{
  "type": "URL",
  "indicator": "https://www.avg.com",
  "general": {
    "sections": [
      "general",
      "url_list",
      "http_scans",
      "screenshot"
    ],
    "indicator": "https://www.avg.com",
    "type": "url",
    "type_title": "URL",
    "validation": [
      {
        "source": "akamai",
        "message": "Akamai rank: #2059",
        "name": "Akamai Popular Domain"
      },
      {
        "source": "whitelist",
        "message": "Whitelisted domain avg.com",
        "name": "Whitelisted domain"
      },
      {
        "source": "majestic",
        "message": "Whitelisted domain avg.com",
        "name": "Whitelisted domain"
      }
    ],
    "base_indicator": {
      "id": 4272082633,
      "indicator": "https://www.avg.com",
      "type": "URL",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 4,
      "pulses": [
        {
          "id": "69ca9a4803d223469fbdc580",
          "name": "CAPE Sandbox",
          "description": "Checks available memory\nQueries computer hostname\nQueries the username\nConnects to crypto currency mining pool\nAttempts to connect to a dead IP:Port (1 unique times)\nQueries the keyboard layout\nQueries the computer locale (possible geofencing)\nSetUnhandledExceptionFilter detected (possible anti-debug)\nPossible date expiration check, exits too soon after checking local time disk cont in comments",
          "modified": "2026-04-29T15:36:07.593000",
          "created": "2026-03-30T15:44:08.789000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 0,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 1,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 66,
            "FileHash-SHA1": 68,
            "FileHash-SHA256": 69,
            "domain": 13,
            "hostname": 47,
            "URL": 18
          },
          "indicator_count": 281,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 68,
          "modified_text": "34 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "69ca9a493238bd9eade7dda7",
          "name": "CAPE Sandbox",
          "description": "Checks available memory\nQueries computer hostname\nQueries the username\nConnects to crypto currency mining pool\nAttempts to connect to a dead IP:Port (1 unique times)\nQueries the keyboard layout\nQueries the computer locale (possible geofencing)\nSetUnhandledExceptionFilter detected (possible anti-debug)\nPossible date expiration check, exits too soon after checking local time disk cont in comments",
          "modified": "2026-04-29T15:36:07.593000",
          "created": "2026-03-30T15:44:09.515000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 66,
            "FileHash-SHA1": 68,
            "FileHash-SHA256": 69,
            "domain": 13,
            "hostname": 47,
            "URL": 18
          },
          "indicator_count": 281,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 68,
          "modified_text": "34 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "69ca9cdb34719e60c191a081",
          "name": "VirusTotal report\n                    for avast_business_agent_setup_online.exe",
          "description": "",
          "modified": "2026-04-29T15:36:07.593000",
          "created": "2026-03-30T15:55:06.985000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1040",
              "name": "Network Sniffing",
              "display_name": "T1040 - Network Sniffing"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1057",
              "name": "Process Discovery",
              "display_name": "T1057 - Process Discovery"
            },
            {
              "id": "T1070",
              "name": "Indicator Removal on Host",
              "display_name": "T1070 - Indicator Removal on Host"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1083",
              "name": "File and Directory Discovery",
              "display_name": "T1083 - File and Directory Discovery"
            },
            {
              "id": "T1518",
              "name": "Software Discovery",
              "display_name": "T1518 - Software Discovery"
            },
            {
              "id": "T1543",
              "name": "Create or Modify System Process",
              "display_name": "T1543 - Create or Modify System Process"
            },
            {
              "id": "T1560",
              "name": "Archive Collected Data",
              "display_name": "T1560 - Archive Collected Data"
            },
            {
              "id": "T1574",
              "name": "Hijack Execution Flow",
              "display_name": "T1574 - Hijack Execution Flow"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 72,
            "FileHash-MD5": 66,
            "FileHash-SHA1": 66,
            "FileHash-SHA256": 226,
            "domain": 7,
            "hostname": 41
          },
          "indicator_count": 478,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 68,
          "modified_text": "34 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "69bab8ec17587e77fb87296c",
