{
  "type": "URL",
  "indicator": "https://www.alberta.ca/",
  "general": {
    "sections": [
      "general",
      "url_list",
      "http_scans",
      "screenshot"
    ],
    "indicator": "https://www.alberta.ca/",
    "type": "url",
    "type_title": "URL",
    "validation": [
      {
        "source": "majestic",
        "message": "Whitelisted domain alberta.ca",
        "name": "Whitelisted domain"
      }
    ],
    "base_indicator": {
      "id": 3932825835,
      "indicator": "https://www.alberta.ca/",
      "type": "URL",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 5,
      "pulses": [
        {
          "id": "6a191c2f71c868406024097f",
          "name": "\u0432\u0437\u043b\u043e\u043c\u0430\u043d\u043d\u044b\u0439",
          "description": "\u041a \u0447\u0451\u0440\u0442\u0443 \u044d\u0442\u0443 \u043f\u0440\u043e\u0432\u0438\u043d\u0446\u0438\u044e. \u0417\u0430\u0445\u043e\u0434\u0438\u0442\u0435 \u0432\u0441\u0435, \u0432\u043e\u0434\u0430 \u043e\u0442\u043b\u0438\u0447\u043d\u0430\u044f.",
          "modified": "2026-05-29T04:55:11.325000",
          "created": "2026-05-29T04:55:11.325000",
          "tags": [
            "tuca",
            "sct1",
            "seg0",
            "gaz1",
            "p1780029305477",
            "sid1780029305",
            "euaaaaagac",
            "nsi1",
            "p1780029178835",
            "ccc https",
            "locale"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "Canada",
            "Poland"
          ],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "Government",
            "Education"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "UCP_GoA23",
            "id": "382539",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_382539/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 543,
            "FileHash-MD5": 3,
            "FileHash-SHA256": 3,
            "IPv4": 119,
            "domain": 44,
            "hostname": 86
          },
          "indicator_count": 798,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 18,
          "modified_text": "2 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "69e72d44bb57858cd46b3c8e",
          "name": "04.21.26 - AHS/Covenant Health/United Nurses/Alberta Doctors",
          "description": "Analyses of a few samples of problems that continue to spread around as a direct result of inaction by AHS/Covenant Health/Gov. Alberta/UAlberta.\nPII/PHI - Alberta Doctors & United Nurses // NathanIP Jodi Notified",
          "modified": "2026-05-21T09:40:07.961000",
          "created": "2026-04-21T07:54:44.662000",
          "tags": [
            "sandbox",
            "malware",
            "analysis",
            "online",
            "submit",
            "vxstream",
            "sample",
            "download",
            "trojan",
            "apt",
            "hybrid analysis",
            "api key",
            "vetting process",
            "please note",
            "please",
            "AMA",
            "UNA",
            "AHS",
            "Covenant Health",
            "Connect Care",
            "AlbertaNDP"
          ],
          "references": [
            "http://hybrid-analysis.com/file-collection/69c88e067efe5c20ff0e14da",
            "http://hybrid-analysis.com/file-collection/69c88ddb7a828cc98a0b5d0a",
            "http://hybrid-analysis.com/file-collection/69897cf33ec0874455036fdc",
            "http://hybrid-analysis.com/sample/0783c904e06bd678d9a060e2792a66a51d16e175ffb26f351cd5af17f61d5475",
            "http://hybrid-analysis.com/sample/5cbc6aba25c2151d71a2deb58f07a86097fafb4c375458f841c1e337cafc01c7/69203be81fa431c05d0e157f",
            "http://hybrid-analysis.com/sample/81e7491b17d5bf7a75c4fe9d24eb269d0a85bf8f8ac5c1be6b909e627287b8f4/68445d370bb5610af304f98c",
            "307fabc3ec54d141b7e9a8ae27258c4edd3801aaed9febb8c8e166c93eeaa466 4661ff6c9cece9774f34be180106d42b1d7dc770e7ef19a909e11b5899f8407a 9c4b06c1e8d0bdd6c16ca5efe547bdb067b372aaee54b5e2973c99f9d7f0641f 3132f97617635455e66f7f53282b4c7023f3939ce481ec13b4fbb39da0134140 6f533ccc79227e38f18bfc63bfc961ef4d3ee0e2bf33dd097ccf3548a12b743b 97cd8014827953e8d4c1b4797d03c47ed04e55c6957164439380bf3b7c962dad 6b3d6e268dcb76e175a7db3d9e031349ab2c32654c7e57581a851e64dd6214ab 7d592c61d98abf019ad7c47fb074f9c25a58149ceaf536005306d9d9e",
            "http://hybrid-analysis.com/file-collection/69dbfef2c548c576f7040936",
            "http://hybrid-analysis.com/sample/ca3ad00eb0c08e6cf6f4d0aec3fa82fc3bb715aba6d0365af89165560e569cff/6840e93d07e1fb99850dc5fb",
            "",
            "http://hybrid-analysis.com/sample/c3bebbff9e57e640178494d9d73eae1bf5859fe6edad062dea89dd6262d2a910/67f0335dd833bf8f7a06b644"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "Canada"
          ],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "Healthcare",
            "Education",
            "Government"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Disable_Duck",
