{
  "type": "URL",
  "indicator": "https://www.g.this.info",
  "general": {
    "sections": [
      "general",
      "url_list",
      "http_scans",
      "screenshot"
    ],
    "indicator": "https://www.g.this.info",
    "type": "url",
    "type_title": "URL",
    "validation": [],
    "base_indicator": {
      "id": 3157199869,
      "indicator": "https://www.g.this.info",
      "type": "URL",
      "title": "",
      "description": "",
      "content": "",
      "access_type": "public",
      "access_reason": ""
    },
    "pulse_info": {
      "count": 15,
      "pulses": [
        {
          "id": "698904c316bc7710b967d01d",
          "name": "Rare Tier 1 Persistence - Critical \"Patched\", Non Patched Vulnerabilities Remain bypassing Lockdown Mode",
          "description": "Researcher Note (Feb 08, 2026):\nThis artifact represents a sophisticated Cross-Protocol Mesh. Observations confirm that the Cymt/Nemucod wrapper is being utilized as a delivery vehicle for a Firmware-resident ELF binary (Mirai variant).\nThe persistence is notable for its ability to survive Full DFU Restores and Faraday-isolated states, likely due to JTAG-level interaction with the Power Management IC (Chip 4799). This is not a standard opportunistic infection; it is a targeted provisioning event leveraging IDMSA (Identity Management) bridges and Verizon/Akamai Edge infrastructure.\nThe integration with CalendarKit and Maps for geofenced execution suggests a highly coordinated surveillance objective. Forensic analysts should pay specific attention to the sizeofrawdata_antidbg anomalies, which indicate a focus on bypassing Apple Lockdown Mode and Secure Enclave. \nresearcher credit: msudoSOS",
          "modified": "2026-03-27T09:05:26.285000",
          "created": "2026-02-08T21:48:49.147000",
          "tags": [
            "#supportsitewebsiteabuse #rootcertificatefailure #cryptographicf"
          ],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "msudosos",
            "id": "381696",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 909,
            "URL": 1779,
            "CVE": 126,
            "domain": 659,
            "email": 23,
            "JA3": 1,
            "FileHash-MD5": 230,
            "FileHash-SHA1": 227,
            "FileHash-SHA256": 934,
            "CIDR": 13
          },
          "indicator_count": 4901,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 54,
          "modified_text": "24 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "684c65464466dd19b089f325",
          "name": "Zesp\u00f3\u0142 Profilaktyki i Rehabilitacji w Janowicach Wielkich - YouTube",
          "description": "If d=void 0===c,w(\"trustedResourceUrl\",d: \"Trusted resourceUrl,\" thend=c.src,d, c.js, then d:",
          "modified": "2025-06-13T17:56:28.689000",
          "created": "2025-06-13T17:52:06.399000",
          "tags": [
            "rehabilitacji w",
            "youtube tv",
            "dami jelenia",
            "tv dami",
            "jelenia gra",
            "zakupy wycz",
            "jeli",
            "nie korzystasz",
            "filmy",
            "aby tego",
            "copyright",
            "closure library",
            "argument",
            "ifunction",
            "error",
            "null",
            "type",
            "cast",
            "webchannel",
            "su2028u2029",
            "chrome",
            "xmlhttp",
            "kkvoid",
            "remotecontrol",
            "android",
            "unknown",
            "screen",
            "desktop",
            "function",
            "string",
            "array",
            "number",
            "vfunction",
            "f8192",
            "n432",
            "true",
            "j2048",
            "this",
            "window",
            "void",
            "date",
            "pokau017c",
            "pytfunction",
            "fe8function",
            "qgzfunction",
            "afunction",
            "hb28",
            "r150",
            "promise",
            "bigint",
            "post",
            "edge",
            "swhealthlog",
            "symbol",
            "trident",
            "infinity",
            "embed",
            "webkitkeyframes",
            "zoomin",
            "zoominx",
            "zoomoutx",
            "zoominy",
            "zoomouty",
            "2000px",
            "90deg",
            "20px",
            "30deg",
            "30px",
            "10px",
            "10deg",
            "3deg",
            "5deg",
            "djmegamenu",
            "use license",
            "tabindex",
            "menu",
            "close",
            "msie",
            "beforechange",
            "imagehassize",
            "buildcontrols",
            "magnific popup",
            "dmitry semenov",
            "http",
            "beforeclose",
            "afterclose",
            "open",
            "next",
            "open source",
            "bsd license",
            "george mcginley",
            "smith",
            "djimageslider",
            "subpackage",
            "webkit",
            "khtml",
            "icab",
            "countto",
            "callback",
            "handler",
            "object",
            "typeof",
            "method",
            "gnugplv2",
            "website",
            "set module",
            "height script",
            "regexp",
            "screenheight",
            "highcontrast2",
            "highcontrast3",
            "highcontrast",
            "wide",
            "night",
            "body",
            "normalbutton",
            "cookie plugin",
            "https",
            "klaus hartl",
            "mit license",
            "register",
            "nodecommonjs",
            "factory",
            "jquery",
            "write",
            "sticky bar",
            "stickybar",
            "count",
            "offcanvas",
            "html",
            "noscroll",
            "offcanvas var",
            "toggle nav",
            "click jquery",
            "ajax",
            "autocomplete",
            "tomas kirda",
            "typeof define",
            "esc27",
            "tab9",
            "return13",
            "left37",
            "up38",
            "twitter",
            "custom version",
            "joomla",
            "rolemenu",
            "boolean",
            "get adobe",
            "flash player",
            "title",
            "text",
            "typeof data",
            "typeof s",
            "accept",
            "width",
            "foundation",
            "backspace8",
            "comma188",
            "delete46",
            "down40",
            "end35",
            "enter13",
            "escape27",
            "value",
            "migrate",
            "backcompat",
            "quirks mode",
            "typeof f",
            "xtablet768",
            "document",
            "ui sortable",
            "leftright",
            "gnu general",
            "public license",
            "dddddd",
            "ffffcc",
            "eeeeee",
            "verdana",
            "geneva",
            "arial",
            "helvetica",
            "f0f0f0",
            "sans",
            "charset",
            "utf8",
            "fontawesome",
            "typeof b",
            "pseudo",
            "child",
            "sufeffxa0",
            "class",
            "attr",
            "general slider",
            "slide",
            "rgba",
            "navigation",
            "15deg",
            "300px",
            "20deg",
            "transition",
            "scale",
            "baskerville",
            "main image",
            "bdbdbd",
            "f3f3f3",
            "remove",
            "fontface",
            "woff2",
            "u0131",
            "u01520153",
            "u02bb02bc",
            "u02c6",
            "u02da",
            "u02dc",
            "u0304",
            "dirrtl",
            "msviewport",
            "href",
            "span",
            "legend",
            "halflings",
            "fieldset",
            "typeimage",
            "f2f2f2",
            "d9edf7",
            "dff0d8",
            "f2dede",
            "thead",
            "tbody",
            "tahoma",
            "00a0",
            "video",
            "script",
            "2500",
            "xnew ita",
            "dnew jta",
            "dataset",
            "orfunction",
            "prfunction",
            "nsafunction",
            "xsafunction",
            "vrfunction",
            "cakes",
            "ovbfunction",
            "pvbfunction",
            "rvbfunction",
            "qvbfunction",
            "tvbfunction",
            "uvbfunction",
            "vvbclass",
            "xvbclass",
            "yvbclass",
            "svbclass",
            "lvafunction",
            "ggfunction",
            "mvafunction",
            "ovafunction",
            "pvafunction",
            "uvafunction",
            "tvafunction",
            "qvafunction",
            "vvafunction",
            "nvaclass",
            "dark",
            "vector",
            "yy49",
            "raster",
            "roboto",
            "new tk",
            "qael",
            "przechyl",
            "mars",
            "mercury",
            "venus",
            "pluto",
            "titan",
            "weakset",
            "wfclass",
            "googlelayer",
            "uint8array",
            "weakmap",
            "5001",
            "mouseevent",
            "webassembly",
            "180180",
            "9090",
            "google maps",
            "javascript api",
            "internal",
            "small",
            "lightrail",
            "false",
            "february",
            "light",
            "hybrid",
            "bounce",
            "drop",
            "inside",
            "outside",
            "marker",
            "gc"
          ],
          "references": [
            "embed.html",
            "ad_status.js.pobrane",
            "f5Y41t9wqY4.html",
            "cast_sender.js.pobrane",
            "remote.js.pobrane",
            "sw3VTUzeRvWIVwvWSyk6S5gHWPxOOwU1OxerozmN4Hw.js.pobrane",
            "embed.js.pobrane",
            "www-embed-player.js.pobrane",
            "animate.ext.css",
            "animate.min.css",
            "jquery.djmegamenu.js.pobrane",
            "jquery.djmobilemenu.js.pobrane",
            "magnific.js.pobrane",
            "jquery.easing.min.js.pobrane",
            "slider.js.pobrane",
            "jquery.countTo.js.pobrane",
            "scripts.js.pobrane",
            "magnific-init.js.pobrane",
            "pagesettings.js.pobrane",
            "jquery.cookie.js.pobrane",
            "stickybar.js.pobrane",
            "fontswitcher.js.pobrane",
            "offcanvas.js.pobrane",
            "jquery.autocomplete.min.js.pobrane",
            "bootstrap.min.js.pobrane",
            "jcemediabox.js.pobrane",
            "jquery.ui.core.min.js.pobrane",
            "jquery-migrate.min.js.pobrane",
            "layout.min.js.pobrane",
            "jquery.ui.sortable.min.js.pobrane",
            "caption.js.pobrane",
            "finder.css",
            "jquery-noconflict.js.pobrane",
            "djmegamenu.26.css",
            "animations.css",
            "djmobilemenu.css",
            "jquery.min.js.pobrane",
            "djimageslider.css",
            "offcanvas.css",
            "magnific.css",
            "font_switcher.26.css",
            "css",
            "template_responsive.26.css",
            "offcanvas.26.css",
            "bootstrap_responsive.26.css",
            "extended_layouts.26.css",
            "style.css",
            "content.css",
            "template.26.css",
            "bootstrap.26.css",
            "jcemediabox.css",
            "js",
            "onion.js.pobrane",
            "search_impl.js.pobrane",
            "overlay.js.pobrane",
            "map.js.pobrane",
            "util.js.pobrane",
            "search.js.pobrane",
            "common.js.pobrane",
            "geometry.js.pobrane",
