{
  "type": "URL",
  "indicator": "https://www.clicnews.com/",
  "general": {
    "sections": [
      "general",
      "url_list",
      "http_scans",
      "screenshot"
    ],
    "indicator": "https://www.clicnews.com/",
    "type": "url",
    "type_title": "URL",
    "validation": [],
    "base_indicator": {
      "id": 3445854104,
      "indicator": "https://www.clicnews.com/",
      "type": "URL",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 3,
      "pulses": [
        {
          "id": "684a3719a2708183b1b16d00",
          "name": "Follow Bot (black-basta_cova_cryptb) affects threat researcher(s)account(s)",
          "description": "Surprised: \nFollow bot account  affects threat researcher(s)account(s). % path , attempts DoS. Threatening account name,. \n\n\n(00285c99b52d41679b1aa3b8a80895b037df8a7500f4ad97ce06068eac4a95b7 | =\nfollow) \n|| {2025-05-20_bf3a6ba6e3421a7214ffbfe97642a578_amadey_black-basta_cova_cryptbot_elex_luca-stealer\nFastCopy5.9.0.exe}\n\nET DNS Query for .cc \n PROTOCOL-ICMP PATH MTU denial of service attempt\nPROTOCOL-ICMP Destination Unreachable Fragmentation Needed and DF bit was set",
          "modified": "2025-07-12T01:02:11.925000",
          "created": "2025-06-12T02:10:33.839000",
          "tags": [
            "gtmkvjvztk",
            "open threat",
            "learn",
            "levelblue",
            "exchange meta",
            "tags twitter",
            "alienvault",
            "script tags",
            "iframe tags",
            "google tag",
            "html internet",
            "html document",
            "ascii text",
            "ta0004 defense",
            "evasion ta0005",
            "command",
            "control ta0011",
            "number",
            "cnmicrosoft ecc",
            "update secure",
            "server ca",
            "cus subject",
            "stwa lredmond",
            "omicrosoft c",
            "resolved ips",
            "get http",
            "dns resolutions",
            "request",
            "response",
            "windows nt",
            "win64",
            "khtml",
            "gecko",
            "defense evasion",
            "ta0009 command",
            "impact ta0040",
            "catalog tree",
            "analysis ob0001",
            "analysis ob0002",
            "ob0007 impact",
            "ob0012 file",
            "system oc0001",
            "process oc0003",
            "data oc0004",
            "oc0008",
            "get https",
            "vis1",
            "oid2",
            "post https",
            "cjutxg",
            "base64uidenc",
            "error https"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 27,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 1,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Q.Vashti",
            "id": "337942",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-MD5": 162,
            "FileHash-SHA1": 28,
            "FileHash-SHA256": 2459,
            "domain": 889,
            "hostname": 1217,
            "URL": 4326,
            "FilePath": 1
          },
          "indicator_count": 9082,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 143,
          "modified_text": "325 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "64de49881646bdef1ba1cf2f",
          "name": "Top 100 virus-infected websites named",
          "description": "The 100 websites most affected by viruses each have about 18,000 nasties to attack net users' computers, an internet security company says.\n\nSimply visiting one of the \"Top 100 Dirtiest\" websites - without downloading or even clicking anything - could expose your computer to infection and put your personal information into the hands of criminals, anti-virus software company Norton Symantec says.",
          "modified": "2023-08-17T16:27:43.704000",
          "created": "2023-08-17T16:23:36.147000",
          "tags": [
            "el malware",
            "el ransomware",
            "loki",
            "triton",
            "aplicar",
            "malware",
            "aunque sus",
            "clasificacin",
            "la mayora",
            "cuando",
            "fareit",
            "lokibot",
            "el",
            "dark web",
            "por ejemplo",
            "botmaster",
            "arkei",
            "cyber security",
            "markets",
            "en este",
            "sin embargo",
            "redline",
            "todo",
            "como",
            "comando",
            "android",
            "anubis",
            "emotet",
            "mirai",
            "pink",
            "una",
            "estos",
            "please",
            "independent",
            "ms connor",
            "subscribe",