            "id": "244325",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_244325/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 471,
            "FileHash-MD5": 315,
            "FileHash-SHA1": 245,
            "SSLCertFingerprint": 74,
            "URL": 652,
            "domain": 123,
            "hostname": 183,
            "email": 28
          },
          "indicator_count": 2091,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 132,
          "modified_text": "10 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "67e709c0cfa1a1851d81a657",
          "name": "Government of Alberta ** Domain Analysis - 05.05.25",
          "description": "Domain Name: alberta.ca\nRegistry Domain ID: D198023-CIRA\nRegistrar WHOIS Server: whois.ca.fury.ca\nRegistrar URL: webnames.ca\nRegistrar: Webnames.ca Inc.\nRegistrar IANA ID: 456\nRegistrar Abuse Contact Email: abuse@webnames.ca\nRegistrar Abuse Contact Phone: +1.8662217878\n\nRegistry Registrant ID: R2532-CIRA\nRegistrant Name: Alberta Provincial Government\n3720 - 76 Avenue, Main Floor - Access Building\nEdmonton, AB T6B2N9, CA\nPh: +1.7806381828\nFax: +1.7806385949\nRegistrant Email: dutyweb@gov.ab.ca\nRegistry Admin ID: C851779-CIRA\nAdmin Name: CERTS Analyst\nAdmin Email: certs@gov.ab.ca\nRegistry Tech ID: C851781-CIRA\n\nName Server: is-dns1.gov.ab.ca\nName Server: is-dns3.gov.ab.ca\nDNSSEC: unsigned",
          "modified": "2025-06-05T02:05:37.765000",
          "created": "2025-03-28T20:42:40.389000",
          "tags": [
            "sandbox",
            "malware",
            "analysis",
            "online",
            "submit",
            "vxstream",
            "sample",
            "download",
            "trojan",
            "apt",
            "ansi",
            "symbol",
            "memoryfile scan",
            "path",
            "alberta",
            "prefetch8 ansi",
            "please",
            "show process",
            "date",
            "span",
            "find",
            "facebook",
            "twitter",
            "footer",
            "iframe",
            "suspicious",
            "body",
            "generator",
            "april",
            "energy",
            "comspec",
            "hybrid",
            "form",
            "main",
            "model",
            "close",
            "click",
            "hosts",
            "general",
            "starfield",
            "strings",
            "contact",
            "triage",
            "report",
            "reported",
            "analyze",
            "download submit",
            "sha512",
            "sha256",
            "prefetch8",
            "sha1",
            "filesize",
            "file",
            "prefetch1",
            "dataedge cloud",
            "process key",
            "config",
            "copy",
            "target",
            "impact",
            "javascript",
            "threat intelligence",
            "feed",
            "ioc",
            "change theme",
            "contact us",
            "intelligence",
            "threats api",
            "analyze api",
            "overview",
            "threats explore",
            "rate limits",
            "stixtaxii",
            "bulk export",
            "virus",
            "ransomware",
            "static",
            "indicator of compromise",
            "extraction",
            "emulation",
            "platform",
            "eid2",
            "eid3",
            "uaaaaaaai",
            "eid104",
            "malcore",
            "file analysis",
            "historical dns",
            "info",
            "login",
            "scan",
            "domain analysis",
            "discovered ip",
            "subdomains",
            "info malcore",
            "simple file",
            "policy terms",
            "intelligence x",
            "results",
            "product blog",
            "sign",
            "most relevant",
            "darknet",
            "please search",
            "search advanced",
            "categories date",
            "term",
            "slow",
            "scroll",
            "schedule",
            "cavalier",
            "bayonet",
            "full report",
            "users",
            "free report",
            "hudson rock",
            "attack surface",
            "customers",
            "demo explore",
            "tools",
            "third",
            "protect",
            "over",
            "rock",
            "service"
          ],
          "references": [
            "https://hybrid-analysis.com/sample/b0221df98cf7c8cbb752166c2942167038905c6ce60cd4289bee7d6c9d9c9981/67e70010db76da6d2704fa75",
            "https://tria.ge/250328-yq3hrsz1c1/behavioral1",
            "https://www.virustotal.com/gui/domain/alberta.ca",
            "https://pulsedive.com/indicator/?iid=9866511",
