{
  "type": "URL",
  "indicator": "https://www.cscglobal.com/__",
  "general": {
    "sections": [
      "general",
      "url_list",
      "http_scans",
      "screenshot"
    ],
    "indicator": "https://www.cscglobal.com/__",
    "type": "url",
    "type_title": "URL",
    "validation": [],
    "base_indicator": {
      "id": 2991146550,
      "indicator": "https://www.cscglobal.com/__",
      "type": "URL",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 9,
      "pulses": [
        {
          "id": "65708a8f3203633312147d1e",
          "name": "www.virgilio. various Malacious tld's",
          "description": "",
          "modified": "2023-12-06T14:51:59.166000",
          "created": "2023-12-06T14:51:59.166000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "CVE": 1,
            "FileHash-SHA256": 238,
            "URL": 818,
            "domain": 177,
            "hostname": 336,
            "email": 6,
            "FileHash-MD5": 79,
            "FileHash-SHA1": 47
          },
          "indicator_count": 1702,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "907 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "65707e09372dc83478c07fa1",
          "name": "doctoroz.com",
          "description": "",
          "modified": "2023-12-06T13:58:33.053000",
          "created": "2023-12-06T13:58:33.053000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 517,
            "hostname": 1115,
            "URL": 3648,
            "domain": 603,
            "email": 3,
            "FileHash-MD5": 4,
            "CVE": 2,
            "CIDR": 3,
            "FileHash-SHA1": 4
          },
          "indicator_count": 5899,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "907 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "62a3fa87f14c1ec9bbfea5c0",
          "name": "tweet intent  pfffff",
          "description": "",
          "modified": "2022-07-11T00:03:00.528000",
          "created": "2022-06-11T02:14:31.807000",
          "tags": [
            "CVE-2021-22941"
          ],
          "references": [
            "https://hybrid-analysis.com/sample/fdf871aba97a2ff9a6772f33c8221dd485b73572b950250c2f32b5a616643014/629f77d05f1eb82a785185cf",
            "https://twitter.com/intent/tweet?url=https%3A%2F%2Fwww.virustotal.com%2Fgraph%2Fembed%2Fg6867fe74e19241439df95963d29d7f447d548740aeb241ce9c15b09a2f0b043b&amp;text=Have%20a%20look%20to%20this%20graph%3A%20HollyHighSchool.com%20-%20I%20wonder%20which%20school%20childs%20device%20this%20host%20lives%20on.%20#vtgraph"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 3,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "dorkingbeauty1",
            "id": "80137",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 19,
            "email": 2,
            "domain": 12,
            "URL": 41,
            "FileHash-SHA256": 59,
            "CVE": 1,
            "FileHash-MD5": 28,
            "FileHash-SHA1": 27
          },
          "indicator_count": 189,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 392,
          "modified_text": "1421 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "629e17078f3ae44e3119c0ee",
          "name": "http://nlhfd1.ce.apple-dns.net/ CVE-2021-22941",
          "description": "looks like cscglobal has issues backdoor/SC",
          "modified": "2022-07-06T00:03:51.272000",
          "created": "2022-06-06T15:02:31.004000",
          "tags": [
            "http://nlhfd1.ce.apple-dns.net/'",
            "cve-2021-22941",
            "cscglobal backdoored?"