            "main.js.pobrane"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Gc",
              "display_name": "Gc",
              "target": null
            }
          ],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 26,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "Arek-BTC",
            "id": "212764",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_212764/resized/80/avatar_3b9c358f36.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 2779,
            "hostname": 661,
            "domain": 684,
            "email": 4,
            "FileHash-MD5": 1,
            "FileHash-SHA256": 689
          },
          "indicator_count": 4818,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 122,
          "modified_text": "310 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "65708ea5a3214f63e1d6d94f",
          "name": "lumen.me Honeybadger",
          "description": "",
          "modified": "2023-12-06T15:09:25.749000",
          "created": "2023-12-06T15:09:25.749000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 3,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 475,
            "hostname": 315,
            "domain": 233,
            "URL": 1133
          },
          "indicator_count": 2156,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "866 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "65708c8a9635f156e79238f1",
          "name": "intel gained from a spam text",
          "description": "",
          "modified": "2023-12-06T15:00:26.727000",
          "created": "2023-12-06T15:00:26.727000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "CVE": 1,
            "FileHash-SHA256": 823,
            "domain": 717,
            "URL": 2245,
            "hostname": 615,
            "email": 4,
            "FileHash-MD5": 5,
            "FileHash-SHA1": 1
          },
          "indicator_count": 4411,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 110,
          "modified_text": "866 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "65708c37c54dd9e78f85c0fa",
          "name": "\u7ea2\u674f\u89c6\u9891 malware",
          "description": "",
          "modified": "2023-12-06T14:59:03.859000",
          "created": "2023-12-06T14:59:03.859000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 4,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 1686,
            "hostname": 2218,
            "URL": 5740,
            "domain": 901,
            "FileHash-MD5": 3
          },
          "indicator_count": 10548,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "866 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "65708bbc4c8bf557c17688e1",
          "name": "\u9ad8\u5c71tv,\u9ad8\u5c71tv,\u9ad8\u5c71tv\u5f71\u9662,\u9ad8\u5c71tv\u770b\u7247\u7f51",
          "description": "",
          "modified": "2023-12-06T14:57:00.280000",
          "created": "2023-12-06T14:57:00.280000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "CVE": 1,
            "FileHash-SHA256": 233,
            "domain": 361,
            "hostname": 563,
            "URL": 1374,
            "FileHash-SHA1": 1,
            "FileHash-MD5": 1
          },
          "indicator_count": 2534,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "866 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "65707e5b7df6f60133e8fb50",
          "name": "Jeeng / Powerbox",
          "description": "",
          "modified": "2023-12-06T13:59:55.129000",
          "created": "2023-12-06T13:59:55.129000",
          "tags": [],
          "references": [],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "green",
          "cloned_from": null,
          "export_count": 2,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "api",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "StreamMiningEx",
            "id": "262917",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "CVE": 3,
            "FileHash-SHA256": 9072,
            "domain": 2500,
            "hostname": 3584,
            "URL": 13548,
            "FileHash-MD5": 197,
            "FileHash-SHA1": 162,
            "email": 19,
            "CIDR": 20,
            "SSLCertFingerprint": 2,
            "BitcoinAddress": 1
          },
          "indicator_count": 29108,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 109,
          "modified_text": "866 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "628af7e3df399fbe9095245f",
          "name": "lumen.me Honeybadger",
          "description": "window.ju_sha256, a new type of code, is written by the same characters:var l,b,c,g,p,a,h,d, c.",
          "modified": "2022-06-21T00:01:09.886000",
          "created": "2022-05-23T02:56:35.154000",
          "tags": [
            "reduceright",
            "lj",
            "number",
            "query",
            "string",
            "trackevent",
            "date",
            "u003e div",
            "simulator",
            "error",
            "regexp",
            "pageview",
            "path",
            "void",
            "code",
            "l420",
            "g5vs2ll0p80",
            "copyright",
            "json",
            "uint8array",
            "ssnull",
            "script",
            "closure library",
            "xdfunction",
            "adfunction",
            "typeof t",
            "typeof symbol",
            "typeof",
            "window",
            "value",
            "function",
            "customevent",
            "image",
            "null",
            "sbfu",
            "typeof n",
            "object",
            "array",
            "control",
            "other",
            "android",
            "x3e div",
            "gtmnwh4dh2",
            "host",
            "page title",
            "page path",
            "typeerror",
            "promise",
            "typeof e",
            "typeof window",
            "aggregateerror",
            "math",
            "target",
            "rangeerror",
            "buffer",
            "index",
            "attempt",
            "argument",
            "google",
            "link",
            "ad tech",
            "providers",
            "ffffff",
            "ip address",
            "combine",
            "accept",
            "save",
            "explorer",
            "cookie",
            "back",
            "iframe",
            "blank",
            "position",
            "juorderid",
            "justuno",
            "body",
            "juorigtop",
            "event",
            "follow",
            "post",
            "config",
            "click",
            "local",
            "fast",
            "comp",
            "form",
            "unknown",
            "push",
            "trcimpl",
            "trcwarn"
          ],
          "references": [
            "https://cdn.taboola.com/scripts/cds-pips.js",
            "https://www.iubenda.com/cookie-solution/confs/js/53119375.js",
            "https://cdn.jst.ai/mwgt_4.1.js?v=5.28",
            "https://cdn.iubenda.com/cookie_solution/iubenda_cs/1.38.0/core-en.js",
            "https://s.pinimg.com/ct/lib/main.32155010.js",
            "https://analytics.tiktok.com/i18n/pixel/config.js?sdkid=C3I4VUA8DUF9JOO44QC0&hostname=lumen.me",
            "https://js.pvd.to/c/v1/pixel-1sdz.js?t=1653350400000",
            "https://cdn.jst.ai/vck.js",
            "https://www.googletagmanager.com/gtm.js?id=GTM-NWH4DH2",
            "https://analytics.tiktok.com/i18n/pixel/events.js?sdkid=C3I4VUA8DUF9JOO44QC0&lib=ttq",
            "https://cdn.taboola.com/libtrc/unip/1262365/tfa.js",
            "https://s.pinimg.com/ct/core.js",
            "https://www.googleoptimize.com/optimize.js?id=OPT-TQC6JW4",
            "https://www.googletagmanager.com/gtag/js?id=G-5VS2LL0P80&l=dataLayer&cx=c",
            "https://www.googletagmanager.com/gtm.js?id=GTM-PF3JNK2&gtm_auth=a6AgvzJ0SAOcyjADNwrdlQ&gtm_preview=env-1&gtm_cookies_win=x"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "Lj",
              "display_name": "Lj",
              "target": null
            },
            {
              "id": "ReduceRight",
              "display_name": "ReduceRight",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 10,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "adjadex1@gmail.com",
            "id": "187163",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 1134,
            "hostname": 315,
            "domain": 233,
            "FileHash-SHA256": 475
          },
          "indicator_count": 2157,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 67,
          "modified_text": "1399 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "620c3b1f8af7ea0dcf2c1218",
          "name": "Jeeng / Powerbox",
          "description": "",
          "modified": "2022-06-12T22:01:23.105000",
          "created": "2022-02-15T23:45:35.234000",
          "tags": [
            "Jeeng",
            "tim pool",
            "timcast"
          ],
          "references": [
            "cf20ed53-cb6d-4dfd-a4e8-794fbe163efc.pcap"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [
            "United States of America"
          ],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 10,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "scnrscnr",
            "id": "126475",
            "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_126475/resized/80/avatar_67ca5b7bae.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "FileHash-SHA256": 9072,
            "domain": 2500,
            "URL": 13548,
            "hostname": 3584,
            "FileHash-MD5": 197,
            "FileHash-SHA1": 162,
            "CVE": 3,
            "CIDR": 20,
            "SSLCertFingerprint": 2,
            "email": 19,
            "BitcoinAddress": 1
          },
          "indicator_count": 29108,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 97,
          "modified_text": "1407 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6266f7e0e0264cba210a4e9e",
          "name": "intel gained from a spam text",
          "description": "var b[f]=g, if b(f) is not allowed to reach its maximum by the end of a set, then a.b(b) will be able to do so at the same time as a",
          "modified": "2022-05-25T00:04:03.622000",
          "created": "2022-04-25T19:34:56.772000",
          "tags": [
            "array",
            "typeerror",
            "symbol",
            "null",
            "string",
            "iterator",
            "object",
            "error",
            "boolean",
            "function",
            "service",
            "date",
            "phonenumber",
            "facebook",
            "meta",
            "typeof e",
            "typeof u",
            "typeof window",
            "es modules",
            "use esm",
            "webkit",
            "component",
            "typeof",
            "typeof y",
            "typeof symbol",
            "suspense",
            "context",
            "forwardref",
            "unknown",
            "4096",
            "typeof n",
            "promise",
            "weakmap",
            "dataview",
            "typeof t",
            "webpackrequire",
            "modulenotfound",
            "e1342177279",
            "array int8array",
            "loanup",
            "insurance",
            "group",
            "health",
            "solutions",
            "policy",
            "site",
            "america",
            "company",
            "life",
            "plan",
            "direct",
            "media",
            "alliance",
            "click",
            "team",
            "never",
            "advantage",
            "general",
            "light",
            "february",
            "april",
            "june",
            "august",
            "footer",
            "protect",
            "banker",
            "explorer",
            "fast",
            "martin",
            "union",
            "carrier",
            "next",
            "colony",
            "energy",
            "empire",
            "gerber",
            "philadelphia",
            "hippo",
            "king",
            "agent",
            "mercury",
            "moss",
            "premium",