            "https://www.filescan.io/uploads/67e70367631830704a8a8a0c/reports/0cb06032-68da-40e4-8f2a-f2ef06384df8/ioc",
            "https://app.malcore.io/share/652553f6aec33d70a1dbbd25/67ab2665da3e8886f5e4ecce = Domain Analysis (refer to databreaches)",
            "https://intelx.io/?s=alberta.ca",
            "https://www.hudsonrock.com/search?domain=alberta.ca",
            "https://polyswarm.network/scan/results/url/8f3e04dffd9a4447667ca0135138ca8da321c66c9dbd6be815c17e2aa6e6f292",
            "https://www.urlvoid.com/whois-lookup/",
            "https://app.pentester.com/scans/U2NhblR5cGU6NjM1NDk1OA==",
            "https://cwe.mitre.org/data/definitions/79.html",
            "https://www.virustotal.com/gui/domain/alberta.ca/relations",
            "http://ci-www.threatcrowd.org/domain.php?domain=alberta.ca",
            "https://app.malcore.io/share/652553f6aec33d70a1dbbd25/67ab2665da3e8886f5e4ecce",
            "https://www.hybrid-analysis.com/sample/9b22c3771c435ce35bd0d8c766594a7e01156167829b60155e028d8852c69ba2/681974f451849933040662f6",
            "https://www.filescan.io/uploads/68197523c7418694c8a5dcd3/reports/ae06283d-f5d8-426d-a32c-1a04566e7635/ioc"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "Canada"
          ],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1105",
              "name": "Ingress Tool Transfer",
              "display_name": "T1105 - Ingress Tool Transfer"
            },
            {
              "id": "T1129",
              "name": "Shared Modules",
              "display_name": "T1129 - Shared Modules"
            },
            {
              "id": "T1518",
              "name": "Software Discovery",
              "display_name": "T1518 - Software Discovery"
            },
            {
              "id": "T1553",
              "name": "Subvert Trust Controls",
              "display_name": "T1553 - Subvert Trust Controls"
            },
            {
              "id": "T1566",
              "name": "Phishing",
              "display_name": "T1566 - Phishing"
            },
            {
              "id": "T1568",
              "name": "Dynamic Resolution",
              "display_name": "T1568 - Dynamic Resolution"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            },
            {
              "id": "T1583",
              "name": "Acquire Infrastructure",
              "display_name": "T1583 - Acquire Infrastructure"
            },
            {
              "id": "T1012",
              "name": "Query Registry",
              "display_name": "T1012 - Query Registry"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1217",
              "name": "Browser Bookmark Discovery",
              "display_name": "T1217 - Browser Bookmark Discovery"
            }
          ],
          "industries": [
            "Education",
            "Technology",
            "Government",
            "Healthcare"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 62,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 2,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Disable_Duck",
            "id": "244325",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_244325/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 126,
            "FileHash-SHA1": 118,
            "FileHash-SHA256": 347,
            "SSLCertFingerprint": 18,
            "domain": 149,
            "email": 16,
            "URL": 478,
            "hostname": 1562,
            "CVE": 7
          },
          "indicator_count": 2821,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 130,
          "modified_text": "360 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "66ac05add039aad334f4ee36",
          "name": "Alberta Health Services (AHS)",
          "description": "One Branch of the Province of Alberta Healthcare System\n\nUpdate 02.11.25 - need to add Malcore IOCs: https://app.malcore.io/share/652553f6aec33d70a1dbbd25/67ab2665782e1dfbf8ec2d3c",
          "modified": "2025-03-30T02:04:31.271000",
          "created": "2024-08-01T22:01:17.145000",
          "tags": [
            "UAlberta",
            "Alberta Health Services",
            "AHS"
          ],
          "references": [
            "https://www.virustotal.com/graph/embed/g6ec84c0946bf424a9d95f11fc77dcaff262f4a13daa6464386b17bb2a0ed4bbf?theme=dark",
            "https://www.virustotal.com/gui/collection/ba238f4d585b87abb85c126f927090cb866facfa9e4e2e0db8e307aff553397d",
            "https://www.virustotal.com/gui/collection/ba238f4d585b87abb85c126f927090cb866facfa9e4e2e0db8e307aff553397d/graph",
            "https://www.virustotal.com/gui/collection/ba238f4d585b87abb85c126f927090cb866facfa9e4e2e0db8e307aff553397d/iocs",
            "10.18.24: https://www.virustotal.com/graph/embed/g6ec84c0946bf424a9d95f11fc77dcaff262f4a13daa6464386b17bb2a0ed4bbf?theme=dark",
            "https://app.malcore.io/share/652553f6aec33d70a1dbbd25/67ab2665782e1dfbf8ec2d3c"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "Canada"
