Engine",
          "modified": "2025-12-31T02:50:14.377000",
          "created": "2025-12-31T02:50:14.377000",
          "tags": [
            "precog",
            "automated",
            "novel-ioc",
            "c2",
            "malware"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix/master",
            "https://github.com/pduggusa/dugganusa-research"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 84,
            "domain": 23,
            "hostname": 180
          },
          "indicator_count": 287,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "153 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "69548d0f752545a25786dd1c",
          "name": "PreCog Sweep - 2025-12-31 02h",
          "description": "Novel threat indicators detected by PreCog Sweep Engine",
          "modified": "2025-12-31T02:40:15.962000",
          "created": "2025-12-31T02:40:15.962000",
          "tags": [
            "precog",
            "automated",
            "novel-ioc",
            "c2",
            "malware"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix/master",
            "https://github.com/pduggusa/dugganusa-research"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 84,
            "domain": 23,
            "hostname": 180
          },
          "indicator_count": 287,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "153 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "69548ab81491e428bbb9ff50",
          "name": "PreCog Sweep - 2025-12-31 02h",
          "description": "Novel threat indicators detected by PreCog Sweep Engine",
          "modified": "2025-12-31T02:30:16.214000",
          "created": "2025-12-31T02:30:16.214000",
          "tags": [
            "precog",
            "automated",
            "novel-ioc",
            "c2",
            "malware"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix/master",
            "https://github.com/pduggusa/dugganusa-research"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 84,
            "domain": 23,
            "hostname": 180
          },
          "indicator_count": 287,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "153 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6954885e52450fd1819ea54c",
          "name": "PreCog Sweep - 2025-12-31 02h",
          "description": "Novel threat indicators detected by PreCog Sweep Engine",
          "modified": "2025-12-31T02:20:14.816000",
          "created": "2025-12-31T02:20:14.816000",
          "tags": [
            "precog",
            "automated",
            "novel-ioc",
            "c2",
            "malware"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix/master",
            "https://github.com/pduggusa/dugganusa-research"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 84,
            "domain": 23,
            "hostname": 180
          },
          "indicator_count": 287,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "153 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "69548606c36d4d91ef457086",
          "name": "PreCog Sweep - 2025-12-31 02h",
          "description": "Novel threat indicators detected by PreCog Sweep Engine",
          "modified": "2025-12-31T02:10:13.995000",
          "created": "2025-12-31T02:10:13.995000",
          "tags": [
            "precog",
            "automated",
            "novel-ioc",
            "c2",
            "malware"
          ],
          "references": [
            "https://analytics.dugganusa.com/api/v1/stix/master",
            "https://github.com/pduggusa/dugganusa-research"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "pduggusa",
            "id": "371400",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 84,
            "domain": 23,
            "hostname": 180
          },
          "indicator_count": 287,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 197,
          "modified_text": "153 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": false,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "https://analytics.dugganusa.com/api/v1/stix/master",
        "https://threatfox.abuse.ch",
        "https://github.com/pduggusa/dugganusa-research",
        "https://analytics.dugganusa.com/api/v1/stix-feed/v2"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 0
        },
        "other": {
          "adversary": [],
          "malware_families": [
            "Gootloader",
            "Cobalt strike",
            "Sliver",
            "Clearfake",
            "Unknown malware"
          ],
          "industries": [],
          "unique_indicators": 367
        }
      }
    },
    "false_positive": [],