          "name": "CAPE Sandbox - Immediate Research",
          "description": "Hundreds of thousands of people have signed an online petition calling for the removal of the UK's Prime Minister, David Cameron, from the EU's EU referendum, which has now been held in Germany.",
          "modified": "2026-04-17T14:12:53.840000",
          "created": "2026-03-18T14:38:36.655000",
          "tags": [
            "strong",
            "library",
            "address virtual",
            "host",
            "name",
            "file size",
            "mwdb",
            "bazaar",
            "sha3384",
            "ssdeep",
            "ironchain",
            "accept",
            "bitcoin",
            "service",
            "date",
            "execution",
            "openssl",
            "python",
            "title",
            "shutdown",
            "impact",
            "whirlpool",
            "project",
            "enterprise",
            "ransomware",
            "body",
            "crypt32"
          ],
          "references": [
            "https://vtbehaviour.commondatastorage.googleapis.com/0a563b64423a632dad9cb2b52129d79e1cd336902c699376b749b509ac34cc8b_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1773844718&Signature=IO42eMrLK%2FbIjlFqk5%2FGLr3hVuiKBEV%2F7z6YdTxH%2BKfch%2F5FpMOjzzpMyHE%2BjQrYjooxOOfFiuzomTf%2BKgpeO823xO3kVrolF7WjT%2BtRXU3WcJK8GwxuHM%2BeridLzjBJaEs36CMlTwvdgKwTrtyvYs2ZU%2BUZB9sZt%2Balg%2Bc%2Fhk3XSpyitjPffFVwVijVsh5XRZlDrgY%2BK9BDiOE0rXsuMt3mUVwJVmo5fL"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1014",
              "name": "Rootkit",
              "display_name": "T1014 - Rootkit"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            },
            {
              "id": "T1036",
              "name": "Masquerading",
              "display_name": "T1036 - Masquerading"
            },
            {
              "id": "T1055",
              "name": "Process Injection",
              "display_name": "T1055 - Process Injection"
            },
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1064",
              "name": "Scripting",
              "display_name": "T1064 - Scripting"
            },
            {
              "id": "T1070",
              "name": "Indicator Removal on Host",
              "display_name": "T1070 - Indicator Removal on Host"
            },
            {
              "id": "T1071",
              "name": "Application Layer Protocol",
              "display_name": "T1071 - Application Layer Protocol"
            },
            {
              "id": "T1082",
              "name": "System Information Discovery",
              "display_name": "T1082 - System Information Discovery"
            },
            {
              "id": "T1112",
              "name": "Modify Registry",
              "display_name": "T1112 - Modify Registry"
            },
            {
              "id": "T1202",
              "name": "Indirect Command Execution",
              "display_name": "T1202 - Indirect Command Execution"
            },
            {
              "id": "T1486",
              "name": "Data Encrypted for Impact",
              "display_name": "T1486 - Data Encrypted for Impact"
            },
            {
              "id": "T1490",
              "name": "Inhibit System Recovery",
              "display_name": "T1490 - Inhibit System Recovery"
            },
            {
              "id": "T1496",
              "name": "Resource Hijacking",
              "display_name": "T1496 - Resource Hijacking"
            },
            {
              "id": "T1539",
              "name": "Steal Web Session Cookie",
              "display_name": "T1539 - Steal Web Session Cookie"
            },
            {
              "id": "T1542",
              "name": "Pre-OS Boot",
              "display_name": "T1542 - Pre-OS Boot"
            },
            {
              "id": "T1546",
              "name": "Event Triggered Execution",
              "display_name": "T1546 - Event Triggered Execution"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            },
            {
              "id": "T1548",
              "name": "Abuse Elevation Control Mechanism",
              "display_name": "T1548 - Abuse Elevation Control Mechanism"
            },
            {
              "id": "T1562",
              "name": "Impair Defenses",
              "display_name": "T1562 - Impair Defenses"
            },
            {
              "id": "T1564",
              "name": "Hide Artifacts",
              "display_name": "T1564 - Hide Artifacts"
            }
          ],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 1,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 219,
            "FileHash-SHA1": 163,
            "FileHash-SHA256": 242,
            "domain": 41,
            "hostname": 95,
            "URL": 96,
            "email": 2
          },
          "indicator_count": 858,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 68,