          ],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "Healthcare",
            "Technology",
            "Telecommunications"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 18,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Disable_Duck",
            "id": "244325",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_244325/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 358,
            "hostname": 850,
            "CIDR": 1,
            "FileHash-MD5": 17,
            "FileHash-SHA1": 17,
            "FileHash-SHA256": 434,
            "domain": 139,
            "email": 2,
            "SSLCertFingerprint": 412
          },
          "indicator_count": 2230,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 131,
          "modified_text": "427 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6614565faf9eb7bd8f9b7956",
          "name": "Government of Alberta: U of A -> Telus -> Advanced Education",
          "description": "So I retraced some steps. I guess I'm admin. Neat. Already notified Ministry of Advanced Education, Government of Alberta Cybersecurity (not helpful). I don't have access to this account anymore (well, I haven't tried), but I did work my way back in an attempt to figure out why I could administrate the \"Honourable Ministry of Education\". \n\nUpdate on the alberta.ca domain: by malcore on 02.11.25 in references. **Need to add malcore IOCs** https://app.malcore.io/share/652553f6aec33d70a1dbbd25/67ab2665da3e8886f5e4ecce",
          "modified": "2025-03-14T21:04:23.242000",
          "created": "2024-04-08T20:41:03.850000",
          "tags": [],
          "references": [
            "https://www.virustotal.com/graph/embed/g4f693a77e33b425bba54132d3a641fcd8b78af74d8fc44528a643c4a264d582f?theme=dark",
            "https://www.virustotal.com/gui/collection/8d65d93130b4775903adbffbb53820d40bb9425dcf1848b806ffee65ee883984/iocs",
            "https://www.virustotal.com/gui/collection/8d65d93130b4775903adbffbb53820d40bb9425dcf1848b806ffee65ee883984",
            "https://www.alberta.ca/minister-of-advanced-education",
            "https://app.malcore.io/share/652553f6aec33d70a1dbbd25/67ab2665782e1dfbf8ec2d3c",
            "https://app.malcore.io/share/652553f6aec33d70a1dbbd25/67ab2665da3e8886f5e4ecce"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "Canada",
            "United States of America"
          ],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "Government",
            "Education",
            "Telecommunications",
            "Technology"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 13,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 5,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Disable_Duck",
            "id": "244325",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_244325/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 5137,
            "hostname": 3405,
            "domain": 1659,
            "URL": 2452,
            "FileHash-MD5": 576,
            "FileHash-SHA1": 567,
            "CIDR": 9,
            "email": 7,
            "CVE": 15
          },
          "indicator_count": 13827,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 134,
          "modified_text": "442 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "",
        "https://app.malcore.io/share/652553f6aec33d70a1dbbd25/67ab2665da3e8886f5e4ecce = Domain Analysis (refer to databreaches)",
        "https://intelx.io/?s=alberta.ca",
        "https://pulsedive.com/indicator/?iid=9866511",
        "https://www.filescan.io/uploads/68197523c7418694c8a5dcd3/reports/ae06283d-f5d8-426d-a32c-1a04566e7635/ioc",
        "https://www.filescan.io/uploads/67e70367631830704a8a8a0c/reports/0cb06032-68da-40e4-8f2a-f2ef06384df8/ioc",
        "https://www.virustotal.com/gui/domain/alberta.ca",
        "http://hybrid-analysis.com/file-collection/69897cf33ec0874455036fdc",
        "https://www.hudsonrock.com/search?domain=alberta.ca",
        "http://hybrid-analysis.com/file-collection/69dbfef2c548c576f7040936",
        "307fabc3ec54d141b7e9a8ae27258c4edd3801aaed9febb8c8e166c93eeaa466 4661ff6c9cece9774f34be180106d42b1d7dc770e7ef19a909e11b5899f8407a 9c4b06c1e8d0bdd6c16ca5efe547bdb067b372aaee54b5e2973c99f9d7f0641f 3132f97617635455e66f7f53282b4c7023f3939ce481ec13b4fbb39da0134140 6f533ccc79227e38f18bfc63bfc961ef4d3ee0e2bf33dd097ccf3548a12b743b 97cd8014827953e8d4c1b4797d03c47ed04e55c6957164439380bf3b7c962dad 6b3d6e268dcb76e175a7db3d9e031349ab2c32654c7e57581a851e64dd6214ab 7d592c61d98abf019ad7c47fb074f9c25a58149ceaf536005306d9d9e",
        "https://app.malcore.io/share/652553f6aec33d70a1dbbd25/67ab2665782e1dfbf8ec2d3c",
        "http://hybrid-analysis.com/sample/81e7491b17d5bf7a75c4fe9d24eb269d0a85bf8f8ac5c1be6b909e627287b8f4/68445d370bb5610af304f98c",
        "http://hybrid-analysis.com/sample/0783c904e06bd678d9a060e2792a66a51d16e175ffb26f351cd5af17f61d5475",