    "alexa": "http://www.alexa.com/siteinfo/8659.se",
    "whois": "http://whois.domaintools.com/8659.se",
    "domain": "8659.se",
    "hostname": "www.8659.se"
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 49,
  "pulses": [
    {
      "id": "6954c79d5e6d3536b0e2c2b1",
      "name": "OSINT Volley 2025-12-31 - ClearFake/Unknown malware/Cobalt Strike",
      "description": "Automated OSINT sweep from ThreatFox. Top malware: ClearFake(265), Unknown malware(151), Cobalt Strike(108), GootLoader(63), Sliver(62). Source: abuse.ch ThreatFox API. SSL enriched: 103 IPs with HTTPS, 17 self-signed (C2 candidates). Pattern 54: sweep\u2192volley automation.",
      "modified": "2026-01-30T06:00:51.865000",
      "created": "2025-12-31T06:50:05.401000",
      "tags": [
        "osint-volley",
        "threatfox",
        "automated",
        "clearfake",
        "unknown-malware",
        "cobalt-strike",
        "c2-infrastructure"
      ],
      "references": [
        "https://analytics.dugganusa.com/api/v1/stix-feed/v2",
        "https://threatfox.abuse.ch"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "ClearFake",
          "display_name": "ClearFake",
          "target": null
        },
        {
          "id": "Unknown malware",
          "display_name": "Unknown malware",
          "target": null
        },
        {
          "id": "Cobalt Strike",
          "display_name": "Cobalt Strike",
          "target": null
        },
        {
          "id": "GootLoader",
          "display_name": "GootLoader",
          "target": null
        },
        {
          "id": "Sliver",
          "display_name": "Sliver",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1189",
          "name": "Drive-by Compromise",
          "display_name": "T1189 - Drive-by Compromise"
        },
        {
          "id": "T1204.002",
          "name": "Malicious File",
          "display_name": "T1204.002 - Malicious File"
        },
        {
          "id": "T1566.002",
          "name": "Spearphishing Link",
          "display_name": "T1566.002 - Spearphishing Link"
        },
        {
          "id": "T1071.001",
          "name": "Web Protocols",
          "display_name": "T1071.001 - Web Protocols"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1059.001",
          "name": "PowerShell",
          "display_name": "T1059.001 - PowerShell"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 1,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "pduggusa",
        "id": "371400",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 76,
        "URL": 67,
        "domain": 5
      },
      "indicator_count": 148,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 197,
      "modified_text": "123 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6954c095f9326c2811926a9e",
      "name": "OSINT Volley 2025-12-31 - ClearFake/Unknown malware/Cobalt Strike",
      "description": "Automated OSINT sweep from ThreatFox. Top malware: ClearFake(265), Unknown malware(151), Cobalt Strike(108), GootLoader(63), Sliver(62). Source: abuse.ch ThreatFox API. SSL enriched: 103 IPs with HTTPS, 17 self-signed (C2 candidates). Pattern 54: sweep\u2192volley automation.",
      "modified": "2026-01-30T06:00:51.865000",
      "created": "2025-12-31T06:20:05.383000",
      "tags": [
        "osint-volley",
        "threatfox",
        "automated",
        "clearfake",
        "unknown-malware",
        "cobalt-strike",
        "c2-infrastructure"
      ],
      "references": [
        "https://analytics.dugganusa.com/api/v1/stix-feed/v2",
        "https://threatfox.abuse.ch"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "ClearFake",
          "display_name": "ClearFake",
          "target": null
        },
        {
          "id": "Unknown malware",
          "display_name": "Unknown malware",
          "target": null
        },
        {
          "id": "Cobalt Strike",
          "display_name": "Cobalt Strike",
          "target": null
        },
        {
          "id": "GootLoader",
          "display_name": "GootLoader",
          "target": null
        },
        {
          "id": "Sliver",
          "display_name": "Sliver",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1189",
          "name": "Drive-by Compromise",
          "display_name": "T1189 - Drive-by Compromise"
        },
        {
          "id": "T1204.002",
          "name": "Malicious File",
          "display_name": "T1204.002 - Malicious File"
        },
        {
          "id": "T1566.002",
          "name": "Spearphishing Link",
          "display_name": "T1566.002 - Spearphishing Link"
        },
        {