            "nextgen",
            "oscar",
            "phoenix",
            "loans",
            "pure",
            "ramsey",
            "ranger",
            "solar",
            "titan",
            "tristate",
            "viking",
            "easy",
            "push",
            "code",
            "stop",
            "carriers",
            "live",
            "lucky",
            "moral",
            "story",
            "back",
            "lfunction",
            "dfunction",
            "cfunction",
            "typeof self",
            "number",
            "copyright",
            "closure library",
            "xdfunction",
            "cdfunction",
            "ddfunction",
            "bded",
            "kefunction",
            "reduceright",
            "gj9pcw0f6jv",
            "regexp",
            "r420",
            "uint8array",
            "typeof d",
            "void"
          ],
          "references": [
            "https://www.googletagmanager.com/gtag/js?id=G-J9PCW0F6JV",
            "https://www.googletagmanager.com/gtag/js?id=UA-185991747-1",
            "https://insurancerateusa.com/polyfill-036b4a134d8725752ba0.js",
            "xfe-URL-insurancerateusa.com-stix2-2.1-export.json",
            "https://insurancerateusa.com/app-74647f151b541f3098c2.js",
            "https://insurancerateusa.com/bfcc7b67-0b189ba6da3fc3ae8b88.js",
            "https://insurancerateusa.com/94297995-69529ad7536f090aa776.js",
            "https://insurancerateusa.com/3bea8d40-8926f4790c0b3689a361.js",
            "https://insurancerateusa.com/framework-19eddc0d879a49dfe606.js",
            "https://insurancerateusa.com/webpack-runtime-f014a3267add02a94afb.js",
            "https://connect.facebook.net/signals/config/3689470801106673?v=2.9.57&r=stable"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "ReduceRight",
              "display_name": "ReduceRight",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 10,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "adjadex1@gmail.com",
            "id": "187163",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 615,
            "URL": 2246,
            "FileHash-SHA256": 823,
            "domain": 717,
            "CVE": 1,
            "email": 4,
            "FileHash-MD5": 5,
            "FileHash-SHA1": 1
          },
          "indicator_count": 4412,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 70,
          "modified_text": "1426 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "628bc74f5b92614c08d99f88",
          "name": "Update Agent - Dinan.",
          "description": "",
          "modified": "2022-05-23T17:41:35.234000",
          "created": "2022-05-23T17:41:35.234000",
          "tags": [
            "dinan",
            "performance",
            "update agent",
            "help center",
            "products",
            "lubricants",
            "engine hardware",
            "exhaust",
            "dinan dealer",
            "dealer login",
            "mini",
            "contact",
            "agent",
            "download",
            "alpha",
            "verdana",
            "arial",
            "opacity35",
            "copyright",
            "foundation",
            "opacity0",
            "opacity70",
            "opacity80",
            "hubspot script",
            "loader",
            "closure library",
            "number",
            "string",
            "regexp",
            "uint8array",
            "date",
            "fnumber",
            "aw1027984682",
            "xdfunction",
            "code",
            "null",
            "error",
            "activexobject",
            "xmlhttprequest",
            "android",
            "worker",
            "installtrigger",
            "ccon",
            "false",
            "error occured",
            "body",
            "please",
            "shippingphone",
            "event",
            "item",
            "shippingaddress",
            "billingphone",
            "promise",
            "click",
            "window",
            "this",
            "close",
            "model",
            "drop",
            "main",
            "facebook",
            "form",
            "next",
            "february",
            "april",
            "june",
            "august",
            "atom",
            "cookie",
            "back",
            "bounce",
            "open",
            "express",
            "spinner",
            "copy",
            "typeof e",
            "typeof t",
            "class",
            "attr",
            "pseudo",
            "child",
            "function",
            "typeof module",
            "0x4b3a",
            "error message",
            "signifydglobal",
            "0x1c7d",
            "current order",
            "x0x4b3a",
            "gtmpkdjjpc",
            "host",
            "path",
            "adfunction"
          ],
          "references": [
            "https://www.googletagmanager.com/gtm.js?id=GTM-PKDJJPC",
            "https://cdn-scripts.signifyd.com/api/script-tag.js",
            "https://ajax.googleapis.com/ajax/libs/jquery/3.6.0/jquery.min.js",
            "https://www.dinancars.com/assets/js/combine/min/v1653077793/e88cd3e3db8ab2b910e50cf4deb60529f/default;jquery-ui.min;js.cookie;util;nav;cart;accountfunctions;jquery.activity-indicator-1.0.0.min;drawer_plugin;floating_label_gen;jquery.autoellipsis-1.0.10;fresco;fresco-custom;isotope_imagesloaded.min;promo_autoplus_helpers;slick.min;widgets;jquery.custom-carousel;waterfall_helpers/",
            "https://imgs.signifyd.com/fp/tags.js?org_id=w2txo5aa&session_id=7632E9E9-DE48-41D8-9BAC-1E27A98D17EC&pageid=2",
            "https://www.googletagmanager.com/gtag/js?id=AW-1027984682",
            "https://googleads.g.doubleclick.net/pagead/viewthroughconversion/1027984682/?random=1653327072015&cv=9&fst=1653327072015&num=1&bg=ffffff&guid=ON&resp=GooglemKTybQhCsO&u_h=844&u_w=390&u_ah=844&u_aw=390&u_cd=32&u_his=6&u_tz=-240&u_java=false&u_nplug=0&u_nmime=0&gtm=2oa5b0&sendb=1&ig=1&data=event%3Dgtag.config&frm=0&url=https%3A%2F%2Fwww.dinancars.com%2Fabout%2F&ref=https%3A%2F%2Fwww.dinancars.com%2Fupdate-agent&tiba=About%20Dinan%20-%20Dinan&hn=www.googleadservices.com&async=1&rfmt=3&fmt=4",
            "https://js.hs-scripts.com/8009596.js",
            "https://www.dinancars.com/assets/css/jquery-ui-custom.css",
            "https://www.dinancars.com/update-agent"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1495",
              "name": "Firmware Corruption",
              "display_name": "T1495 - Firmware Corruption"
            },
            {
              "id": "T1027",
              "name": "Obfuscated Files or Information",
              "display_name": "T1027 - Obfuscated Files or Information"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 9,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "adjadex1@gmail.com",
            "id": "187163",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 1806,
            "hostname": 682,
            "FileHash-SHA256": 240,
            "domain": 274
          },
          "indicator_count": 3002,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 68,
          "modified_text": "1427 days ago ",
          "is_modified": false,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "62606584633e2b9a3bc935b9",
          "name": "\u7ea2\u674f\u89c6\u9891 malware",
          "description": "function s(t,e), o, is a new type of function, which throws new TypeError when it comes to trying to make a function out of its own language or its form.",
          "modified": "2022-05-20T00:01:19.453000",
          "created": "2022-04-20T19:56:52.162000",
          "tags": [
            "typeof t",
            "typeof define",
            "moztransform",
            "success",
            "error",
            "make sure",
            "stop",
            "ajax",
            "action",
            "click",
            "open",
            "active",
            "button",
            "toggle btn",
            "body",
            "scroll",
            "isotope",
            "preloader",
            "function",
            "javascript",
            "mit license",
            "typeof module",
            "gplv3",
            "license",
            "copyright",
            "metafizzy",
            "math",
            "typeof",
            "typeerror",
            "hidden",
            "show",
            "typeof n",
            "version",
            "hide",
            "focusin",
            "focusout",
            "shown",
            "startr",
            "endr",
            "federico zivolo",
            "distributed",
            "html",
            "statict",
            "flip",
            "regexp",
            "null",
            "void",
            "width",
            "object",
            "pseudo",
            "child",
            "class",
            "date",
            "accept",
            "webpackrequire",
            "name",
            "number",
            "arraybuffer",
            "iterator",
            "typedarray",
            "prototype",
            "string",
            "index",
            "meta",
            "target",
            "infinity",
            "zero",
            "epsilon",
            "observer",
            "android",
            "trim",
            "enumerate",
            "freeze",
            "internal",
            "bind",
            "window",
            "next",
            "find",
            "this",
            "rest",
            "middle",
            "canvas",
            "slidercaptcha",
            "createelement",
            "textdanger",
            "plugin",
            "rgba",
            "imagedata",
            "false",
            "touchstart",
            "trident",
            "applewebkit",
            "safari",
            "base",
            "presto",
            "gecko",
            "khtml",
            "micromessenger",
            "typeof e",
            "swiper",
            "most",
            "september",
            "customevent",
            "image",
            "typeof c",
            "twitter",
            "bootstrap",
            "rolemenu",
            "typeof f",
            "typeof g",
            "cookie plugin",
            "https",
            "klaus hartl",
            "register",
            "nodecommonjs",
            "factory",
            "jquery",
            "write",
            "typeof b",
            "array",
            "sufeffxa0",
            "attr",
            "\u706b\u7bad\u5185\u6d4b\u7b7e\u540d",
            "0x1d9131",
            "0x180bcc",
            "0x4b6177",
            "0x13f349",
            "0x3bcb54",
            "0xbbe80d",
            "0x57b7de",
            "0x2ea74e",
            "0x4fb0f2",
            "0x25f113",
            "push",
            "shift",
            "tencent",
            "barrio",
            "slice",
            "symbol",
            "typeof window",
            "maximum",
            "typeof symbol",
            "udc66udc67",
            "ud83d",
            "ufe0f",
            "ud83e",
            "udc68udc69",
            "udfcbudfcc",
            "u2640u2642",
            "ufe0fg",
            "ud83dudc6cud83c",
            "ud83dudc6dud83c",
            "welcome",
            "datav66d78640",
            "datav2f8052f5",
            "90deg",
            "datav5f1e575c",
            "datave97d7462",
            "helvetica neue",
            "helvetica",
            "10px",
            "pingfang sc",
            "arial",
            "45deg",
            "typenumber",
            "opacity0",
            "mozopacity0",
            "khtmlopacity0",
            "opacity100",
            "event",
            "boolean",
            "uint8array",
            "errordetails",
            "info",
            "checker",
            "generator",
            "blink",
            "keepalive",
            "4096",
            "unknown",
            "meteor",
            "rhino",
            "mini",
            "comment",
            "verify",
            "yeke",
            "codec",
            "media",
            "live",
            "speed",