        "https://www.urlvoid.com/whois-lookup/",
        "https://www.virustotal.com/gui/collection/8d65d93130b4775903adbffbb53820d40bb9425dcf1848b806ffee65ee883984/iocs",
        "https://www.virustotal.com/gui/collection/ba238f4d585b87abb85c126f927090cb866facfa9e4e2e0db8e307aff553397d",
        "http://hybrid-analysis.com/file-collection/69c88ddb7a828cc98a0b5d0a",
        "https://app.malcore.io/share/652553f6aec33d70a1dbbd25/67ab2665da3e8886f5e4ecce",
        "http://hybrid-analysis.com/sample/ca3ad00eb0c08e6cf6f4d0aec3fa82fc3bb715aba6d0365af89165560e569cff/6840e93d07e1fb99850dc5fb",
        "http://hybrid-analysis.com/sample/c3bebbff9e57e640178494d9d73eae1bf5859fe6edad062dea89dd6262d2a910/67f0335dd833bf8f7a06b644",
        "https://www.hybrid-analysis.com/sample/9b22c3771c435ce35bd0d8c766594a7e01156167829b60155e028d8852c69ba2/681974f451849933040662f6",
        "https://www.virustotal.com/gui/collection/ba238f4d585b87abb85c126f927090cb866facfa9e4e2e0db8e307aff553397d/iocs",
        "https://cwe.mitre.org/data/definitions/79.html",
        "https://www.virustotal.com/gui/collection/ba238f4d585b87abb85c126f927090cb866facfa9e4e2e0db8e307aff553397d/graph",
        "https://app.pentester.com/scans/U2NhblR5cGU6NjM1NDk1OA==",
        "https://www.virustotal.com/graph/embed/g6ec84c0946bf424a9d95f11fc77dcaff262f4a13daa6464386b17bb2a0ed4bbf?theme=dark",
        "https://hybrid-analysis.com/sample/b0221df98cf7c8cbb752166c2942167038905c6ce60cd4289bee7d6c9d9c9981/67e70010db76da6d2704fa75",
        "http://hybrid-analysis.com/file-collection/69c88e067efe5c20ff0e14da",
        "http://ci-www.threatcrowd.org/domain.php?domain=alberta.ca",
        "https://www.virustotal.com/graph/embed/g4f693a77e33b425bba54132d3a641fcd8b78af74d8fc44528a643c4a264d582f?theme=dark",
        "https://www.virustotal.com/gui/domain/alberta.ca/relations",
        "https://tria.ge/250328-yq3hrsz1c1/behavioral1",
        "https://www.virustotal.com/gui/collection/8d65d93130b4775903adbffbb53820d40bb9425dcf1848b806ffee65ee883984",
        "http://hybrid-analysis.com/sample/5cbc6aba25c2151d71a2deb58f07a86097fafb4c375458f841c1e337cafc01c7/69203be81fa431c05d0e157f",
        "10.18.24: https://www.virustotal.com/graph/embed/g6ec84c0946bf424a9d95f11fc77dcaff262f4a13daa6464386b17bb2a0ed4bbf?theme=dark",
        "https://www.alberta.ca/minister-of-advanced-education",
        "https://polyswarm.network/scan/results/url/8f3e04dffd9a4447667ca0135138ca8da321c66c9dbd6be815c17e2aa6e6f292"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 0
        },
        "other": {
          "adversary": [],
          "malware_families": [],
          "industries": [
            "Government",
            "Education",
            "Telecommunications",
            "Healthcare",
            "Technology"
          ],
          "unique_indicators": 9702
        }
      }
    },
    "false_positive": [],
    "alexa": "http://www.alexa.com/siteinfo/alberta.ca",
    "whois": "http://whois.domaintools.com/alberta.ca",
    "domain": "alberta.ca",
    "hostname": "www.alberta.ca"
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 5,
  "pulses": [
    {
      "id": "6a191c2f71c868406024097f",
      "name": "\u0432\u0437\u043b\u043e\u043c\u0430\u043d\u043d\u044b\u0439",
      "description": "\u041a \u0447\u0451\u0440\u0442\u0443 \u044d\u0442\u0443 \u043f\u0440\u043e\u0432\u0438\u043d\u0446\u0438\u044e. \u0417\u0430\u0445\u043e\u0434\u0438\u0442\u0435 \u0432\u0441\u0435, \u0432\u043e\u0434\u0430 \u043e\u0442\u043b\u0438\u0447\u043d\u0430\u044f.",
      "modified": "2026-05-29T04:55:11.325000",
      "created": "2026-05-29T04:55:11.325000",
      "tags": [
        "tuca",
        "sct1",
        "seg0",
        "gaz1",
        "p1780029305477",
        "sid1780029305",
        "euaaaaagac",
        "nsi1",
        "p1780029178835",
        "ccc https",
        "locale"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "Canada",
        "Poland"
      ],
      "malware_families": [],
      "attack_ids": [],
      "industries": [
        "Government",
        "Education"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "UCP_GoA23",
        "id": "382539",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_382539/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 543,
        "FileHash-MD5": 3,
        "FileHash-SHA256": 3,
        "IPv4": 119,
        "domain": 44,
        "hostname": 86
      },
      "indicator_count": 798,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 18,
      "modified_text": "2 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "69e72d44bb57858cd46b3c8e",
      "name": "04.21.26 - AHS/Covenant Health/United Nurses/Alberta Doctors",
      "description": "Analyses of a few samples of problems that continue to spread around as a direct result of inaction by AHS/Covenant Health/Gov. Alberta/UAlberta.\nPII/PHI - Alberta Doctors & United Nurses // NathanIP Jodi Notified",