          "id": "T1071.001",
          "name": "Web Protocols",
          "display_name": "T1071.001 - Web Protocols"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1059.001",
          "name": "PowerShell",
          "display_name": "T1059.001 - PowerShell"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "pduggusa",
        "id": "371400",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 76,
        "URL": 67,
        "domain": 5
      },
      "indicator_count": 148,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 197,
      "modified_text": "123 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6954b98c294205f7f86672e6",
      "name": "OSINT Volley 2025-12-31 - ClearFake/Unknown malware/Cobalt Strike",
      "description": "Automated OSINT sweep from ThreatFox. Top malware: ClearFake(265), Unknown malware(151), Cobalt Strike(108), GootLoader(63), Sliver(62). Source: abuse.ch ThreatFox API. SSL enriched: 103 IPs with HTTPS, 17 self-signed (C2 candidates). Pattern 54: sweep\u2192volley automation.",
      "modified": "2026-01-30T05:00:01.077000",
      "created": "2025-12-31T05:50:04.286000",
      "tags": [
        "osint-volley",
        "threatfox",
        "automated",
        "clearfake",
        "unknown-malware",
        "cobalt-strike",
        "c2-infrastructure"
      ],
      "references": [
        "https://analytics.dugganusa.com/api/v1/stix-feed/v2",
        "https://threatfox.abuse.ch"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "ClearFake",
          "display_name": "ClearFake",
          "target": null
        },
        {
          "id": "Unknown malware",
          "display_name": "Unknown malware",
          "target": null
        },
        {
          "id": "Cobalt Strike",
          "display_name": "Cobalt Strike",
          "target": null
        },
        {
          "id": "GootLoader",
          "display_name": "GootLoader",
          "target": null
        },
        {
          "id": "Sliver",
          "display_name": "Sliver",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1189",
          "name": "Drive-by Compromise",
          "display_name": "T1189 - Drive-by Compromise"
        },
        {
          "id": "T1204.002",
          "name": "Malicious File",
          "display_name": "T1204.002 - Malicious File"
        },
        {
          "id": "T1566.002",
          "name": "Spearphishing Link",
          "display_name": "T1566.002 - Spearphishing Link"
        },
        {
          "id": "T1071.001",
          "name": "Web Protocols",
          "display_name": "T1071.001 - Web Protocols"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1059.001",
          "name": "PowerShell",
          "display_name": "T1059.001 - PowerShell"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "pduggusa",
        "id": "371400",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 67,
        "hostname": 76,
        "domain": 5
      },
      "indicator_count": 148,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 197,
      "modified_text": "123 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6954ab794f39613db3e136fa",
      "name": "OSINT Volley 2025-12-31 - ClearFake/Unknown malware/Cobalt Strike",
      "description": "Automated OSINT sweep from ThreatFox. Top malware: ClearFake(265), Unknown malware(143), Cobalt Strike(108), GootLoader(63), Sliver(62). Source: abuse.ch ThreatFox API. SSL enriched: 103 IPs with HTTPS, 17 self-signed (C2 candidates). Pattern 54: sweep\u2192volley automation.",
      "modified": "2026-01-30T04:03:08.625000",
      "created": "2025-12-31T04:50:01.971000",
      "tags": [
        "osint-volley",
        "threatfox",
        "automated",
        "clearfake",
        "unknown-malware",
        "cobalt-strike",
        "c2-infrastructure"
      ],
      "references": [
        "https://analytics.dugganusa.com/api/v1/stix-feed/v2",
        "https://threatfox.abuse.ch"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "ClearFake",
          "display_name": "ClearFake",
          "target": null
        },
        {
          "id": "Unknown malware",
          "display_name": "Unknown malware",
          "target": null
        },
        {
          "id": "Cobalt Strike",
          "display_name": "Cobalt Strike",
          "target": null
        },
        {
          "id": "GootLoader",
          "display_name": "GootLoader",
          "target": null
        },
        {
          "id": "Sliver",
          "display_name": "Sliver",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1189",
          "name": "Drive-by Compromise",
          "display_name": "T1189 - Drive-by Compromise"