            "headname",
            "axiostimeout",
            "apiurl",
            "bmi86hjtsk",
            "root",
            "length",
            "indexof",
            "x0ax20x20x20x20",
            "location",
            "0x10",
            "0x18",
            "history",
            "config",
            "cookie",
            "onload",
            "video",
            "afunction",
            "indexnotice",
            "sitehome",
            "x20trnf",
            "please",
            "strong"
          ],
          "references": [
            "xfe-URL-sys95.com-stix2-2.1-export.json",
            "https://2001.habyc.com/?channelNo=2001#/home",
            "https://sdk.51.la/event/js-sdk-event.min.js?u=JdoUNv3VSW0GHUpw",
            "https://2001.habyc.com/static/js/chunk-7d5d3bac.efb700c7.js",
            "https://sdk.51.la/js-sdk-pro.min.js",
            "https://2001.habyc.com/js/config.js",
            "xfe-URL-2001.habyc.com-stix2-2.1-export.json",
            "https://2001.habyc.com/static/js/chunk-vendors.9d7684f4.js",
            "xfe-URL-habyc.com-stix2-2.1-export.json",
            "https://2001.habyc.com/static/css/chunk-vendors.6a41b67e.css",
            "https://2001.habyc.com/static/css/app.88afcfd8.css",
            "https://2001.habyc.com/static/css/chunk-7d5d3bac.e1a32335.css",
            "https://2001.dwlww.com/?channelNo=2001#/home",
            "https://2001.dwlww.com/static/js/chunk-7d5d3bac.efb700c7.js",
            "https://2001.dwlww.com/js/config.js",
            "https://2001.dwlww.com/static/js/chunk-vendors.9d7684f4.js",
            "https://2001.dwlww.com/static/js/app.9d5d18d7.js",
            "https://2001.dwlww.com/static/css/chunk-vendors.6a41b67e.css",
            "https://2001.dwlww.com/static/css/app.88afcfd8.css",
            "https://2001.dwlww.com/static/css/chunk-7d5d3bac.e1a32335.css",
            "https://www.tidio.com/talk/kv6vcosd7tmhsetmarsoawzaglejnny4",
            "https://chatting.page/kv6vcosd7tmhsetmarsoawzaglejnny4",
            "https://widget-v4.tidiochat.com/code/kv6vcosd7tmhsetmarsoawzaglejnny4.js",
            "https://m4244.com:35003/",
            "https://www.8098.app:21568/?agent=7691755704",
            "https://www.8098.app:21568/js/jquery-1.11.3.min.js",
            "https://www.8098.app:21568/js/xinstall_inner_e.min.js?v=1004",
            "https://app.ynsdty.cn//package/GmCC6WISh",
            "https://app.ynsdty.cn/dist/js/jquery.min.js",
            "https://app.ynsdty.cn/dist/js/jquery.cookie.js",
            "https://app.ynsdty.cn/dist/vendors/bootstrap/js/bootstrap.min.js",
            "https://app.ynsdty.cn/dist/vendors/swiper/swiper.min.js",
            "https://app.ynsdty.cn/dist/js/app.base.js",
            "https://app.ynsdty.cn/dist/js/longbow.slidercaptcha.js",
            "https://app.ynsdty.cn/dist/vendors/core-js/core.js",
            "xfe-URL-sun.net.hk-stix2-2.1-export.json",
            "https://www.sunnetwork.com.sg/sun_21/js/vendor/jquery-3.5.0.min.js",
            "https://www.sunnetwork.com.sg/sun_21/js/popper.min.js",
            "https://www.sunnetwork.com.sg/sun_21/js/bootstrap.min.js",
            "https://www.sunnetwork.com.sg/sun_21/js/isotope.pkgd.min.js",
            "https://www.sunnetwork.com.sg/sun_21/js/imagesloaded.pkgd.min.js",
            "https://www.sunnetwork.com.sg/sun_21/js/main.js",
            "https://www.sunnetwork.com.sg/sun_21/js/ajax-form.js",
            "https://www.sunnetwork.com.sg/sun_21/js/slick.min.js"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 8,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "adjadex1@gmail.com",
            "id": "187163",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "domain": 901,
            "URL": 5740,
            "hostname": 2218,
            "FileHash-SHA256": 1686,
            "FileHash-MD5": 3
          },
          "indicator_count": 10548,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 69,
          "modified_text": "1431 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "6256f92778c2f2177bdd4de9",
          "name": "\u9ad8\u5c71tv,\u9ad8\u5c71tv,\u9ad8\u5c71tv\u5f71\u9662,\u9ad8\u5c71tv\u770b\u7247\u7f51",
          "description": "Here is a full list of highlights from the Chinese TV series, which began in 2011 and has now been broadcast on Chinese television, online and mobile devices, and is now available to watch online.",
          "modified": "2022-05-13T00:03:35.765000",
          "created": "2022-04-13T16:24:07.391000",
          "tags": [
            "date",
            "cnzzdata",
            "czuuid",
            "umdistinctid",
            "typeof symbol",
            "https",
            "zeno rocha",
            "typeof",
            "typeof define",
            "error",
            "array",
            "12863",
            "qrcode",
            "2g2g2h2h0g",
            "dhdh",
            "exptable",
            "logtable",
            "string",
            "typeof j",
            "regexp",
            "typeof e",
            "typeof t",
            "class",
            "attr",
            "pseudo",
            "child",
            "function",
            "typeof module",
            "ahgr",
            "0x40",
            "h0x1",
            "mm32",
            "indexof",
            "length",
            "h0x0",
            "0x248",
            "h0x2",
            "0x17b",
            "webpackrequire",
            "webpackexports",
            "object",
            "default",
            "hn return",
            "importsnvar",
            "truennnn",
            "iostf",
            "android",
            "nvar",
            "clickdownload",
            "this",
            "path",
            "service",
            "roboto",
            "boolean",
            "number",
            "createnamespace",
            "n default",
            "nn return",
            "null",
            "click",
            "void",
            "istanbul",
            "false",
            "close",
            "window",
            "info",
            "target",
            "find",
            "footer",
            "delta",
            "generator",
            "cascade",
            "code",
            "trigger",
            "next",
            "arrow",
            "slice",
            "checkbox",
            "body",
            "green",
            "phase",
            "copy",
            "infinity",
            "middle",
            "open",
            "calendar",
            "flex",
            "fail",
            "shift",
            "super",
            "internal",
            "form",
            "locale",
            "spinner",
            "spin",
            "multi",
            "mask",
            "write",
            "flip",
            "logic",
            "patch",
            "abcd",
            "skew",
            "main",
            "rest",
            "trim",
            "dark",
            "canvas",
            "facebook",
            "executor",
            "span",
            "tips",
            "sticky",
            "uploader",
            "bind",
            "config",
            "startpage",
            "speed",
            "toolbar",
            "refresh",
            "done",
            "format",
            "cardinal",
            "outside",
            "install",
            "public",
            "github",
            "vuejs",
            "jump",
            "browser",
            "sign",
            "view",
            "sponsor",
            "github sponsors",
            "mit license",
            "contact",
            "star",
            "stars",
            "javascript",
            "please",
            "strong",
            "\u9ad8\u5c71tv",
            "\u9ad8\u5c71tv\u5f71\u9662",
            "\u9ad8\u5c71tv\u770b\u7247\u7f51",
            "hd 20210830",
            "hd mu",
            "hd heydouga",
            "poro",
            "tv tv",
            "hd ok",
            "hd fol",
            "hd nanami2",
            "hd \uff13",
            "hd 20210927"
          ],
          "references": [
            "http://www.bbbbop13.com:1313/",
            "xfe-URL-hyqxsnjj.com-stix2-2.1-export.json",
            "https://web.op39v.xyz/?channelCode=pingguo",
            "https://github.com/vuejs/vue-devtools",
            "https://web.op39v.xyz/js/chunk-vendors.js",
            "https://web.op39v.xyz/js/chunk-common.js",
            "https://res-1257422681.file.myqcloud.com/assets/yeyue/boinstall.js",
            "https://cdn.staticfile.org/jquery/3.6.0/jquery.min.js",
            "https://cdn.staticfile.org/qrcodejs/1.0.0/qrcode.min.js",
            "https://cdn.staticfile.org/clipboard.js/2.0.8/clipboard.min.js",
            "https://s9.cnzz.com/z_stat.php?id=1280740152&web_id=1280740152",
            "https://c.cnzz.com/core.php?web_id=1280740152&t=z"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 4,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "adjadex1@gmail.com",
            "id": "187163",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "URL": 1374,
            "hostname": 563,
            "CVE": 1,
            "domain": 361,
            "FileHash-SHA256": 233,
            "FileHash-SHA1": 1,
            "FileHash-MD5": 1
          },
          "indicator_count": 2534,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 68,
          "modified_text": "1438 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "624fff22683106d256390a89",
          "name": "'Chinese botnet",
          "description": "\u00c2\u00a31.3m (838m euros) - that is the amount of money the Chinese government has to spend on upgrading the country's economy - but how much is it going to cost?",
          "modified": "2022-05-08T09:06:05.710000",
          "created": "2022-04-08T09:23:46.746000",
          "tags": [
            "datav7a53b450",
            "microsoft yahei",
            "label",
            "arial",
            "verdana",
            "simsun",
            "simhei",
            "stheiti",
            "helvetica",
            "aba8a8",
            "font awesome",
            "license",
            "font",
            "sil ofl",
            "mit license",
            "woff2",
            "woff",
            "truetype",
            "fontawesome",
            "0xb6f109",
            "0x9e4f21",
            "0x464801",
            "0x21c094",
            "object",
            "0x54da69",
            "0x28e5ab",
            "promise",
            "0x3aef82",
            "0x12d16a",
            "this",
            "push",
            "window",
            "code",
            "date",
            "bind",
            "error",
            "path",
            "target",
            "middle",
            "null",
            "open",
            "download",
            "blank",
            "refresh",
            "config",
            "span",
            "mark",
            "canvas",
            "mask",
            "9999",
            "close",
            "shift",
            "android",
            "encrypt",
            "getclass",
            "checker",
            "agent",
            "4328",
            "trim",
            "service",
            "slice",
            "crypto",
            "stop",
            "7910",
            "zero",
            "checkbox",
            "format",
            "model",
            "spinner",
            "clickdownload",
            "meta",
            "sport",
            "click",
            "next",
            "class",
            "hammer",
            "body",
            "boolean",
            "number",
            "string",
            "array",
            "typeof t",
            "function",
            "regexp",
            "typeof e",
            "generator",
            "4096",
            "ping",
            "f6cf32",
            "modulenotfound",
            "n noticecontent",
            "typeerror",
            "circular",
            "infinite",
            "mouseevent",
            "dommousescroll",
            "lotteryhallhome",
            "void",
            "bubble",
            "vnode",
            "vuessrcontext",
            "swiper",
            "typeof o",
            "mozperspective",
            "msperspective",