      "modified": "2026-05-21T09:40:07.961000",
      "created": "2026-04-21T07:54:44.662000",
      "tags": [
        "sandbox",
        "malware",
        "analysis",
        "online",
        "submit",
        "vxstream",
        "sample",
        "download",
        "trojan",
        "apt",
        "hybrid analysis",
        "api key",
        "vetting process",
        "please note",
        "please",
        "AMA",
        "UNA",
        "AHS",
        "Covenant Health",
        "Connect Care",
        "AlbertaNDP"
      ],
      "references": [
        "http://hybrid-analysis.com/file-collection/69c88e067efe5c20ff0e14da",
        "http://hybrid-analysis.com/file-collection/69c88ddb7a828cc98a0b5d0a",
        "http://hybrid-analysis.com/file-collection/69897cf33ec0874455036fdc",
        "http://hybrid-analysis.com/sample/0783c904e06bd678d9a060e2792a66a51d16e175ffb26f351cd5af17f61d5475",
        "http://hybrid-analysis.com/sample/5cbc6aba25c2151d71a2deb58f07a86097fafb4c375458f841c1e337cafc01c7/69203be81fa431c05d0e157f",
        "http://hybrid-analysis.com/sample/81e7491b17d5bf7a75c4fe9d24eb269d0a85bf8f8ac5c1be6b909e627287b8f4/68445d370bb5610af304f98c",
        "307fabc3ec54d141b7e9a8ae27258c4edd3801aaed9febb8c8e166c93eeaa466 4661ff6c9cece9774f34be180106d42b1d7dc770e7ef19a909e11b5899f8407a 9c4b06c1e8d0bdd6c16ca5efe547bdb067b372aaee54b5e2973c99f9d7f0641f 3132f97617635455e66f7f53282b4c7023f3939ce481ec13b4fbb39da0134140 6f533ccc79227e38f18bfc63bfc961ef4d3ee0e2bf33dd097ccf3548a12b743b 97cd8014827953e8d4c1b4797d03c47ed04e55c6957164439380bf3b7c962dad 6b3d6e268dcb76e175a7db3d9e031349ab2c32654c7e57581a851e64dd6214ab 7d592c61d98abf019ad7c47fb074f9c25a58149ceaf536005306d9d9e",
        "http://hybrid-analysis.com/file-collection/69dbfef2c548c576f7040936",
        "http://hybrid-analysis.com/sample/ca3ad00eb0c08e6cf6f4d0aec3fa82fc3bb715aba6d0365af89165560e569cff/6840e93d07e1fb99850dc5fb",
        "",
        "http://hybrid-analysis.com/sample/c3bebbff9e57e640178494d9d73eae1bf5859fe6edad062dea89dd6262d2a910/67f0335dd833bf8f7a06b644"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "Canada"
      ],
      "malware_families": [],
      "attack_ids": [],
      "industries": [
        "Healthcare",
        "Education",
        "Government"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Disable_Duck",
        "id": "244325",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_244325/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 471,
        "FileHash-MD5": 315,
        "FileHash-SHA1": 245,
        "SSLCertFingerprint": 74,
        "URL": 652,
        "domain": 123,
        "hostname": 183,
        "email": 28
      },
      "indicator_count": 2091,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 132,
      "modified_text": "10 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "67e709c0cfa1a1851d81a657",
      "name": "Government of Alberta ** Domain Analysis - 05.05.25",
      "description": "Domain Name: alberta.ca\nRegistry Domain ID: D198023-CIRA\nRegistrar WHOIS Server: whois.ca.fury.ca\nRegistrar URL: webnames.ca\nRegistrar: Webnames.ca Inc.\nRegistrar IANA ID: 456\nRegistrar Abuse Contact Email: abuse@webnames.ca\nRegistrar Abuse Contact Phone: +1.8662217878\n\nRegistry Registrant ID: R2532-CIRA\nRegistrant Name: Alberta Provincial Government\n3720 - 76 Avenue, Main Floor - Access Building\nEdmonton, AB T6B2N9, CA\nPh: +1.7806381828\nFax: +1.7806385949\nRegistrant Email: dutyweb@gov.ab.ca\nRegistry Admin ID: C851779-CIRA\nAdmin Name: CERTS Analyst\nAdmin Email: certs@gov.ab.ca\nRegistry Tech ID: C851781-CIRA\n\nName Server: is-dns1.gov.ab.ca\nName Server: is-dns3.gov.ab.ca\nDNSSEC: unsigned",
      "modified": "2025-06-05T02:05:37.765000",
      "created": "2025-03-28T20:42:40.389000",
      "tags": [
        "sandbox",
        "malware",
        "analysis",
        "online",
        "submit",
        "vxstream",
        "sample",
        "download",
        "trojan",
        "apt",
        "ansi",
        "symbol",
        "memoryfile scan",
        "path",
        "alberta",
        "prefetch8 ansi",
        "please",
        "show process",
        "date",
        "span",
        "find",
        "facebook",
        "twitter",
        "footer",
        "iframe",
        "suspicious",
        "body",
        "generator",
        "april",
        "energy",
        "comspec",
        "hybrid",
        "form",
        "main",
        "model",
        "close",
        "click",
        "hosts",
        "general",
        "starfield",
        "strings",
        "contact",
        "triage",
        "report",
        "reported",
        "analyze",
        "download submit",
        "sha512",
        "sha256",
        "prefetch8",
        "sha1",
        "filesize",
        "file",
        "prefetch1",
        "dataedge cloud",
        "process key",
        "config",
        "copy",
        "target",
        "impact",
        "javascript",