        },
        {
          "id": "T1204.002",
          "name": "Malicious File",
          "display_name": "T1204.002 - Malicious File"
        },
        {
          "id": "T1566.002",
          "name": "Spearphishing Link",
          "display_name": "T1566.002 - Spearphishing Link"
        },
        {
          "id": "T1071.001",
          "name": "Web Protocols",
          "display_name": "T1071.001 - Web Protocols"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1059.001",
          "name": "PowerShell",
          "display_name": "T1059.001 - PowerShell"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 3,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "pduggusa",
        "id": "371400",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 80,
        "URL": 59,
        "domain": 5
      },
      "indicator_count": 144,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 197,
      "modified_text": "123 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6954a47345eb9d2e5bb21694",
      "name": "OSINT Volley 2025-12-31 - ClearFake/Unknown malware/Cobalt Strike",
      "description": "Automated OSINT sweep from ThreatFox. Top malware: ClearFake(265), Unknown malware(143), Cobalt Strike(108), GootLoader(63), Sliver(62). Source: abuse.ch ThreatFox API. SSL enriched: 103 IPs with HTTPS, 17 self-signed (C2 candidates). Pattern 54: sweep\u2192volley automation.",
      "modified": "2026-01-30T04:03:08.625000",
      "created": "2025-12-31T04:20:03.638000",
      "tags": [
        "osint-volley",
        "threatfox",
        "automated",
        "clearfake",
        "unknown-malware",
        "cobalt-strike",
        "c2-infrastructure"
      ],
      "references": [
        "https://analytics.dugganusa.com/api/v1/stix-feed/v2",
        "https://threatfox.abuse.ch"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "ClearFake",
          "display_name": "ClearFake",
          "target": null
        },
        {
          "id": "Unknown malware",
          "display_name": "Unknown malware",
          "target": null
        },
        {
          "id": "Cobalt Strike",
          "display_name": "Cobalt Strike",
          "target": null
        },
        {
          "id": "GootLoader",
          "display_name": "GootLoader",
          "target": null
        },
        {
          "id": "Sliver",
          "display_name": "Sliver",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1189",
          "name": "Drive-by Compromise",
          "display_name": "T1189 - Drive-by Compromise"
        },
        {
          "id": "T1204.002",
          "name": "Malicious File",
          "display_name": "T1204.002 - Malicious File"
        },
        {
          "id": "T1566.002",
          "name": "Spearphishing Link",
          "display_name": "T1566.002 - Spearphishing Link"
        },
        {
          "id": "T1071.001",
          "name": "Web Protocols",
          "display_name": "T1071.001 - Web Protocols"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1059.001",
          "name": "PowerShell",
          "display_name": "T1059.001 - PowerShell"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "pduggusa",
        "id": "371400",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 80,
        "URL": 59,
        "domain": 5
      },
      "indicator_count": 144,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 197,
      "modified_text": "123 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "69549d6d0809241237ea459d",
      "name": "OSINT Volley 2025-12-31 - ClearFake/Unknown malware/Cobalt Strike",
      "description": "Automated OSINT sweep from ThreatFox. Top malware: ClearFake(265), Unknown malware(137), Cobalt Strike(106), GootLoader(63), Sliver(62). Source: abuse.ch ThreatFox API. SSL enriched: 97 IPs with HTTPS, 17 self-signed (C2 candidates). Pattern 54: sweep\u2192volley automation.",
      "modified": "2026-01-30T03:04:44.497000",
      "created": "2025-12-31T03:50:03.518000",
      "tags": [
        "osint-volley",
        "threatfox",
        "automated",
        "clearfake",
        "unknown-malware",
        "cobalt-strike",
        "c2-infrastructure"
      ],
      "references": [
        "https://analytics.dugganusa.com/api/v1/stix-feed/v2",
        "https://threatfox.abuse.ch"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "ClearFake",
          "display_name": "ClearFake",
          "target": null
        },
        {
          "id": "Unknown malware",
          "display_name": "Unknown malware",
          "target": null
        },
        {
          "id": "Cobalt Strike",
          "display_name": "Cobalt Strike",