          ],
          "references": [
            "https://hybrid-analysis.com/sample/340c88cee4585c860cd29074319a2fae222cff748714b503382d1bbf228e80a7/629e116a0185693289247234",
            "http://nlhfd1.ce.apple-dns.net/'"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 4,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "dorkingbeauty1",
            "id": "80137",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 11,
            "email": 2,
            "domain": 4,
            "URL": 27,
            "CVE": 1,
            "FileHash-MD5": 27,
            "FileHash-SHA1": 26,
            "FileHash-SHA256": 27
          },
          "indicator_count": 125,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 392,
          "modified_text": "1426 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "629e181e69391f02cedbcccd",
          "name": "http://me.apple-dns.net - CVE-2021-22941",
          "description": "",
          "modified": "2022-07-06T00:03:51.272000",
          "created": "2022-06-06T15:07:10.845000",
          "tags": [
            "http://me.apple-dns.net/"
          ],
          "references": [
            "https://hybrid-analysis.com/sample/3b4fb99f22ec11d8b5f716c18defcf1c181f7707f14361a9833701e9a76d271c/629e1047ab744c3b9947c4f3"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 4,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "dorkingbeauty1",
            "id": "80137",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 3,
            "URL": 27,
            "hostname": 8,
            "email": 2,
            "CVE": 1,
            "FileHash-MD5": 27,
            "FileHash-SHA1": 26,
            "FileHash-SHA256": 27
          },
          "indicator_count": 121,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 392,
          "modified_text": "1426 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "628044fcc9bd52bb0e411c24",
          "name": "home.netscape.net aol.me housing the russians",
          "description": "",
          "modified": "2022-06-26T21:34:29.113000",
          "created": "2022-05-15T00:10:36.710000",
          "tags": [
            "sandbox",
            "malware",
            "analysis",
            "online",
            "submit",
            "vxstream",
            "sample",
            "download",
            "trojan",
            "apt",
            "ansi",
            "data",
            "decrypted ssl",
            "threat level",
            "i4uh4mms",
            "sha256",
            "path",
            "size",
            "report",
            "report domain",
            "date",
            "hybrid",
            "close",
            "click",
            "hosts",
            "general",
            "local",
            "factory",
            "accept",
            "mozilla",
            "trident",
            "strings",
            "suspicious",
            "team",
            "february"
          ],
          "references": [
            "https://hybrid-analysis.com/sample/eeb62e8e3d3373e43b3d5ecc634e5cb3edcc23a1b7cfba14e7d3e2d5c05a5e7d/62803bf2d533e72bdd4c9fee",
            "https://hybrid-analysis.com/sample/d4a9a495a96d75151e82501d725b8356b1bd30f5d272d699772b64520136f2eb/62803c41ad106561d3495eb0"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 3,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "dorkingbeauty1",
            "id": "80137",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 152,
            "hostname": 111,
            "FileHash-SHA256": 165,
            "domain": 24,
            "email": 7,
            "CVE": 1,
            "FileHash-MD5": 41,
            "FileHash-SHA1": 40
          },
          "indicator_count": 541,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 394,
          "modified_text": "1435 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "624df7adeb106d4f2736b2d2",
          "name": "http://fpdownload.adobe.com/ -  how-to-get-unlimited-robux_GM431946152.pdf",
          "description": "",
          "modified": "2022-05-06T00:03:41.989000",
          "created": "2022-04-06T20:27:25.144000",
          "tags": [
            "how-to-get-unlimited-robux_GM431946152.pdf"
          ],
          "references": [
            "https://hybrid-analysis.com/sample/a649645f6de177e9670caa6aec7604e34508af48714d207724a0dc3510c70f7a/5d9690f80388387c804fe71e",
            "895e20b81e5636e094f3e024df00c61e129709c2274db53ba3ce4e840207034f",
            "how-to-get-unlimited-robux_GM431946152.pdf"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1035",
              "name": "Service Execution",
              "display_name": "T1035 - Service Execution"
            },
            {
              "id": "T1179",
              "name": "Hooking",
              "display_name": "T1179 - Hooking"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 5,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "dorkingbeauty1",
            "id": "80137",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 706,
            "hostname": 344,
            "FileHash-SHA256": 1746,
            "domain": 142,
            "CVE": 1,
            "FileHash-MD5": 69,
            "FileHash-SHA1": 61
          },
          "indicator_count": 3069,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 397,
          "modified_text": "1487 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "62498485afc3d6ebba050b8b",
          "name": "www.virgilio. various Malacious tld's",