            "tridentg",
            "event",
            "bscroll",
            "u200",
            "typeof s",
            "newatchman",
            "fetch",
            "timeout",
            "ofunction",
            "zfunction",
            "watchman",
            "dfunction",
            "domutils",
            "typeof n",
            "4294967295",
            "parseint",
            "utf8",
            "utils",
            "post",
            "channelcode",
            "0xa60881",
            "0x1e0610",
            "0x489cca",
            "0x4d5bd1",
            "0x1a7a9a",
            "0x3145fc",
            "0x2d9acb",
            "0xbf1b3e",
            "0x47699d",
            "cookie",
            "info",
            "jb3tu",
            "0x1d9131",
            "0x180bcc",
            "0x4b6177",
            "0x13f349",
            "0x3bcb54",
            "0xbbe80d",
            "0x57b7de",
            "0x2ea74e",
            "0x4fb0f2",
            "0x25f113",
            "tencent",
            "barrio",
            "\u77ed\u89c6\u9891",
            "\u641e\u7b11\u89c6\u9891",
            "\u89c6\u9891\u5206\u4eab",
            "\u514d\u8d39\u89c6\u9891",
            "\u5728\u7ebf\u89c6\u9891",
            "\u9884\u544a\u7247",
            "yuwvm",
            "g 18",
            "720p",
            "hd luna",
            "hd 99",
            "ktvp",
            "part",
            "hd h",
            "dykthr",
            "jquery",
            "titlestr",
            "viewport"
          ],
          "references": [
            "xfe-IP-154.36.230.14-stix2-2.0-export.json",
            "http://www.jxhykj1210.com/common.js",
            "http://www.jxhykj1210.com/tj.js",
            "https://17se.xyz/",
            "https://www.bibo18.app:2171/?agent=2207259251",
            "https://www.bibo18.app:2171/js/xinstall_inner_e.min.js?v=1004",
            "https://cstaticdun.126.net/load.min.js?v=2203141811",
            "https://www.shareinstall.com.cn/js/page/jshareinstall.min.js",
            "https://acstatic-dun.126.net/tool.min.js?t=1647252792143",
            "https://9755w.com:2188/m/js/2203141811-HomeLogin~LotteryHall~VnsLogin~activity~amhgLogin~aqvnsLogin~betnewLocgin~blrLogin~blushLogin~cLogin~6995ba01.js",
            "https://9755w.com:2188/m/js/2203141811-LotteryHall~agent-doc~cpxpjLogin~download~game~home~member~sports~vnsoLogin~vnstLogin2.js",
            "https://9755w.com:2188/m/js/2203141811-JieBei~YuEBao~agent-center-modec~agent-center-new~bet~game~home~invite~member.js",
            "https://9755w.com:2188/m/js/2203141811-LotteryHall~home.js",
            "https://9755w.com:2188/m/js/2203141811-home.js",
            "https://9755w.com:2188/m/js/2203141811-fhcpLogin.js",
            "https://9755w.com:2188/m/js/2203141811-view-page.js",
            "https://9755w.com:2188/m/js/2203141811-chunk-vendors.js",
            "https://9755w.com:2188/m/js/2203141811-index.js",
            "https://netdna.bootstrapcdn.com/font-awesome/4.7.0/css/font-awesome.min.css",
            "https://9755w.com:2188/m/css/fhcpLogin.css?v=2203141811"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [],
          "attack_ids": [
            {
              "id": "T1547",
              "name": "Boot or Logon Autostart Execution",
              "display_name": "T1547 - Boot or Logon Autostart Execution"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 4,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "adjadex1@gmail.com",
            "id": "187163",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 306,
            "URL": 1135,
            "FileHash-SHA256": 122,
            "domain": 172,
            "FileHash-MD5": 4
          },
          "indicator_count": 1739,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 71,
          "modified_text": "1443 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        },
        {
          "id": "624fc692f1d830cd6e86956b",
          "name": "ReduceRight",
          "description": "If you want to know what to do with your intercoms, spare a thought for e.intercom and add a new listener to your browser.. and use it to control the system.",
          "modified": "2022-05-08T00:03:14.586000",
          "created": "2022-04-08T05:22:26.672000",
          "tags": [
            "typerange",
            "40deg",
            "segoe ui",
            "roboto",
            "arial",
            "consolas",
            "liberation mono",
            "menlo",
            "45deg",
            "webkitkeyframes",
            "object",
            "error",
            "please",
            "post",
            "urlsearchparams",
            "paused",
            "sfunction",
            "scene",
            "event",
            "after",
            "problem",
            "date",
            "next",
            "close",
            "typeof define",
            "typeof module",
            "html tags",
            "ox20trnf",
            "dom element",
            "regexp",
            "typeof e",
            "typeof t",
            "class",
            "attr",
            "pseudo",
            "child",
            "function",
            "symbol",
            "corejs",
            "denis pushkarev",
            "array",
            "typeof window",
            "typeof self",
            "string",
            "ieproto",
            "activexobject",
            "formdata",
            "customevent",
            "typeof o",
            "typeof s",
            "json response",
            "refill",
            "wpcf7",
            "wpcf7locale",
            "typeerror",
            "generator",
            "iab2",
            "code",
            "n color",
            "number",
            "cookie",
            "n strictly",
            "hostn host",
            "button",
            "null",
            "65535",
            "typeof symbol",
            "promise",
            "msie",
            "trident",
            "banner",
            "genven",
            "expecting iab",
            "iab tcf",
            "oldcctid",
            "newdomainid",
            "unknown",
            "acceptall",
            "rejectall",
            "checkbox",
            "reduceright",
            "custom",
            "trackevent",
            "purchase",
            "viewcontent",
            "facebook pixel",
            "uetpush",
            "copyright",
            "path",
            "contact",
            "void",
            "image",
            "price",
            "pnull",
            "html",
            "style",
            "ctnull",
            "uint32array",
            "fanull",
            "license",
            "ynull",
            "config",
            "meta",
            "body",
            "iframe",
            "accept",
            "syntaxerror",
            "xmlhttprequest",
            "samesitelax",
            "innull",
            "snnull",
            "addtocart",
            "signup",
            "addtowishlist",
            "lead",
            "typeof require",
            "sha256",
            "search",
            "typeof",
            "pixel code",
            "iterator",
            "constantvalue",
            "globalvariable",
            "facebook",
            "service",
            "phonenumber",
            "boolean",
            "functional",
            "member",
            "bnew regexp",
            "qfunction",
            "adview",
            "addbillinginfo",
            "addtolist",
            "download",
            "install",
            "09af",
            "ver0",
            "tag0",
            "extdata0",
            "ua ch",
            "invalid",
            "edge",
            "dataname",
            "intercom",
            "apple",
            "webkiti",
            "criosi"
          ],
          "references": [
            "https://widget.intercom.io/widget/wsyrfbge",
            "xfe-IP-193.176.186.154-stix2-2.0-export.json",
            "https://bat.bing.com/bat.js",
            "https://snap.licdn.com/li.lms-analytics/insight.min.js",
            "https://connect.facebook.net/signals/config/459577157542621?v=2.9.57&r=stable",
            "https://connect.facebook.net/signals/plugins/identity.js?v=2.9.57",
            "https://connect.facebook.net/en_US/fbevents.js",
            "https://www.redditstatic.com/ads/pixel.js",
            "https://sc.lfeeder.com/lftracker_v1_lYNOR8xM56G7WQJZ.js",
            "https://h.clarity.ms/s/0.6.34/clarity.js",
            "https://www.clarity.ms/tag/7oq672bycl",
            "https://www.googletagmanager.com/gtm.js?id=GTM-5GRKNZJ",
            "https://cdn-ukwest.onetrust.com/scripttemplates/otSDKStub.js",
            "https://www.clickcease.com/monitor/stat.js",
            "https://cdn-ukwest.onetrust.com/scripttemplates/6.17.0/otBannerSdk.js",
            "https://www.heficed.com/wp/wp-includes/js/dist/vendor/regenerator-runtime.min.js",
            "https://www.heficed.com/wp/wp-includes/js/dist/vendor/wp-polyfill.min.js",
            "https://www.heficed.com/app/cache/min/1/app/plugins/contact-form-7/includes/js/index.js?ver=1647518891",
            "https://www.heficed.com/wp/wp-includes/js/jquery/jquery.min.js",
            "https://www.heficed.com/wp/wp-includes/js/jquery/jquery-migrate.min.js",
            "https://www.heficed.com/app/cache/min/1/app/themes/heficed-theme/dist/scripts/main_66bf268e.js?ver=1647518891",
            "https://www.heficed.com/app/cache/min/1/05ffa85815681d905ca82cbee25d8762.css"
          ],
          "public": 1,
          "adversary": "",
          "targeted_countries": [],
          "malware_families": [
            {
              "id": "ReduceRight",
              "display_name": "ReduceRight",
              "target": null
            }
          ],
          "attack_ids": [
            {
              "id": "T1059",
              "name": "Command and Scripting Interpreter",
              "display_name": "T1059 - Command and Scripting Interpreter"
            },
            {
              "id": "T1140",
              "name": "Deobfuscate/Decode Files or Information",
              "display_name": "T1140 - Deobfuscate/Decode Files or Information"
            }
          ],
          "industries": [],
          "TLP": "white",
          "cloned_from": null,
          "export_count": 5,
          "upvotes_count": 0,
          "downvotes_count": 0,
          "votes_count": 0,
          "locked": false,
          "pulse_source": "web",
          "validator_count": 0,
          "comment_count": 0,
          "follower_count": 0,
          "vote": 0,
          "author": {
            "username": "adjadex1@gmail.com",
            "id": "187163",
            "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
            "is_subscribed": false,
            "is_following": false
          },
          "indicator_type_counts": {
            "hostname": 242,
            "URL": 401,
            "FileHash-SHA256": 69,
            "domain": 47,
            "FileHash-MD5": 1,
            "email": 1
          },
          "indicator_count": 761,
          "is_author": false,
          "is_subscribing": null,
          "subscriber_count": 69,
          "modified_text": "1443 days ago ",
          "is_modified": true,
          "groups": [],
          "in_group": false,
          "threat_hunter_scannable": true,
          "threat_hunter_has_agents": 1,
          "related_indicator_type": "URL",
          "related_indicator_is_active": 1
        }
      ],
      "references": [
        "scripts.js.pobrane",
        "jcemediabox.css",
        "https://www.iubenda.com/cookie-solution/confs/js/53119375.js",
        "https://9755w.com:2188/m/js/2203141811-JieBei~YuEBao~agent-center-modec~agent-center-new~bet~game~home~invite~member.js",
        "animations.css",
        "https://cdn-ukwest.onetrust.com/scripttemplates/6.17.0/otBannerSdk.js",
        "jquery.min.js.pobrane",
        "https://9755w.com:2188/m/js/2203141811-LotteryHall~home.js",
        "css",
        "https://www.8098.app:21568/js/xinstall_inner_e.min.js?v=1004",
        "https://www.sunnetwork.com.sg/sun_21/js/ajax-form.js",
        "https://widget.intercom.io/widget/wsyrfbge",