          "target": null
        },
        {
          "id": "GootLoader",
          "display_name": "GootLoader",
          "target": null
        },
        {
          "id": "Sliver",
          "display_name": "Sliver",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1189",
          "name": "Drive-by Compromise",
          "display_name": "T1189 - Drive-by Compromise"
        },
        {
          "id": "T1204.002",
          "name": "Malicious File",
          "display_name": "T1204.002 - Malicious File"
        },
        {
          "id": "T1566.002",
          "name": "Spearphishing Link",
          "display_name": "T1566.002 - Spearphishing Link"
        },
        {
          "id": "T1071.001",
          "name": "Web Protocols",
          "display_name": "T1071.001 - Web Protocols"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1059.001",
          "name": "PowerShell",
          "display_name": "T1059.001 - PowerShell"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 1,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "pduggusa",
        "id": "371400",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 94,
        "URL": 60,
        "domain": 5
      },
      "indicator_count": 159,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 197,
      "modified_text": "123 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "69549663b367946d1418e92a",
      "name": "OSINT Volley 2025-12-31 - ClearFake/Unknown malware/Cobalt Strike",
      "description": "Automated OSINT sweep from ThreatFox. Top malware: ClearFake(265), Unknown malware(137), Cobalt Strike(106), GootLoader(63), Sliver(62). Source: abuse.ch ThreatFox API. SSL enriched: 97 IPs with HTTPS, 17 self-signed (C2 candidates). Pattern 54: sweep\u2192volley automation.",
      "modified": "2026-01-30T03:04:44.497000",
      "created": "2025-12-31T03:20:03.906000",
      "tags": [
        "osint-volley",
        "threatfox",
        "automated",
        "clearfake",
        "unknown-malware",
        "cobalt-strike",
        "c2-infrastructure"
      ],
      "references": [
        "https://analytics.dugganusa.com/api/v1/stix-feed/v2",
        "https://threatfox.abuse.ch"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "ClearFake",
          "display_name": "ClearFake",
          "target": null
        },
        {
          "id": "Unknown malware",
          "display_name": "Unknown malware",
          "target": null
        },
        {
          "id": "Cobalt Strike",
          "display_name": "Cobalt Strike",
          "target": null
        },
        {
          "id": "GootLoader",
          "display_name": "GootLoader",
          "target": null
        },
        {
          "id": "Sliver",
          "display_name": "Sliver",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1189",
          "name": "Drive-by Compromise",
          "display_name": "T1189 - Drive-by Compromise"
        },
        {
          "id": "T1204.002",
          "name": "Malicious File",
          "display_name": "T1204.002 - Malicious File"
        },
        {
          "id": "T1566.002",
          "name": "Spearphishing Link",
          "display_name": "T1566.002 - Spearphishing Link"
        },
        {
          "id": "T1071.001",
          "name": "Web Protocols",
          "display_name": "T1071.001 - Web Protocols"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1059.001",
          "name": "PowerShell",
          "display_name": "T1059.001 - PowerShell"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "pduggusa",
        "id": "371400",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 94,
        "URL": 60,
        "domain": 5
      },
      "indicator_count": 159,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 197,
      "modified_text": "123 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "695488536274682db9451c77",
      "name": "OSINT Volley 2025-12-31 - ClearFake/Unknown malware/Cobalt Strike",
      "description": "Automated OSINT sweep from ThreatFox. Top malware: ClearFake(265), Unknown malware(137), Cobalt Strike(106), GootLoader(63), Sliver(62). Source: abuse.ch ThreatFox API. SSL enriched: 97 IPs with HTTPS, 17 self-signed (C2 candidates). Pattern 54: sweep\u2192volley automation.",
      "modified": "2026-01-30T02:00:24.431000",
      "created": "2025-12-31T02:20:03.938000",
      "tags": [
        "osint-volley",
        "threatfox",
        "automated",
        "clearfake",
        "unknown-malware",
        "cobalt-strike",
        "c2-infrastructure"
      ],
      "references": [
        "https://analytics.dugganusa.com/api/v1/stix-feed/v2",