          "description": "",
          "modified": "2022-05-03T00:01:26.398000",
          "created": "2022-04-03T11:27:01.556000",
          "tags": [
            "virgillo"
          ],
          "references": [
            "https://hybrid-analysis.com/sample/c914c5cc1371bbc7d2285bbbeec77a94a0d1586c73d3a3f95b48766f1452cca8/6248c9f1f90df91459524ac8"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1012",
              "name": "Query Registry",
              "display_name": "T1012 - Query Registry"
            },
            {
              "id": "T1573",
              "name": "Encrypted Channel",
              "display_name": "T1573 - Encrypted Channel"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 5,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "dorkingbeauty1",
            "id": "80137",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 336,
            "domain": 177,
            "URL": 818,
            "FileHash-SHA256": 238,
            "CVE": 1,
            "FileHash-MD5": 79,
            "FileHash-SHA1": 47,
            "email": 6
          },
          "indicator_count": 1702,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 398,
          "modified_text": "1490 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "62096e251f1ca9c1530d2d57",
          "name": "doctoroz.com",
          "description": "",
          "modified": "2022-03-14T00:03:07.473000",
          "created": "2022-02-13T20:46:29.205000",
          "tags": [
            "win32 exe",
            "csc corporate",
            "domains",
            "code",
            "server",
            "registrar abuse",
            "iana id",
            "tech email",
            "admin country",
            "ozmedia",
            "davis",
            "android",
            "dns replication",
            "date",
            "contact phone",
            "registrar url",
            "contact email",
            "registrar iana",
            "expiration date",
            "registrar whois",
            "aaaa",
            "algorithm",
            "full name",
            "time cisco",
            "umbrella",
            "utc statvoo",
            "utc alexa",
            "utc quantcast",
            "dns records",
            "record type",
            "info",
            "ssl certificate",
            "whois record"
          ],
          "references": [
            "https://www.virustotal.com/graph/g9f48f3119de04e009c4fb74b0f288480d61de0a5c3b04ef38c92871ea0ec6952"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [],
          "attack_ids": [],
          "industries": [
            "Media"
          ],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 7,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Kailula4",
            "id": "131997",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 3648,
            "hostname": 1115,
            "domain": 603,
            "FileHash-SHA256": 517,
            "CVE": 2,
            "CIDR": 3,
            "FileHash-SHA1": 4,
            "email": 3,
            "FileHash-MD5": 4
          },
          "indicator_count": 5899,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 407,
          "modified_text": "1540 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "how-to-get-unlimited-robux_GM431946152.pdf",
        "https://hybrid-analysis.com/sample/c914c5cc1371bbc7d2285bbbeec77a94a0d1586c73d3a3f95b48766f1452cca8/6248c9f1f90df91459524ac8",
        "https://twitter.com/intent/tweet?url=https%3A%2F%2Fwww.virustotal.com%2Fgraph%2Fembed%2Fg6867fe74e19241439df95963d29d7f447d548740aeb241ce9c15b09a2f0b043b&amp;text=Have%20a%20look%20to%20this%20graph%3A%20HollyHighSchool.com%20-%20I%20wonder%20which%20school%20childs%20device%20this%20host%20lives%20on.%20#vtgraph",
        "https://hybrid-analysis.com/sample/d4a9a495a96d75151e82501d725b8356b1bd30f5d272d699772b64520136f2eb/62803c41ad106561d3495eb0",
        "https://hybrid-analysis.com/sample/3b4fb99f22ec11d8b5f716c18defcf1c181f7707f14361a9833701e9a76d271c/629e1047ab744c3b9947c4f3",
        "https://www.virustotal.com/graph/g9f48f3119de04e009c4fb74b0f288480d61de0a5c3b04ef38c92871ea0ec6952",
        "https://hybrid-analysis.com/sample/eeb62e8e3d3373e43b3d5ecc634e5cb3edcc23a1b7cfba14e7d3e2d5c05a5e7d/62803bf2d533e72bdd4c9fee",
        "https://hybrid-analysis.com/sample/fdf871aba97a2ff9a6772f33c8221dd485b73572b950250c2f32b5a616643014/629f77d05f1eb82a785185cf",
        "https://hybrid-analysis.com/sample/a649645f6de177e9670caa6aec7604e34508af48714d207724a0dc3510c70f7a/5d9690f80388387c804fe71e",
        "895e20b81e5636e094f3e024df00c61e129709c2274db53ba3ce4e840207034f",
        "http://nlhfd1.ce.apple-dns.net/'",
        "https://hybrid-analysis.com/sample/340c88cee4585c860cd29074319a2fae222cff748714b503382d1bbf228e80a7/629e116a0185693289247234"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 0
        },
        "other": {
          "adversary": [],
          "malware_families": [],
          "industries": [
            "Media"
          ],
          "unique_indicators": 11574
        }
      }
    },
    "false_positive": [],
    "alexa": "http://www.alexa.com/siteinfo/cscglobal.com",
    "whois": "http://whois.domaintools.com/cscglobal.com",
    "domain": "cscglobal.com",
    "hostname": "www.cscglobal.com"
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 9,
  "pulses": [
    {
      "id": "65708a8f3203633312147d1e",
      "name": "www.virgilio. various Malacious tld's",