            "register",
            "women",
            "world cup",
            "puzzles most",
            "ask me",
            "anything",
            "love",
            "tech",
            "august",
            "cyber",
            "contact",
            "code"
          ],
          "references": [
            "https://www.independent.co.uk/tech/top-100-virusinfected-websites-named-1775399.html"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "El",
              "display_name": "El",
              "target": null
            },
            {
              "id": "Una",
              "display_name": "Una",
              "target": null
            },
            {
              "id": "Mirai",
              "display_name": "Mirai",
              "target": null
            },
            {
              "id": "Estos",
              "display_name": "Estos",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1498",
              "name": "Network Denial of Service",
              "display_name": "T1498 - Network Denial of Service"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            },
            {
              "id": "T1568",
              "name": "Dynamic Resolution",
              "display_name": "T1568 - Dynamic Resolution"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 29,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "joserraUC3M",
            "id": "248916",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 60,
            "FileHash-SHA256": 19,
            "hostname": 66,
            "URL": 443
          },
          "indicator_count": 588,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 21,
          "modified_text": "1019 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "627c4aa67b671e713d743036",
          "name": "CYB303 - MIDTERM",
          "description": "This is a pulse created for my midterm.",
          "modified": "2022-05-11T23:45:42.383000",
          "created": "2022-05-11T23:45:42.383000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "ccornelius",
            "id": "188510",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 17,
            "hostname": 2,
            "URL": 26,
            "domain": 2
          },
          "indicator_count": 47,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 35,
          "modified_text": "1482 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "https://www.independent.co.uk/tech/top-100-virusinfected-websites-named-1775399.html"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 0
        },
        "other": {
          "adversary": [],
          "malware_families": [
            "El",
            "Mirai",
            "Una",
            "Estos"
          ],
          "industries": [],
          "unique_indicators": 9830
        }
      }
    },
    "false_positive": [],
    "alexa": "http://www.alexa.com/siteinfo/clicnews.com",
    "whois": "http://whois.domaintools.com/clicnews.com",
    "domain": "clicnews.com",
    "hostname": "www.clicnews.com"
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 3,
  "pulses": [
    {
      "id": "684a3719a2708183b1b16d00",
      "name": "Follow Bot (black-basta_cova_cryptb) affects threat researcher(s)account(s)",
      "description": "Surprised: \nFollow bot account  affects threat researcher(s)account(s). % path , attempts DoS. Threatening account name,. \n\n\n(00285c99b52d41679b1aa3b8a80895b037df8a7500f4ad97ce06068eac4a95b7 | =\nfollow) \n|| {2025-05-20_bf3a6ba6e3421a7214ffbfe97642a578_amadey_black-basta_cova_cryptbot_elex_luca-stealer\nFastCopy5.9.0.exe}\n\nET DNS Query for .cc \n PROTOCOL-ICMP PATH MTU denial of service attempt\nPROTOCOL-ICMP Destination Unreachable Fragmentation Needed and DF bit was set",
      "modified": "2025-07-12T01:02:11.925000",
      "created": "2025-06-12T02:10:33.839000",
      "tags": [
        "gtmkvjvztk",
        "open threat",
        "learn",
        "levelblue",
        "exchange meta",
        "tags twitter",
        "alienvault",
        "script tags",
        "iframe tags",
        "google tag",
        "html internet",
        "html document",
        "ascii text",
        "ta0004 defense",
        "evasion ta0005",
        "command",
        "control ta0011",
        "number",
        "cnmicrosoft ecc",
        "update secure",
        "server ca",
        "cus subject",
        "stwa lredmond",
        "omicrosoft c",
        "resolved ips",
        "get http",
        "dns resolutions",
        "request",
        "response",
        "windows nt",
        "win64",
        "khtml",
        "gecko",
        "defense evasion",
        "ta0009 command",
        "impact ta0040",
        "catalog tree",
        "analysis ob0001",
        "analysis ob0002",