        "https://threatfox.abuse.ch"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "ClearFake",
          "display_name": "ClearFake",
          "target": null
        },
        {
          "id": "Unknown malware",
          "display_name": "Unknown malware",
          "target": null
        },
        {
          "id": "Cobalt Strike",
          "display_name": "Cobalt Strike",
          "target": null
        },
        {
          "id": "GootLoader",
          "display_name": "GootLoader",
          "target": null
        },
        {
          "id": "Sliver",
          "display_name": "Sliver",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1189",
          "name": "Drive-by Compromise",
          "display_name": "T1189 - Drive-by Compromise"
        },
        {
          "id": "T1204.002",
          "name": "Malicious File",
          "display_name": "T1204.002 - Malicious File"
        },
        {
          "id": "T1566.002",
          "name": "Spearphishing Link",
          "display_name": "T1566.002 - Spearphishing Link"
        },
        {
          "id": "T1071.001",
          "name": "Web Protocols",
          "display_name": "T1071.001 - Web Protocols"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1059.001",
          "name": "PowerShell",
          "display_name": "T1059.001 - PowerShell"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "pduggusa",
        "id": "371400",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 60,
        "domain": 5,
        "hostname": 94
      },
      "indicator_count": 159,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 197,
      "modified_text": "123 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "69571965fd278704548024e0",
      "name": "ThreatFox Hunt: GootLoader IOCs - 2026-01-02",
      "description": "Automated ThreatFox hunt for GootLoader indicators. 82 IOCs collected via Pattern 49 intelligence streaming. MITRE ATT&CK: T1071.001, T1105. Reference: https://analytics.dugganusa.com",
      "modified": "2026-01-02T01:03:33.873000",
      "created": "2026-01-02T01:03:33.873000",
      "tags": [
        "gootloader",
        "threatfox",
        "automated-hunt",
        "pattern-49",
        "dugganusa",
        "loader"
      ],
      "references": [
        "https://analytics.dugganusa.com/api/v1/stix-feed/v2",
        "https://threatfox.abuse.ch"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "GootLoader",
          "display_name": "GootLoader",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1071.001",
          "name": "Web Protocols",
          "display_name": "T1071.001 - Web Protocols"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "pduggusa",
        "id": "371400",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 25,
        "domain": 5,
        "URL": 52
      },
      "indicator_count": 82,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 197,
      "modified_text": "151 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "69570e6e20bb1811a53de517",
      "name": "ThreatFox Hunt: GootLoader IOCs - 2026-01-02",
      "description": "Automated ThreatFox hunt for GootLoader indicators. 82 IOCs collected via Pattern 49 intelligence streaming. MITRE ATT&CK: T1071.001, T1105. Reference: https://analytics.dugganusa.com",
      "modified": "2026-01-02T00:16:45.998000",
      "created": "2026-01-02T00:16:45.998000",
      "tags": [
        "gootloader",
        "threatfox",
        "automated-hunt",
        "pattern-49",
        "dugganusa",
        "loader"
      ],
      "references": [
        "https://analytics.dugganusa.com/api/v1/stix-feed/v2",
        "https://threatfox.abuse.ch"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "GootLoader",
          "display_name": "GootLoader",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1071.001",
          "name": "Web Protocols",
          "display_name": "T1071.001 - Web Protocols"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "pduggusa",
        "id": "371400",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_371400/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 25,
        "domain": 5,
        "URL": 52
      },
      "indicator_count": 82,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 197,
      "modified_text": "152 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": false,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "https://www.8659.se/",
    "type": "URL"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "https://www.8659.se/",
    "type": "URL",
    "found": false,
    "verdict": "clean",
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780447895.4967608
}