          "modified_text": "46 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "https://vtbehaviour.commondatastorage.googleapis.com/0a563b64423a632dad9cb2b52129d79e1cd336902c699376b749b509ac34cc8b_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1773844718&Signature=IO42eMrLK%2FbIjlFqk5%2FGLr3hVuiKBEV%2F7z6YdTxH%2BKfch%2F5FpMOjzzpMyHE%2BjQrYjooxOOfFiuzomTf%2BKgpeO823xO3kVrolF7WjT%2BtRXU3WcJK8GwxuHM%2BeridLzjBJaEs36CMlTwvdgKwTrtyvYs2ZU%2BUZB9sZt%2Balg%2Bc%2Fhk3XSpyitjPffFVwVijVsh5XRZlDrgY%2BK9BDiOE0rXsuMt3mUVwJVmo5fL"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 0
        },
        "other": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 1129
        }
      }
    },
    "false_positive": [],
    "alexa": "http://www.alexa.com/siteinfo/avg.com",
    "whois": "http://whois.domaintools.com/avg.com",
    "domain": "avg.com",
    "hostname": "www.avg.com"
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 4,
  "pulses": [
    {
      "id": "69ca9a4803d223469fbdc580",
      "name": "CAPE Sandbox",
      "description": "Checks available memory\nQueries computer hostname\nQueries the username\nConnects to crypto currency mining pool\nAttempts to connect to a dead IP:Port (1 unique times)\nQueries the keyboard layout\nQueries the computer locale (possible geofencing)\nSetUnhandledExceptionFilter detected (possible anti-debug)\nPossible date expiration check, exits too soon after checking local time disk cont in comments",
      "modified": "2026-04-29T15:36:07.593000",
      "created": "2026-03-30T15:44:08.789000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 0,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 1,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 66,
        "FileHash-SHA1": 68,
        "FileHash-SHA256": 69,
        "domain": 13,
        "hostname": 47,
        "URL": 18
      },
      "indicator_count": 281,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 68,
      "modified_text": "34 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "69ca9a493238bd9eade7dda7",
      "name": "CAPE Sandbox",
      "description": "Checks available memory\nQueries computer hostname\nQueries the username\nConnects to crypto currency mining pool\nAttempts to connect to a dead IP:Port (1 unique times)\nQueries the keyboard layout\nQueries the computer locale (possible geofencing)\nSetUnhandledExceptionFilter detected (possible anti-debug)\nPossible date expiration check, exits too soon after checking local time disk cont in comments",
      "modified": "2026-04-29T15:36:07.593000",
      "created": "2026-03-30T15:44:09.515000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 1,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 66,
        "FileHash-SHA1": 68,
        "FileHash-SHA256": 69,
        "domain": 13,
        "hostname": 47,
        "URL": 18
      },
      "indicator_count": 281,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 68,
      "modified_text": "34 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "69ca9cdb34719e60c191a081",
      "name": "VirusTotal report\n                    for avast_business_agent_setup_online.exe",
      "description": "",
      "modified": "2026-04-29T15:36:07.593000",
      "created": "2026-03-30T15:55:06.985000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1040",
          "name": "Network Sniffing",
          "display_name": "T1040 - Network Sniffing"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1057",
          "name": "Process Discovery",
          "display_name": "T1057 - Process Discovery"
        },
        {
          "id": "T1070",
          "name": "Indicator Removal on Host",
          "display_name": "T1070 - Indicator Removal on Host"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1083",
          "name": "File and Directory Discovery",
          "display_name": "T1083 - File and Directory Discovery"
        },
        {
          "id": "T1518",
          "name": "Software Discovery",
          "display_name": "T1518 - Software Discovery"
        },
        {
          "id": "T1543",
          "name": "Create or Modify System Process",
          "display_name": "T1543 - Create or Modify System Process"
        },
        {
          "id": "T1560",
          "name": "Archive Collected Data",
          "display_name": "T1560 - Archive Collected Data"
        },
        {
          "id": "T1574",
          "name": "Hijack Execution Flow",
          "display_name": "T1574 - Hijack Execution Flow"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 1,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 72,
        "FileHash-MD5": 66,
        "FileHash-SHA1": 66,
        "FileHash-SHA256": 226,
        "domain": 7,
        "hostname": 41
      },
      "indicator_count": 478,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 68,
      "modified_text": "34 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "69bab8ec17587e77fb87296c",
      "name": "CAPE Sandbox - Immediate Research",