        "https://www.googleoptimize.com/optimize.js?id=OPT-TQC6JW4",
        "https://app.ynsdty.cn/dist/js/app.base.js",
        "bootstrap_responsive.26.css",
        "https://2001.dwlww.com/js/config.js",
        "jquery.countTo.js.pobrane",
        "http://www.jxhykj1210.com/tj.js",
        "https://2001.dwlww.com/static/css/app.88afcfd8.css",
        "https://9755w.com:2188/m/js/2203141811-LotteryHall~agent-doc~cpxpjLogin~download~game~home~member~sports~vnsoLogin~vnstLogin2.js",
        "f5Y41t9wqY4.html",
        "https://app.ynsdty.cn/dist/vendors/bootstrap/js/bootstrap.min.js",
        "https://www.sunnetwork.com.sg/sun_21/js/imagesloaded.pkgd.min.js",
        "https://cdn.iubenda.com/cookie_solution/iubenda_cs/1.38.0/core-en.js",
        "https://insurancerateusa.com/framework-19eddc0d879a49dfe606.js",
        "https://s.pinimg.com/ct/core.js",
        "https://2001.habyc.com/static/js/chunk-vendors.9d7684f4.js",
        "https://www.redditstatic.com/ads/pixel.js",
        "https://www.clarity.ms/tag/7oq672bycl",
        "https://js.hs-scripts.com/8009596.js",
        "jcemediabox.js.pobrane",
        "https://connect.facebook.net/signals/plugins/identity.js?v=2.9.57",
        "template.26.css",
        "https://2001.habyc.com/static/css/chunk-vendors.6a41b67e.css",
        "https://www.sunnetwork.com.sg/sun_21/js/main.js",
        "https://www.googletagmanager.com/gtag/js?id=G-J9PCW0F6JV",
        "sw3VTUzeRvWIVwvWSyk6S5gHWPxOOwU1OxerozmN4Hw.js.pobrane",
        "xfe-URL-hyqxsnjj.com-stix2-2.1-export.json",
        "https://www.bibo18.app:2171/?agent=2207259251",
        "https://www.googletagmanager.com/gtm.js?id=GTM-5GRKNZJ",
        "xfe-URL-habyc.com-stix2-2.1-export.json",
        "https://2001.habyc.com/js/config.js",
        "https://www.dinancars.com/update-agent",
        "https://2001.dwlww.com/static/js/chunk-7d5d3bac.efb700c7.js",
        "https://googleads.g.doubleclick.net/pagead/viewthroughconversion/1027984682/?random=1653327072015&cv=9&fst=1653327072015&num=1&bg=ffffff&guid=ON&resp=GooglemKTybQhCsO&u_h=844&u_w=390&u_ah=844&u_aw=390&u_cd=32&u_his=6&u_tz=-240&u_java=false&u_nplug=0&u_nmime=0&gtm=2oa5b0&sendb=1&ig=1&data=event%3Dgtag.config&frm=0&url=https%3A%2F%2Fwww.dinancars.com%2Fabout%2F&ref=https%3A%2F%2Fwww.dinancars.com%2Fupdate-agent&tiba=About%20Dinan%20-%20Dinan&hn=www.googleadservices.com&async=1&rfmt=3&fmt=4",
        "https://cdn.jst.ai/vck.js",
        "https://2001.habyc.com/static/css/app.88afcfd8.css",
        "https://insurancerateusa.com/94297995-69529ad7536f090aa776.js",
        "finder.css",
        "https://imgs.signifyd.com/fp/tags.js?org_id=w2txo5aa&session_id=7632E9E9-DE48-41D8-9BAC-1E27A98D17EC&pageid=2",
        "search_impl.js.pobrane",
        "https://widget-v4.tidiochat.com/code/kv6vcosd7tmhsetmarsoawzaglejnny4.js",
        "https://cdn.staticfile.org/clipboard.js/2.0.8/clipboard.min.js",
        "https://17se.xyz/",
        "http://www.bbbbop13.com:1313/",
        "https://snap.licdn.com/li.lms-analytics/insight.min.js",
        "https://www.8098.app:21568/js/jquery-1.11.3.min.js",
        "onion.js.pobrane",
        "animate.ext.css",
        "https://app.ynsdty.cn/dist/js/jquery.min.js",
        "https://netdna.bootstrapcdn.com/font-awesome/4.7.0/css/font-awesome.min.css",
        "embed.js.pobrane",
        "ad_status.js.pobrane",
        "https://app.ynsdty.cn//package/GmCC6WISh",
        "https://cstaticdun.126.net/load.min.js?v=2203141811",
        "https://9755w.com:2188/m/js/2203141811-home.js",
        "https://res-1257422681.file.myqcloud.com/assets/yeyue/boinstall.js",
        "https://www.heficed.com/app/cache/min/1/app/themes/heficed-theme/dist/scripts/main_66bf268e.js?ver=1647518891",
        "https://insurancerateusa.com/3bea8d40-8926f4790c0b3689a361.js",
        "https://sc.lfeeder.com/lftracker_v1_lYNOR8xM56G7WQJZ.js",
        "extended_layouts.26.css",
        "jquery-noconflict.js.pobrane",
        "cf20ed53-cb6d-4dfd-a4e8-794fbe163efc.pcap",
        "https://app.ynsdty.cn/dist/vendors/swiper/swiper.min.js",
        "jquery.autocomplete.min.js.pobrane",
        "offcanvas.css",
        "https://sdk.51.la/event/js-sdk-event.min.js?u=JdoUNv3VSW0GHUpw",
        "https://www.heficed.com/wp/wp-includes/js/jquery/jquery-migrate.min.js",
        "https://www.googletagmanager.com/gtm.js?id=GTM-PKDJJPC",
        "https://chatting.page/kv6vcosd7tmhsetmarsoawzaglejnny4",
        "www-embed-player.js.pobrane",
        "https://js.pvd.to/c/v1/pixel-1sdz.js?t=1653350400000",
        "search.js.pobrane",
        "https://insurancerateusa.com/bfcc7b67-0b189ba6da3fc3ae8b88.js",
        "https://sdk.51.la/js-sdk-pro.min.js",
        "bootstrap.26.css",
        "https://www.googletagmanager.com/gtag/js?id=G-5VS2LL0P80&l=dataLayer&cx=c",
        "https://www.heficed.com/wp/wp-includes/js/dist/vendor/regenerator-runtime.min.js",
        "main.js.pobrane",
        "style.css",
        "https://2001.dwlww.com/static/css/chunk-vendors.6a41b67e.css",
        "https://2001.habyc.com/static/css/chunk-7d5d3bac.e1a32335.css",
        "http://www.jxhykj1210.com/common.js",
        "jquery.ui.sortable.min.js.pobrane",
        "https://www.8098.app:21568/?agent=7691755704",
        "djmegamenu.26.css",
        "https://bat.bing.com/bat.js",
        "https://www.googletagmanager.com/gtag/js?id=UA-185991747-1",
        "slider.js.pobrane",
        "jquery-migrate.min.js.pobrane",
        "https://www.heficed.com/app/cache/min/1/05ffa85815681d905ca82cbee25d8762.css",
        "https://9755w.com:2188/m/js/2203141811-fhcpLogin.js",
        "https://web.op39v.xyz/js/chunk-common.js",
        "overlay.js.pobrane",
        "caption.js.pobrane",
        "https://connect.facebook.net/signals/config/3689470801106673?v=2.9.57&r=stable",
        "https://www.sunnetwork.com.sg/sun_21/js/isotope.pkgd.min.js",
        "https://cdn.staticfile.org/jquery/3.6.0/jquery.min.js",
        "font_switcher.26.css",
        "https://s9.cnzz.com/z_stat.php?id=1280740152&web_id=1280740152",
        "https://h.clarity.ms/s/0.6.34/clarity.js",
        "https://www.dinancars.com/assets/css/jquery-ui-custom.css",
        "xfe-URL-2001.habyc.com-stix2-2.1-export.json",
        "https://connect.facebook.net/signals/config/459577157542621?v=2.9.57&r=stable",
        "util.js.pobrane",
        "https://cdn.taboola.com/libtrc/unip/1262365/tfa.js",
        "geometry.js.pobrane",
        "https://9755w.com:2188/m/js/2203141811-HomeLogin~LotteryHall~VnsLogin~activity~amhgLogin~aqvnsLogin~betnewLocgin~blrLogin~blushLogin~cLogin~6995ba01.js",
        "https://2001.dwlww.com/static/css/chunk-7d5d3bac.e1a32335.css",
        "fontswitcher.js.pobrane",
        "https://www.bibo18.app:2171/js/xinstall_inner_e.min.js?v=1004",
        "template_responsive.26.css",
        "jquery.djmegamenu.js.pobrane",
        "animate.min.css",
        "https://ajax.googleapis.com/ajax/libs/jquery/3.6.0/jquery.min.js",
        "https://2001.dwlww.com/static/js/app.9d5d18d7.js",
        "https://web.op39v.xyz/js/chunk-vendors.js",
        "content.css",
        "https://2001.dwlww.com/?channelNo=2001#/home",
        "djmobilemenu.css",
        "js",
        "https://insurancerateusa.com/polyfill-036b4a134d8725752ba0.js",
        "https://www.shareinstall.com.cn/js/page/jshareinstall.min.js",
        "magnific.js.pobrane",
        "https://cdn.taboola.com/scripts/cds-pips.js",
        "https://www.heficed.com/wp/wp-includes/js/dist/vendor/wp-polyfill.min.js",
        "bootstrap.min.js.pobrane",
        "https://app.ynsdty.cn/dist/js/longbow.slidercaptcha.js",
        "https://m4244.com:35003/",
        "jquery.ui.core.min.js.pobrane",
        "https://www.googletagmanager.com/gtm.js?id=GTM-NWH4DH2",
        "https://acstatic-dun.126.net/tool.min.js?t=1647252792143",
        "xfe-URL-insurancerateusa.com-stix2-2.1-export.json",
        "offcanvas.26.css",
        "https://c.cnzz.com/core.php?web_id=1280740152&t=z",
        "common.js.pobrane",
        "https://2001.dwlww.com/static/js/chunk-vendors.9d7684f4.js",
        "https://www.googletagmanager.com/gtm.js?id=GTM-PF3JNK2&gtm_auth=a6AgvzJ0SAOcyjADNwrdlQ&gtm_preview=env-1&gtm_cookies_win=x",
        "xfe-URL-sun.net.hk-stix2-2.1-export.json",
        "https://www.dinancars.com/assets/js/combine/min/v1653077793/e88cd3e3db8ab2b910e50cf4deb60529f/default;jquery-ui.min;js.cookie;util;nav;cart;accountfunctions;jquery.activity-indicator-1.0.0.min;drawer_plugin;floating_label_gen;jquery.autoellipsis-1.0.10;fresco;fresco-custom;isotope_imagesloaded.min;promo_autoplus_helpers;slick.min;widgets;jquery.custom-carousel;waterfall_helpers/",
        "https://www.tidio.com/talk/kv6vcosd7tmhsetmarsoawzaglejnny4",
        "https://cdn.jst.ai/mwgt_4.1.js?v=5.28",
        "https://app.ynsdty.cn/dist/vendors/core-js/core.js",
        "https://www.clickcease.com/monitor/stat.js",
        "pagesettings.js.pobrane",
        "https://app.ynsdty.cn/dist/js/jquery.cookie.js",
        "https://insurancerateusa.com/webpack-runtime-f014a3267add02a94afb.js",
        "djimageslider.css",
        "https://www.googletagmanager.com/gtag/js?id=AW-1027984682",
        "https://cdn-ukwest.onetrust.com/scripttemplates/otSDKStub.js",
        "cast_sender.js.pobrane",
        "embed.html",
        "offcanvas.js.pobrane",
        "https://connect.facebook.net/en_US/fbevents.js",
        "https://analytics.tiktok.com/i18n/pixel/config.js?sdkid=C3I4VUA8DUF9JOO44QC0&hostname=lumen.me",
        "remote.js.pobrane",
        "magnific-init.js.pobrane",
        "https://9755w.com:2188/m/js/2203141811-index.js",
        "https://s.pinimg.com/ct/lib/main.32155010.js",
        "https://www.sunnetwork.com.sg/sun_21/js/slick.min.js",
        "https://www.sunnetwork.com.sg/sun_21/js/popper.min.js",
        "https://2001.habyc.com/static/js/chunk-7d5d3bac.efb700c7.js",
        "https://web.op39v.xyz/?channelCode=pingguo",
        "jquery.cookie.js.pobrane",
        "xfe-IP-193.176.186.154-stix2-2.0-export.json",
        "https://2001.habyc.com/?channelNo=2001#/home",
        "https://9755w.com:2188/m/js/2203141811-chunk-vendors.js",
        "https://9755w.com:2188/m/css/fhcpLogin.css?v=2203141811",
        "layout.min.js.pobrane",
        "xfe-URL-sys95.com-stix2-2.1-export.json",
        "https://github.com/vuejs/vue-devtools",
        "map.js.pobrane",
        "https://analytics.tiktok.com/i18n/pixel/events.js?sdkid=C3I4VUA8DUF9JOO44QC0&lib=ttq",
        "https://insurancerateusa.com/app-74647f151b541f3098c2.js",
        "https://cdn-scripts.signifyd.com/api/script-tag.js",
        "https://cdn.staticfile.org/qrcodejs/1.0.0/qrcode.min.js",
        "https://www.heficed.com/wp/wp-includes/js/jquery/jquery.min.js",
        "jquery.djmobilemenu.js.pobrane",
        "stickybar.js.pobrane",
        "https://www.heficed.com/app/cache/min/1/app/plugins/contact-form-7/includes/js/index.js?ver=1647518891",
        "magnific.css",
        "https://www.sunnetwork.com.sg/sun_21/js/vendor/jquery-3.5.0.min.js",
        "xfe-IP-154.36.230.14-stix2-2.0-export.json",
        "https://www.sunnetwork.com.sg/sun_21/js/bootstrap.min.js",
        "https://9755w.com:2188/m/js/2203141811-view-page.js",
        "jquery.easing.min.js.pobrane"
      ],
      "related": {
        "alienvault": {
          "adversary": [],
          "malware_families": [],
          "industries": [],
          "unique_indicators": 0
        },
        "other": {
          "adversary": [],
          "malware_families": [
            "Gc",
            "Lj",
            "Reduceright"
          ],
          "industries": [],
          "unique_indicators": 55985
        }
      }
    },
    "false_positive": [],
    "alexa": "http://www.alexa.com/siteinfo/this.info",
    "whois": "http://whois.domaintools.com/this.info",
    "domain": "this.info",
    "hostname": "www.g.this.info"
  },
  "geo": {},
  "geo_ipapicom": {},
  "pulse_count": 15,
  "pulses": [
    {
      "id": "698904c316bc7710b967d01d",
      "name": "Rare Tier 1 Persistence - Critical \"Patched\", Non Patched Vulnerabilities Remain bypassing Lockdown Mode",