        "threat intelligence",
        "feed",
        "ioc",
        "change theme",
        "contact us",
        "intelligence",
        "threats api",
        "analyze api",
        "overview",
        "threats explore",
        "rate limits",
        "stixtaxii",
        "bulk export",
        "virus",
        "ransomware",
        "static",
        "indicator of compromise",
        "extraction",
        "emulation",
        "platform",
        "eid2",
        "eid3",
        "uaaaaaaai",
        "eid104",
        "malcore",
        "file analysis",
        "historical dns",
        "info",
        "login",
        "scan",
        "domain analysis",
        "discovered ip",
        "subdomains",
        "info malcore",
        "simple file",
        "policy terms",
        "intelligence x",
        "results",
        "product blog",
        "sign",
        "most relevant",
        "darknet",
        "please search",
        "search advanced",
        "categories date",
        "term",
        "slow",
        "scroll",
        "schedule",
        "cavalier",
        "bayonet",
        "full report",
        "users",
        "free report",
        "hudson rock",
        "attack surface",
        "customers",
        "demo explore",
        "tools",
        "third",
        "protect",
        "over",
        "rock",
        "service"
      ],
      "references": [
        "https://hybrid-analysis.com/sample/b0221df98cf7c8cbb752166c2942167038905c6ce60cd4289bee7d6c9d9c9981/67e70010db76da6d2704fa75",
        "https://tria.ge/250328-yq3hrsz1c1/behavioral1",
        "https://www.virustotal.com/gui/domain/alberta.ca",
        "https://pulsedive.com/indicator/?iid=9866511",
        "https://www.filescan.io/uploads/67e70367631830704a8a8a0c/reports/0cb06032-68da-40e4-8f2a-f2ef06384df8/ioc",
        "https://app.malcore.io/share/652553f6aec33d70a1dbbd25/67ab2665da3e8886f5e4ecce = Domain Analysis (refer to databreaches)",
        "https://intelx.io/?s=alberta.ca",
        "https://www.hudsonrock.com/search?domain=alberta.ca",
        "https://polyswarm.network/scan/results/url/8f3e04dffd9a4447667ca0135138ca8da321c66c9dbd6be815c17e2aa6e6f292",
        "https://www.urlvoid.com/whois-lookup/",
        "https://app.pentester.com/scans/U2NhblR5cGU6NjM1NDk1OA==",
        "https://cwe.mitre.org/data/definitions/79.html",
        "https://www.virustotal.com/gui/domain/alberta.ca/relations",
        "http://ci-www.threatcrowd.org/domain.php?domain=alberta.ca",
        "https://app.malcore.io/share/652553f6aec33d70a1dbbd25/67ab2665da3e8886f5e4ecce",
        "https://www.hybrid-analysis.com/sample/9b22c3771c435ce35bd0d8c766594a7e01156167829b60155e028d8852c69ba2/681974f451849933040662f6",
        "https://www.filescan.io/uploads/68197523c7418694c8a5dcd3/reports/ae06283d-f5d8-426d-a32c-1a04566e7635/ioc"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "Canada"
      ],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1105",
          "name": "Ingress Tool Transfer",
          "display_name": "T1105 - Ingress Tool Transfer"
        },
        {
          "id": "T1129",
          "name": "Shared Modules",
          "display_name": "T1129 - Shared Modules"
        },
        {
          "id": "T1518",
          "name": "Software Discovery",
          "display_name": "T1518 - Software Discovery"
        },
        {
          "id": "T1553",
          "name": "Subvert Trust Controls",
          "display_name": "T1553 - Subvert Trust Controls"
        },
        {
          "id": "T1566",
          "name": "Phishing",
          "display_name": "T1566 - Phishing"
        },
        {
          "id": "T1568",
          "name": "Dynamic Resolution",
          "display_name": "T1568 - Dynamic Resolution"
        },
        {
          "id": "T1573",
          "name": "Encrypted Channel",
          "display_name": "T1573 - Encrypted Channel"
        },
        {
          "id": "T1583",
          "name": "Acquire Infrastructure",
          "display_name": "T1583 - Acquire Infrastructure"
        },
        {
          "id": "T1012",
          "name": "Query Registry",
          "display_name": "T1012 - Query Registry"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1217",
          "name": "Browser Bookmark Discovery",
          "display_name": "T1217 - Browser Bookmark Discovery"
        }
      ],
      "industries": [
        "Education",
        "Technology",
        "Government",
        "Healthcare"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 62,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 2,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Disable_Duck",
        "id": "244325",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_244325/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 126,
        "FileHash-SHA1": 118,
        "FileHash-SHA256": 347,
        "SSLCertFingerprint": 18,
        "domain": 149,
        "email": 16,
        "URL": 478,