      "description": "Hundreds of thousands of people have signed an online petition calling for the removal of the UK's Prime Minister, David Cameron, from the EU's EU referendum, which has now been held in Germany.",
      "modified": "2026-04-17T14:12:53.840000",
      "created": "2026-03-18T14:38:36.655000",
      "tags": [
        "strong",
        "library",
        "address virtual",
        "host",
        "name",
        "file size",
        "mwdb",
        "bazaar",
        "sha3384",
        "ssdeep",
        "ironchain",
        "accept",
        "bitcoin",
        "service",
        "date",
        "execution",
        "openssl",
        "python",
        "title",
        "shutdown",
        "impact",
        "whirlpool",
        "project",
        "enterprise",
        "ransomware",
        "body",
        "crypt32"
      ],
      "references": [
        "https://vtbehaviour.commondatastorage.googleapis.com/0a563b64423a632dad9cb2b52129d79e1cd336902c699376b749b509ac34cc8b_CAPE%20Sandbox.html?GoogleAccessId=758681729565-rc7fgq07icj8c9dm2gi34a4cckv235v1@developer.gserviceaccount.com&Expires=1773844718&Signature=IO42eMrLK%2FbIjlFqk5%2FGLr3hVuiKBEV%2F7z6YdTxH%2BKfch%2F5FpMOjzzpMyHE%2BjQrYjooxOOfFiuzomTf%2BKgpeO823xO3kVrolF7WjT%2BtRXU3WcJK8GwxuHM%2BeridLzjBJaEs36CMlTwvdgKwTrtyvYs2ZU%2BUZB9sZt%2Balg%2Bc%2Fhk3XSpyitjPffFVwVijVsh5XRZlDrgY%2BK9BDiOE0rXsuMt3mUVwJVmo5fL"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1014",
          "name": "Rootkit",
          "display_name": "T1014 - Rootkit"
        },
        {
          "id": "T1027",
          "name": "Obfuscated Files or Information",
          "display_name": "T1027 - Obfuscated Files or Information"
        },
        {
          "id": "T1036",
          "name": "Masquerading",
          "display_name": "T1036 - Masquerading"
        },
        {
          "id": "T1055",
          "name": "Process Injection",
          "display_name": "T1055 - Process Injection"
        },
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        },
        {
          "id": "T1064",
          "name": "Scripting",
          "display_name": "T1064 - Scripting"
        },
        {
          "id": "T1070",
          "name": "Indicator Removal on Host",
          "display_name": "T1070 - Indicator Removal on Host"
        },
        {
          "id": "T1071",
          "name": "Application Layer Protocol",
          "display_name": "T1071 - Application Layer Protocol"
        },
        {
          "id": "T1082",
          "name": "System Information Discovery",
          "display_name": "T1082 - System Information Discovery"
        },
        {
          "id": "T1112",
          "name": "Modify Registry",
          "display_name": "T1112 - Modify Registry"
        },
        {
          "id": "T1202",
          "name": "Indirect Command Execution",
          "display_name": "T1202 - Indirect Command Execution"
        },
        {
          "id": "T1486",
          "name": "Data Encrypted for Impact",
          "display_name": "T1486 - Data Encrypted for Impact"
        },
        {
          "id": "T1490",
          "name": "Inhibit System Recovery",
          "display_name": "T1490 - Inhibit System Recovery"
        },
        {
          "id": "T1496",
          "name": "Resource Hijacking",
          "display_name": "T1496 - Resource Hijacking"
        },
        {
          "id": "T1539",
          "name": "Steal Web Session Cookie",
          "display_name": "T1539 - Steal Web Session Cookie"
        },
        {
          "id": "T1542",
          "name": "Pre-OS Boot",
          "display_name": "T1542 - Pre-OS Boot"
        },
        {
          "id": "T1546",
          "name": "Event Triggered Execution",
          "display_name": "T1546 - Event Triggered Execution"
        },
        {
          "id": "T1547",
          "name": "Boot or Logon Autostart Execution",
          "display_name": "T1547 - Boot or Logon Autostart Execution"
        },
        {
          "id": "T1548",
          "name": "Abuse Elevation Control Mechanism",
          "display_name": "T1548 - Abuse Elevation Control Mechanism"
        },
        {
          "id": "T1562",
          "name": "Impair Defenses",
          "display_name": "T1562 - Impair Defenses"
        },
        {
          "id": "T1564",
          "name": "Hide Artifacts",
          "display_name": "T1564 - Hide Artifacts"
        }
      ],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 1,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 219,
        "FileHash-SHA1": 163,
        "FileHash-SHA256": 242,
        "domain": 41,
        "hostname": 95,
        "URL": 96,
        "email": 2
      },
      "indicator_count": 858,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 68,
      "modified_text": "46 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "https://www.avg.com",
    "type": "URL"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "https://www.avg.com",
    "type": "URL",
    "found": false,
    "verdict": "clean",
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780455672.9615388
}