      "description": "Researcher Note (Feb 08, 2026):\nThis artifact represents a sophisticated Cross-Protocol Mesh. Observations confirm that the Cymt/Nemucod wrapper is being utilized as a delivery vehicle for a Firmware-resident ELF binary (Mirai variant).\nThe persistence is notable for its ability to survive Full DFU Restores and Faraday-isolated states, likely due to JTAG-level interaction with the Power Management IC (Chip 4799). This is not a standard opportunistic infection; it is a targeted provisioning event leveraging IDMSA (Identity Management) bridges and Verizon/Akamai Edge infrastructure.\nThe integration with CalendarKit and Maps for geofenced execution suggests a highly coordinated surveillance objective. Forensic analysts should pay specific attention to the sizeofrawdata_antidbg anomalies, which indicate a focus on bypassing Apple Lockdown Mode and Secure Enclave. \nresearcher credit: msudoSOS",
      "modified": "2026-03-27T09:05:26.285000",
      "created": "2026-02-08T21:48:49.147000",
      "tags": [
        "#supportsitewebsiteabuse #rootcertificatefailure #cryptographicf"
      ],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "msudosos",
        "id": "381696",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 909,
        "URL": 1779,
        "CVE": 126,
        "domain": 659,
        "email": 23,
        "JA3": 1,
        "FileHash-MD5": 230,
        "FileHash-SHA1": 227,
        "FileHash-SHA256": 934,
        "CIDR": 13
      },
      "indicator_count": 4901,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 54,
      "modified_text": "24 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "684c65464466dd19b089f325",
      "name": "Zesp\u00f3\u0142 Profilaktyki i Rehabilitacji w Janowicach Wielkich - YouTube",
      "description": "If d=void 0===c,w(\"trustedResourceUrl\",d: \"Trusted resourceUrl,\" thend=c.src,d, c.js, then d:",
      "modified": "2025-06-13T17:56:28.689000",
      "created": "2025-06-13T17:52:06.399000",
      "tags": [
        "rehabilitacji w",
        "youtube tv",
        "dami jelenia",
        "tv dami",
        "jelenia gra",
        "zakupy wycz",
        "jeli",
        "nie korzystasz",
        "filmy",
        "aby tego",
        "copyright",
        "closure library",
        "argument",
        "ifunction",
        "error",
        "null",
        "type",
        "cast",
        "webchannel",
        "su2028u2029",
        "chrome",
        "xmlhttp",
        "kkvoid",
        "remotecontrol",
        "android",
        "unknown",
        "screen",
        "desktop",
        "function",
        "string",
        "array",
        "number",
        "vfunction",
        "f8192",
        "n432",
        "true",
        "j2048",
        "this",
        "window",
        "void",
        "date",
        "pokau017c",
        "pytfunction",
        "fe8function",
        "qgzfunction",
        "afunction",
        "hb28",
        "r150",
        "promise",
        "bigint",
        "post",
        "edge",
        "swhealthlog",
        "symbol",
        "trident",
        "infinity",
        "embed",
        "webkitkeyframes",
        "zoomin",
        "zoominx",
        "zoomoutx",
        "zoominy",
        "zoomouty",
        "2000px",
        "90deg",
        "20px",
        "30deg",
        "30px",
        "10px",
        "10deg",
        "3deg",
        "5deg",
        "djmegamenu",
        "use license",
        "tabindex",
        "menu",
        "close",
        "msie",
        "beforechange",
        "imagehassize",
        "buildcontrols",
        "magnific popup",
        "dmitry semenov",
        "http",
        "beforeclose",
        "afterclose",
        "open",
        "next",
        "open source",
        "bsd license",
        "george mcginley",
        "smith",
        "djimageslider",
        "subpackage",
        "webkit",
        "khtml",
        "icab",
        "countto",
        "callback",
        "handler",
        "object",
        "typeof",
        "method",
        "gnugplv2",
        "website",
        "set module",
        "height script",
        "regexp",
        "screenheight",
        "highcontrast2",
        "highcontrast3",
        "highcontrast",
        "wide",
        "night",
        "body",
        "normalbutton",
        "cookie plugin",
        "https",
        "klaus hartl",
        "mit license",
        "register",
        "nodecommonjs",
        "factory",
        "jquery",
        "write",
        "sticky bar",
        "stickybar",
        "count",
        "offcanvas",
        "html",
        "noscroll",
        "offcanvas var",
        "toggle nav",
        "click jquery",
        "ajax",
        "autocomplete",
        "tomas kirda",
        "typeof define",
        "esc27",
        "tab9",
        "return13",
        "left37",
        "up38",
        "twitter",
        "custom version",
        "joomla",
        "rolemenu",
        "boolean",
        "get adobe",
        "flash player",
        "title",
        "text",
        "typeof data",
        "typeof s",
        "accept",
        "width",
        "foundation",
        "backspace8",
        "comma188",
        "delete46",
        "down40",
        "end35",
        "enter13",
        "escape27",
        "value",
        "migrate",
        "backcompat",
        "quirks mode",
        "typeof f",
        "xtablet768",
        "document",
        "ui sortable",
        "leftright",
        "gnu general",
        "public license",
        "dddddd",
        "ffffcc",
        "eeeeee",
        "verdana",
        "geneva",
        "arial",
        "helvetica",
        "f0f0f0",
        "sans",
        "charset",
        "utf8",
        "fontawesome",
        "typeof b",
        "pseudo",
        "child",
        "sufeffxa0",
        "class",
        "attr",
        "general slider",
        "slide",
        "rgba",
        "navigation",
        "15deg",
        "300px",
        "20deg",
        "transition",
        "scale",
        "baskerville",
        "main image",
        "bdbdbd",
        "f3f3f3",
        "remove",
        "fontface",
        "woff2",
        "u0131",
        "u01520153",
        "u02bb02bc",
        "u02c6",
        "u02da",
        "u02dc",
        "u0304",
        "dirrtl",
        "msviewport",
        "href",
        "span",
        "legend",
        "halflings",
        "fieldset",
        "typeimage",
        "f2f2f2",
        "d9edf7",
        "dff0d8",
        "f2dede",
        "thead",
        "tbody",
        "tahoma",
        "00a0",
        "video",
        "script",
        "2500",
        "xnew ita",
        "dnew jta",
        "dataset",
        "orfunction",
        "prfunction",
        "nsafunction",
        "xsafunction",
        "vrfunction",
        "cakes",
        "ovbfunction",
        "pvbfunction",
        "rvbfunction",
        "qvbfunction",
        "tvbfunction",
        "uvbfunction",
        "vvbclass",
        "xvbclass",
        "yvbclass",
        "svbclass",
        "lvafunction",
        "ggfunction",
        "mvafunction",
        "ovafunction",
        "pvafunction",
        "uvafunction",
        "tvafunction",
        "qvafunction",
        "vvafunction",
        "nvaclass",
        "dark",
        "vector",
        "yy49",
        "raster",
        "roboto",
        "new tk",
        "qael",
        "przechyl",
        "mars",
        "mercury",
        "venus",
        "pluto",
        "titan",
        "weakset",
        "wfclass",
        "googlelayer",
        "uint8array",
        "weakmap",
        "5001",
        "mouseevent",
        "webassembly",
        "180180",
        "9090",
        "google maps",
        "javascript api",
        "internal",
        "small",
        "lightrail",
        "false",
        "february",
        "light",
        "hybrid",
        "bounce",
        "drop",
        "inside",
        "outside",
        "marker",
        "gc"
      ],
      "references": [
        "embed.html",
        "ad_status.js.pobrane",
        "f5Y41t9wqY4.html",
        "cast_sender.js.pobrane",
        "remote.js.pobrane",
        "sw3VTUzeRvWIVwvWSyk6S5gHWPxOOwU1OxerozmN4Hw.js.pobrane",
        "embed.js.pobrane",
        "www-embed-player.js.pobrane",
        "animate.ext.css",
        "animate.min.css",
        "jquery.djmegamenu.js.pobrane",
        "jquery.djmobilemenu.js.pobrane",
        "magnific.js.pobrane",
        "jquery.easing.min.js.pobrane",
        "slider.js.pobrane",
        "jquery.countTo.js.pobrane",
        "scripts.js.pobrane",
        "magnific-init.js.pobrane",
        "pagesettings.js.pobrane",
        "jquery.cookie.js.pobrane",
        "stickybar.js.pobrane",
        "fontswitcher.js.pobrane",
        "offcanvas.js.pobrane",
        "jquery.autocomplete.min.js.pobrane",
        "bootstrap.min.js.pobrane",
        "jcemediabox.js.pobrane",
        "jquery.ui.core.min.js.pobrane",
        "jquery-migrate.min.js.pobrane",
        "layout.min.js.pobrane",
        "jquery.ui.sortable.min.js.pobrane",
        "caption.js.pobrane",
        "finder.css",
        "jquery-noconflict.js.pobrane",
        "djmegamenu.26.css",
        "animations.css",
        "djmobilemenu.css",
        "jquery.min.js.pobrane",
        "djimageslider.css",
        "offcanvas.css",
        "magnific.css",
        "font_switcher.26.css",
        "css",
        "template_responsive.26.css",
        "offcanvas.26.css",
        "bootstrap_responsive.26.css",
        "extended_layouts.26.css",
        "style.css",
        "content.css",
        "template.26.css",
        "bootstrap.26.css",
        "jcemediabox.css",
        "js",
        "onion.js.pobrane",
        "search_impl.js.pobrane",
        "overlay.js.pobrane",
        "map.js.pobrane",
        "util.js.pobrane",
        "search.js.pobrane",
        "common.js.pobrane",
        "geometry.js.pobrane",
        "main.js.pobrane"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Gc",
          "display_name": "Gc",
          "target": null
        }
      ],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 26,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "Arek-BTC",
        "id": "212764",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_212764/resized/80/avatar_3b9c358f36.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 2779,
        "hostname": 661,
        "domain": 684,
        "email": 4,
        "FileHash-MD5": 1,
        "FileHash-SHA256": 689
      },
      "indicator_count": 4818,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 122,
      "modified_text": "310 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "65708ea5a3214f63e1d6d94f",
      "name": "lumen.me Honeybadger",
      "description": "",
      "modified": "2023-12-06T15:09:25.749000",
      "created": "2023-12-06T15:09:25.749000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 3,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 475,
        "hostname": 315,
        "domain": 233,
        "URL": 1133
      },
      "indicator_count": 2156,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "866 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "65708c8a9635f156e79238f1",
      "name": "intel gained from a spam text",
      "description": "",
      "modified": "2023-12-06T15:00:26.727000",
      "created": "2023-12-06T15:00:26.727000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "CVE": 1,
        "FileHash-SHA256": 823,
        "domain": 717,
        "URL": 2245,
        "hostname": 615,
        "email": 4,
        "FileHash-MD5": 5,
        "FileHash-SHA1": 1
      },
      "indicator_count": 4411,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 110,
      "modified_text": "866 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "65708c37c54dd9e78f85c0fa",
      "name": "\u7ea2\u674f\u89c6\u9891 malware",
      "description": "",
      "modified": "2023-12-06T14:59:03.859000",
      "created": "2023-12-06T14:59:03.859000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 4,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 1686,
        "hostname": 2218,
        "URL": 5740,
        "domain": 901,
        "FileHash-MD5": 3
      },
      "indicator_count": 10548,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "866 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "65708bbc4c8bf557c17688e1",