      "description": "",
      "modified": "2023-12-06T14:51:59.166000",
      "created": "2023-12-06T14:51:59.166000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "CVE": 1,
        "FileHash-SHA256": 238,
        "URL": 818,
        "domain": 177,
        "hostname": 336,
        "email": 6,
        "FileHash-MD5": 79,
        "FileHash-SHA1": 47
      },
      "indicator_count": 1702,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "907 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "65707e09372dc83478c07fa1",
      "name": "doctoroz.com",
      "description": "",
      "modified": "2023-12-06T13:58:33.053000",
      "created": "2023-12-06T13:58:33.053000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 517,
        "hostname": 1115,
        "URL": 3648,
        "domain": 603,
        "email": 3,
        "FileHash-MD5": 4,
        "CVE": 2,
        "CIDR": 3,
        "FileHash-SHA1": 4
      },
      "indicator_count": 5899,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "907 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "62a3fa87f14c1ec9bbfea5c0",
      "name": "tweet intent  pfffff",
      "description": "",
      "modified": "2022-07-11T00:03:00.528000",
      "created": "2022-06-11T02:14:31.807000",
      "tags": [
        "CVE-2021-22941"
      ],
      "references": [
        "https://hybrid-analysis.com/sample/fdf871aba97a2ff9a6772f33c8221dd485b73572b950250c2f32b5a616643014/629f77d05f1eb82a785185cf",
        "https://twitter.com/intent/tweet?url=https%3A%2F%2Fwww.virustotal.com%2Fgraph%2Fembed%2Fg6867fe74e19241439df95963d29d7f447d548740aeb241ce9c15b09a2f0b043b&amp;text=Have%20a%20look%20to%20this%20graph%3A%20HollyHighSchool.com%20-%20I%20wonder%20which%20school%20childs%20device%20this%20host%20lives%20on.%20#vtgraph"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 3,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "dorkingbeauty1",
        "id": "80137",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 19,
        "email": 2,
        "domain": 12,
        "URL": 41,
        "FileHash-SHA256": 59,
        "CVE": 1,
        "FileHash-MD5": 28,
        "FileHash-SHA1": 27
      },
      "indicator_count": 189,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 392,
      "modified_text": "1421 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "629e17078f3ae44e3119c0ee",
      "name": "http://nlhfd1.ce.apple-dns.net/ CVE-2021-22941",
      "description": "looks like cscglobal has issues backdoor/SC",
      "modified": "2022-07-06T00:03:51.272000",
      "created": "2022-06-06T15:02:31.004000",
      "tags": [
        "http://nlhfd1.ce.apple-dns.net/'",
        "cve-2021-22941",
        "cscglobal backdoored?"
      ],
      "references": [
        "https://hybrid-analysis.com/sample/340c88cee4585c860cd29074319a2fae222cff748714b503382d1bbf228e80a7/629e116a0185693289247234",
        "http://nlhfd1.ce.apple-dns.net/'"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 4,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "dorkingbeauty1",
        "id": "80137",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 11,
        "email": 2,
        "domain": 4,
        "URL": 27,
        "CVE": 1,
        "FileHash-MD5": 27,
        "FileHash-SHA1": 26,
        "FileHash-SHA256": 27
      },
      "indicator_count": 125,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 392,
      "modified_text": "1426 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "629e181e69391f02cedbcccd",
      "name": "http://me.apple-dns.net - CVE-2021-22941",
      "description": "",
      "modified": "2022-07-06T00:03:51.272000",
      "created": "2022-06-06T15:07:10.845000",
      "tags": [
        "http://me.apple-dns.net/"
      ],
      "references": [
        "https://hybrid-analysis.com/sample/3b4fb99f22ec11d8b5f716c18defcf1c181f7707f14361a9833701e9a76d271c/629e1047ab744c3b9947c4f3"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 4,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "dorkingbeauty1",
        "id": "80137",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "domain": 3,
        "URL": 27,
        "hostname": 8,
        "email": 2,
        "CVE": 1,
        "FileHash-MD5": 27,
        "FileHash-SHA1": 26,
        "FileHash-SHA256": 27
      },
      "indicator_count": 121,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 392,
      "modified_text": "1426 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "628044fcc9bd52bb0e411c24",
      "name": "home.netscape.net aol.me housing the russians",
      "description": "",
      "modified": "2022-06-26T21:34:29.113000",
      "created": "2022-05-15T00:10:36.710000",
      "tags": [
        "sandbox",
        "malware",
        "analysis",
        "online",
        "submit",
        "vxstream",
        "sample",
        "download",
        "trojan",
        "apt",
        "ansi",
        "data",
        "decrypted ssl",
        "threat level",
        "i4uh4mms",
        "sha256",
        "path",
        "size",
        "report",
        "report domain",
        "date",
        "hybrid",
        "close",
        "click",
        "hosts",
        "general",
        "local",
        "factory",
        "accept",
        "mozilla",
        "trident",
        "strings",
        "suspicious",
        "team",
        "february"
      ],
      "references": [
        "https://hybrid-analysis.com/sample/eeb62e8e3d3373e43b3d5ecc634e5cb3edcc23a1b7cfba14e7d3e2d5c05a5e7d/62803bf2d533e72bdd4c9fee",