        "hostname": 1562,
        "CVE": 7
      },
      "indicator_count": 2821,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 130,
      "modified_text": "360 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "66ac05add039aad334f4ee36",
      "name": "Alberta Health Services (AHS)",
      "description": "One Branch of the Province of Alberta Healthcare System\n\nUpdate 02.11.25 - need to add Malcore IOCs: https://app.malcore.io/share/652553f6aec33d70a1dbbd25/67ab2665782e1dfbf8ec2d3c",
      "modified": "2025-03-30T02:04:31.271000",
      "created": "2024-08-01T22:01:17.145000",
      "tags": [
        "UAlberta",
        "Alberta Health Services",
        "AHS"
      ],
      "references": [
        "https://www.virustotal.com/graph/embed/g6ec84c0946bf424a9d95f11fc77dcaff262f4a13daa6464386b17bb2a0ed4bbf?theme=dark",
        "https://www.virustotal.com/gui/collection/ba238f4d585b87abb85c126f927090cb866facfa9e4e2e0db8e307aff553397d",
        "https://www.virustotal.com/gui/collection/ba238f4d585b87abb85c126f927090cb866facfa9e4e2e0db8e307aff553397d/graph",
        "https://www.virustotal.com/gui/collection/ba238f4d585b87abb85c126f927090cb866facfa9e4e2e0db8e307aff553397d/iocs",
        "10.18.24: https://www.virustotal.com/graph/embed/g6ec84c0946bf424a9d95f11fc77dcaff262f4a13daa6464386b17bb2a0ed4bbf?theme=dark",
        "https://app.malcore.io/share/652553f6aec33d70a1dbbd25/67ab2665782e1dfbf8ec2d3c"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "Canada"
      ],
      "malware_families": [],
      "attack_ids": [],
      "industries": [
        "Healthcare",
        "Technology",
        "Telecommunications"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 18,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Disable_Duck",
        "id": "244325",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_244325/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 358,
        "hostname": 850,
        "CIDR": 1,
        "FileHash-MD5": 17,
        "FileHash-SHA1": 17,
        "FileHash-SHA256": 434,
        "domain": 139,
        "email": 2,
        "SSLCertFingerprint": 412
      },
      "indicator_count": 2230,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 131,
      "modified_text": "427 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6614565faf9eb7bd8f9b7956",
      "name": "Government of Alberta: U of A -> Telus -> Advanced Education",
      "description": "So I retraced some steps. I guess I'm admin. Neat. Already notified Ministry of Advanced Education, Government of Alberta Cybersecurity (not helpful). I don't have access to this account anymore (well, I haven't tried), but I did work my way back in an attempt to figure out why I could administrate the \"Honourable Ministry of Education\". \n\nUpdate on the alberta.ca domain: by malcore on 02.11.25 in references. **Need to add malcore IOCs** https://app.malcore.io/share/652553f6aec33d70a1dbbd25/67ab2665da3e8886f5e4ecce",
      "modified": "2025-03-14T21:04:23.242000",
      "created": "2024-04-08T20:41:03.850000",
      "tags": [],
      "references": [
        "https://www.virustotal.com/graph/embed/g4f693a77e33b425bba54132d3a641fcd8b78af74d8fc44528a643c4a264d582f?theme=dark",
        "https://www.virustotal.com/gui/collection/8d65d93130b4775903adbffbb53820d40bb9425dcf1848b806ffee65ee883984/iocs",
        "https://www.virustotal.com/gui/collection/8d65d93130b4775903adbffbb53820d40bb9425dcf1848b806ffee65ee883984",
        "https://www.alberta.ca/minister-of-advanced-education",
        "https://app.malcore.io/share/652553f6aec33d70a1dbbd25/67ab2665782e1dfbf8ec2d3c",
        "https://app.malcore.io/share/652553f6aec33d70a1dbbd25/67ab2665da3e8886f5e4ecce"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "Canada",
        "United States of America"
      ],
      "malware_families": [],
      "attack_ids": [],
      "industries": [
        "Government",
        "Education",
        "Telecommunications",
        "Technology"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 13,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 5,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Disable_Duck",
        "id": "244325",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_244325/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 5137,
        "hostname": 3405,
        "domain": 1659,
        "URL": 2452,
        "FileHash-MD5": 576,
        "FileHash-SHA1": 567,
        "CIDR": 9,
        "email": 7,
        "CVE": 15
      },
      "indicator_count": 13827,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 134,
      "modified_text": "442 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "https://www.alberta.ca/",
    "type": "URL"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "https://www.alberta.ca/",
    "type": "URL",
    "found": false,
    "verdict": "clean",
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780247060.1640668
}