      "name": "\u9ad8\u5c71tv,\u9ad8\u5c71tv,\u9ad8\u5c71tv\u5f71\u9662,\u9ad8\u5c71tv\u770b\u7247\u7f51",
      "description": "",
      "modified": "2023-12-06T14:57:00.280000",
      "created": "2023-12-06T14:57:00.280000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "CVE": 1,
        "FileHash-SHA256": 233,
        "domain": 361,
        "hostname": 563,
        "URL": 1374,
        "FileHash-SHA1": 1,
        "FileHash-MD5": 1
      },
      "indicator_count": 2534,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "866 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "65707e5b7df6f60133e8fb50",
      "name": "Jeeng / Powerbox",
      "description": "",
      "modified": "2023-12-06T13:59:55.129000",
      "created": "2023-12-06T13:59:55.129000",
      "tags": [],
      "references": [],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "green",
      "cloned_from": null,
      "export_count": 2,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "api",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "StreamMiningEx",
        "id": "262917",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "CVE": 3,
        "FileHash-SHA256": 9072,
        "domain": 2500,
        "hostname": 3584,
        "URL": 13548,
        "FileHash-MD5": 197,
        "FileHash-SHA1": 162,
        "email": 19,
        "CIDR": 20,
        "SSLCertFingerprint": 2,
        "BitcoinAddress": 1
      },
      "indicator_count": 29108,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 109,
      "modified_text": "866 days ago ",
      "is_modified": false,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "628af7e3df399fbe9095245f",
      "name": "lumen.me Honeybadger",
      "description": "window.ju_sha256, a new type of code, is written by the same characters:var l,b,c,g,p,a,h,d, c.",
      "modified": "2022-06-21T00:01:09.886000",
      "created": "2022-05-23T02:56:35.154000",
      "tags": [
        "reduceright",
        "lj",
        "number",
        "query",
        "string",
        "trackevent",
        "date",
        "u003e div",
        "simulator",
        "error",
        "regexp",
        "pageview",
        "path",
        "void",
        "code",
        "l420",
        "g5vs2ll0p80",
        "copyright",
        "json",
        "uint8array",
        "ssnull",
        "script",
        "closure library",
        "xdfunction",
        "adfunction",
        "typeof t",
        "typeof symbol",
        "typeof",
        "window",
        "value",
        "function",
        "customevent",
        "image",
        "null",
        "sbfu",
        "typeof n",
        "object",
        "array",
        "control",
        "other",
        "android",
        "x3e div",
        "gtmnwh4dh2",
        "host",
        "page title",
        "page path",
        "typeerror",
        "promise",
        "typeof e",
        "typeof window",
        "aggregateerror",
        "math",
        "target",
        "rangeerror",
        "buffer",
        "index",
        "attempt",
        "argument",
        "google",
        "link",
        "ad tech",
        "providers",
        "ffffff",
        "ip address",
        "combine",
        "accept",
        "save",
        "explorer",
        "cookie",
        "back",
        "iframe",
        "blank",
        "position",
        "juorderid",
        "justuno",
        "body",
        "juorigtop",
        "event",
        "follow",
        "post",
        "config",
        "click",
        "local",
        "fast",
        "comp",
        "form",
        "unknown",
        "push",
        "trcimpl",
        "trcwarn"
      ],
      "references": [
        "https://cdn.taboola.com/scripts/cds-pips.js",
        "https://www.iubenda.com/cookie-solution/confs/js/53119375.js",
        "https://cdn.jst.ai/mwgt_4.1.js?v=5.28",
        "https://cdn.iubenda.com/cookie_solution/iubenda_cs/1.38.0/core-en.js",
        "https://s.pinimg.com/ct/lib/main.32155010.js",
        "https://analytics.tiktok.com/i18n/pixel/config.js?sdkid=C3I4VUA8DUF9JOO44QC0&hostname=lumen.me",
        "https://js.pvd.to/c/v1/pixel-1sdz.js?t=1653350400000",
        "https://cdn.jst.ai/vck.js",
        "https://www.googletagmanager.com/gtm.js?id=GTM-NWH4DH2",
        "https://analytics.tiktok.com/i18n/pixel/events.js?sdkid=C3I4VUA8DUF9JOO44QC0&lib=ttq",
        "https://cdn.taboola.com/libtrc/unip/1262365/tfa.js",
        "https://s.pinimg.com/ct/core.js",
        "https://www.googleoptimize.com/optimize.js?id=OPT-TQC6JW4",
        "https://www.googletagmanager.com/gtag/js?id=G-5VS2LL0P80&l=dataLayer&cx=c",
        "https://www.googletagmanager.com/gtm.js?id=GTM-PF3JNK2&gtm_auth=a6AgvzJ0SAOcyjADNwrdlQ&gtm_preview=env-1&gtm_cookies_win=x"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "Lj",
          "display_name": "Lj",
          "target": null
        },
        {
          "id": "ReduceRight",
          "display_name": "ReduceRight",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 10,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "adjadex1@gmail.com",
        "id": "187163",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "URL": 1134,
        "hostname": 315,
        "domain": 233,
        "FileHash-SHA256": 475
      },
      "indicator_count": 2157,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 67,
      "modified_text": "1399 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "620c3b1f8af7ea0dcf2c1218",
      "name": "Jeeng / Powerbox",
      "description": "",
      "modified": "2022-06-12T22:01:23.105000",
      "created": "2022-02-15T23:45:35.234000",
      "tags": [
        "Jeeng",
        "tim pool",
        "timcast"
      ],
      "references": [
        "cf20ed53-cb6d-4dfd-a4e8-794fbe163efc.pcap"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [
        "United States of America"
      ],
      "malware_families": [],
      "attack_ids": [],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 10,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "scnrscnr",
        "id": "126475",
        "avatar_url": "/otxapi/users/avatar_image/media/avatars/user_126475/resized/80/avatar_67ca5b7bae.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "FileHash-SHA256": 9072,
        "domain": 2500,
        "URL": 13548,
        "hostname": 3584,
        "FileHash-MD5": 197,
        "FileHash-SHA1": 162,
        "CVE": 3,
        "CIDR": 20,
        "SSLCertFingerprint": 2,
        "email": 19,
        "BitcoinAddress": 1
      },
      "indicator_count": 29108,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 97,
      "modified_text": "1407 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    },
    {
      "id": "6266f7e0e0264cba210a4e9e",
      "name": "intel gained from a spam text",
      "description": "var b[f]=g, if b(f) is not allowed to reach its maximum by the end of a set, then a.b(b) will be able to do so at the same time as a",
      "modified": "2022-05-25T00:04:03.622000",
      "created": "2022-04-25T19:34:56.772000",
      "tags": [
        "array",
        "typeerror",
        "symbol",
        "null",
        "string",
        "iterator",
        "object",
        "error",
        "boolean",
        "function",
        "service",
        "date",
        "phonenumber",
        "facebook",
        "meta",
        "typeof e",
        "typeof u",
        "typeof window",
        "es modules",
        "use esm",
        "webkit",
        "component",
        "typeof",
        "typeof y",
        "typeof symbol",
        "suspense",
        "context",
        "forwardref",
        "unknown",
        "4096",
        "typeof n",
        "promise",
        "weakmap",
        "dataview",
        "typeof t",
        "webpackrequire",
        "modulenotfound",
        "e1342177279",
        "array int8array",
        "loanup",
        "insurance",
        "group",
        "health",
        "solutions",
        "policy",
        "site",
        "america",
        "company",
        "life",
        "plan",
        "direct",
        "media",
        "alliance",
        "click",
        "team",
        "never",
        "advantage",
        "general",
        "light",
        "february",
        "april",
        "june",
        "august",
        "footer",
        "protect",
        "banker",
        "explorer",
        "fast",
        "martin",
        "union",
        "carrier",
        "next",
        "colony",
        "energy",
        "empire",
        "gerber",
        "philadelphia",
        "hippo",
        "king",
        "agent",
        "mercury",
        "moss",
        "premium",
        "nextgen",
        "oscar",
        "phoenix",
        "loans",
        "pure",
        "ramsey",
        "ranger",
        "solar",
        "titan",
        "tristate",
        "viking",
        "easy",
        "push",
        "code",
        "stop",
        "carriers",
        "live",
        "lucky",
        "moral",
        "story",
        "back",
        "lfunction",
        "dfunction",
        "cfunction",
        "typeof self",
        "number",
        "copyright",
        "closure library",
        "xdfunction",
        "cdfunction",
        "ddfunction",
        "bded",
        "kefunction",
        "reduceright",
        "gj9pcw0f6jv",
        "regexp",
        "r420",
        "uint8array",
        "typeof d",
        "void"
      ],
      "references": [
        "https://www.googletagmanager.com/gtag/js?id=G-J9PCW0F6JV",
        "https://www.googletagmanager.com/gtag/js?id=UA-185991747-1",
        "https://insurancerateusa.com/polyfill-036b4a134d8725752ba0.js",
        "xfe-URL-insurancerateusa.com-stix2-2.1-export.json",
        "https://insurancerateusa.com/app-74647f151b541f3098c2.js",
        "https://insurancerateusa.com/bfcc7b67-0b189ba6da3fc3ae8b88.js",
        "https://insurancerateusa.com/94297995-69529ad7536f090aa776.js",
        "https://insurancerateusa.com/3bea8d40-8926f4790c0b3689a361.js",
        "https://insurancerateusa.com/framework-19eddc0d879a49dfe606.js",
        "https://insurancerateusa.com/webpack-runtime-f014a3267add02a94afb.js",
        "https://connect.facebook.net/signals/config/3689470801106673?v=2.9.57&r=stable"
      ],
      "public": 1,
      "adversary": "",
      "targeted_countries": [],
      "malware_families": [
        {
          "id": "ReduceRight",
          "display_name": "ReduceRight",
          "target": null
        }
      ],
      "attack_ids": [
        {
          "id": "T1059",
          "name": "Command and Scripting Interpreter",
          "display_name": "T1059 - Command and Scripting Interpreter"
        }
      ],
      "industries": [],
      "TLP": "white",
      "cloned_from": null,
      "export_count": 10,
      "upvotes_count": 0,
      "downvotes_count": 0,
      "votes_count": 0,
      "locked": false,
      "pulse_source": "web",
      "validator_count": 0,
      "comment_count": 0,
      "follower_count": 0,
      "vote": 0,
      "author": {
        "username": "adjadex1@gmail.com",
        "id": "187163",
        "avatar_url": "https://otx.alienvault.com/assets/images/default-avatar.png",
        "is_subscribed": false,
        "is_following": false
      },
      "indicator_type_counts": {
        "hostname": 615,
        "URL": 2246,
        "FileHash-SHA256": 823,
        "domain": 717,
        "CVE": 1,
        "email": 4,
        "FileHash-MD5": 5,
        "FileHash-SHA1": 1
      },
      "indicator_count": 4412,
      "is_author": false,
      "is_subscribing": null,
      "subscriber_count": 70,
      "modified_text": "1426 days ago ",
      "is_modified": true,
      "groups": [],
      "in_group": false,
      "threat_hunter_scannable": true,
      "threat_hunter_has_agents": 1,
      "related_indicator_type": "URL",
      "related_indicator_is_active": 1
    }
  ],
  "error": null,
  "vt": {
    "error": "VirusTotal rate limit reached. Try again shortly.",
    "indicator": "https://www.g.this.info",
    "type": "URL"
  },
  "abuseipdb": null,
  "urlhaus": {
    "indicator": "https://www.g.this.info",
    "type": "URL",
    "found": false,
    "verdict": "clean",
    "error": null
  },
  "from_cache": true,
  "_cached_at": 1776703133.3240492
}