        "https://hybrid-analysis.com/sample/d4a9a495a96d75151e82501d725b8356b1bd30f5d272d699772b64520136f2eb/62803c41ad106561d3495eb0"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 3,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "dorkingbeauty1",
        "id": "80137",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 152,
        "hostname": 111,
        "FileHash-SHA256": 165,
        "domain": 24,
        "email": 7,
        "CVE": 1,
        "FileHash-MD5": 41,
        "FileHash-SHA1": 40
      },
      "indicator_count": 541,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 394,
      "modified_text": "1435 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "624df7adeb106d4f2736b2d2",
      "name": "http://fpdownload.adobe.com/ -  how-to-get-unlimited-robux_GM431946152.pdf",
      "description": "",
      "modified": "2022-05-06T00:03:41.989000",
      "created": "2022-04-06T20:27:25.144000",
      "tags": [
        "how-to-get-unlimited-robux_GM431946152.pdf"
      ],
      "references": [
        "https://hybrid-analysis.com/sample/a649645f6de177e9670caa6aec7604e34508af48714d207724a0dc3510c70f7a/5d9690f80388387c804fe71e",
        "895e20b81e5636e094f3e024df00c61e129709c2274db53ba3ce4e840207034f",
        "how-to-get-unlimited-robux_GM431946152.pdf"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1035",
          "name": "Service Execution",
          "display_name": "T1035 - Service Execution"
        },
        {
          "id": "T1179",
          "name": "Hooking",
          "display_name": "T1179 - Hooking"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 5,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "dorkingbeauty1",
        "id": "80137",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 706,
        "hostname": 344,
        "FileHash-SHA256": 1746,
        "domain": 142,
        "CVE": 1,
        "FileHash-MD5": 69,
        "FileHash-SHA1": 61
      },
      "indicator_count": 3069,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 397,
      "modified_text": "1487 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "62498485afc3d6ebba050b8b",
      "name": "www.virgilio. various Malacious tld's",
      "description": "",
      "modified": "2022-05-03T00:01:26.398000",
      "created": "2022-04-03T11:27:01.556000",
      "tags": [
        "virgillo"
      ],
      "references": [
        "https://hybrid-analysis.com/sample/c914c5cc1371bbc7d2285bbbeec77a94a0d1586c73d3a3f95b48766f1452cca8/6248c9f1f90df91459524ac8"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [
        {
          "id": "T1012",
          "name": "Query Registry",
          "display_name": "T1012 - Query Registry"
        },
        {
          "id": "T1573",
          "name": "Encrypted Channel",
          "display_name": "T1573 - Encrypted Channel"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 5,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "dorkingbeauty1",
        "id": "80137",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 336,
        "domain": 177,
        "URL": 818,
        "FileHash-SHA256": 238,
        "CVE": 1,
        "FileHash-MD5": 79,
        "FileHash-SHA1": 47,
        "email": 6
      },
      "indicator_count": 1702,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 398,
      "modified_text": "1490 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "62096e251f1ca9c1530d2d57",
      "name": "doctoroz.com",
      "description": "",
      "modified": "2022-03-14T00:03:07.473000",
      "created": "2022-02-13T20:46:29.205000",
      "tags": [
        "win32 exe",
        "csc corporate",
        "domains",
        "code",
        "server",
        "registrar abuse",
        "iana id",
        "tech email",
        "admin country",
        "ozmedia",
        "davis",
        "android",
        "dns replication",
        "date",
        "contact phone",
        "registrar url",
        "contact email",
        "registrar iana",
        "expiration date",
        "registrar whois",
        "aaaa",
        "algorithm",
        "full name",
        "time cisco",
        "umbrella",
        "utc statvoo",
        "utc alexa",
        "utc quantcast",
        "dns records",
        "record type",
        "info",
        "ssl certificate",
        "whois record"
      ],
      "references": [
        "https://www.virustotal.com/graph/g9f48f3119de04e009c4fb74b0f288480d61de0a5c3b04ef38c92871ea0ec6952"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [],
      "attack_ids": [],
      "industries": [
        "Media"
      ],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 7,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Kailula4",
        "id": "131997",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 3648,
        "hostname": 1115,
        "domain": 603,
        "FileHash-SHA256": 517,
        "CVE": 2,
        "CIDR": 3,
        "FileHash-SHA1": 4,
        "email": 3,
        "FileHash-MD5": 4
      },
      "indicator_count": 5899,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 407,
      "modified_text": "1540 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "https://www.cscglobal.com/__",
    "type": "URL"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "https://www.cscglobal.com/__",
    "type": "URL",
    "found": false,
    "verdict": "clean",
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1780301909.4688208
}