        "ob0007 impact",
        "ob0012 file",
        "system oc0001",
        "process oc0003",
        "data oc0004",
        "oc0008",
        "get https",
        "vis1",
        "oid2",
        "post https",
        "cjutxg",
        "base64uidenc",
        "error https"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 27,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 1,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Q.Vashti",
        "id": "337942",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-MD5": 162,
        "FileHash-SHA1": 28,
        "FileHash-SHA256": 2459,
        "domain": 889,
        "hostname": 1217,
        "URL": 4326,
        "FilePath": 1
      },
      "indicator_count": 9082,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 143,
      "modified_text": "325 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "64de49881646bdef1ba1cf2f",
      "name": "Top 100 virus-infected websites named",
      "description": "The 100 websites most affected by viruses each have about 18,000 nasties to attack net users' computers, an internet security company says.\n\nSimply visiting one of the \"Top 100 Dirtiest\" websites - without downloading or even clicking anything - could expose your computer to infection and put your personal information into the hands of criminals, anti-virus software company Norton Symantec says.",
      "modified": "2023-08-17T16:27:43.704000",
      "created": "2023-08-17T16:23:36.147000",
      "tags": [
        "el malware",
        "el ransomware",
        "loki",
        "triton",
        "aplicar",
        "malware",
        "aunque sus",
        "clasificacin",
        "la mayora",
        "cuando",
        "fareit",
        "lokibot",
        "el",
        "dark web",
        "por ejemplo",
        "botmaster",
        "arkei",
        "cyber security",
        "markets",
        "en este",
        "sin embargo",
        "redline",
        "todo",
        "como",
        "comando",
        "android",
        "anubis",
        "emotet",
        "mirai",
        "pink",
        "una",
        "estos",
        "please",
        "independent",
        "ms connor",
        "subscribe",
        "register",
        "women",
        "world cup",
        "puzzles most",
        "ask me",
        "anything",
        "love",
        "tech",
        "august",
        "cyber",
        "contact",
        "code"
      ],
      "references": [
        "https://www.independent.co.uk/tech/top-100-virusinfected-websites-named-1775399.html"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "El",
          "display_name": "El",
          "target": null
        },
        {
          "id": "Una",
          "display_name": "Una",
          "target": null
        },
        {
          "id": "Mirai",
          "display_name": "Mirai",
          "target": null
        },
        {
          "id": "Estos",
          "display_name": "Estos",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1498",
          "name": "Network Denial of Service",
          "display_name": "T1498 - Network Denial of Service"
        },
        {
          "id": "T1140",
          "name": "Deobfuscate/Decode Files or Information",
          "display_name": "T1140 - Deobfuscate/Decode Files or Information"
        },
        {
          "id": "T1568",
          "name": "Dynamic Resolution",
          "display_name": "T1568 - Dynamic Resolution"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 29,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "joserraUC3M",
        "id": "248916",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 60,
        "FileHash-SHA256": 19,
        "hostname": 66,
        "URL": 443
      },
      "indicator_count": 588,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 21,
      "modified_text": "1019 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "627c4aa67b671e713d743036",
      "name": "CYB303 - MIDTERM",
      "description": "This is a pulse created for my midterm.",
      "modified": "2022-05-11T23:45:42.383000",
      "created": "2022-05-11T23:45:42.383000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "ccornelius",
        "id": "188510",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 17,
        "hostname": 2,
        "URL": 26,
        "domain": 2
      },
      "indicator_count": 47,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 35,
      "modified_text": "1482 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "https://www.clicnews.com/",
    "type": "URL"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "https://www.clicnews.com/",
    "type": "URL",
    "found": false,
    "verdict": "clean",
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780370054.2675126
}